Infrastructure
June 2026
No one settles real money on a number that can go stale, be gamed, or be faked. This memo lays out the guard against each of those failures, and the process that resolves a disagreement once both parties have acted on the same figure.
An oracle is the single number a set of counterparties agrees to trust. Ravariant is that oracle for private funds, and it holds none of the loans it reports on and takes no side among the parties that do.
Lenders extend NAV loans to private funds, secured against the fund's net asset value. When one of those loans goes bad, the loss lands in a private book an accountant later confirms, leaving the risk on these loans with no shared figure anyone can cite. Ravariant publishes that figure as PARI, the realized audited loss for a cohort of similar loans. A pricing engine or settlement system reads PARI and acts on it without a human in the loop, which is why the figure has to be unambiguous before it ships.
| Label | The plain question it answers | Example |
|---|---|---|
| What it means | What does this number measure? | Realized audited loss, period to date |
| When | What period, published when? | Period ending March 31, released June 9 |
| Which method | Which method produced it? | loss_index 3.2 |
| Can it change | Could it be corrected later? | Corrections ship as a new release |
| Where it came from | Did it come from Ravariant, unchanged? | Signed at release; the signature checks |
Those five labels are what let software treat the figure as settled rather than a vague suggestion.
PARI rests on losses the lenders actually took. Every loan that joins the standard commits to report its losses, and the anchor of the figure is the lender's annual audit, where the lender's own outside accountant confirms that a loss is real and sizes it. The fund and its manager submit nothing, which keeps the party with the strongest incentive to flatter the number out of the inputs entirely. Many lenders blend into one cohort figure, so no individual loan can be read back out of it.
Audits land once a year, and systems still have to act in the months between them. The fund administrator, the firm that strikes a fund's value on a set schedule, supplies an interim reading to bridge the gap, and the annual audit overrides that reading once it arrives. Each release states which of the two a reader is holding.
| Source | How often | Who confirms it | Role in the number |
|---|---|---|---|
| Lender audit | Once a year | Lender’s outside accountant | The confirmed fact, size verified |
| Administrator reading | Between audits | Fund administrator | Interim, replaced by the next audit |
| Fund or manager | Never | Not used | They hand in nothing |
PARI can fail three ways, and this page takes the first. A figure goes out of date when it stops updating while systems keep acting on it, whether an audit runs late, an interim reading slips, or a feed breaks. The danger is quiet: a system reads a figure from a period months gone as though it were current, nothing trips, and the cost surfaces only later.
The guard is to put the age in front of any reader who might miss it. Every figure carries the period it covers, and every feed sends a heartbeat, a small signed note confirming the feed is alive and the last figure still stands, which separates a feed that is merely quiet from one that has broken. A feed that misses its schedule flips to a visible stale flag that software can read directly.
| Feed | Expected schedule | Last update | Published status |
|---|---|---|---|
| Cohort loss, from audits | Yearly | 47 days ago | CURRENT |
| Cohort reading, administrator | Quarterly | 11 days ago | CURRENT |
| Cohort reading, administrator | Quarterly | 124 days ago | STALE, late, heartbeat alive |
How to act on a stale figure belongs to the system reading it, governed by rules its own committees approve, whether that means holding at the last confirmed figure, widening a buffer, or pausing automatic changes. Ravariant owns only the narrow guarantee underneath all of that, that no system can mistake an old figure for a fresh one.
A figure gets gamed when someone with money riding on it works to nudge it their way, so a publisher has to design as though they will. LIBOR is the cautionary case: a rate banks reported about themselves with no outside check, one traders learned to push.
The lender sits closest to PARI because it reports its own loss, so the first guard is a tight definition of what a loss even is. Only a realized credit event counts: the borrower failed to repay, the collateral was worked out below the loan, and the audited shortfall is the loss.
| Treatment | The event | Why |
|---|---|---|
| Counts | Fund cannot repay, collateral worked out below the loan, auditor confirms the shortfall | A real credit event the lender cannot size alone. |
| Excluded | Voluntary sale of the loan at a discount | The lender could print a loss to order. Not a credit event. |
| Excluded | A soft valuation writedown | A discretionary mark, an opinion, not a settled fact. |
| Excluded | Anything below the conforming line | Not the loss this number reports. |
Three further guards close what the definition leaves open. PARI draws only on losses an outside accountant confirmed, the method is published and exact so the same audited inputs return the same figure, and any change to it ships ahead of time under a new version.
The third failure does not reach the publisher. A system acts on a figure that did not actually come from Ravariant, either an invented release or a genuine one relayed with its value altered. The farther a figure travels, through vendors, resellers, and copies of copies, the more room there is for that to happen.
The guard is a signature applied once, at the source, the instant a figure is published. It works as a tamper seal over the value, the meaning, the method version, and the period bound together, so altering any one of them breaks the seal. Anyone downstream can verify it against Ravariant's public key without calling Ravariant first, and the same mechanism forces a single official copy, since for each feed, method version, and period exactly one signed figure exists.
| Reader | How it reads | What it holds |
|---|---|---|
| Analyst on the dashboard | Sees a chart from the number | Same signed number, on screen |
| Software pulling the feed | Fetches it automatically | Same signed number, raw |
| Lender’s risk system | Loads the feed each night | Same signed number, seal checked on load |
| Settlement system | Reads it at settling | Same signed number, seal checked first |
No premium tier carries better data and no channel gets a private version. When two readers disagree about what the figure was, the dispute reduces to comparing seals, which either match or they do not.
When two parties disagree about what the figure is, the oracle needs a referee, and Ravariant's determination mechanism is that referee. It resolves the question against the audit, so the answer is a confirmed fact rather than a judgment call. A written rulebook and a set of cross checks point to the audited release the rules make official, and a committee ratifies it. Nothing is invented along the way, because the accountant confirmed the loss before the disagreement ever started.
Figures do get corrected, when an interim reading gives way to the annual audit, when an accountant restates a confirmed loss, or when a late confirmation arrives. Each correction ships as a new release carrying its own time stamp and a stated reason, while the original release stays live with its seal intact. The record accumulates rather than being overwritten.
| Release | Value | Released | Reason |
|---|---|---|---|
| Period ending March 31, release 1 | Administrator reading | May 12 | Interim reading from the administrator |
| Period ending March 31, release 2 | Audited loss | June 9 | Audit confirmed; replaces the interim reading |
A deal that closed on May 20 settled against release 1, the official figure at that moment. The June 9 correction does not reach back and void it, since anyone can call up release 1, check its seal, and reproduce exactly what was settled. Whether a later correction reopens an earlier deal is for the parties and their own rulebook to decide, not Ravariant. Method changes run under the same discipline, each under a new version announced before it takes effect.
Reading the published figures is open to anyone, and that openness is what builds the standard, because a reference number only holds if everyone argues from the same figure. The revenue comes from the systems that settle trades on PARI, which pay Ravariant a license. It is the index publisher model: the level of a well known index is free to look up, while the products that settle against it pay the firm that publishes it.
The fee follows from the role. Ravariant publishes the figure, takes no side, and makes no loans, while the parties that settle on it carry the risk and keep the gains. It is paid as the referee rather than as a player, and that neutrality is the product, since a reference number published by someone holding a position in the outcome carries a conflict the whole structure exists to remove.
For the entry rules that let separate loans be pooled and indexed, see doc 00 The Settlement Standard for NAV Loan Risk. For how the audited loss figure is built, see doc 02 How the Numbers Are Made. For what settles on it, see doc 04 Use Cases.