1. Purpose and Scope
1.1 Purpose
These Rules govern securities represented, issued, recorded, transferred or administered using blockchain, distributed ledger or other approved digital-ledger infrastructure. They seek to ensure clear legal rights, accurate correspondence with legally issued securities, lawful issuance and transfer, investor and transfer controls, reliable ownership reconciliation, operational security, support for investor rights and corporate actions, prevention of unauthorised creation or transfer, accurate ownership records and market integrity.
2. Application
These Rules apply, as relevant, to Issuers, Sponsors, Brokers, Trading Participants, Market Makers, Underwriters, Custodians, transfer agents, registry operators, technology and wallet-infrastructure providers, and any other person involved in issuance, transfer, custody, administration or settlement of a Digital Security.
3. Definition of Digital Security
A Digital Security is a security or financial product represented by a digital token, blockchain or distributed-ledger record, natively issued using such infrastructure, or otherwise represented electronically through IDSX-approved technology. It may represent equity, debt, managed investment, convertible, preference, fund or other approved investment rights.
4. Technology-Neutral Legal Character
Technology does not alter the legal character of the underlying product. Classification follows substantive legal and economic rights: a token representing shares remains equity; a token representing debt remains debt; and other products retain the classification applicable to their rights.
5. Token Is Not a Cryptocurrency Merely Because It Is On-Chain
A Digital Security is not an unrestricted cryptocurrency merely because it uses blockchain. Securities law, ownership and transfer requirements, market rules, disclosure, AML/CFT, sanctions, corporate law, investor protection and other Applicable Law continue to apply.
6. Legal Rights Must Be Defined
Before admission, the Issuer must define and disclose the rights represented, including ownership, voting, dividends and distributions, redemption, conversion, liquidation, interest, maturity, participation and other statutory or contractual rights. Technical specifications must not materially conflict with those rights.
7. Legal Relationship Between Token and Security
The Issuer must explain the legal relationship between the token, underlying security, registered holder, beneficial owner, legal register and any custodian or nominee, including whether the token is the security, represents or evidences it, represents beneficial ownership through an intermediary, or represents another recognised interest.
8. Authoritative Ownership Record
Before admission, the Issuer must identify and disclose the legally authoritative ownership record, which may be a blockchain ledger, statutory or securities register, transfer-agent or nominee register, custodian sub-register or other legally recognised register.
9. Blockchain as Legal Register
A blockchain may be the authoritative register only where Applicable Law permits, the Issuer validly adopts it, ownership is reliably identifiable, legally required corrections and corporate actions can be administered, lost-key events and court or regulatory orders can be addressed, and IDSX approves the arrangement.
10. Dual-Record Structure
Where blockchain is not the legally recognised register, the Issuer must maintain an appropriate legal register and procedures to reconcile Blockchain Record ↔ Legal Securities Register. Material discrepancies must be investigated promptly.
11. Reconciliation
Reconcile at a frequency appropriate to the security, confirming legally issued securities, outstanding tokens, treasury positions, tokens pending settlement, cancellations or burns, frozen securities, beneficial ownership and exceptions or discrepancies.
12. One-to-One Representation
Where each token represents one underlying security, maintain a one-to-one correspondence unless a different ratio is expressly disclosed and approved.
13. Fractional Securities
Where fractional representation is legally valid, disclose unit size, voting and distribution treatment, corporate actions, transfer restrictions, rounding methodology and legal ownership structure.
14. Token Supply
Authorised token supply must correspond to the legally authorised quantity represented. Tokens outstanding must not exceed represented legally issued securities unless a different legally valid and disclosed structure is approved by IDSX.
15. Token Minting
Only an authorised person or system may mint. No minting may occur unless the underlying security is validly authorised, corporate approvals and issuance requirements are satisfied, issuance is recorded and IDSX requirements are met.
16. Minting Controls
Minting infrastructure must use appropriate controls, such as multisignature approval, hardware security modules, role-based access, dual authorisation, audit logs, transaction limits, change management and independent reconciliation.
