ANIMA/KERNEL · REAL ESTATE

Every closing,
a signed chain every party can replay

A tamper-evident audit layer for the whole transaction — identity, offer, escrow, funds, title, deed — across both US and EU law in one kernel. Court-reproducible proof that a specific party made a specific decision at a specific time. It does not warrant clean title; it proves what happened.

13 capsules · BUILT & full Go↔Rust parity Platform integration · ROADMAP Business overview · June 2026
01 · the problem

A closing touches six parties.
None of them share a signed record.

Buyer, seller, agents, title, escrow, lender, recorder — each in a siloed system. The closing package is a PDF stack on a file server. When wire instructions are spoofed, a deed is stolen, or a closing is litigated, there is no canonical signed event ledger to replay. The same gap exists in every jurisdiction.

$275M

US real-estate wire fraud losses in 2025 — up 59% YoY (FBI IC3). Business Email Compromise overall hit $3.04B; the vector is spoofed wire instructions between parties with no shared signed record.

A signed escrow chain with verified parties makes a rerouted wire detectable before funds move.

63%

of industry participants witnessed title fraud or deed theft in the past year (NAR 2025). Reversing a fraudulent transfer costs $50–150K in legal fees; 16 US states have no deed-fraud law.

No cryptographic binding ties the grantor's identity to the signed closing record.

41 days

Average US residential close — 150–200+ discrete tasks across 6+ independent parties. The EU adds 3–4M closings/yr under 27 distinct land-law regimes.

Reconstructing a disputed closing means subpoenaing six parties for six different versions.

The common failure: no shared, signed, replayable record of the transaction.
02 · the root cause

The transaction lives as six private files,
not one signed chain.

Each party records their own slice in their own system. Nothing binds the escrow release to the offer it settles, or the deed to the identity that signed it. Anima has each party sign their own event at the moment it happens — and chains each capsule to the digest of the one upstream.

// escrow event · EIP-712 typed · secp256k1
{
  "type": "escrow_event",
  "kind": "RELEASE",
  "acceptance_digest": "0x9f3c…b71a",
  "escrow_agent": "party:0x41…",
  "amount": 487500_00,
  "ledger_proof": "0xa1b2…2345"
}

→ The deed-transfer capsule will not hash unless both a title-verification digest and a funds-confirmation digest are present. The closing condition is enforced in code, not workflow.

03 · are the laws helping us

Both legal systems now privilege
signed, attributable, timestamped records.

ESIGN + UETA · US

E-signatures carry handwritten weight when attribution is reliable. No specific technical standard is required — EIP-712 signed digests with party-identity chaining satisfy it.

reliable attribution

RON + SECURE Act · US

49 states + DC have permanent remote-notarization statutes; the 2025 SECURE Notarization Act adds interstate recognition. RON records need anchoring into the closing chain.

notarization, anchored

eIDAS 2.0 · QES · EU

QES has handwritten-signature effect across all 27 states. EUDI Wallets issue by end-2026; relying parties must accept them in 2027. Our capsule encodes all four regimes.

QES + EUDI native

Land-Registry Digitalization · EU + UK

HM Land Registry digital-by-default; Estonia's e-Land Register; Sweden's blockchain pilot. Mandatory digital submission with cross-border eIDAS recognition.

DeedTransferEU surface

FinCEN RRE Rule · US

Non-financed transfers to entities/trusts must be reported (vacated 2025, revision anticipated). The duty falls on settlement, title, and escrow agents — our RegulatorAuditView buyers.

AML audit demand

Independently replayable · both

No law mandates the technical form — but every one rewards a record that opposing counsel or a regulator can self-verify offline in minutes, not weeks of discovery.

court-producible
04 · what's out there

Everyone coordinates, signs, or underwrites.
No one produces the shared chain.

COORDINATE — the workflow

Qualia · SoftPro · Resware

Practice-management software for title and escrow. They produce a closing file that lives in their database — a workflow extract, not independently verifiable outside the platform.

database, not proof
SIGN / NOTARIZE — one event

Proof · DocuSign · Snapdocs

E-signature, RON, eVault. They attest that a signature happened — but the audit log is proprietary and platform-bound. They don't chain identity → offer → escrow → funds → deed.

single-event audit log
UNDERWRITE / CHAIN — risk & ledgers

Doma · Propy · Lantmäteriet

AI title underwriting and blockchain land-registry pilots. Faster risk pricing, or a new on-chain registry needing a government mandate — not a signed, party-held chain over existing rails.

new infra, not a shared chain
The empty slot: a chain-linked proof each party signs, re-verifiable offline by anyone.
05 · what we provide · code-verified

Thirteen built capsules. One closing chain.

Every capsule is an EIP-712 typed struct, secp256k1-signed, with input schema, output schema, unit test, and a Go↔Rust/WASM parity-emit test in CI. EU-jurisdiction capsules marked with a purple edge. Source: internal/realestate/signing/ · range 0x9000…0010–00F0.

