

Private markets do not suffer from a shortage of capital or a shortage of good assets. They suffer from an infrastructure problem, and at the centre of that problem sits something unglamorous: the register.
Every fund administrator, transfer agent, custodian and manager maintains its own record of who owns what. These systems were built separately, decades apart, and they do not speak to one another. A single secondary transfer can require weeks of reconciliation between three or four firms, each confirming against its own books, each trusting the others to have kept theirs accurately.
The consequences compound. Settlement takes days or weeks rather than moments. Administration is manual and expensive, which pushes minimum ticket sizes up and shuts out smaller allocations. Secondary liquidity barely functions, because moving a position means restarting the reconciliation process from the beginning. Investors accept ten-year lock-ups not because the assets require it, but because the plumbing does.
This is not a failure of any individual firm. It is what happens when an industry runs on fragmented, mutually incompatible private ledgers.

Strip away the vocabulary that has attached itself to this technology over the past decade and a blockchain is a database. Specifically, it is a distributed database that updates according to open-source rules no participant can unilaterally change.
That sounds modest. It is not. Three properties, in combination, make it something finance has never previously had.
It is standardised and updates in real time. Every participant reads the same data structure at the same moment. There is no version of the truth that depends on whose books you happen to be reading, and no delay between an event occurring and the record reflecting it.
It is immutable. Once written, an entry cannot be altered or deleted. The complete history of any holding — issuance, every subsequent transfer, every corporate action — remains permanently reconstructible.
It is independently verifiable. This is the property that matters most and is least understood. A counterparty, an auditor or a regulator does not need to trust EVIDENT's assurance that a record is accurate. They can verify it themselves, cryptographically, without our cooperation and without our permission.
Taken together, these amount to something genuinely new: a standardised global database for financial records. Not a faster version of what exists. A different category of thing.
This is why we describe blockchain as a new system of record, and why we treat that description as precise rather than rhetorical. It is not a payment technology, an asset class, or a product we sell. It is the layer underneath, and the reason we can operate a market that settles in real time rather than in weeks.
The instruments themselves are unchanged. The SFC puts this more elegantly than we could, describing tokenised securities as fundamentally traditional securities with a tokenisation wrapper. Same legal character, same investor protections, same regulatory framework. What differs is the register they are recorded on.

Once you accept that a shared, immutable, verifiable register solves the reconciliation problem, a second question follows immediately. Which register?
The SFC sets out the choice precisely, distinguishing three network architectures: private-permissioned networks, being closed-loop private networks with a central authority controlling and restricting access to predetermined users; public-permissioned networks, being public networks where a central authority controls and restricts access through authentication; and public-permissionless networks, being open and public networks that do not restrict access, characterised by decentralisation, pseudonymity and a large number of users.
Most institutions, on first encountering this choice, reach for a permissioned option. It resembles the systems they already run. The governance is legible to a legal department. There is someone to call.
We think that instinct is mistaken, and that the reasons matter enough to set out carefully.
A permissioned ledger answers to whoever controls it. That single fact generates three failure modes.
It reintroduces a single point of failure. The entire value of a shared register rests on its continuity. If the consortium fractures, a key member exits, or the operator encounters financial or regulatory difficulty, the ledger's operation is in question. The infrastructure inherits the institutional risk of its operator, which is precisely the dependency a shared register exists to remove.
It cannot offer credible neutrality. Where a gatekeeper has the technical ability to alter entries, censor participants, or suspend the network, the immutability of the record is a policy rather than a property. Participants are asked to trust that the operator will not exercise powers it demonstrably holds. That is the same trust relationship private markets already rely on, relocated rather than removed.
It fragments liquidity. Closed networks do not interoperate. Each becomes an island with its own participants, standards and assets. An asset issued on one cannot move to another without an intermediary, which is where we started. Ten permissioned networks are not a market; they are ten silos with better technology inside each.
The pattern is consistent. Each of these problems is a restatement of the reconciliation problem in newer language.
EVIDENT records its securities on Ethereum. The reasoning is structural rather than ideological.
Resilience. The network runs across tens of thousands of independently operated validators distributed globally. There is no operator to fail, no data centre to lose, no corporate event that interrupts it. For infrastructure intended to hold the definitive record of ownership over multi-decade assets, this durability is not a secondary consideration.
Credible neutrality. No participant, including us, can alter the ledger, reverse a settled transaction or exclude a counterparty at the protocol level. When we tell an investor that their ownership record is immutable, this is a description of how the system works, not an undertaking we are asking them to accept on trust.
Composability. Open standards allow our infrastructure to interoperate with custody providers, identity frameworks, settlement mechanisms and analytics tools without negotiating bilateral agreements or requesting anyone's permission. Innovation happens at the edges without coordination overhead at the centre.
Continuous global settlement. The network operates without market hours, holidays or correspondent banking dependencies. Delivery versus payment occurs in real time, globally, whenever a trade is matched.
Network effects rather than network isolation. Assets recorded on an open standard remain reachable by the widest possible set of counterparties. Liquidity concentrates rather than fragments. For a firm whose central purpose is making private positions genuinely tradeable, this is decisive.

