
A financial institution choosing a blockchain for tokenization should evaluate five things: where issuer control lives in the stack, what those controls actually permit, how the network handles privacy and disclosure, how long settlement takes to become final, and who validates transactions.
The order matters. Most selection processes open with throughput and cost, which are the two criteria least likely to constrain a regulated issuance, and close with control and disclosure, which are the two most likely to. What follows is each criterion, why it decides the outcome, and the question to put to a network before committing to it.
1. Where Issuer Control Lives in the Stack
Every network offering institutional tokenization will tell you it supports compliance controls. The question that separates them is which layer those controls sit in, because that determines what happens when something goes wrong.
Sponsored
There are four broad approaches in production today.
Controls can live in the token layer itself, as properties of the asset rather than code the issuer writes. Stellar takes this approach, exposing issuer permissions as flags set on the asset: authorization required, authorization revocable, authorization immutable, and clawback enabled. Solana’s Token Extensions work similarly, operating at protocol level inside the token program rather than as an application-layer contract.
Controls can live in a smart contract standard. On Ethereum, ERC-3643 is the most widely adopted permissioned-token standard, pairing an on-chain identity system with transfer rules that every transaction is checked against. Its own documentation describes it as a suite of smart contracts rather than a protocol-level standard.
Controls can live in network configuration. Avalanche’s Evergreen L1s implement user and validator permissioning through stateful precompiles, including transaction and contract allowlists, geofencing, and KYC/KYB requirements. These are configured per L1 rather than at the main network level, so each deployment sets its own rules.
Controls can live in the privacy architecture. Canton Network restricts what each party sees at sub-transaction level, so in a delivery-versus-payment flow the bank sees the cash leg and the securities registrar sees the asset leg, with neither seeing the other.
The question to ask: if the issuing contract were replaced tomorrow, would the control survive? Protocol-level controls do. Contract-level controls are only as durable as the contract, and as trustworthy as whoever holds the keys to upgrade it.

2. What the Controls Actually Permit, and What They Cost You
Naming a capability is not the same as understanding its trade-off. Three capabilities matter for most regulated issuances, and each carries a constraint worth knowing before issuance rather than after.
Freezing, meaning the ability to stop a specific holder transacting. On Stellar this works by revoking trustline authorization, which prevents that account from transferring or trading the asset, and it can be reduced from complete to limited authorization without cancelling open orders.
Recovery, meaning the ability to reclaim an asset from a holder. Stellar exposes this as a clawback flag, and here is the trade-off most selection documents miss: the clawback flag requires that the revocable flag is also enabled. An issuer cannot offer holders the assurance that their holdings can never be frozen while retaining the ability to claw them back. Those two promises are mutually exclusive at the protocol level.
Permanence, meaning the ability to guarantee something will not change. Stellar’s authorization immutable flag locks the issuing account so no other authorization flags can be set and the account cannot be merged. It is not reversible. Supply can be capped the same way, by setting the issuing account’s master weight to zero, which permanently disables that account for any future action.
The question to ask: which of these decisions are irreversible, and which can be changed after issuance? Most institutions discover this ordering problem late, because irreversible choices are usually the ones made fastest.
3. Privacy and Disclosure are One Decision, Not Two
A public ledger makes every position and counterparty visible by default, which is disqualifying for a great deal of institutional activity. The naive fix, a fully private ledger, removes the auditability that made the ledger attractive in the first place. The useful question is not how much privacy a network offers but who can see what, and who can compel disclosure.
Canton’s model is the most explicit on this point. Parties record only the portions of a transaction that apply to them, and infrastructure operators see limited metadata needed for ordering and consistency, such as transaction status and the parties involved, rather than transaction data itself.
Solana approaches the same problem differently, with confidential transfers that mask balances and transfer amounts while preserving auditability from the issuer. Note that the extension set has documented interactions worth checking directly with the network before relying on a combination of features. [needs verification: current compatibility between transfer hooks and confidential transfers]
The question to ask: name the parties who can see a given position, and name the parties who can compel its disclosure. If a network cannot answer both in one sentence, the model is not settled.
4. Settlement Finality is a Defined Term, and the Definition Varies
Finality is when a transaction can no longer be reversed. Networks define that threshold differently, so headline figures are not directly comparable without knowing the definition behind each.
OpenChainBench, which measures time to finality on a rolling basis across tracked chains, reports Avalanche at around 1.3 seconds, Stellar at around 4 seconds, Solana at around 8.3 seconds, and Ethereum at around 15.9 minutes, measured as a median over a 24 hour window. The definitions behind those numbers differ materially: Ethereum’s figure reflects Casper FFG finalising a checkpoint two epochs after justification, Solana’s reflects 32 confirmed slots, and Stellar’s reflects deterministic finality at every ledger close under federated Byzantine agreement.
