aarnâ
0%
Loading
Technology

Infrastructure for
Regulated Tokenized Assets

Built around a single constraint: every asset on the platform has to be tokenized and satisfy IFSCA regulatory requirements at the same time. No compromise on either.

ERC-3643 permissioned tokensONCHAINID identity claimsMulti-signature NAV attestation
Standards

The standards underneath

Compliance is a property of the instrument here, not a process wrapped around it. Three standards carry that: one for the token, one for the identity that may hold it, one for the price it is carried at.

ERC-3643

Permissioned tokens

All aarna tokenized assets are issued as ERC-3643 permissioned digital tokens. The standard enforces compliance at the token level: transfers execute only between wallets holding valid identity claims. The compliance layer is built into the token contract itself, not bolted on around it.

In practice: an ICT token cannot be transferred to an unverified wallet. Secondary trading, when enabled, respects the same identity and jurisdiction rules as primary issuance. Selected transfer and eligibility controls are programmable and auditable.

What the standard enforces
  • Token-level compliance
  • Identity-gated transfers
  • Programmable eligibility
  • Auditable controls
ONCHAINID

Decentralised identity

Investor identity is managed through ONCHAINID, a decentralised identity standard integrated with ERC-3643. On completing Sumsub KYC, identity claims are issued on-chain - accredited status, jurisdiction, AML clearance - portable across any ERC-3643 asset aarna issues.

Attestation

Independent NAV

ICT's net asset value is certified on a defined cycle, aligned with the reporting cadence of the underlying funds, and published onchain through a multi-signature attestation process, so pricing is transparent and independently verifiable.

Security

Controls of record

The platform has completed internal smart-contract and application security reviews. An independent penetration test and external smart-contract audit are scheduled before launch.

L1Data
AES-256 encryption
Encrypted at rest and in transit, keys held in AWS KMS.
Private by default
Personal data stays masked; every access is time-boxed and logged.
L2Access
Least-privilege access
Scoped roles, with two-person approval on sensitive actions.
Unchangeable audit trail
Every action recorded in tamper-proof, append-only ledgers.
L3Build and infrastructure
Secure by build
Signed releases, automated code and dependency scans, and security testing in the release pipeline.
Hardened infrastructure
TLS everywhere, and no public data stores.
AI at aarnâ

The intelligence layer across aarnâ

aTARS is aarnâ's agentic layer, operating across investor interaction, platform operations and continuous monitoring. Actions stay bounded by defined permissions, controls and auditable workflows.

ATARS

Three functional areas, each with a defined job and an explicit status.

Live

Operational orchestration

Prepares, simulates, validates and reconciles workflows across the token lifecycle, reducing manual coordination while preserving deterministic controls and an auditable trail.

Every prepared transaction is simulated, checked against the guardrails, its invariants verified and its reconciliation confirmed before it is proposed for signing. The same discipline runs over the NAV attestation pipeline.

Live

Intelligent investor interaction

Understands the product, its structure and the investor's own position, answering questions and assembling relevant information and workflows in context.

It answers how ICT works, where a subscription has reached and when the next distribution falls, at the point the investor asks rather than after a ticket has sat overnight. Where something needs a person, it hands over with the full context already assembled.

In development

Continuous monitoring

Continuously observes infrastructure, transaction states and the underlying portfolio between reporting dates, reporting the findings to the team.

Not built yet - credit decisions over the underlying stay with the funds' authorised, SEBI-regulated managers.

Agentic audit

Agentic audit, four passes

Before deploying to mainnet, the ICT contract suite went through four separate review passes, each one taking the system as the previous pass left it.

Multi-agent security scan

A scan ran across the full codebase in parallel, each agent probing a different class of failure.

Smart-contract auditor

A dedicated auditor agent then took the whole system on its own and reviewed it end to end.

Remediation traced to invariants

A third pass traced every remediation at the invariant level, confirming each fix did what it claimed rather than taking the patch at face value.

Internal engineering review

A final internal engineering review closed it out.

4
Independent agentic review passes
Before mainnet
1,408
Automated tests
Unit, fuzz and invariant coverage, alongside static analysis tooling
0
Outstanding Critical or High findings
On the most recent full-system review

Every Critical and High severity finding raised across the programme has been resolved, and the most recent full-system review returned no outstanding Critical or High findings.

Roadmap

Under evaluation

Neither of these is committed. Both depend on institutional demand rather than on a date.

Under evaluation

Deeper DeFi composability

Subject to institutional demand.

Under evaluation

Multi-chain deployment

Extending beyond Ethereum to chains with institutional adoption.