Cross-Border Settlement Register · what each jurisdiction permits through its inbound gate, cited to primary law
May this money cross this border?
CBSR turns that question into a machine-citable record — pinned to a specific provision, dated, versioned, and refusing to answer when the evidence chain is incomplete.
Why the fourth number is zero: 103 records have an official source, 41 have one reviewer, and 0 have a reconciled independent second review. It governs citable_law(), not the register as a whole — the corridor layer still resolves an edge, it just will not call the result settled current law. build-time snapshot
One proposition · six axes · all showingv0.11.0
Every axis also states what it does not establish.
The licensee must not pay any interest on issued stablecoins.
Stablecoins Ordinance (Cap. 656) · Schedule 2, s.15 · read 20 August 2026 · official text
Claimtier1_legalClassifies the proposition; does not validate it.
Instrumentin_force_enactedRecords legal force; does not prove present applicability.
Provenanceresolution_textNames source strength; does not authenticate interpretation.
SourceofficialPoints to official text; does not guarantee it remains current.
FreshnessunknownRefuses current-law projection; does not mean the provision changed.
ReviewunreviewedShows no independent second read; does not imply the record is wrong.
Current projection: declined. Four axes pass; freshness and review remain open. This is fail-closed operation, not a coverage failure.
Every record in the register has this shape. No hidden confidence score, no summary whose provenance cannot be named — six fields, each of which can be pointed at and questioned, and each of which states what it does not establish.
dependency order · four layers
Each layer is empty if the one below it is not true.
The usual way a project like this dies is starting at the third layer: sell first, source the evidence afterwards, discover the evidence will not come. So the order is written down, and so is the state of each one.
The test is not that it is right. It is that a wrong entry can be pointed at.
Fluent, against checkable
A general model, unaided
Q: Can a euro-area e-money token issuer offer into the United States today?
“Yes, subject to registration at federal level as a permitted payment stablecoin issuer and to state money transmitter licensing. Cross-border offering is additionally subject to the applicable anti-money-laundering requirements.”
01It reads a regime that is enacted but not yet commenced as if it were operative. There is no federal issuer status available to obtain today.
02It carries no date. An answer with no date never goes stale, and never turns out to have been wrong.
03It carries no provision. You cannot check it. You can only decide whether to believe it.
The same model, reading CBSR
Q: Can a euro-area e-money token issuer offer into the United States today?
“EU → US is Category T, regime in transition. The destination has adopted a comprehensive regime that is not yet operative, so today there is no inbound authorization to obtain and no prohibition to cite. The edge resolves to Category II on 18 January 2027, the outer date for the GENIUS Act §18 comparability gate. Here is the record it rests on.”
✓The verdict arrives with its class, its gating mechanism, and the provision it rests on.
✓It carries an as_of date and a register version, so it can be shown to have been wrong later.
✓It treats “not yet in force” as a named state rather than a hedge in prose.
Both panels are written illustrations, not transcripts. The second answer is not more confident. It is less confident, in writing, in a form software can act on.
The engine that reads it never returns permission to execute
The register answers what the law says. The engine answers a narrower and more dangerous question: given this specific proposed action, what do the axes actually support. The failure mode is returning something actionable when the evidence does not reach, so evaluate_action() is built so that it structurally cannot.
// the first field is a constant, in every version
{
"execution_authorized": false,
"decision": "review_required",
"because": "evidence_chain_open",
"binding_axis": "review",
"corridor_class": "T",
"resolves_on": "2027-01-18",
"register": "v0.11.0",
"receipt": "sha256:…"
}
false
the value of execution_authorized. Every call, every release.
31
table-driven policy scenarios pinned in the test suite.
13
receipt mutations the tamper check must catch.
what the receipt claims, and what it does not
Does
SHA-256 over canonical JSON, with the identifier derived deterministically from that digest. Identical inputs replay to a byte-identical receipt, so two parties can each run it and compare digests instead of trusting each other.
Does not claim
A receipt is not a signature. It detects mutation, not identity, and the audit identity inside it is asserted by the caller and not authenticated by CBSR. The system holds no keys, submits no transactions and custodies nothing.
The verdict it produces is directional, and it is dated
US→EU
EU→US
clears (Cat I)gated (Cat II)blockedregime in transition
The binding rule sits at the destination's inbound gate, with a drag from the origin. Today US → EU clears and EU → US does not, though nothing bars it: the US regime is written and not yet in force. Move the date past 18 January 2027 and that edge resolves to Category II along with seven others into the US. In this register 56 of the 66 jurisdiction pairs read differently depending on which way the money moves. A flat compliance table has one cell per pair. That is the whole problem.
what this layer costs
You get
Data under CC-BY-4.0, tooling under Apache-2.0, every tagged release archived to Zenodo for a DOI, with the citation form in CITATION.cff. The static API is self-describing and api/index.json enumerates every endpoint; tool signatures and the return contract are in MCP_SERVER.md; reproduce the build with python -m tools.verify. No sign-up, no key, no waiting list.
