THE ORACLE STATE MACHINE
State should move as one.
An asset's token, its custody record, its contract and its regulatory status usually live in different systems. Oraclizer is built to move them in one step that either happens everywhere or nowhere.
Designed for tokenized securities, institutional ledgers, and cross-domain asset operations.
The affected domains commit together or roll back together. A partially applied result is outside the permitted state space.
WHY STATE SYNCHRONIZATION
A price can be delivered. A financial state has to be coordinated.
A data feed can tell a contract that a price changed. It cannot, by itself, keep a token, a custody record, an off-chain contract, and a regulatory action in the same causal state. Oraclizer treats the transition, its authority, its policy context, and its result as one protocol object.
Data feed
Observe a value. Publish an update. Leave each destination to determine what happens next.
Oracle state machine
Bind the affected domains. Verify the transition and its context. Commit one result, or leave every bound domain unchanged.
MODEL-LEVEL ASSURANCE
Prove the model. Refine the system.
Oraclizer uses machine-checked formal models to establish declared properties at the model level. The assurance program targets core-wide refinement: a traceable correspondence from those formal semantics through protocol and implementation layers. As refinement obligations are discharged, model-level guarantees become system-level guarantees for the exact mapped code and deployment boundary.
Mechanized semantics
State, authority, transition, failure, and preservation properties are stated in Isabelle/HOL so the proof kernel can check the declared model instead of relying on prose alone.
Adversarial examination
Counterexamples, mutation tests, assumption ledgers, and independent recomputation are used to expose vacuous proofs, hidden preconditions, and claims that exceed their evidence.
Core-wide refinement target
Explicit obligations map formal state and transition semantics into protocol behavior, implementation code, compiled execution, and deployment identity. A system-level claim is made only for the boundary whose correspondence has been demonstrated.
THEORY INTO SYSTEMS
From a proved model to an assured system.
The figure maps mechanized semantics, explicit refinement obligations, executable components, and deployment evidence into one assurance path. It distinguishes the model-level properties demonstrated today from the core-wide refinement target.
SYSTEM ARCHITECTURE
No layer you have to take on faith.
Protocol meaning, execution, proving, sequencing and external integration are kept apart, so each one can be specified, tested and argued with on its own.
OIP v0.5
The public protocol specification defines messages, routing, validation, regulatory actions, cross-domain coordination, and conformance for state synchronization.
Read OIP v0.5 (opens in a new tab)Oracle State Synchronization System
The execution architecture coordinates degree-aware synchronization cycles across participating domains and owns the Bind–Verify–Commit path with a fail-closed boundary.
Implementation link reservedD-quencer
A specialized sequencing layer for synchronization-cycle progress, deterministic ordering under declared Byzantine assumptions, and priority handling for time-sensitive regulatory actions.
Architecture in developmentStateSync-GKR
A prover research and development track for repeated sparse-Merkle state verification and deadline-aware workloads.
Repository reserved for public releaseIntegration layer
The RWA Registry, Canton Driver, and cross-chain message-integrity layer connect asset metadata, enterprise ledgers, and external state paths without making one external system the source of every truth.
Review the architecture (opens in a new tab)USE CASES
Built for assets that cannot tolerate split state.
Institutional assets can exist simultaneously as tokens, contractual rights, custody records, eligibility decisions, and settlement entries. Oraclizer is designed for workflows where those representations must accept one authorized transition and expose one inspectable outcome.
Asset servicing
Coordinate coupon events, maturity, redemption, and ownership changes across a token, its contractual record, and the systems responsible for servicing the asset.
Regulatory actions
Keep freeze, seize, confiscate, restrict, recover, and liquidate distinguishable through their authority, state effect, failure behavior, and execution receipt.
Cross-ledger settlement
Coordinate the accepted transition across blockchain representations, custody records, institutional ledgers, and connected environments such as Canton paths.
These are the workflows the architecture is designed for. Each one is specified in the public protocol and modelled formally, ahead of production.
STANDARDS
A freeze has to mean the same thing everywhere.
Oraclizer's standards work gives regulatory actions, their authority, their outcomes and their receipts a machine-readable identity, so separate ledgers can agree on what actually happened to an asset.