That last distinction is the one that matters for settlement design. Deterministic finality means a transaction is final at a defined point. Probabilistic finality means confidence increases with time and never technically reaches certainty. An institution designing a delivery-versus-payment flow needs to know which of those it is building on, because it changes what the operations team has to monitor.
The question to ask: is finality deterministic or probabilistic on this network, and what is the worst observed case rather than the median?

5. Who Validates, and What It Takes to Become One of Them
Validator structure decides both censorship resistance and who an institution is trusting operationally.
Canton uses what it calls proof-of-stakeholder consensus, where only the parties involved in a transaction validate it, and running a validator node carries no staking requirement. Avalanche lets each L1 operator choose its own validator set, with permissioning available against KYC and KYB standards. Stellar uses federated Byzantine agreement, in which participants choose the sets of other participants they rely on.
These are genuinely different trust models rather than better and worse versions of one model. A consortium of known counterparties may prefer a permissioned validator set. An issuer wanting assets to circulate beyond a closed group will find that same permissioning is a constraint.
The question to ask: who could stop my transaction from being processed, and what would it take for them to do so?
The comparison in one view
| Where control lives | Notable control capability | Privacy model | Finality | |
|---|---|---|---|---|
| Stellar | Token layer, as asset flags | Authorization required, revocable, immutable, clawback | Public ledger | Deterministic, around 4 seconds |
| Solana | Token program, as extensions | Token-gated transfers, permanent delegate, transfer hooks | Confidential transfers with issuer auditability | Around 8.3 seconds at 32 confirmed slots |
| Ethereum | Smart contract standards | ERC-3643 identity and permissioned transfers | Public ledger | Around 15.9 minutes to Casper FFG finality |
| Avalanche | Per-L1 network configuration | Transaction and contract allowlists, KYC/KYB permissioning | Configurable per L1 | Around 1.3 seconds |
| Canton | Privacy architecture | Sub-transaction disclosure scoping | Need-to-know by default | [needs verification] |
Control capability and finality figures as published by each network and by OpenChainBench respectively. Two criteria deliberately absent from this table are custody ecosystem breadth and cost predictability, because neither is published consistently enough across networks to compare fairly. Both should be verified directly with custody providers rather than taken from network documentation.
Red Flags in a Network Evaluation
A network that answers the control question with a roadmap rather than documentation. Controls either exist and are documented or they do not.
A comparison that presents one network’s protocol-level feature against another’s absence of it without noting that the second network implements the same capability at a different layer.
A finality figure quoted without its definition, or a median quoted without a worst case.
Any claim that a capability is unique. Across issuer controls, privacy and permissioning, most capabilities now exist on several networks at different layers, and the meaningful differences are in trade-offs rather than presence.
How the Leading Networks Meet These Criteria
No network wins all five criteria, and an institution that finds one claiming to should treat that as a selection signal in itself.
Ethereum offers the deepest ecosystem and the most mature permissioned-token standards, at the cost of the slowest finality of the networks compared here. Canton offers the most developed answer to the disclosure question, within a smaller ecosystem. Avalanche offers the most configurable environment, with the trade-off that configuration is a per-deployment responsibility. Solana and Stellar both place controls in the token layer rather than in contracts, which makes those controls durable and inspectable, and Stellar is a useful reference implementation of that approach for regulated issuance specifically, given that its authorization and clawback flags are properties of the asset rather than code an issuer has to write and maintain.
The right answer depends on which of the five criteria the issuance cannot compromise on. That is a different question from which network is best, and it is the only version of the question with an answer.
FAQs
There is no single answer, because the binding constraint differs by issuance. An institution needing issuer recovery and freezing should evaluate networks that place those controls in the token layer. One needing transaction-level confidentiality between known counterparties should evaluate networks built around selective disclosure. One prioritising secondary market liquidity will weight ecosystem depth above both.
The distinction is less binary than it was. Public networks now offer protocol-level permissioning and confidential transfers, and permissioned environments are increasingly deployed as configurable instances of public network technology. The practical question is which parties can see a position and which can validate a transaction, not whether the ledger is labelled public or private.
Look for controls at the token or protocol layer rather than in application contracts, documented rather than roadmapped, and check which of them are irreversible once set. A control that depends on a contract remaining unchanged is a weaker guarantee than one that is a property of the asset.
Where issuer control lives, what those controls permit and preclude, who can see and who can compel disclosure, whether finality is deterministic or probabilistic, and who validates. Throughput and cost matter operationally but rarely decide a regulated issuance
Ethereum carries the largest share of tokenized real-world asset activity, with Avalanche, Polygon, Stellar, Solana and Canton all carrying institutional deployments. Deployment counts move quickly, so verify current figures against a tracker rather than against network marketing material.