The risk-engine estate

Machines that price risk, built to show their work.

Before Parallar sells protection on an asset, three questions need answers: how risky is this borrower, what is fair protection worth, and what does the market think?
Each answer is computed by a certified engine, and every number comes with a cryptographic receipt showing exactly how it was made.

Every number checkable · Every model versioned · Every assumption disclosed

Three questions, answered in the open

How risky is this borrower?

An engine reads the borrower's financial statements the way a seasoned underwriter would: debt, earnings, cash flow, payment history. From these it scores the chance of default. A built-in safety rule stops it from ever calling anyone "too safe to fail."

the fundamentals engine

What is fair protection worth?

A second engine turns that risk score into a fair annual price for protection, priced the same way the professional credit-insurance market does it. Safer borrower, cheaper protection; riskier borrower, dearer.

the CDS pricing engine

What does the market think?

Where a real market quote exists for the same name, a third engine reads it as a second opinion and blends it in. The recipe for the blend is published, never improvised.

the market benchmark & blend engines

Every hand-off is sealed

The engines pass their answers down a line, and every hand-off carries a tamper-evident seal: change even one byte of the data anywhere, and the chain of receipts visibly breaks. Nothing depends on trusting the operator. The seals do the trusting.

The five engines

Fundamentals v2

Reads the borrower's own numbers and scores default risk, anchored to decades of real-world default history by credit grade. A good story can tilt the score but never rewrite the base rate.

built · certification pendingaccuracy check: exact

CDS pricer Route A

Turns the risk score into the fair price of protection, using the same two-sided arithmetic the global credit-default-swap market runs on. The asset's terms are inputs; the method never bends per deal.

built · certification pendingaccuracy check: exact

Market benchmark

Reads a real, timestamped market quote and converts it into the market's own implied view of default risk. Kept clearly separate from the model's view: a second opinion, honestly labeled as one.

built · certification pendingaccuracy check: 1 part in a billion

Blend §2(d)

Combines the model's view and the market's view into one number, with the mixing recipe (70% model / 30% market) published and fixed. A name with no market quote keeps its model score. Nothing is invented.

built · certification pendingaccuracy check: exact

Portfolio

The engine already running behind the live testnet: it turns the whole covered book into a premium, an expected loss, and a worst-case reserve. These are the numbers a settlement actually pays on.

live on testnetaccuracy check: matched twin

The safety floor, visibly

Chance of default in a year, before and after the anchor

A model looking only at financial statements can talk itself into absurd confidence: odds of default of 1-in-a-million for a spotless borrower. The anchor forbids that: no borrower scores better than the safest credit grade's real historical base rate (about 2 in 10,000). Ordinary and troubled borrowers are barely moved. Each row is one example borrower; the scale stretches so tiny and huge risks fit together.

v1 · raw logisticv2 · cohort-anchored
data table
archetypev1 PDv2 PD
investment grade0.012 bp2.02 bp
strong0.13 bp5.14 bp
mid1.370%1.359%
stressed99.99%99.98%
near-default99.998%99.996%

What protection costs: the same engine, four borrowers

Protection on a safe borrower costs almost nothing per year. On a troubled one, the annual price explodes, and the expected years of premium collapse (right column), because a name close to default won't be paying premiums for long. That is exactly how the professional market behaves, which is the point: the engine reproduces it, checkably.

data table
namefair spreadRPV01
investment grade / strong< 1 bp4.63 y
mid75 bp4.47 y
stressed40,832 bp0.15 y
near-default43,856 bp0.14 y

One proof. Two chains.

Every settlement boils down to a small sealed receipt, 208 bytes plus a proof, that any chain can check for itself. Stellar checks it and pays out. An Ethereum-style chain checks the same receipt and publishes the verified facts, so lending markets there can rely on them without trusting anyone's word, including ours.

No bridge. No wrapped assets. No oracle committee. Read-only verification mirroring: the mirror is a fact oracle whose facts are proofs.

journal.v1 · 208 B frozen layout · sha256-keyed on both chains · 5-input Groth16 layout shared verbatim

What the receipts do and don't prove, in plain terms: a receipt proves the math was done correctly, by the exact published version of the engine, on the exact data provided. It does not prove the data itself is true (that is a separate, signed attestation), and it does not prove the model is wise. The example calibrations on this page are realistic illustrations, not fitted to live data. Every prediction is recorded so its accuracy can be checked against reality later. The engines shown as "certification pending" are finished, tested code awaiting their final cryptographic registration.

For practitioners: PD/LGD scorecard with a grade × sector through-the-cycle cohort anchor · ISDA-lineage two-leg CDS pricing on a flat hazard · credit-triangle market-implied PD (risk-neutral, labeled) · pinned log-odds blend with a disclosed Q→P haircut · bit-exact fixed-point↔float parity gates · full specifications in the documentation.