RWA disclosure · read-only · expectations first
The reserve number a machine cannot read
Everyone publishes how much tokenized real world asset value exists. Nobody publishes whether
the issuer of that value serves a number a program can read. An attestation PDF signed by an
accounting firm is a strong disclosure and a useless interface. This survey asks only the
interface question, of the issuers this node already tracks, and names every refusal by the
limb that failed.
Not a measure of disclosure quality · not a market survey and not a ranking · no score, no
badge · every URL came from this engine's own recorded data
Population 17 real world asset issuers and tokenized instruments, every one carrying a
dossier card this node exports
Candidate surfaces 15, all drawn from this engine's own recorded data ·
engine commit 63a8337c5ae0
Expectations digest 28961d5d66629b9a0d370b1331bd7b7b66f7c857d78a47145e29567c7c7aef1a published 2026-08-02 04:28 UTC
Ledger digest e4d5d4e38e707632fcbfe2f23a5a0a58c989eaa19176cde8971fb171b4d369f1 run 2026-08-02 05:43 UTC · probe v1.0.2
How to cite / re-check
Cite
expectations.json (published first) and
summary.json. One issuer at a time:
https://geniusflow-federation.vercel.app/rwa/receipts/<ENTITY>.json
Population is this node's tracked issuers, not a sector sample. For issuer-attributable
figures cite
attributable_to_issuer, not the raw 0 of 17 alone.
0
of 17 issuers
serve a machine readable disclosure they operate themselves
Not a low number. Zero. No issuer in this population publishes a structured reserve or asset figure on an origin it controls.
2
of 15 surfaces
serve structured bytes at all
Both belong to the same third party aggregator. The number is readable, and the issuer is not the one publishing it.
0
of 45 requests
to a conventional disclosure path answered
Nine paths across five issuer operated origins. There is no location an issuer could serve this from even if it wanted to.
11
of 17 issuers
have no surface recorded by this node
That refusal belongs to this node, not to the issuer. The rate below is also given with them excluded.
The distinction this survey exists for
A machine readable number about an issuer is not the same thing as an
issuer publishing a machine readable number. In this population only the
first exists.
This engine's own reserve figures for BUIDL and OUSG are read from DefiLlama, not from
BlackRock, Securitize or Ondo, because no issuer here serves an equivalent. Every consumer
of those figures, this node included, holds a dependency on a third party that the issuer
never agreed to and cannot be held to. When the aggregator renames a field, the issuer's
disclosure has not changed and the consumer still breaks.
The same engine's sensor grounding file records the gap for a fourth issuer in its own
notes: BENJI omitted, no live primary AUM endpoint yet. That was written down before this
survey existed and is quoted here rather than discovered by it.
Where the 17 issuers fail
| First failing limb | Issuers |
| disclosure_surface_declared | 11 |
| machine_readable_media_type | 4 |
| issuer_operated_surface | 1 |
| as_of_date_present | 1 |
Eleven of those refusals are no_disclosure_surface_recorded_by_this_node, which is a fact about this node's coverage rather than about the issuer. Excluding them
entirely, 4 of 6 issuers with a
recorded surface still fail at least one MUST limb, and 0 of 17 clear the full
level.
What the surfaces actually served
| Media type sniffed from the bytes | Surfaces |
| html | 13 |
| json | 2 |
The type charged is the one the bytes support, sniffed from the body. A Content-Type header is
a claim, not evidence. Of 15 recorded surfaces, 9
sit on an origin the issuer operates and 0 of
those serve structured data.
Is there a convention to follow
No. The survey asked 45 times across 5 issuer operated origins, using a path list frozen and published before the run:
/.well-known/rwa-disclosure.json/.well-known/reserves.json/.well-known/attestation.json/.well-known/asset-disclosure.json/.well-known/proof-of-reserves.json/reserves.json/disclosure.json/attestations.json/api/reserves
| HTTP status | Responses |
| 404 | 36 |
| 200 | 9 |
None of these paths is a registered well-known URI and none is specified by any standard,
which is the point. There is no location an RWA issuer could serve a reserve figure from even
if it wanted to, and no field name it could use that a consumer would already know how to
read. The 9 responses that returned 200 served no structured bytes: they are catch-all routes answering every path with the application shell. Reading those as a pass would have turned a routing default into a conformance result.
registry_ref discipline
Of 15 recorded surfaces, 1 name any on-chain or securities identifier at all, and 0 name one that is chain qualified. A disclosure that names a contract without naming its
chain does not identify a deployment: the same twenty bytes can be a different contract on
every EVM network, so a consumer has to guess or ask.