Does not claim
Free is not the same as supported. This layer carries no uptime commitment, no support queue, and no undertaking that a corridor still reads today what it read at the dateline. It also will not go behind a paywall, now or after layer three exists.
layer two · the constraint
One axis is stuck at zero, and code will not move it.
Of 152 sourced records, 103 have an official source, 41 have one reviewer, and 0 have a reconciled independent second review. Every layer above rests on the third number, and only a person moves it.
01
The plan is not a recruitment funnel
Two or three named people, covering the jurisdictions the working papers already cover, reconciling the 46 structural candidates. More contributors does not mean faster: every reconciliation requires someone to actually read the primary text, and that does not parallelise cheaply.
02
Governance comes before recruitment
The credibility rule here is that everything written down is defensible, which makes every additional contributor a credibility liability until reviewed. Reviewer eligibility, conflicts of interest, and what happens when a maintainer is wrong have to be settled first. GOVERNANCE.md is a precondition, not a supporting document.
03
The credential is the log, not a badge
A public record that a named person reconciled N cells in one jurisdiction, with the diffs attached, is harder to fake than any tier system and it accrues on its own. Until the register can certify a single proposition as current law, certifying people would be the wrong way round.
This layer does not exist today. It is written down because it eventually will, and how it gets built decides how much credibility the two layers under it keep. The free register promises no uptime and tells you to verify against primary law; the commercial thing would sell precisely the inverse. They cannot hang on the same object.
Separately named
A different object with its own name, its own terms, and its own liability boundary.
Does not claimNot a membership tier bolted onto the register. The free layer's value comes precisely from promising nothing.
Three things
A hosted endpoint pinnable to a version with a service-level commitment; replayable tamper-evident decision receipts for internal audit and model risk; change notification on the 16 scheduled reclassifications.
Does not claimThe buyer is internal audit, compliance and model risk, not a developer. What is paid for is reliance and operations, not more data.
Evidence and audit trail
The system never says you may do X. It says here is what the record supports and here is the receipt that you checked. The customer's own counsel signs off.
Does not claimNot a regulatory conclusion sold for reliance, which in several jurisdictions sits close to unauthorised legal advice. The register itself, the six-axis model, the engine and its receipt format, and the per-cell worklist stay open.
layer four · position
Cited, not bought.
A governance-grade position cannot be bought and cannot be asserted. There is one route: make the thing citable enough that people cite it in formal settings, then wait to be cited. Two seeds are in the ground — one piece filed in the US SEC Crypto Task Force docket, one published on Duke Law's FinReg Blog. Next is continuing to answer regulatory consultations, and taking the KYA framework — Know Your Agent — into an appropriate standards forum.
United Nations boundary
The register's unit of work and the unit of SDG Target 10.c — reducing remittance cost — are the same unit: the corridor. So the mapping is stated as subject-matter alignment, and every row is required to write down what it does not claim. No United Nations endorsement, affiliation, partnership, certification, adoption or compliance status is claimed. This is not official statistics, not part of any national statistical system, not fit as a reporting source for indicators, and no UN marks are used.
who reads it
One infrastructure layer. Different duties.
The same record has to survive legal, technical, policy, research and capital review without changing what it claims.
AI and agent builders
Ground regulatory reasoning in typed, dated, source-pinned records.
Does not claimIt does not authorize execution or make the model a lawyer.
Financial institutions
Scope directed corridors and see which legal mechanism binds.
Does not claimIt does not replace institution-specific counsel, controls or approvals.
Fintech infrastructure
Price the legal path before building rails, products or treasury workflows.
Does not claimIt does not state commercial viability or guarantee market access.
Regulators and policy teams
Track dated regime transitions and test whether AI answers are traceable.
Does not claimIt contains no non-public supervisory data and does not substitute for supervision.
Researchers and standards bodies
Use a reproducible dataset, a DOI, the methods, and the published worklist.
Does not claimIt does not claim consensus, certification, adoption or settled standards.
Funders and institutional homes
Support the independent verification layer that keeps the evidence current.
Does not claimSupport does not buy a verdict, an endorsement or preferential treatment.
scope · the name is wider than the register, and that has to be said
Settlement is the frame. Stablecoins are the first instrument class.
152 sourced records · 46 structural candidates · 0 decision-ready
16 dated reclassifications
~30 typed tools over a fail-closed policy engine
Where the method extends, and does not yet reach
tokenized deposits and tokenized assets
central bank digital currency and fast-payment-system linkages
correspondent banking rails
sanctions and the Travel Rule
agent authorization and identity (see KYA)
why the right column is empty
Because filling it in requires no evidence, and this project's entire credibility rests on everything written down being defensible. Machine-readable regulatory data across several domains and twelve jurisdictions each is not one person's work; claiming otherwise costs the left column its credibility too. The left column is real, which is the only reason the right one has to read like this.
Build the evidence layer between financial regulation and autonomous action.
Open to institutional homes, governance and infrastructure roles, public-interest funding, product-building partnerships, and acquisition conversations that preserve the register's independence and its fail-closed contract.