Design principles
Novrinex treats an exchange as shared financial infrastructure. The network exists so that markets and applications can expand around one execution, settlement, and risk system without creating conflicting records of ownership or fragmenting the financial layer each time.
The design principles below turn that purpose into rules for the protocol.
A trade includes its settlement
Section titled “A trade includes its settlement”Two compatible orders do not make a completed trade by themselves. The resulting positions, fees, profit and loss, and margin must settle at the same time.
Novrinex calculates the entire transition before committing it. If one part is invalid, the market state remains unchanged.
Financial state has one authority
Section titled “Financial state has one authority”Balances, orders, fills, and positions must refer to the same history. Novrinex L1 is the authority for native market state; interfaces and indexers are views of that state.
This lets applications compete on experience and analysis without asking traders to accept a separate ledger for each product.
Safety actions retain access to the network
Section titled “Safety actions retain access to the network”Congestion is most dangerous when it prevents traders from cancelling orders or prevents the system from updating prices and reducing insolvent positions.
FairFlow assigns capacity according to financial purpose. Oracle updates, liquidations, cancellations, and reduce-only orders receive defined access before transactions that create new risk.
Risk follows explicit boundaries
Section titled “Risk follows explicit boundaries”Markets share capital only through a named risk domain. The domain identifies the eligible collateral, admitted markets, margin policy, insurance, and loss-allocation rules.
A builder market begins with its own resources and exposure limits. Its growth does not give it an implicit claim on collateral or insurance elsewhere in the network.
Builders share primitives, not privileges
Section titled “Builders share primitives, not privileges”Market builders can choose what market to create and how to develop its liquidity. They cannot redefine the accounting system or write directly to trader balances.
Every native market inherits the same order, margin, oracle, funding, and liquidation framework. Market ownership and financial authority remain separate.
Every action has bounded work
Section titled “Every action has bounded work”A network cannot remain responsive if one transaction can demand unlimited computation. Orders, oracle batches, liquidations, and blocks therefore have explicit limits.
When a process requires more work, it continues through further bounded actions rather than monopolizing a block.
Data can be reconstructed
Section titled “Data can be reconstructed”The chain publishes ordered, versioned events describing committed state changes. An indexer can rebuild market history and account views from those events without becoming an authority over the underlying balances.
Snapshots shorten recovery, while replay verifies that the restored service reaches the same state.
Performance includes difficult conditions
Section titled “Performance includes difficult conditions”Exchange performance is measured across the full path from receipt to finality and client delivery. Order latency, cancellation latency, data publication, and recovery are observed separately under sustained traffic, bursts, and liquidation load.
The relevant result is how the complete market behaves when demand is high, not how quickly an isolated component runs in ideal conditions.