17. Token Burning
Tokens may be burned or cancelled when securities are redeemed, cancelled, repurchased and cancelled, converted, consolidated, otherwise lawfully extinguished, or corrected through authorised remediation. Burning must be reflected in authoritative records.
18. Treasury Tokens
Issuer-held securities or tokens must be separately identifiable. Treasury tokens are not circulating public securities where the corresponding legal securities do not carry ordinary outstanding-holder rights.
19. No Unauthorised Issuance
No person may mint additional securities, duplicate tokens, create unofficial or mirrored representations, create synthetic equivalents purporting to be IDSX-listed securities, or otherwise increase effective supply without legal authority and IDSX approval.
20. Smart Contract Requirements
Smart contracts must support applicable legal and operational requirements, including as relevant minting, burning, transfer restrictions, whitelisting, freezing, forced transfer, ownership limits, corporate actions, voting, distributions, recovery and upgrades.
21. Smart Contract Review
Material functionality must receive appropriate technical review before admission. IDSX may require code review, independent audit, penetration or security testing, formal verification, testnet deployment, architecture documentation or other assurance.
22. Smart Contract Disclosure
Disclose material administrative powers to mint, burn, freeze, pause, transfer, seize, upgrade, change whitelist status, modify transfer rules or otherwise affect investor holdings.
23. Administrative Keys
Protect privileged keys with appropriate security. Avoid uncontrolled single-person access to material functions. Controls may include multisignature, institutional custody, hardware security modules, segregated duties, approvals, emergency controls and key rotation.
24. Blockchain Selection
Select infrastructure appropriate to the security, considering security, decentralisation, resilience, finality, availability, cost, throughput, smart-contract capability, governance, upgrade risk, regulatory compatibility, wallet and custody support, and long-term viability.
25. Public and Permissioned Networks
Approved Digital Securities may use public or permissioned blockchains, private or hybrid ledgers, or other approved technology. A public blockchain does not require unrestricted transfer to every address.
26. Multiple Blockchain Networks
A Digital Security may use multiple chains only with IDSX approval. Control total supply, prevent duplication, preserve ownership reconciliation and consistent corporate actions, control cross-chain transfers and keep legal ownership determinable.
27. Canonical Token
For multiple chains, identify the canonical asset and authoritative supply record, bridge and mint/burn mechanisms, custody arrangement and reconciliation process.
28. Blockchain Bridges
Do not use a bridge for Digital Securities without IDSX approval. Assess smart-contract, validator, custodian, minting, double-spend, supply-reconciliation, cybersecurity, governance and recovery risks.
29. Wallet Eligibility
Transfers may be made only to wallets permitted under IDSX KYC / AML Requirements, Issuer restrictions, securities laws, sanctions, investor-eligibility requirements and other Applicable Law.
30. Whitelisted Wallets
Where required, transfers follow Sender Wallet → Transfer Compliance Check → Recipient Wallet and may proceed only when applicable conditions are met.
31. Wallet-to-Investor Mapping
Where required, associate each approved wallet with an identifiable verified investor, approved custodian, regulated intermediary, nominee, market-infrastructure provider or other legal person. An address alone is not investor identity.
32. Transfer Restrictions
Smart contracts or associated systems should enforce applicable KYC status, jurisdiction, sanctions, investor category, ownership limits, holding periods, lock-ups, restricted-person, foreign-ownership, offering-exemption and other restrictions.
33. No Uncontrolled Peer-to-Peer Transfers
A security subject to eligibility controls must not transfer to an unidentified or ineligible wallet merely because the blockchain permits it. Enforce compliance at token level where necessary.
34. Off-Market Transfers
Off-market transfers may occur only where legally permitted, the recipient is eligible and verified, restrictions are met, ownership records are updated and IDSX recording requirements are satisfied.
35. Beneficial Ownership Changes
A change in beneficial ownership must comply with transfer requirements. Movement between wallets of the same beneficial owner may be treated differently from a transfer between beneficial owners.
