Skip to content

Design principles

Novrinex treats an exchange as shared financial infrastructure. The network exists so that markets and applications can expand around one execution, settlement, and risk system without creating conflicting records of ownership or fragmenting the financial layer each time.

The design principles below turn that purpose into rules for the protocol.

Two compatible orders do not make a completed trade by themselves. The resulting positions, fees, profit and loss, and margin must settle at the same time.

Novrinex calculates the entire transition before committing it. If one part is invalid, the market state remains unchanged.

Balances, orders, fills, and positions must refer to the same history. Novrinex L1 is the authority for native market state; interfaces and indexers are views of that state.

This lets applications compete on experience and analysis without asking traders to accept a separate ledger for each product.

Safety actions retain access to the network

Section titled “Safety actions retain access to the network”

Congestion is most dangerous when it prevents traders from cancelling orders or prevents the system from updating prices and reducing insolvent positions.

FairFlow assigns capacity according to financial purpose. Oracle updates, liquidations, cancellations, and reduce-only orders receive defined access before transactions that create new risk.

Markets share capital only through a named risk domain. The domain identifies the eligible collateral, admitted markets, margin policy, insurance, and loss-allocation rules.

A builder market begins with its own resources and exposure limits. Its growth does not give it an implicit claim on collateral or insurance elsewhere in the network.

Market builders can choose what market to create and how to develop its liquidity. They cannot redefine the accounting system or write directly to trader balances.

Every native market inherits the same order, margin, oracle, funding, and liquidation framework. Market ownership and financial authority remain separate.

A network cannot remain responsive if one transaction can demand unlimited computation. Orders, oracle batches, liquidations, and blocks therefore have explicit limits.

When a process requires more work, it continues through further bounded actions rather than monopolizing a block.

The chain publishes ordered, versioned events describing committed state changes. An indexer can rebuild market history and account views from those events without becoming an authority over the underlying balances.

Snapshots shorten recovery, while replay verifies that the restored service reaches the same state.

Exchange performance is measured across the full path from receipt to finality and client delivery. Order latency, cancellation latency, data publication, and recovery are observed separately under sustained traffic, bursts, and liquidation load.

The relevant result is how the complete market behaves when demand is high, not how quickly an isolated component runs in ideal conditions.