ERC-8319 · Regulatory Compliance Protocol
Six regulatory actions, and thirty-one requirements drawn from fifteen financial regulators organized under five principles. Assigned number 8319 in the Ethereum ERCs repository, and co-authored with Dan Spuller of the Blockchain Association, writing in an individual capacity.
ERC-TRUST · Typed Regulatory Uniformity for Security Tokens
A comprehensive and adaptable execution standard for regulatory actions on security tokens. It gives actions, authorization, outcomes, failures, and receipts machine-readable identities while leaving policy, identity, and deployment structure environment-specific.
Execution and conformance work in developmentTyped Regulatory Actions and Execution Receipts for Canton Tokens
A Canton Improvement Proposal for interoperable regulatory actions and typed execution receipts in Canton token implementations, complementing the evolving token-standard surface while leaving policy and authority models to each implementation.
Not submittedPUBLISHED RESEARCH
Read the argument before you trust the system.
The requirement frameworks, formal models and design arguments behind Oraclizer are published in full. So are the boundaries of what they cover.
Regulatory Compliance Protocol
A framework for measuring how completely a token standard represents regulatory requirements and enforcement state, applied to the standards already in use.
View on arXiv (opens in a new tab)The Cross-Domain State Preservation Functor
An Isabelle/HOL theory for preserving state across heterogeneous transition systems, organized as a functor.
View on arXiv (opens in a new tab)Formal Verification
Public machine-checked artifacts cover cross-domain state preservation, synchronization-degree monotonicity, and regulatory-action semantics. The degree result is proved in both directions: a higher degree safely carries a lower-degree asset, and a lower one provably cannot.
Explore formal verification (opens in a new tab)Research Library
Research across state synchronization, formal methods, protocol design, regulation, real-world assets, and tokenized markets.
Browse the library (opens in a new tab)NEXT RESEARCH
Typed Regulatory Execution
An ERC-TRUST Security-Token Case Study examining machine-checked regulatory execution semantics, adversarial analysis, implementation refinement, and explicit deployment boundaries.
ECOSYSTEM
The work is checked by people we do not employ.
Oraclizer works with a small number of teams and individuals who read the specification, run the verification and push back on the research.
Horizen Labs
Collaboration across ERC-8319 research and zero-knowledge verification infrastructure.
Visit Horizen Labs (opens in a new tab)zkVerify
Proof-verification infrastructure used in an Oraclizer test path.
Visit zkVerify (opens in a new tab)Blockchain Association
Dan Spuller, Executive Vice President of Industry Affairs at the Blockchain Association, contributes to ERC-8319 in an individual capacity as a co-author and policy contributor.
Visit Blockchain Association (opens in a new tab)Floating Pragma
Oraclizer takes part in the Floating Pragma research working group and is exploring a shared state-preservation benchmark connecting Oraclizer's Isabelle work with Bernhard Müller's Observer-Patch Holography program.
Visit Floating Pragma (opens in a new tab)FREQUENTLY ASKED
Straight answers.
01What is an oracle state machine?
It is an oracle architecture that treats a transition, its authority, its policy context, and its result as coordinated state, rather than as a value delivered to a contract.
Read the core concept (opens in a new tab)02How is S₃ different from ordinary oracle delivery?
At S₃, every bound domain must accept the transition together or return to the prior state together. Ordinary delivery can report a fact without enforcing that shared commit boundary.
Study state synchronization (opens in a new tab)03When is the Oraclizer testnet expected?
The current development target is Q1 2027. Public specifications, research preprints, formal models, and standards work are available now. The testnet target remains subject to completion of the required verification and integration gates.
04Who determines whether an external fact or regulatory action is valid?
The institutions, authorized sources, identity systems, and governing policies connected to an asset define authority and external truth. Oraclizer is designed to verify the declared evidence and policy path, coordinate the accepted transition, and expose its outcome. It does not replace legal judgment or make an external fact true by itself.
05Does Oraclizer replace existing tokens or institutional ledgers?
No. Oraclizer is designed as synchronization and assurance infrastructure around existing token standards, custody systems, institutional ledgers, and connected environments such as Canton. Each system retains its own authority while Oraclizer coordinates the accepted transition across their declared boundaries.
Review the architecture (opens in a new tab)ORACLIZER LABS
One asset should never become two.
Oraclizer Labs is a research and protocol organization building the oracle state machine, so that a regulated asset stays one asset across every system that holds it.
