Privacy and market transparency
Private positions, a public order book and selective disclosure for Canton collateral and settlement.
Private positions, public liquidity
Edel Markets keeps your positions private to your account while making order-book liquidity public. Other traders can see the market’s bids, asks and executed trades; the public feeds do not give them access to your open positions or account risk details.
Our privacy model extends to the Canton layer. Collateral and settlement workflows use Canton’s native selective disclosure, so entitled participants receive the transaction information relevant to their role without broadcasting the full transaction across the network.
What is visible, and to whom
Orders resting on the order book contribute to public liquidity. The book publishes aggregated bid and ask sizes at each price level, rather than an account’s individual order list. A displayed order-book size is not a trader’s position size.
Executed trades publish market, price, size and taker side. The trade feed also includes trade and maker/taker order identifiers, but does not include an account identifier. Public market activity can still be analysed; private account access is not a promise that trading patterns cannot be inferred.
| Information | Visibility | What this means |
|---|---|---|
| Order-book prices and sizes | Public | Aggregated bids and asks show available liquidity, without publishing an account’s order list. |
| Executed trades | Public | Price, size, taker side and trade/order identifiers are published; account identifiers are not included in the trade feed. |
| Your position size, direction and entry price | Private account data | Available through authorized account access and to Edel as venue operator; not published in the public market feeds. |
| Your margin, PnL and liquidation estimates | Private account data | Account-specific risk values require authorization. Public mark prices, market margin parameters and funding rates are separate market information. |
| Leaderboard statistics | Public and pseudonymous | Realized PnL, fees, funding, closed notional and fill count appear under a public handle. The leaderboard does not publish open position size or account liquidation prices. |
| Canton transaction details | Selective disclosure | Relevant transaction views are shared according to contract roles and permissions, including the participants and services needed to process them. |
Account access stays under your control
Your positions endpoint requires an authorized bearer token, and private account streams require a scoped realtime ticket. Sessions and delegated keys can access only the account data and actions their permissions allow. Edel can access account positions to operate matching, risk and settlement.
Keep API keys, passkeys, session credentials and custody signing material confidential. A public leaderboard handle does not grant access to the underlying account, and pseudonymous reporting does not guarantee anonymity. See authentication, API key permissions and account streams.
Where Canton’s native privacy adds value
Private account views and a public order book are complementary parts of a trading venue. Edel’s use of Canton adds selective disclosure at the collateral and settlement layer: transaction participants can verify the information they are entitled to receive without every network participant receiving the full business transaction.
Contract roles and permissions determine the relevant views. Signatories, observers, counterparties and the validator services supporting them may receive information needed for their role. Visibility follows the transaction and application configuration; it is not limited to the end user alone.
This is how we use Canton’s native privacy alongside off-chain execution. Account authorization protects the product’s private views; Canton governs disclosure of ledger transactions. See settlement and the Canton privacy model.
How selective Canton views work
Consider a transaction with two connected parts. Parties A and B are involved in the first, and B and C in the second. A receives its part, C receives its part and B receives both. An unrelated party D receives neither simply by participating in the network. The application’s roles and permissions determine the actual disclosure.
Validator services process the views needed by the parties they host. The synchronizer coordinates encrypted messages without receiving their decrypted business payloads. Authorized transaction participants still receive the information necessary for their role.
| Illustrative participant | Visible transaction view |
|---|---|
| A — stakeholder in part 1 | Part 1 |
| B — stakeholder in both parts | Parts 1 and 2 |
| C — stakeholder in part 2 | Part 2 |
| D — no relevant role | Neither part from network participation alone |
| Synchronizer | Encrypted payloads and coordination information, not decrypted business views |