RWA disclosure · read-only · expectations first

The reserve number a machine cannot read

Everyone publishes how much tokenized real world asset value exists. Nobody publishes whether the issuer of that value serves a number a program can read. An attestation PDF signed by an accounting firm is a strong disclosure and a useless interface. This survey asks only the interface question, of the issuers this node already tracks, and names every refusal by the limb that failed.

Not a measure of disclosure quality · not a market survey and not a ranking · no score, no badge · every URL came from this engine's own recorded data

Population 17 real world asset issuers and tokenized instruments, every one carrying a dossier card this node exports
Candidate surfaces 15, all drawn from this engine's own recorded data · engine commit 63a8337c5ae0
Expectations digest 28961d5d66629b9a0d370b1331bd7b7b66f7c857d78a47145e29567c7c7aef1a published 2026-08-02 04:28 UTC
Ledger digest e4d5d4e38e707632fcbfe2f23a5a0a58c989eaa19176cde8971fb171b4d369f1 run 2026-08-02 05:43 UTC · probe v1.0.2
How to cite / re-check
Cite expectations.json (published first) and summary.json. One issuer at a time: https://geniusflow-federation.vercel.app/rwa/receipts/<ENTITY>.json
Population is this node's tracked issuers, not a sector sample. For issuer-attributable figures cite attributable_to_issuer, not the raw 0 of 17 alone.
0
of 17 issuers
serve a machine readable disclosure they operate themselves
Not a low number. Zero. No issuer in this population publishes a structured reserve or asset figure on an origin it controls.
2
of 15 surfaces
serve structured bytes at all
Both belong to the same third party aggregator. The number is readable, and the issuer is not the one publishing it.
0
of 45 requests
to a conventional disclosure path answered
Nine paths across five issuer operated origins. There is no location an issuer could serve this from even if it wanted to.
11
of 17 issuers
have no surface recorded by this node
That refusal belongs to this node, not to the issuer. The rate below is also given with them excluded.

The distinction this survey exists for

A machine readable number about an issuer is not the same thing as an issuer publishing a machine readable number. In this population only the first exists.

This engine's own reserve figures for BUIDL and OUSG are read from DefiLlama, not from BlackRock, Securitize or Ondo, because no issuer here serves an equivalent. Every consumer of those figures, this node included, holds a dependency on a third party that the issuer never agreed to and cannot be held to. When the aggregator renames a field, the issuer's disclosure has not changed and the consumer still breaks.

The same engine's sensor grounding file records the gap for a fourth issuer in its own notes: BENJI omitted, no live primary AUM endpoint yet. That was written down before this survey existed and is quoted here rather than discovered by it.

Where the 17 issuers fail

First failing limbIssuers
disclosure_surface_declared 11
machine_readable_media_type 4
issuer_operated_surface 1
as_of_date_present 1

Eleven of those refusals are no_disclosure_surface_recorded_by_this_node, which is a fact about this node's coverage rather than about the issuer. Excluding them entirely, 4 of 6 issuers with a recorded surface still fail at least one MUST limb, and 0 of 17 clear the full level.

What the surfaces actually served

Media type sniffed from the bytesSurfaces
html 13
json 2

The type charged is the one the bytes support, sniffed from the body. A Content-Type header is a claim, not evidence. Of 15 recorded surfaces, 9 sit on an origin the issuer operates and 0 of those serve structured data.

Is there a convention to follow

No. The survey asked 45 times across 5 issuer operated origins, using a path list frozen and published before the run:

HTTP statusResponses
404 36
200 9

None of these paths is a registered well-known URI and none is specified by any standard, which is the point. There is no location an RWA issuer could serve a reserve figure from even if it wanted to, and no field name it could use that a consumer would already know how to read. The 9 responses that returned 200 served no structured bytes: they are catch-all routes answering every path with the application shell. Reading those as a pass would have turned a routing default into a conformance result.

registry_ref discipline

Of 15 recorded surfaces, 1 name any on-chain or securities identifier at all, and 0 name one that is chain qualified. A disclosure that names a contract without naming its chain does not identify a deployment: the same twenty bytes can be a different contract on every EVM network, so a consumer has to guess or ask. CAIP-10 exists to close exactly this gap.

ISIN and LEI candidates must pass their real check digit, so a twelve character product code cannot be counted as a security identifier. An all-zero address is discarded. Chain qualification requires the chain to sit in the same object as the address, not merely somewhere in the same file. Every identifier reported here was found inside bytes the surface itself served. This probe supplies none of its own, so there is no address in this ledger a reader has to take on trust from us.

Limbs

There is no specification to cite for any of this, and pretending otherwise would be the same error the survey exists to catch. MUST means a consumer cannot read the number without it, SHOULD means the consumer can read it but cannot rely on it, OBSERVED means the limb records a fact and charges nothing. not_reached means an earlier limb failed first, so this one was never observed: it is neither a pass nor an exemption.

