Program structure (milestones, source-of-funds, budget), verified-module identifiers, and the integration point on your existing payment rail. No changes to your fiscal-agent or Treasury relationship.
Release funds only when the milestone is real.
Audit it forever.
Government housing programs disburse hundreds of millions every year. Keystone's Disbursement Rail lets your program release funds only when the registered module has actually hit the verified milestone — no invoice trust, no over-disbursement, no audit gap.
Three things every program-office conversation opens with.
Funds continue to flow through your existing Treasury, state, or fiscal-agent rail. Keystone never holds or transmits customer funds — we authorize the release signal against verified state and log every event for the IG.
One live milestone-release path, one program office, 10-module sample. Full IG-queryable audit trail on every authorization. 20-30bps SaaS usage fee visible on each release record.
What's broken today
A typical CDBG-DR or LIHTC disbursement happens because someone submitted an invoice and someone else signed off. The invoice says the milestone is met. The auditor years later has to reconstruct whether it actually was. Inspector general reports stack up. Programs that should have released $50M in a year released $12M because nobody could prove anything.
What Keystone fixes
- Verified milestone — the registered module's state (certified / completed / installed) is the release-authorization trigger, not an invoice
- Remaining-budget enforcement — program budget tracks per-milestone disbursement; over-budget release attempts return 422
- SaaS usage-fee transparency — fee in basis points is visible in every disbursement record, billed as a software subscription not a payment-processing fee
- Immutable audit trail — every release attempt — authorized, denied, over-budget — stored forever, queryable by IG
How the money actually moves. Keystone is a verification layer, not a money transmitter. Your existing Treasury / federal / state / fiscal-agent payment rail executes the actual disbursement based on Keystone's signed release-authorization record. Keystone never holds or transmits customer funds. See the partner-model architecture.
Who this is for
- HUD program offices — Section 202, Section 811, CDBG-DR, HOME, NOFA
- State HFAs — TDHCA (TX), FHFC (FL), CalHFA (CA), NYC HCR, NYSHCR, etc.
- Federal disaster-recovery — Helene, Maui, Helene-affected sub-grantees
- Impact partners — LISC, Enterprise Community Partners, NeighborWorks running disbursement-heavy programs
- County + city housing — local jurisdictions running their own modular housing programs
What you keep
Your program lives in your workspace. RLS-enforced. Your disbursement records are visible to you, your funders, and (with permission) your inspector general — and nobody else. Industry-aggregate disbursement velocity reaches the Modular Index only de-identified.
The release happens when the registered module's state says so. The audit trail says so forever. The inspector general's job gets easier.
Walk through a $250k disbursement live.
The sample workspace ships with an $8M HUD/TX program. Three released disbursements + one denied (over-budget) + one denied (raw module — milestone not met). Audit trail on every one.