Legal recognition
No new regulatory framework is required.
The architecture is only useful if the record it produces is the record the law recognizes. It is. The perimeter already exists, the obligations already attach, and the entity carrying them is the entity operating the register.
The mappings on this page are general guidance and not legal advice. Issuers should confirm the application to their own jurisdiction and corporate structure with counsel.
The mapping
What each statute establishes
Where the regulator stands
The position has moved in three steps
“Would not need to maintain a duplicate or ‘digital twin’ of its master securityholder file exclusively off-chain.”
SEC staff, Division of Trading and Markets, FAQ Question 11, 15 May 2025 · sec.gov
“The format in which a security is issued or the methods by which holders are recorded (e.g., onchain vs. offchain) does not affect application of the federal securities laws.”
SEC staff, Statement on Tokenized Securities, 28 January 2026 · sec.gov
Equity remains equity; the substrate changes and the obligations do not. In the staff’s taxonomy this is an issuer-sponsored model, with a registered transfer agent acting as the issuer’s agent in maintaining the master securityholder file onchain. The same term has been applied by other parties to architectures that differ materially from the one specified here.
Supervision
Examination gets better, not worse
A reasonable objection to privacy-native networks is that they impede supervision. The opposite is true, and the same primitive that enforces stakeholder confidentiality is what enables it.
Observer parties
A party with read-only visibility into a contract, including all subsequent updates, but no ability to exercise any choice against it. Observer status is a platform primitive, not an application-level workaround.
SEC examiners under § 17A authority, FINRA, state securities regulators, and — where engaged by the issuer or the transfer agent — external auditors and counsel can be added as Observers. The grant can be scoped to the entire register, a single issuer’s cap table, or a defined subset, and supports both continuous subscription and on-demand inspection.
What it replaces
Inspecting a transfer agent today means the agent produces records on request, with the latency, completeness risk and scope negotiation that produce-on-demand recordkeeping entails.
Observer access replaces that with standing, complete, real-time visibility into exactly what an authority is entitled to see — and the authority verifies the records itself rather than receiving the agent’s account of them.
Corrections, and why nothing is silently changed
OCP corrects by compensating event, never by silent overwrite. The erroneous transaction remains permanently on the register and a subsequent typed OCF transaction records the correction, carrying an explicit reference to the transaction it corrects, a reason code, and — in the transfer agent’s own books — the authorizing documentation: the issuer instruction, the board resolution where one is required, the internal control record.
An examiner reviewing the register at any point sees both the original entry and the corrective sequence, with full attribution and timing. The audit trail is enriched rather than edited. The pattern matches transfer-agent examination practice and how established settlement systems handle reversals, and it satisfies Rule 17Ad-7 cleanly.
Retention and the right to erasure
The register is append-only by default; permanence is what makes the record examinable and disputable rather than merely asserted. Where privacy law grants a right to erasure — GDPR Article 17 and analogous provisions — the reconciliation with retention is a per-jurisdiction analysis performed by the operator, whose accountability for the records is the safeguard against improper deletion. Because identifying data is held off the ledger by default, most erasure requests are satisfied at the offchain layer without the ledger being touched at all.
For identifying fields that are onchain, the position should be stated carefully. Canton provides contract archival and pruning. Whether either constitutes erasure within the meaning of Article 17 is not settled, and the specification does not assert that it does. What the architecture provides is that the question arises rarely, and that where it arises the operator has both the technical means and the statutory accountability to make the call. Permissionless public chains offer neither.
Scope
Beyond Delaware, and beyond corporations
Other US states
Most jurisdictions accommodate the same treatment through their own books-and-records provisions, most of which contain § 224 analogues or have been amended in the same direction.
Foreign jurisdictions
Cayman companies and segregated portfolio companies, BVI business companies, and companies under the UK Companies Act 2006 accommodate it through general books-and-records provisions, paired where required with explicit designation in the entity’s constitutional documents. The protocol does not require US incorporation.
Non-corporate forms
LLCs, partnerships and pooled vehicles hold interests rather than shares, governed by the operating or partnership agreement rather than a corporate code. The protocol layer does not change; the statutory hooks differ and the vocabulary of the objects has to follow. Representing them in OCF is live standards work.
What remains unsettled
A claim that the legal position was complete would be easy to disbelieve. Regulation Crypto Assets, proposed 18 August 2026, establishes exempt offering pathways for covered investment contracts, a token-specific disclosure regime and preemption of state blue sky laws. It does not address custody, trading-platform registration, transfer-agent rules, or whether an onchain record may serve as an issuer’s official register — and it proposes no exemption from exchange, broker, dealer or clearing-agency registration for third parties that transact or intermediate.
That is an argument for the approach taken here rather than against it. The architecture does not depend on a framework that does not yet exist. It relies on statutes that already govern the issuer’s register and on a transfer-agent perimeter that has existed since 1975. Where new law arrives, it will find the architecture already inside the perimeter it regulates.