36. Custodial Transfers
Transfers between Broker, custodian, omnibus, settlement or other infrastructure wallets must preserve records of underlying beneficial ownership.
37. Omnibus Wallets
IDSX may permit omnibus wallets. The responsible Participant must be able to identify each beneficial owner; wallet title alone does not establish that the Custodian beneficially owns all holdings.
38. Settlement
Digital Securities may settle on-chain or off-chain, through central settlement, a custodian, DvP or another IDSX-approved arrangement.
39. Delivery Versus Payment
Where practicable, settlement should coordinate delivery of securities and payment to reduce principal risk. IDSX may support or require DvP.
40. Settlement Assets
Consideration may be fiat, tokenised deposits, approved stablecoins, other digital settlement assets or another IDSX-approved means, subject to Applicable Law.
41. Settlement Finality
The settlement framework must define when a transaction is final. Blockchain confirmation alone does not necessarily establish legal settlement finality.
42. Blockchain Reorganisation
Where reorganisation is possible, establish appropriate confirmation requirements and account for confirmations, network finality, reorganisation and fork risks, and failed or reversed transactions.
43. Forks
For a fork, the Issuer and IDSX determine treatment having regard to network continuity, security, developer and infrastructure support, legal ownership, market integrity and investor protection.
44. No Automatic Rights to Forked Tokens
A holder has no automatic enforceable right to fork-created assets unless recognised by the Issuer and Applicable Law.
45. Network Disruption
For prolonged outage, consensus failure, security breach, congestion, validator failure, attack, reorganisation or other material disruption, IDSX may suspend trading, transfers or settlement.
46. Smart Contract Vulnerabilities
For a material vulnerability, IDSX or the Issuer may pause transfers or trading, freeze contracts, migrate or upgrade them, replace compromised keys or take other necessary protective action.
47. Emergency Pause
Emergency pause functionality may be included where appropriate, with governed circumstances of use. It must not be used for improper commercial purposes.
48. Forced Transfer
Controlled forced-transfer functionality may be used where necessary to implement a court or regulatory order, sanctions, inheritance, insolvency, lost-key recovery, correction, ownership restrictions or another legally valid requirement.
49. Token Freeze
Tokens or wallets may be frozen where legally permitted and reasonably required for sanctions, court or regulatory orders, suspected theft or compromise, ownership disputes, AML or market-integrity investigations, or other legitimate purposes.
50. Lost Private Keys
Loss of a key does not automatically extinguish legal ownership where ownership can otherwise be established. The security structure must provide appropriate lost-key procedures.
51. Key Recovery
Recovery may include identity and ownership verification, loss declaration, security review and waiting period, freezing or cancelling the former wallet, transfer or reissue to a replacement wallet, and record updates.
52. Stolen Keys
Relevant Participants must rapidly escalate suspected key theft. IDSX may freeze a wallet, prevent transfers, suspend trading, require re-verification, initiate recovery or cooperate with authorities.
53. Mistaken Transfers
Blockchain irreversibility does not preclude legal correction of an invalid or mistaken securities transfer. Where appropriate, IDSX or the Issuer may require reversal, re-registration, forced transfer, cancellation and reissue, or another corrective action.
54. Corporate Actions
Digital Securities must support or appropriately reflect dividends, interest, voting, rights and bonus issues, splits, consolidations, mergers, tender offers, redemptions, conversions and liquidation distributions.
55. Record Date
For a corporate action with a record date, eligibility follows the applicable ownership record at that time. The Issuer must identify the authoritative record.
56. Dividends and Distributions
Distributions may be paid through traditional systems, approved digital assets, smart contracts or another lawful mechanism. The method must be disclosed and preserve investor rights.
57. Voting
Blockchain voting may be used where legally permitted. Ensure eligible holders can vote, duplicate votes are prevented, entitlement reflects legal ownership, records are auditable and confidentiality is maintained where appropriate.
58. Stock Splits and Consolidations
Adjust token supply for splits or consolidations consistently with legally issued securities.
