Parcel
15:00#----Open
Transparency

The NAV Prover

A custody product proves it holds the asset behind the number. Every figure here reconciles to Robinhood Chain: what each Lot holds, which oracle priced it and how old that price is, the sum equalling published NAV, and the orders netting in the open epoch. Click any row through to the chain and check it yourself.

No oracle prices yet
Open epoch

Orders netting now

Creations and redemptions net against each other every 15 minutes; only the difference reaches the market, and the whole batch settles at one price or rolls to the next epoch.

Regular session#----Open epoch

Orders net against each other, then settle whole.

Creations · inflow

USDG filing in to mint Parcels at settlement.

No orders queued
To market

Awaiting the netting engine

Redemptions · outflow

Parcels burning back to USDG at settlement.

No orders queued

Execution band 50 bps. If the epoch VWAP would breach the tolerance against oracle NAV, the batch is cancelled and every order rolls to the next epoch rather than filling off-mark.

Fill priorityCross · BlockRound LotOdd Lot

The board is at rest. Filed creations and redemptions appear here as tickets the moment the netting engine is live; the figure above previews the current epoch’s net flow.


NAV ledger

What each Lot holds, reconciled

One reconciled ledger per Lot: every constituent held in custody, the applied price and its age, actual weight against target, and the value. The footing rule proves the custody sum equals the published NAV.


Oracle

Price freshness

A price older than 15 minutes pauses that constituent's swap; a feed stale enough closes USDG primary while in-kind redemption stays open. This is the graded degradation the ledger colours above trace back to.

Oracles

Price freshness

Every constituent price, its source and how old it is. When a feed passes its age limit the vaults that depend on it are marked halted and mints are refused rather than priced on a guess.


Custody

Who can move the assets, and the way out

V1 runs on a multisig custody signer behind a 48-hour timelock. In-kind redemption is always live; the escape hatch is the last-resort exit if governance ever goes dark.

Custody model

Multisig behind a timelock

Custody open
Signer

A multisig, not a single key. No one wallet can move custody alone.

Timelock

Custody-level changes queue behind a 48-hour delay, giving holders time to exit in-kind before any change takes effect.

Accounting

Balances are read directly from the Custody Lot and priced with the same oracle the NAV engine uses.

Escape hatch

The last-resort exit

In-kind redemption live

You can always burn Parcels and take each constituent straight from custody — no oracle, no DEX, no permission. The escape hatch is the stronger guarantee: if the protocol is abandoned or frozen, holders can force an orderly wind-down. It arms under any of these conditions.

Custody paused beyond 7 days

If deposits, redemptions and rebalances stay paused for more than a week, the hatch can be armed.

No custody transaction in 30 days

A month of silence from the custody signer is treated as an abandoned protocol.

Wind-down vote passes

Holders can vote to arm the hatch directly, independent of the two timers above.

Current state: not armed. The conditions above have not been met.

Contracts

The verified surface

Every contract that runs the protocol on Robinhood Chain, straight from the deployment manifest. Read the source on Blockscout before you trust any of it.

Contracts

Deployed addresses

The full protocol surface on Robinhood Chain, straight from the deployment manifest. Read the source on Blockscout before you trust any of it.


Risks

Stated plainly

The standing disclosures for the protocol. Shown in full whether or not the API is reachable.

R-01Critical

Custody contract

The Custody Vault stores real value: a bug in its logic loses deposited assets — it doesn't just distort a chart, as in a purely analytical product.

R-02Critical

Multisig in V1

Multisig custody in V1 adds trust in the operators on top of smart-contract risk.

R-03Risk

Oracle failure

An oracle that goes stale or feeds wrong data moves NAV in the wrong direction and opens an arbitrage window against the holders.

R-04Risk

Basis risk

Tokenized equities trade with basis risk to the stock price on the traditional exchange: the gap widens in periods of thin liquidity, or when the exchange is closed while the token keeps trading.

R-05Risk

Epoch timing

Primary creations and redemptions are batched and priced at settlement, not at the moment you file them: your fill is set by the epoch's execution, not the quote you saw. If the epoch's VWAP would breach the tolerance band against oracle NAV, the epoch is cancelled and your order rolls to the next window rather than executing at a bad price.

R-06Risk

Backstop cap

The Backstop Module is first-loss capital: stakers absorb shortfalls before Lot holders, but only up to a 30% slash cap per event. A loss larger than the backstop can cover is borne by Lot holders — the module reduces the blast radius, it does not remove it.

R-07Risk

USDG execution

Redeeming to USDG sells each constituent on-chain in the next epoch, so it carries DEX slippage and a flow-impact fee, and it pauses when the oracle feed degrades. In-kind redemption — burning Parcels for the underlying constituents straight from custody — needs no oracle or DEX and stays available even when the USDG path is closed.