03 · Disbursement Rail

No release without verified proof.

Government programs disburse millions every month through their existing payment infrastructure. Keystone's Disbursement Rail adds a verification gate on top: funds release only when the registered asset has actually hit the verified milestone. The money still flows through existing rails — Keystone is the signal that says when.

How programs are set up

A program in Keystone carries:

  • Budget — total funding available
  • Fee in basis points — SaaS usage fee charged for verified release, billed in bps of disbursement amount for cost transparency
  • Funder — HUD, state HFA, LISC, Enterprise, county, etc.
  • Jurisdiction — where the assets must be located
  • Payment rail reference — pointer to the program's existing disbursement infrastructure (Treasury, state payment system, etc.)

The verification rule

The disburse Edge Function validates the registered asset meets the requested milestone:

  • "Asset certified" — inspection certified record required
  • "Completed" or "Installed" — state must equal "completed" or "in-structure"
  • Remaining-budget — disbursement amount cannot exceed remaining program budget

If the verification passes, the API emits a signed release-authorization record. The program's existing payment rail (Treasury, state HFA payment system, fiscal-agent ACH) then executes the actual disbursement based on that authorization. If verification fails, the call returns 422, no authorization record is emitted, and the program's payment rail does not move funds.

Important. Keystone is a verification layer, not a money transmitter. Funds flow through the program's existing federal, state, or Treasury payment infrastructure — Keystone never holds or transmits customer funds. See the partner-model architecture for the full counterparty mapping.

The rail fee (SaaS, not payment processing)

On verified release, Keystone charges the program a SaaS usage fee, billed in basis points of the disbursement amount for cost transparency on the program's books. A $250k disbursement at 25bps = $625 in usage fees. The fee is structurally a software subscription — visible as a line item on the program's books, auditable by program funders and IGs. Program funders see the rail fee explicitly; the rate is set per program at creation.

The audit trail

Every disbursement attempt — release-authorized, denied, over- budget — is inserted into the immutable disbursement record. Auditors, inspectors general, and program funders see every authorized release tied to a specific verified asset record and a specific KeyScore.

Who pays for it

HUD program offices, state HFAs (TDHCA, FHFC, CalHFA, etc.), LISC, Enterprise Community Partners, county housing authorities, and federal disaster-recovery sub-grantees. Any program where disbursement timing has been a friction point (which is most of them).

The disbursement releases when the registered asset's state says so. The audit trail says so forever. The actual money moves through the rail that's already there.
Next step

Watch a $250k release-authorization in real-time.

The sample workspace ships with a $8M HUD/TX program — three completed authorizations, immutable audit trail, $625 SaaS usage fee on the first release.