LimbLevelokfailn/anot reached
disclosure_surface_declared MUST 6 11 0 0
surface_resolves MUST 6 0 0 11
machine_readable_media_type MUST 2 4 0 11
body_parses_as_served_type MUST 2 0 0 15
figure_addressable_by_key_path SHOULD 2 0 0 15
as_of_date_present SHOULD 1 1 0 15
issuer_operated_surface SHOULD 0 2 0 15
registry_ref_present OBSERVED 1 1 0 15
registry_ref_chain_qualified OBSERVED 0 1 0 16
conventional_path_answers OBSERVED 0 4 2 11

Predictions, scored

These were written into the expectations file and published before the run, at digest 28961d5d66629b9a. They are scored here without editing.

PredictionObservedResult
No issuer in this population serves a machine readable disclosure surface on an origin it operates itself. 0 of 17 issuers had one met
Every machine readable surface in the population belongs to a third party aggregator rather than to the issuer. 2 machine readable surfaces, of which 0 were issuer operated met
No path in the frozen conventional list answers with structured bytes on any issuer operated origin. 0 of 45 conventional path requests answered with structured bytes met
No surface in the population carries a chain qualified registry reference. 0 of 15 recorded surfaces carried one met
More than half of the population has no disclosure surface recorded by this node at all. 11 of 17 had none met

Per issuer

EntityRoleVerdictRefuse reasonReceipt
BACKED issuer refuse disclosure_surface_declared:no_disclosure_surface_recorded_by_this_node json
BLACKROCK issuer refuse machine_readable_media_type:html_document json
CIRCLE issuer refuse machine_readable_media_type:html_document json
CIRCLE_RESERVE_FUND issuer refuse disclosure_surface_declared:no_disclosure_surface_recorded_by_this_node json
MAPLE issuer refuse disclosure_surface_declared:no_disclosure_surface_recorded_by_this_node json
ONDO issuer refuse machine_readable_media_type:html_document json
ONDO_YIELD_ASSETS issuer refuse disclosure_surface_declared:no_disclosure_surface_recorded_by_this_node json
PAXOS issuer refuse disclosure_surface_declared:no_disclosure_surface_recorded_by_this_node json
SECURITIZE issuer refuse disclosure_surface_declared:no_disclosure_surface_recorded_by_this_node json
SPIKO issuer refuse disclosure_surface_declared:no_disclosure_surface_recorded_by_this_node json
TETHER issuer refuse machine_readable_media_type:html_document json
BLACKROCK_BUIDL instrument admit issuer_operated_surface:surface_is_third_party:llama.fi json
CIRCLE_USYC instrument refuse disclosure_surface_declared:no_disclosure_surface_recorded_by_this_node json
OUSG instrument admit as_of_date_present:no_as_of_date_on_the_surface json
PAXOS_GOLD instrument refuse disclosure_surface_declared:no_disclosure_surface_recorded_by_this_node json
TETHER_GOLD instrument refuse disclosure_surface_declared:no_disclosure_surface_recorded_by_this_node json
USDY instrument refuse disclosure_surface_declared:no_disclosure_surface_recorded_by_this_node json

Two defects this survey found in itself

The first run exposed faults in the probe rather than in the population. They are recorded instead of quietly fixed, because a probe that hides its own misses has no standing to publish anyone else's. The population, the limb order, the admit rules and the predictions were not touched, so the expectations digest is unchanged and still verifies.

conventional_path_answers was sequenced behind the media type limb. Every issuer operated surface in this population is an HTML document, so the receipt returned before the convention limb was ever observed. The first run made zero conventional path requests and still scored the prediction about them as met, which is a claim on no evidence. The limb asks about the issuer's origin rather than about the surface the other limbs read, so it is now evaluated for every issuer that has an origin at all, independent of what the earlier limbs found. The prediction now scores as missed when no request was made.

a body clipped at this probe's own size cap was charged as a parse error. One aggregator surface is larger than the original 2 MB cap. The probe truncated it, failed to parse its own truncation, and recorded the failure against the surface. That is a refusal this probe manufactured. The cap is raised to 32 MB, truncation is detected explicitly, and a clipped body is now named body_truncated_at_probe_cap and attributed to this probe rather than to the publisher.

the registry reference limbs accepted false positives. The ISIN pattern matched any twelve character uppercase code, so two DefiLlama pool names were reported as securities identifiers. Chain qualification accepted a chain key anywhere in the document, so a two megabyte pool listing qualified an address that appeared nowhere near it, and an all-zero address counted as a reference. ISIN and LEI candidates now have to pass their real check digits, the all-zero address is discarded, and chain qualification requires the chain to sit in the same object as the address. This is the limb the survey is loudest about, so it is the one that had to be strictest.

Who is not here

The population is the set of issuers this node already tracks, which is not the set of largest issuers and not a sample of anything. Issuers named in the request for this survey that this node holds no dossier card for were left out rather than added to satisfy the request.

A source this survey refused to use

Read it yourself

One issuer at a time: https://geniusflow-federation.vercel.app/rwa/receipts/<ENTITY>.json. Any entity not in the population returns 404, which is the population boundary rather than a missing file.

Re-run it

PYTHONPATH=engine python3 engine/tools/rwa_disclosure_run.py expect
PYTHONPATH=engine python3 engine/tools/rwa_disclosure_run.py run
PYTHONPATH=engine python3 engine/tools/rwa_pages_export.py

The expectations file pins the population and every candidate surface, so a disagreement is about what the surfaces served, not about which issuers were picked. run aborts if the expectations digest stops matching its contents.

What this is not