59. Rights Issues
Determine rights entitlements from the applicable legal ownership record. Rights may be digitally represented where permitted.
60. Redemption
On redemption, extinguish or appropriately treat the underlying security, burn/cancel/disable the token, process payment, update ownership records and reconcile supply.
61. Delisting
Delisting does not itself extinguish the security. The Issuer must provide for continued ownership recognition, custody, transfers, investor communications, redemption where applicable and migration where appropriate.
62. Technology Migration
A migration between chains or infrastructure requires IDSX approval and a plan covering notice, snapshot, cancellation and replacement, supply reconciliation, wallet migration, custody, pending transactions, corporate actions and legal continuity.
63. Smart Contract Upgrade
Govern material upgrades and assess effects on investor rights, supply, transfer restrictions, custody, settlement, security, administration and legal treatment. Material changes may require IDSX approval and disclosure.
64. Token Contract Address
Publish the official contract address or unique digital identifier through an official IDSX or Issuer channel so investors can distinguish admitted securities from fraudulent or unofficial tokens.
65. Fake and Imitation Tokens
The Issuer and IDSX may act reasonably against tokens falsely claiming to represent a listed security. Use of a company name, ticker, logo, description or similar identifier does not give holders rights against the Issuer.
66. Custody
The custody model—direct investor holding, self-custody, Broker, institutional Custodian, nominee or other approved arrangement—must be clearly disclosed.
67. Self-Custody
Where permitted, investors are responsible for key protection subject to available recovery processes. Self-custody does not remove KYC, eligibility, transfer, sanctions or legal ownership requirements.
68. Custodian Responsibilities
Custodians must maintain controls appropriate to key security, segregation, wallet governance, transaction authorisation, reconciliation, disaster recovery, cybersecurity, continuity and beneficial-ownership records.
69. Securities Lending and Encumbrances
Securities may be lent, pledged, charged or otherwise encumbered only as permitted by law and IDSX Rules. Record encumbrances where required.
70. Investor Disclosure
Before admission, disclose material infrastructure information: blockchain and token standard, official address, custody and authoritative register, restrictions and wallet requirements, administrative powers, smart-contract and network risks, recovery and upgrade processes, and settlement arrangements.
71. Technology Risks
Inform investors of material risks including blockchain failure, contract vulnerabilities, cyber incidents, key loss, wallet compromise, congestion, forks, fees, infrastructure failure, migration and third-party technology risk.
72. No Guarantee of Blockchain Availability
Listing or approved technology does not guarantee continued blockchain operation, stable fees, vulnerability-free contracts, compatible wallets, unchanged governance or indefinite infrastructure availability.
73. Cybersecurity
Issuers and infrastructure providers must maintain role-appropriate cybersecurity for privileged access, key management, software development and deployment, monitoring, vulnerability management, incident response, backups, recovery and third-party risk.
74. Business Continuity
Material infrastructure must maintain continuity and recovery arrangements to preserve ownership records, investor rights, supply, transaction history, legal records and critical administration.
75. Incident Notification
The Issuer or relevant Participant must promptly notify IDSX of material unauthorised issuance, exploits, key compromise, blockchain attacks, reconciliation discrepancies, unauthorised transfers, wallet breaches, prolonged outages, lost ownership records or other material incidents.
76. Emergency Powers of IDSX
Where an incident threatens investors or integrity, IDSX may suspend trading, deposits/withdrawals, transfers or settlement; require wallet freezes or reconciliation, migration, enhanced disclosure or independent technical review; or take other action under IDSX Rules.
77. Role of Sponsor
The Sponsor must understand the structure sufficiently to assess legal rights, ownership, supply, investor restrictions, registry, contract controls, corporate actions, key risks and consistency between technology and Issuer disclosures.
78. Role of Broker
A Broker must ensure Clients meet applicable KYC, investor eligibility, wallet, transfer and product requirements.
79. Role of Trading Participant
A Trading Participant must ensure Digital Security orders comply with IDSX trading and settlement requirements.
