Written for four readers at once: anyone deciding whether to use Aftr, anyone who wants to read its data from their own contract, anyone assessing how far along it is, and anyone auditing it. Everything below is checkable — on chain, or in the repository.
Last updated 7 August 2026
01
What Aftr is
Aftr is infrastructure for real-world assets on Robinhood Chain. It is a layered system, not a single product: a data layer at the bottom that any contract can read, and products built on top of it — starting with an index vault.
Tokens tracking real equities already trade on that chain, held by tens of thousands of addresses and moving between wallets every day. What has not arrived is the infrastructure underneath them. These are equities: they close at four, they halt, they observe holidays. The primitives around them were built for assets that never close.
Aftr publishes market hours and price health on chain, so a contract that asks the right question gets an answer that fails safe instead of a number that looks fine.
02
Status — what is live and what is not
Stated plainly, because a roadmap that hides its gaps is a sales document.
Component
State
Notes
Foundation contracts
Written, tested, not deployed
Registry, market hours, price oracle, access control
Off-chain services
Written, tested, not running
Indexer, data API, publishers, monitors
Terminal (screener, portfolio)
Live, waiting for data
Fills itself once contracts are deployed
Index vault
Written, tested, not deployed
Holds user funds — waits for an external audit
External audit
Not started
A gate before the vault, not a formality
Markets, credit, derivatives
Not started
Later floors; nothing is built out of order
03
The foundation layer
Four contracts. None of them holds money; all of them answer questions.
Contract
Answers
Upgradeable
AssetRegistry
What is this asset, legally and technically?
Yes, via 48h timelock
MarketHours
Is this exchange open right now?
Yes, via 48h timelock
PriceOracle
What is the price, and is it trustworthy?
Yes, via 48h timelock
AftrRoles
Who is allowed to do what?
No — never
AssetRegistry records the claim type of every asset. An instrument tracking a share price, a wrapped equity, a fund unit and a treasury are four legally distinct things, and the registry refuses to flatten them into one.
MarketHours models weekly sessions, daylight-saving shifts published a year ahead, holidays, half days and halts. It deliberately decides nothing — it only answers. What to do when a market is closed lives in the contract that asked.
AftrRoles cannot be upgraded because it is the root of trust. A root that can be swapped quietly makes every other safeguard meaningless.
04
For builders — reading Aftr from your contract
This is the part that a database could not do. Your contract can read Aftr from inside its own transaction, and get an answer that stops you rather than misleads you.
The oracle exposes two read functions, and choosing the wrong one is the mistake worth avoiding.
// Moving value? Use getPrice. It REVERTS when the price is stale,
// the feed is frozen, or the asset is halted.
(uint256 price, uint256 publishedAt, bool atClose) = oracle.getPrice(assetId);
// Only displaying? Use peekPrice. It never reverts and hands you
// the health flag so you can show the number and its condition.
(uint256 p, uint256 at, bool atClose_, bool healthy) = oracle.peekPrice(assetId);
// Market state, straight from the chain.
SessionState s = marketHours.state(calendarId);
// CLOSED · PRE_MARKET · REGULAR · POST_MARKET · HALTED
marketHours.lastClose(calendarId); // last regular close, unix seconds
marketHours.nextOpen(calendarId); // next regular open
marketHours.isAssetHalted(assetId); // per-asset halt
There is also a read-only HTTP API for anything that is not a contract — asset lists, prices with their health, calendars and portfolios. It is open, needs no key, and is a mirror: if it disappears entirely, contracts reading the chain are unaffected.
05
The index vault
One deposit gives you a maintained basket of real-world assets as a single token. No yield is promised, because none is manufactured — the value is that the basket maintains itself and the share token is usable elsewhere.
Three design decisions matter more than the rest, and each exists because of a specific way vaults lose money.
Redemption returns a pro-rata slice of every asset held, never a single one. It uses no price feed at all, so withdrawals are never held hostage by an oracle — and early redeemers cannot get better terms than late ones.
Pausing stops deposits and never stops withdrawals. Halting deposits protects newcomers; halting withdrawals only moves risk onto the people already inside.
The first deposit permanently locks a small number of shares. Without that, a first depositor can donate tokens directly to the vault and take the second depositor's money through rounding.
The vault reads the foundation layer the same way any third party would: it calls getPrice when issuing shares, and refuses deposits when MarketHours reports the market closed. It is the first real consumer of its own infrastructure.
06
Governance and upgrades
Change
Path
Delay
Contract implementation
Timelock contract holds the upgrade role
48 hours
Loosening a risk parameter
Timelock
48 hours
Tightening a cap or disabling deposits
Admin or guardian
Immediate
Halting a market, asset or price feed
Guardian
Immediate
The guardian key is deliberately stripped of every ability except stopping. It can halt a market, halt an asset and freeze a price feed — it can never write a value, and it cannot lift a halt it placed itself. A stolen guardian key is disruptive, not destructive.
The upgrade role is held by a timelock contract rather than a person, so the delay cannot be skipped even by the multisig that proposes the change.
07
Risks we accept
Listed openly rather than discovered later.
Issuer dependency. Aftr does not issue assets. A change of terms, a halt, or a custody problem at an issuer reaches our users directly. Being asset-agnostic limits the blast radius; it does not remove it.
Price publishing is centralised today. A single key publishes prices. A deviation guard caps the damage per transaction and a guardian can freeze a feed in seconds, but these bound the loss rather than prevent it. Additional independent publishers come when credit products raise the stakes.
Upgradeable core contracts. Three of the four can be upgraded through a 48-hour timelock. That asks for more trust than immutability would; the delay is what makes it auditable.
A young chain. Robinhood Chain is weeks old. First-mover advantage arrives together with first-mover risk.
Smart contract risk. Nothing has been externally audited yet. That is why no contract holding user funds is deployed.
08
What Aftr never claims
These bind every page, post and document we publish. They exist because the space is full of confusion, and being the honest explainer is worth more than being the loud one.
That you own shares, or hold any shareholder right. Most assets here track a price; they are not equity carrying votes.
That Aftr issues or guarantees any asset. We are infrastructure; issuers are third parties.
Any yield figure as a promise.
Any affiliation with, partnership with, or endorsement by Robinhood. Aftr is built on Robinhood Chain — a public, permissionless network. That is the entire relationship.