CAIP-10 exists to close exactly this gap.
ISIN and LEI candidates must pass their real check digit, so a twelve character product code cannot be counted as a security identifier. An all-zero address is discarded. Chain qualification requires the chain to sit in the same object as the address, not merely somewhere in the same file. Every identifier reported here was found inside
bytes the surface itself served. This probe supplies none of its own, so there is no address
in this ledger a reader has to take on trust from us.
Limbs
There is no specification to cite for any of this, and pretending otherwise would be the same
error the survey exists to catch. MUST means a consumer cannot read the number without it,
SHOULD means the consumer can read it but cannot rely on it, OBSERVED means the limb records a
fact and charges nothing. not_reached means an earlier limb failed
first, so this one was never observed: it is neither a pass nor an exemption.
| Limb | Level | ok | fail | n/a | not reached |
| disclosure_surface_declared | MUST | 6 | 11 | 0 | 0 |
| surface_resolves | MUST | 6 | 0 | 0 | 11 |
| machine_readable_media_type | MUST | 2 | 4 | 0 | 11 |
| body_parses_as_served_type | MUST | 2 | 0 | 0 | 15 |
| figure_addressable_by_key_path | SHOULD | 2 | 0 | 0 | 15 |
| as_of_date_present | SHOULD | 1 | 1 | 0 | 15 |
| issuer_operated_surface | SHOULD | 0 | 2 | 0 | 15 |
| registry_ref_present | OBSERVED | 1 | 1 | 0 | 15 |
| registry_ref_chain_qualified | OBSERVED | 0 | 1 | 0 | 16 |
| conventional_path_answers | OBSERVED | 0 | 4 | 2 | 11 |
Predictions, scored
These were written into the expectations file and published before the run, at digest 28961d5d66629b9a. They are scored here without editing.
| Prediction | Observed | Result |
| No issuer in this population serves a machine readable disclosure surface on an origin it operates itself. | 0 of 17 issuers had one | met |
| Every machine readable surface in the population belongs to a third party aggregator rather than to the issuer. | 2 machine readable surfaces, of which 0 were issuer operated | met |
| No path in the frozen conventional list answers with structured bytes on any issuer operated origin. | 0 of 45 conventional path requests answered with structured bytes | met |
| No surface in the population carries a chain qualified registry reference. | 0 of 15 recorded surfaces carried one | met |
| More than half of the population has no disclosure surface recorded by this node at all. | 11 of 17 had none | met |
Per issuer
| Entity | Role | Verdict | Refuse reason | Receipt |
| BACKED | issuer | refuse | disclosure_surface_declared:no_disclosure_surface_recorded_by_this_node |
json
|
| BLACKROCK | issuer | refuse | machine_readable_media_type:html_document |
json
|
| CIRCLE | issuer | refuse | machine_readable_media_type:html_document |
json
|
| CIRCLE_RESERVE_FUND | issuer | refuse | disclosure_surface_declared:no_disclosure_surface_recorded_by_this_node |
json
|
| MAPLE | issuer | refuse | disclosure_surface_declared:no_disclosure_surface_recorded_by_this_node |
json
|
| ONDO | issuer | refuse | machine_readable_media_type:html_document |
json
|
| ONDO_YIELD_ASSETS | issuer | refuse | disclosure_surface_declared:no_disclosure_surface_recorded_by_this_node |
json
|
| PAXOS | issuer | refuse | disclosure_surface_declared:no_disclosure_surface_recorded_by_this_node |
json
|
| SECURITIZE | issuer | refuse | disclosure_surface_declared:no_disclosure_surface_recorded_by_this_node |
json
|
| SPIKO | issuer | refuse | disclosure_surface_declared:no_disclosure_surface_recorded_by_this_node |
json
|
| TETHER | issuer | refuse | machine_readable_media_type:html_document |
json
|
| BLACKROCK_BUIDL | instrument | admit | issuer_operated_surface:surface_is_third_party:llama.fi |
json
|
| CIRCLE_USYC | instrument | refuse | disclosure_surface_declared:no_disclosure_surface_recorded_by_this_node |
json
|
| OUSG | instrument | admit | as_of_date_present:no_as_of_date_on_the_surface |
json
|
| PAXOS_GOLD | instrument | refuse | disclosure_surface_declared:no_disclosure_surface_recorded_by_this_node |
json
|
| TETHER_GOLD | instrument | refuse | disclosure_surface_declared:no_disclosure_surface_recorded_by_this_node |
json
|
| USDY | instrument | refuse | disclosure_surface_declared:no_disclosure_surface_recorded_by_this_node |
json
|
Two defects this survey found in itself
The first run exposed faults in the probe rather than in the population. They are recorded
instead of quietly fixed, because a probe that hides its own misses has no standing to
publish anyone else's. The population, the limb order, the admit rules and the predictions
were not touched, so the expectations digest is unchanged and still verifies.