Capsule
ID
What it attests
Status
party_identity
0x9000…0010
KYC of any of 12 party kinds; mDL / EUDI Wallet method, eIDAS LoA + NIST IAL assurance.
✓ parity
purchase_offer
0x9000…0020
Signed offer: price, earnest money, contingencies hash, closing date, chained buyer identity.
✓ parity
offer_acceptance
0x9000…0021
AS_IS / COUNTER / WITH_ADDENDUM; chains the offer digest, counter-terms enforced in code.
✓ parity
contract_assignment
0x9000…0022
Wholesaler assigns contract position to end buyer/investor; chains the acceptance digest.
✓ parity
escrow_event
0x9000…0030
OPEN / FUND / RELEASE / REFUND / AMEND in one capsule; chains acceptance or assignment.
✓ parity
funds_confirmation
0x9000…0031
Bank wire/ACH/SWIFT receipt; account ids hashed at platform layer; chains escrow digest.
✓ parity
title_verification_us
0x9000…0040
US title agent attests CLEAR/CLOUDED/REJECTED with APN, county office, chain-of-title hash.
✓ parity
title_verification_eu
0x9000…0041
EU notary/registrar attests title vs land registry + cadastral ref (Grundbuch/Cadastre).
✓ parity
deed_transfer_us
0x9000…0042
County-recorder deed; requires title + funds digests non-zero before it will hash.
✓ parity
deed_transfer_eu
0x9000…0043
Two-step NOTARIZED → RECORDED conveyance into Grundbuch/Cadastre; distinct 15-field struct.
✓ parity
e_signature
0x9000…0050
One struct, four regimes: ESIGN/UETA + eIDAS SES/AES/QES; QES requires a QTSP party.
✓ parity
regulator_audit_view
0x9000…0060
Signed receipt of who viewed which receipts, under what authority, when — Merkle root of views.
✓ parity
external_anchor
0x9000…00F0
Anchors any digest to RFC 3161 TSA, eIDAS QTSP, OpenTimestamps, chain, or court registry.
✓ parity
06 · the chain is the moat

Identity to deed,
each link signed by the party who was there.

No incumbent produces this: a chain where the title agent signs the title capsule, the bank signs the funds capsule, the recorder signs the deed — each referencing the digest above it, each re-verifiable offline.

identityparty_identity
contractoffer → acceptance
moneyescrow → funds
titletitle_verification
gated closedeed_transfer ✓
2-of-2

The deed_transfer capsule structurally refuses to hash unless both a title-verification digest and a funds-confirmation digest are non-zero. The closing condition — title clear, money settled — is a cryptographic invariant, not a checklist. The same gate exists in both the US and EU deed structs.

→ One kernel, two legal systems: distinct US and EU structs for title and deed, a four-regime signature capsule, and an anchor to any existing trust authority. No new blockchain required.

07 · market

The provenance layer
under every property transfer

Residential closings · US + EU
9–10M

Closings per year — ~5–6M in the US ($2–3T value) plus ~3–4M across EU member states. Every one needs a signed identity → deed chain that no system produces today.

Risk-absorber spend · proxy
$17.6B

US title-insurance premiums written (ALTA, 2023) — the industry that directly absorbs the fraud and title risk Anima attests to. EU notarial and registry fees add a parallel pool under eIDAS.

One signing kernel · many buyers
Title / escrow
verification
Title insurers
risk absorber
Banks / lenders
funds
Notaries / RON
eIDAS · SECURE
Land registries
deed recording
Regulators
FinCEN · AML
08 · honest state

What is built — and what is not.

Anima is not a title oracle. It does not warrant that title is clean or that no fraud occurred — it attests that a specific party made a specific decision, with these inputs, at this time, and lets anyone replay it. That distinction is the legal moat.

Built & parity-tested today

  • All 13 capsules — EIP-712, secp256k1, schemas + Go↔Rust/WASM parity in CI
  • Distinct US and EU structs for title verification and deed transfer
  • Deed transfer gated on title + funds digests (2-of-2, enforced in code)
  • Four-regime e-signature (ESIGN/UETA + eIDAS SES/AES/QES)
  • External anchor to RFC 3161 TSA / eIDAS QTSP / court registry

Roadmap — not yet built

  • WASM build pipeline verified for real-estate capsule IDs (fintech is the reference)
  • Platform integration — no API/SDK into Qualia, SoftPro, Snapdocs yet
  • On-chain registry deployment (runs fully off-chain at launch, ChainID 0)
  • FinCEN filing-format output + RON audio/video capture
  • Lender / MISMO origination capsules (vertical covers offer → deed only)

One signed chain:
identity, offer, money, title, deed.

Each link signed by the party who was there. Re-verifiable offline, by anyone, in any jurisdiction.
For the first time, a closing can prove itself.

Pilot the kernel → Read the brief →
anima.kernel · software secp256k1 · EIP-712 · Merkle ledger · real-estate vertical · US + EU · © 2026