Autonomous arbitration for tokenized RWAs

Too small to litigate.Too big to walk away from.

When capital is locked in a vault against a real-world obligation and the parties disagree, the money is stuck. Arbitration costs more than the claim, so the dispute is never resolved at all. Judr reads the contract and the evidence, returns a verdict with a complete audit trail, and the vault settles against it.

  • Every verdict names the clause that decided it
  • Confidence is measured across re-runs, never self-reported
  • Funds move on-chain only after the appeal window closes, or a reviewer decides
Fig. 1Judr’s own interface, telling one story. A. Moreau and B. Adeyemi are a sample case; the reasoning shown is a real decision, made live on SERV on 26 September 2026 and saved as it came back, timings included.

How it works

From a pile of documents to a decision you can audit.

Four stages, seven typed steps in the app. Each one produces output that is checked before the next is allowed to see it.

  1. Evidence is screened before it is read

    Evidence comes from the parties, so it is adversarial by construction. Every document is checked for text aimed at the adjudicator rather than at the facts - forged system turns, instructions to disregard the contract, demands for a particular outcome. Deterministic patterns catch what cannot be talked out of firing; a model pass catches the rest. High-severity hits are quarantined and excluded from the decision entirely.

  2. The contract becomes typed clauses

    Each operative term is extracted verbatim and given a stable identifier: the obligation, the deadline, the notice period, the exclusion. Nothing is paraphrased and nothing is invented. Every later step refers to clauses by id, which is what makes the final citation check possible.

  3. Evidence is weighed clause by clause

    Not in aggregate. For each clause in dispute, both sides' positions are recorded, the documents relied on are cited by id, and the clause is marked satisfied, breached or indeterminate. An honest indeterminate is worth more than a confident guess - the verdict is not permitted to rest on one.

  4. The verdict is verified, then posted - not executed

    A deterministic pass resolves every clause and evidence id the verdict cites and rejects anything that does not hold up. Then the verdict is posted with its digest and an appeal window. The vault refuses a release call until that window closes unchallenged, so being wrong costs a delay rather than somebody's escrow.

Bounded reasoning

One prompt gives you an answer. A graph gives you a record.

An arbitration decision that cannot be defended afterwards is worthless, because the whole point is that a losing party has to be able to accept it. So the work is split into narrow steps with explicit dependencies, each one schema-validated before the next may consume it.

screenpatterns + modelextract_clausestypedclassify_claimtypedevaluatetypedadjudicate ×3consensusverifydeterministicschema violation → repair in place
model step, schema-bound deterministic - plain code, no modeladjudicate runs three times; agreement becomes confidence

An audit trail, not an answer

Every step records its input digest, engine, schema result and output. A losing party can be shown precisely which clause and which document decided the matter - and can attack that step, rather than the system as a whole.

Confidence that is derived

Models are famously bad at reporting their own certainty, so Judr never asks. The decision is reached several times independently and agreement is measured, combined with the share of decisive clauses carrying a real finding. A verdict that changes when you run it again is not one anybody should act on.

Verification that is not a model

A model asked to check its own citations will agree with itself. The final pass is ordinary code: it resolves every clause and evidence id, and rejects a verdict resting on a clause that does not exist or on an indeterminate finding. Failure caps confidence hard.

Safeguards

The right reaction to an automated judge is distrust.

So the interesting question is not how confident the system sounds. It is what the system is structurally prevented from doing.

  1. A verdict moves no money by itself

    A verdict is posted, not executed. It carries a digest over the decision payload and opens an appeal window, and the vault refuses a release call until that window closes - the check lives with the funds, not with the caller. Only then, or after a reviewer decides an appeal, does the escrow agent pay the winner, and the case shows the transaction. An appeal halts settlement and escalates to human review; Judr cannot overrule one.

  2. Tampered evidence is quarantined, not cleaned up

    A document that tries to instruct the adjudicator is excluded from the decision entirely, and the exclusion is recorded in the audit trail. It is never sanitised and used anyway. Screening is deterministic first, so it holds even when the model pass is unavailable.

  3. A verdict must rest on something real

    Every clause and evidence identifier is resolved against what was actually submitted. A decision citing a clause that does not appear in the contract, or leaning on a finding the evidence did not settle, fails verification and is reported as failed rather than quietly shipped.