conventional_path_answers was sequenced behind the media type limb. Every issuer operated surface in this population is an HTML document, so the receipt returned before the convention limb was ever observed. The first run made zero conventional path requests and still scored the prediction about them as met, which is a claim on no evidence. The limb asks about the issuer's origin rather than about the surface the other limbs read, so it is now evaluated for every issuer that has an origin at all, independent of what the earlier limbs found. The prediction now scores as missed when no request was made.
a body clipped at this probe's own size cap was charged as a parse error. One aggregator surface is larger than the original 2 MB cap. The probe truncated it, failed to parse its own truncation, and recorded the failure against the surface. That is a refusal this probe manufactured. The cap is raised to 32 MB, truncation is detected explicitly, and a clipped body is now named body_truncated_at_probe_cap and attributed to this probe rather than to the publisher.
the registry reference limbs accepted false positives. The ISIN pattern matched any twelve character uppercase code, so two DefiLlama pool names were reported as securities identifiers. Chain qualification accepted a chain key anywhere in the document, so a two megabyte pool listing qualified an address that appeared nowhere near it, and an all-zero address counted as a reference. ISIN and LEI candidates now have to pass their real check digits, the all-zero address is discarded, and chain qualification requires the chain to sit in the same object as the address. This is the limb the survey is loudest about, so it is the one that had to be strictest.
Who is not here
The population is the set of issuers this node already tracks, which is not the set of largest
issuers and not a sample of anything. Issuers named in the request for this survey that this
node holds no dossier card for were left out rather than added to satisfy the request.
- Franklin Templeton (BENJI, FOBXX): this node holds no dossier card for it, so it is out of population and this survey makes no claim about it. This engine's own sensor grounding file records the same gap in its notes: BENJI omitted, no live primary AUM endpoint yet.
- Superstate (USTB, USCC): no dossier card on this node; out of population
- Hashnote (USYC): no dossier card under that name. The instrument is tracked as CIRCLE_USYC following its acquisition, and CIRCLE_USYC is in population.
- Centrifuge, Goldfinch: no dossier card on this node; out of population
A source this survey refused to use
-
data/entity_tvl_cache.json · entities.<SLUG>.url
: the cache is populated by fuzzy name matching against DefiLlama and several of its RWA matches are wrong. ONDO and BACKED both resolve to a Kujira project called FIN, TOKENIZED_TREASURY and CIRCLE_RESERVE_FUND both resolve to a protocol called Re, and BLACKROCK resolves to securitize.io. Using these as issuer origins would attribute one company's website to another.
Read it yourself
One issuer at a time: https://geniusflow-federation.vercel.app/rwa/receipts/<ENTITY>.json. Any
entity not in the population returns 404, which is the population boundary rather than a
missing file.
Re-run it
PYTHONPATH=engine python3 engine/tools/rwa_disclosure_run.py expect
PYTHONPATH=engine python3 engine/tools/rwa_disclosure_run.py run
PYTHONPATH=engine python3 engine/tools/rwa_pages_export.py
The expectations file pins the population and every candidate surface, so a disagreement is
about what the surfaces served, not about which issuers were picked. run aborts if the expectations digest stops matching its contents.
What this is not
- This is not a measure of disclosure quality. An issuer serving a signed monthly attestation PDF prepared by an accounting firm is disclosing more than one serving an unsigned JSON file. The survey asks only whether a program can read the number, which is a different question and a smaller one.
- This is not a market survey and not a ranking. The population is the set of issuers this node already tracks, which is not the set of largest issuers and not a sample of anything. No rate here should be quoted as a sector rate.
- A refusal at the first limb is a fact about this node's coverage, not about the issuer. Those refusals are separated out in the summary and the headline is given both ways.
- No issuer was contacted beyond a plain GET of URLs that are already public, plus the frozen conventional path list on origins the issuer already serves.
- No registry address, contract address or identifier in this survey was supplied by the probe. Every reference reported was found inside bytes the surface itself served.