Learn · Payments architecture

Escrow & Settlement Explained: No Invoices

The hardest problem in any compute marketplace is not matching — it's money. Who holds the funds? Who verifies the meter? What happens when the numbers are disputed? VirtEngine answers all three with protocol machinery: escrow, signed usage reporting, and windowed settlement.

A hand writing in a ledger — metered usage being settled.
Metered usage, settled from escrow.

Figures

The usage-reporting and settlement pipeline, from workload meter to escrow payout

Escrow: commitment without transfer

When a tenant creates a deployment, they fund an escrow account (x/escrow). The balance is provably committed — providers can verify it exists before serving a lease — but provably not yet transferred: it moves only under settlement rules, never at a counterparty's discretion.

This single mechanism removes both directions of payment risk. The provider is not extending credit to a stranger, and the tenant is not prepaying a stranger. If escrow runs dry, leases close for non-payment; if the deployment closes with balance remaining, it returns to the tenant.

  1. Escrow — Fund commitment, not payment
  2. Meter — Hourly signed records
  3. Dispute — 24 hours to correct
  4. Settle — Line items become payout

The metering pipeline

On the provider side, a usage meter collects per-workload resource metrics. A scheduled collector runs hourly: collect metrics, process them into usage records, run anomaly detection, and submit signed batches to the chain. Batches carry the provider's signature — the meter's output is attributable and non-repudiable.

The settlement pipeline defaults are conservative and configurable: one-hour settlement intervals, batches of ten records, three retry attempts, and a reconciliation pass every six hours that cross-checks chain-reported usage against platform metrics with a configurable discrepancy threshold.

The 24-hour dispute window

No usage record settles immediately. Each sits in a 24-hour window during which either party can dispute or correct it. Anomaly detection has usually flagged outliers before submission, so the window is a backstop — but it is a real one, and disputed records escalate through support intake (x/support) and, where misconduct is alleged, fraud handling (x/fraud).

Settlement and payout

After the window closes, the settlement module converts validated records into line items priced by lease terms and draws them down from escrow. The provider receives the agreed settlement amount at the full agreed amount — protocol parameters set by governance, not a private platform take. Validator transaction fees apply to chain messages and are designed to be approximately 90% lower than standard network transaction fees. The provider's revenue arrives as settled chain state, with a complete audit trail from meter to payment.

What this replaces

In conventional cloud billing, the seller runs the meter, prices the usage, issues the invoice, and adjudicates disputes — a full conflict of interest stack. VirtEngine distributes those roles: the provider meters but signs, the protocol prices and settles, both parties can dispute, and consensus adjudicates by rule. It is billing designed for counterparties who have never met.

Asked about escrow & settlement

What happens if escrow runs dry?

Leases close for non-payment and service stops. If a deployment closes with balance remaining, it returns to the tenant — funds are committed, never stranded.

What are the metering pipeline defaults?

One-hour settlement intervals, batches of ten records, three retry attempts, and a reconciliation pass every six hours cross-checking chain-reported usage against platform metrics with a configurable discrepancy threshold.

x/settlement module

Who can dispute a usage record?

Either party, inside the 24-hour window. Disputed records escalate through support intake, and to fraud handling where misconduct is alleged.

x/escrow module

More questions → FAQ