The substantive question is not whether open networks are useful. It is whether a licensed intermediary can use one consistently with its obligations. In Hong Kong, that question has a documented answer.
The SFC has addressed tokenisation directly. Its guidance treats tokenised securities as securities as defined under Schedule 1 to the Securities and Futures Ordinance, where ownership and other information are recorded using a blockchain or other distributed ledger technology instead of a traditional central register of holders. The existing regulatory framework applies in full. There is no separate regime and no gap.
On network choice, the SFC is specific rather than prohibitive. It identifies heightened risk in one particular configuration: tokenised securities in bearer form issued using permissionless tokens on a public-permissionless network. The concern is coherent — bearer-form, self-custodial permissionless tokens carry higher cybersecurity exposure and greater money-laundering and know-your-customer risk relative to tokenised securities in registered form.
For SFC-authorised investment products offered to the Hong Kong public, the requirement is expressed as a condition rather than a ban: product providers must not use public-permissionless networks without additional and proper controls, for example by imposing additional control through the use of permissioned tokens. The SFC also requires that providers remain ultimately responsible for the operational soundness of the tokenisation arrangement and for record keeping of ownership regardless of any outsourcing, that proper records of token holders' ownership interests are maintained, and that appropriate measures manage cybersecurity, data privacy, system outage and recovery risks.
Read carefully, the SFC is not describing an obstacle to open networks. It is describing an architecture: permissioned tokens on a public network, in registered rather than bearer form, with the licensed intermediary retaining responsibility for the ownership record.
That is precisely what EVIDENT operates.
Our securities are recorded on Ethereum using independently audited smart contracts built to the ERC-3643 standard — a permissioned token standard. Transfers are restricted at the token level to addresses associated with verified, onboarded counterparties. Nothing on our infrastructure is a bearer instrument. There is no self-custodial permissionless token, no anonymous transferability, and no circumstance in which a security can move to a party we have not identified and cleared.
The network beneath is open, which gives us resilience, neutrality and reach. The tokens recorded on it are permissioned, which gives the SFC and our counterparties the control the framework requires. These are not competing design choices. They are complementary layers, and the SFC's guidance anticipates exactly this combination.
One boundary is worth stating plainly. The strictest requirements sit in the SFC's guidance on authorised investment products, which governs products authorised by the SFC for public offering in Hong Kong under Part IV of the Securities and Futures Ordinance, such as public funds, collective investment schemes and exchange-traded funds. EVIDENT does not deal in authorised retail products. We operate exclusively with professional investors, and the professional investor perimeter is a deliberate feature of how we are built rather than a limitation we work around. We nonetheless design to the standard the authorised-product framework describes, because we regard it as the correct benchmark for institutional infrastructure.
The principle underlying all of this is straightforward and it is the point institutional counterparties most often miss. Regulatory obligations attach to the licensed intermediary. They do not attach to the underlying network.
EVIDENT is the regulated party. We conduct customer identification and due diligence. We screen wallets and counterparties. We monitor transactions, report suspicious activity and comply with travel rule obligations. Every one of these controls operates at our layer, where the customer relationship exists and where regulators expect them to sit. None requires the network beneath to be gated.
Two observations follow.
Compliance frameworks are risk-based, not zero-tolerance. Anti-money-laundering standards in Hong Kong and globally require firms to maintain reasonably designed, risk-based programmes proportionate to identified risk. No programme eliminates all risk, and supervisory attention focuses on systemic or knowing failure rather than isolated technical exposure.
Protocol-level interaction is not facilitation. Submitting a transaction to an open network involves paying protocol-defined fees to a validator selected algorithmically. The sender cannot choose, direct or identify which validator processes the transaction. This is neutral infrastructure in the same sense that an internet packet routed through foreign servers, or a telephone call crossing third-party switches, is neutral infrastructure — a distinction long recognised in regulatory frameworks that exclude entities merely providing delivery, communication or network access from the obligations attaching to financial intermediaries.
The regulatory environment here is not merely permissive. It is actively building.
The HKMA's Project Ensemble has moved from framework to execution, and EVIDENT participates in Project Ensemble TX alongside institutions including BlackRock, HSBC and Bank of China. The "TX" is transaction, and the shift in name is the shift in posture: from white papers and pilots to live settlement of real assets against tokenised money. Hong Kong's regulators are not asking whether this infrastructure will be built. They are constructing the conditions for it.
The international picture points the same way. A detailed legal analysis of these questions under United States law, covering Bank Secrecy Act obligations, sanctions exposure and the treatment of validator interactions, reaches conclusions consistent with our own assessment. Supervisory practice has followed: banking regulators have confirmed that national banks may operate nodes, validate transactions and pay protocol fees on permissionless networks; securities regulators have permitted broker-dealers to custody digital asset securities recorded on public ledgers; and major asset managers including BlackRock, Franklin Templeton and Apollo operate live regulated fund products on public networks today.
The institutional question is no longer whether this is permissible. It is which firms build the operational discipline to do it well.
A public record of ownership sounds incompatible with commercial confidentiality. It is not, because what appears on the network and what identifies a client are two different things.
Identity is held off-chain. Client identity, allocations and sub-ledger positions are maintained within EVIDENT's regulated systems. The public network records cryptographic addresses and asset state. The association between an address and a person exists only inside our permissioned environment, accessible to regulators on request and to nobody else.
Structural separation. Omnibus and tiered custody arrangements further separate on-chain activity from individual client position data.
Cryptographic proof without disclosure. Zero-knowledge techniques allow us to prove specific facts to a regulator or counterparty — that an investor meets professional investor criteria, that reserves match liabilities — without publishing the underlying amounts or identities.
The result is a register that is verifiable in the ways that matter and confidential in the ways that matter, which is precisely the combination institutional participants require.
Our financial integrity framework runs at the application layer across nine areas.
Client-facing controls. Customer identification and due diligence, including enhanced due diligence where risk warrants. Wallet and counterparty screening against sanctions lists and analytics databases before any issuance, deposit or transfer. Transaction monitoring calibrated to on-chain typologies, with suspicious activity reporting that includes precise on-chain identifiers. Travel rule compliance through established interoperability protocols. Independent audit and testing.
Programme and network controls. Board-approved governance setting explicit risk boundaries for on-chain activity, with documented assessment of validator diversity, consensus health and smart contract audit history before any asset class is deployed. Documented sanctions escalation procedures, including transfer restriction and account freezing at the token level. Third-party risk management across node providers, custodians and analytics vendors, with redundant node operation to remove single-vendor dependency. Institutional key management under hardware security module and multi-party computation standards.
Responsibility for the ownership record remains ours in every case. Outsourcing any component of the arrangement does not transfer that responsibility, and we do not structure it as though it could.

