A transfer that breaks the rules does not happen.
Stobox Orbit is a permissioned tokenization protocol: contracts that issue and govern tokens for real-world assets. Investors are verified once, the rules live inside the token, and anyone can read the state. Today they run on Base; not yet live.

- ✓
Base
- ✓Not yet live
- ✓No Stobox key controls an investor's assets
A plain token can be sent by anyone to anyone. A security cannot.
The gap is normally filled by a transfer agent, a spreadsheet and a lawyer, so non-compliance is found after it settles. A security token has to answer on every transfer: may this person hold this asset, now, in this amount?
Transfers are slow and manual
Every movement waits on somebody checking a list, so the register and the paperwork drift apart.
Ask yourselfHow long does a transfer of your instrument take today, and who checks it?
Compliance is retrospective
The breach is found in an audit, after it has settled, when it is expensive to unwind.
Ask yourselfWhen did you last find a transfer that should not have happened?
Ownership is opaque
Nobody outside can read who holds what, under which rule, without asking you for a spreadsheet.
Ask yourselfCould a counterparty rebuild your register without asking you?

A transfer that breaks the rules does not fail an audit later. It does not happen.
Every transfer is checked against the token's own rules before it executes. A compliance bug can stop trading. It can never corrupt supply.
Seven questions, in order, before any balance changes.
Anyone can ask first: canTransfer and whyBlocked are free, never revert, and name the rule. Pick the question a transfer fails on, or let it pass. This is an illustration of the order, not a live token.
All seven questions are answered yes, so the balance moves and the register updates in the same transaction.
Every party, every step, one ledger.
Pick a story and follow it from the first instruction to the last record on Base: an offering, a transfer between holders, a distribution, a redemption, and an enforcement action. Each step names who acts, whether it happens on Base or off it, and what the chain records.
Talk to usIs Orbit right for your asset?
Tell us the asset, the jurisdiction and who has to hold it. We will say plainly whether Orbit fits, and what is still in development.
The life of a token, as the contracts run it.
01Create
One call to the factory deploys the token, its treasury and its rule set from a preset, writes the instrument record and grants the issuer's roles. The factory then revokes its own.
What it gives youCreated, declared and handed over, in one transaction.
02Hand over
Each role moves to the issuer's Safe in two steps: propose, then accept from the Safe. The issuer labels its wallets so the wallet map covers all supply.
What it gives youNo platform role remains.
03Onboard investors
An investor is verified once as a subject, identified by a hash and never a name. Their wallet binds with their own signature. Named issuers write claims with an expiry.
What it gives youEligibility is a claim, not a spreadsheet row.
04Offer and settle
An offering escrows payments in the treasury and reserves tokens. Nothing moves until settlement. Anyone can settle once the minimum is met, or open refunds if it is missed.
What it gives youEach purchase becomes the issuer's only when delivered.
05Transfer
Every movement passes the seven checks. The register and the history can be rebuilt from the event logs alone.
What it gives youThe same object everyone is looking at.
06Distribute
Dividends, coupons or fund payouts are published as a list of entitlements at a record block and funded in the same call. Claims go only to the holder.
What it gives youMoney is never swept back to the issuer.
07Act as an officer
Freezes, lock-ups and pauses carry a reason and an evidence hash. Forced operations exist only if the optional emergency facet is installed, and wait in public first.
What it gives youEvery act that could take something from a holder is announced.
Every act that could take something from a holder is announced first.
The delays are enforced by the contracts, not by a policy document. Bar length shows the order of the waits, not a scale.
Treasury withdrawalAnnounced first, paid a day later.
Forced transfer, burn or mintOnly if the optional emergency facet is installed. Announced, then executed after the delay, with a reason and an evidence hash.
Directory replacementThe shared component addresses are named in one place, with history. A replacement waits.
Code changeAn upgrade of a token's logic is announced and waits at least this long.
Freeze review dateA freeze names the date it is reviewed, no later than this.
Twelve parts, each doing one job.
Orbit is a protocol, not a screen. It ships no user interface: consoles, client portals and agents are consumers of it, and Compass is the visual front end Stobox lays over it.
Creates the token, its treasury and its rule set in one transaction, and keeps no role.
An ERC-20 whose ledger functions cannot be replaced. Everything else is a facet.
Small stateless rules, each asking one question, composed per token from a preset.
Starting configurations for Reg D 506(c), Reg S, funds and Luxembourg vehicles. Not legal advice.
Subjects, bound wallets and claims, each with a named issuer and an expiry.
Dated restrictions with an origin that decides who can lift them and how fast.
Primary sales, escrow and refunds. Payment becomes the issuer's only when the purchase is delivered.
Pays holders at a record block from a published list of entitlements.
Figures in channels with named signers, an evidence hash and a staleness flag.
One place that names the current address of every shared component.
Read-only, with no admin, keys or money. Reports tokens, attested value and who holds roles.
Links a fund's class tokens together.
Thirteen properties, each saying how it is met.
Nothing here is a promise with a date. A property is met by code when a test proves it, met by configuration when the deployment sets it, partial when part of it is built, and planned when it is not.
Roles sit in Safes, and destructive acts wait on a timelock.
PartialThe supply cap is fixed at deployment.
Met by configurationAfter go-live no platform role remains, and a handover event records it.
Met by codeEligibility is a claim with a named issuer and an expiry, never a blanket bypass.
PartialLock-ups are written at distribution and cannot be bypassed.
Met by codeForced operations carry a reason and an evidence hash in a dedicated event.
Met by codePause stops minting, burning, forced operations and treasury replacement.
Met by codeLimits come from a policy with an expiry.
Met by codeA redemption names its settlement reference.
PartialEvery contract is verified and its interface equals its code.
PartialThe on-chain wallet map covers 100 percent of supply.
Met by codeValue attestation is on chain with a staleness flag.
PartialThe treasury and the sale module live under the same regime as the token.
Met by codeVerified once, as a hash. Never a name.
No name and no document is on chain. Subject ids, wallet addresses, claim records and evidence hashes are pseudonymous, and are treated as potentially personal data. The register is readable by anyone, so Orbit never claims that transfers are invisible. Erasure is an off-chain procedure; no function deletes an on-chain record.
Stobox holds no private keys that control an investor's assets. Investors bring their own wallet, or create one through a third-party wallet service under their own control.