80. Role of Custodian
A Custodian must safeguard Digital Securities under applicable Custody Rules and maintain accurate beneficial-ownership records.
81. Role of Issuer
The Issuer remains responsible for valid issuance, enforceable investor rights, accurate supply and ownership records, corporate actions, accurate disclosure and management of material technical changes.
82. Technology Provider
External providers do not remove Issuer responsibility. The Issuer must oversee material smart-contract, blockchain, wallet, registry, settlement, bridge, custody-integration and corporate-action providers.
83. Outsourcing
Infrastructure may be outsourced, but the responsible Issuer or Participant remains accountable for IDSX Rule compliance.
84. Regulatory Classification
Before admission, Issuer and Sponsor must determine regulatory classification. IDSX may require legal analysis or opinion, regulatory confirmation, exemption or designation analysis, or other evidence of legal status.
85. Cross-Border Securities
For securities under another jurisdiction’s laws, identify governing corporate law, investor rights, transfer and register requirements, offering and foreign-ownership restrictions, applicable securities laws and enforceability of digital representation.
86. Jurisdiction Does Not Follow Blockchain Location
Determine legal obligations from relevant legal relationships and laws, not solely the location of nodes, validators, cloud servers or technology providers.
87. IDSX Admission Approval
No Digital Security may be described as IDSX-listed or admitted unless formally admitted. Technical infrastructure approval alone does not approve the Issuer or security.
88. Technical Approval
IDSX may separately review the Issuer, product, application and technical implementation. Admission may depend on satisfactory technical review.
89. Change Control
Notify IDSX in advance where practicable of material architecture changes, including chain migration, contract replacement, custody or registry model, bridge or settlement changes, major upgrades or changes in administrative control.
90. Audit Trail
Infrastructure must preserve an audit trail capable of reconstructing issuance, ownership, transfers, minting, burning, freezes, forced transfers, corporate actions, contract upgrades and administrative actions.
91. Record Retention
Retain relevant records for periods required by law and IDSX Rules. Historical ownership information must remain available when a blockchain or contract is replaced.
92. Legal Record Prevails Where Required
Where blockchain and legally authoritative records conflict, the legally authoritative record prevails to the extent required by law. Investigate and correct discrepancies promptly.
93. Smart Contract Does Not Override Law
Automated code outcomes do not override Applicable Law, court orders, regulatory directions, enforceable investor rights, valid corporate actions or IDSX Rules.
94. Code Is Not Sole Legal Authority
“Code is law” does not apply where inconsistent with enforceable rights or IDSX Rules. Code implements legal rights and market processes; it does not replace them.
95. Prohibited Conduct
No person may knowingly mint unauthorised securities, falsify supply or ownership, bypass wallet or eligibility controls, create fraudulent securities, exploit contracts to obtain securities improperly, conceal beneficial ownership, interfere with reconciliation, misuse administrative keys or otherwise misuse infrastructure.
96. Enforcement
Breaches may result in correction, enhanced supervision, transfer or trading suspension, technical remediation or replacement, Participant restriction, delisting, suspension or termination of Participant status, or referral to an authority.
97. IDSX Technical Standards
IDSX may publish standards for token types, blockchains, wallets, contract interfaces, whitelist APIs, settlement, custody, registry reconciliation, corporate actions, cybersecurity, key management, bridges and technical certification.
98. Technology-Neutral Interpretation
Interpret these Rules neutrally across blockchain, token, wallet, smart-contract and distributed-ledger technologies, including equivalent methods performing substantially equivalent functions.
99. Applicable Law
Digital Securities remain subject to Applicable Law. Financial-product obligations continue regardless of digital representation; these Rules create no exemption.
100. Amendments
IDSX may amend these Rules to reflect legal or regulatory change, technology, market practice, cybersecurity and infrastructure developments, or other relevant matters.
101. Effective Date
These Rules take effect on the date determined and published by IDSX.
IDSX · Digital Securities Rules — Version 1.0