RWA Vaults · with IXS

Idle escrow is dead capital. Judr puts it to work.

While a dispute is open the escrow need not sit idle. A SERV reasoning step reads IXS’s live vault list and proposes a licensed real-world-asset yield vault or cash; a deterministic policy refuses anything it cannot reach or should not hold. At settlement the escrow is redeemed, Judr takes its fee from the yield, and the winner receives principal plus what is left.

That is the business model. Nobody pays out of pocket to have a dispute decided; the time the money was stuck pays for it. A dispute that lasts minutes cannot hold its own position: the vault’s contract forwards a deposit to custody at once, holds a 100 USDC minimum, and leaves finalisation to an IXS operator, hours to days by its history. So the agent keeps one standing position in the permissionless Avalanche vault, real USDC signed with the same key that pays winners on Base, and cases account against it. The worked figures below are a projection at the live rate.

Projection · 10,000.00 USDC · 32 days · not executed
Principal
10,000.00
Yield at 3.07% TTM, as IXS reports it
+ 26.91
Judr fee · 25% of yield, 20.00 floor, from yield only
− 20.00
Paid to the winning party
10,006.91 USDC

Principal is never touched. If the window is too short for the yield to cover the floor, the fee is whatever was earned and nothing more is owed.

Standing position · IX High Yield Bond (USDC) · Avalanche C-Chain
Status
finalised · shares held
Requested
100 USDC
Shares at 1.08282 USDC
92.3515
Worth
100.00 USDC

The request is on Snowscan; the state above is read from the chain when this page renders.

IXS vaults · live read · 3 Oct, 13:12 UTC
VaultChainAccessTTM yieldOn-chain
IX High Yield Bond (USDC) ixv1bscpermissionless3.07%-
IX High Yield Bond (USDC) IXHYBAvalanche C-Chainpermissionless3.07%823.45 USDC · share 1.08282
IX High Yield Bond (USDC) ix7540v1BSC Mainnetwhitelist3.07%-
IX High Yield Bond (USDC) IXHYBAvalanche C-Chainwhitelist3.07%-
  1. The agent proposes; the policy decides

    The SERV step sees chain, access terms, reported yield and live on-chain totals, and proposes a vault or proposes holding cash, with its risks stated. The policy is plain code: a vault that requires a whitelist the escrow agent is not on, a paused vault, a zero rate, or a proposal with no stated risk is refused, and the refusal goes on the record.

  2. Transactions are built, not signed

    Subscription and redemption requests are built with IXS’s own agent SDK as ERC-7540 call data and shown in the trail exactly as a signer would send them. Judr signs nothing on the vault’s chain. The redemption is requested when the verdict posts, because the vault operator finalises on its own schedule.

Built with

What is underneath.

SERV reasoning
Every model step runs against SERV's OpenAI-compatible endpoint, bound to a JSON Schema and re-validated locally on the way back. Invalid output is repaired against the validator's own error list rather than accepted.
Coinbase AgentKit
The escrow agent. A CDP wallet on Base mainnet holds the escrow as real USDC and pays the winning party with an on-chain ERC-20 transfer when a case settles; on testnet it tops itself up from Coinbase's faucet. Payouts are capped per address and per day, and a case is locked while one is in flight.
IXS vaults
Where the escrow earns while a dispute is open. The vault list, whitelist status and reported yield are read live from IXS's API; totals and share price for the Avalanche vault are read on-chain; and the agent holds a standing 100 USDC position in the permissionless Avalanche vault, requested with its own key through IXS's SDK and read back from the chain. Per-case deposits are accounted against it, not sent.
Next.js 16 · React 19
Server-streamed arbitration over SSE, vanilla CSS, no UI framework and no state library. Fifty-one unit tests run on Node's type stripping - no test framework, no build step - including the SERV client against a mock endpoint and the allocation policy against the recorded vault list.

Watch it decide. It takes about half a minute.

The demo runs a real dispute end to end: seven steps, a verdict that turns on a deadline neither party leads with, and an escrow that settles. Tick Include tampered evidence to watch an injected instruction get caught and thrown out.