Every number names the call that reproduces it.
Value is attested value: a named attestor, a fresh figure, stale ones excluded. Aggregators label it TVL; Orbit does not. Orbit metrics begin at the first live deployment. Demo readings are labelled and never reported as Orbit metrics.
A lens call at a named block.
Units outstanding are supply minus the treasury balance.
Units outstanding times a fresh figure with a named attestor. Stale figures are shown, never summed.
Settled offerings, per currency, never summed across currencies.
Per currency.
People and entities, never wallets.
From event logs only.
Anyone can reproduce a metric from the chain with the lens and the event logs.
Two ways in, and no screen to learn.
Web3 reads are free calls through any RPC; writes are signed by the role holder. The Orbit API, an HTTP service in front of the contracts, is planned: reads through the lens and an indexer, writes returned unsigned, holding no key any contract recognises. Every external function carries documentation, and the build fails on a gap.
Web3, today
- Read
- Free calls: canSend, canReceive, canTransfer, getFrozenTokens and whyBlocked, which never revert.
- Write
- Signed by the role holder, or proposed to the issuer's Safe.
- Standards
- ERC-20, EIP-2535, ERC-165, ERC-2612, EIP-712, ERC-1271 and ERC-1404.
Orbit API and SDK, planned
- Reads
- Through the lens and an indexer, with signed webhooks.
- Writes
- Returned as an unsigned transaction, an EIP-712 payload or a Safe proposal. The API signs nothing and pays no gas.
- SDK
- TypeScript, generated from the references. It signs nothing either.
Built for Base.
Base is the first chain for Orbit. The whole stack is built on Base. Nothing here is live yet, and no date is given.
Orbit on Base. Not yet live.
The current stack was deployed on Base on 1 October 2026: 40 contracts, each with its source verified on Basescan, and 128 transactions, none failed. One demo token under Reg D 506(c) sold 3,500 units to two demo investors, settled and delivered with a lock-up. The contract directory on Basescan names every component.
Built and tested
- Tested contracts, formal proofs of the treasury, pricing and rounding paths, and tests that neuter each safeguard to see it caught
- Documented every external function carries documentation, and the build fails on a gap
- Deployed on Base the whole stack, run end to end
Not yet
- Live deployment not yet, and no date is given
- Audit an internal audit of the frozen code gates the first deployment
- Orbit API, SDK, alerting planned
- Metric views built, not deployed; aggregator submissions follow the live deployment
- Licences Orbit claims no regulatory licence and no regulatory approval
Not custody, not a market, not an approval.
Orbit does not
- Approve
- Whether a configuration is right for an asset is the issuer's decision, with counsel.
- Hold keys
- It is not custody and not a signer for others.
- Vouch
- It shows who signed a figure, when, on what evidence and whether it is fresh. It does not guarantee an attestor is honest.
The issuer still supplies
- The law
- Marketing, solicitation, filings, licensing and the legal choice of regime are off chain.
- Monitoring
- Orbit runs no transaction monitoring or screening for an issuer.
- The records
- Reconciling the off-chain register with the chain is the issuer's job.
Not sure where your asset stands? Score it first.
Twenty-five questions about the asset, the paperwork and who owns what. You get a score across seven dimensions, and a plain list of what is missing. It takes about eight minutes.
About eight minutes. Nobody calls unless you ask.
- 25questions about the asset
- 8minutes, about
- 7dimensions scored
What is missing
Move the sliders and watch the profile change. The real score comes from twenty-five questions about your own asset.
One record, one package, one front end, one protocol.

One verified record of your company, every answer with its evidence.
Read →
Offering documents written from the record and signed off by your counsel.
Read →
The console and the passport an issuer and a counterparty actually use.
Read →
The permissioned tokenization protocol underneath: rules enforced on every transfer.
You are here →
Building something that needs rules inside the token?
Tell us the asset, the jurisdiction and who has to hold it. We will say plainly whether Orbit fits, and what is still in development. Stobox is a technology provider; regulated activity runs through licensed firms.
Talk to usSee Compass →Updated 3 October 2026