Infrastructure is only worth building for what it enables. Three consequences follow from an open system of record, and they are the reason this matters beyond technology.
Private markets become genuinely tradeable. When ownership, transfer and settlement all resolve on one verifiable ledger, liquidity stops being arranged deal by deal and becomes a property of the asset itself. Discovery, pricing, clearing and settlement run on the same rails and reach the whole network. A position can change hands faster, at lower cost, and more often, and the more easily it moves, the deeper the market in that asset becomes.
Access improves at every level. Real-time administration removes the manual cost that has kept minimum ticket sizes high and made private allocations impractical for anyone other than the largest institutions. Family offices, external asset managers, private banks and the wealth platforms that serve them gain access, flexibility and liquidity on terms that previously did not exist. Over time, the same efficiency opens the door to far larger pools of capital, including pension and retirement money that has long been structurally underweight private assets not because the investment case was weak, but because the operations were impossible at scale.
It provides the foundation for automation. Agentic systems are constrained by the integrity of the data they read. Reasoning across fragmented, editable, proprietary databases produces unreliable output. A standardised, immutable, verifiable ledger is the opposite condition: a single source of truth that supports automated valuation, corporate actions, servicing and reporting with deterministic inputs. This is why we describe blockchain as the system of record and AI as the system of orchestration. The second depends on the first.
When financial institutions moved their communications and payment channels onto the internet, they did not build private internets. They built encryption, authentication and compliance controls around an open, permissionless protocol that nobody owned. The open architecture delivered the resilience and reach; the institutions supplied the controls.
The transition of private capital markets to an open system of record is the same transition. The network stays open, neutral and verifiable. The controls sit at the token layer and with the licensed firms operating above it, which is where regulators expect them and where they belong.
EVIDENT operates this way because we think it is the correct architecture, not merely a permissible one. We welcome scrutiny of that position and feedback from regulators, counterparties and clients.