Most databases are generalists. They store documents, serve queries and handle transactions well enough for many purposes. A ledger has narrower, harsher requirements: it must not lose money, must not double-count, and must hold its integrity at volume. SUPA's proprietary double-entry ledger runs on TigerBeetle, a database built specifically for this kind of work.

What a ledger engine must guarantee

A payment ledger is judged on invariants rather than features. Every debit has a matching credit. A balance is the sum of its entries and nothing else. Concurrent operations cannot both consume the same funds. These are not reporting concerns; they are correctness concerns, and a general-purpose stack often leaves them to application code, where they are easy to get subtly wrong.

Why a purpose-built engine

TigerBeetle is designed around precisely these constraints: double-entry semantics, high throughput and strong consistency as first principles rather than additions. Placing those guarantees in the storage layer means the application is not the last line of defence for the money. The ledger is not a view over operational data; it is the record of truth. The choice also affects operational confidence: when the engine enforces matching entries itself, an entire class of application bugs becomes impossible rather than merely unlikely.

What sits on top

SUPA's ledger keeps attribution as well as balances. Every entry resolves to a principal, an agent and a policy version, so an operation can be traced to who authorised it and under which rules. That structure is what makes later reconstruction possible — you can prove not only that a balance changed but why.

Volume matters for a second reason. The protocol is designed to net offsetting flows: approved operations enter a single order book, offsetting flows cancel internally, and only the remainder is routed outward. A ledger engine that can carry that load reliably is a precondition for the model working at all.

In short

  • Ledger correctness is about invariants — matching entries, derived balances, no double-spend.
  • A purpose-built engine keeps those guarantees in storage, not in hope.
  • Attribution to principal, agent and policy version is part of the record.
  • Volume capacity underpins netting and internal settlement.

Read how the ledger fits the wider stack: protocol.