# Corda 4.x: the open source DLT platform where transactions stay private

> Corda is an Apache-2.0 distributed ledger built for business use, written in Kotlin and running on the JVM. This review covers what the 4.x codebase in corda/corda actually provides, how to get a CorDapp running, and why the project points new work at a separate repository.

**corda/corda** — Corda is an open source blockchain project, designed for business from the start. Only Corda allows you to build interoperable blockchain networks that transact in strict privacy. Corda's smart contract technology allows businesses to transact directly, with value.

- Repository: https://github.com/corda/corda
- Website: https://www.corda.net
- Stars: 4,076 · Forks: 1,069
- Language: Kotlin
- License: Apache-2.0
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/corda-corda

## What corda/corda solves, and for whom

A shared ledger normally forces a trade-off: either every participant sees every transaction, or you keep a private database and lose the shared record. Corda is built for the second problem, taking the shared-record half. The README states that Corda lets you build interoperable blockchain networks that transact in strict privacy, and that smart contract technology lets businesses transact directly, with value. That is the whole pitch in one line, and it is a narrower claim than most distributed ledger projects make.

The audience is a JVM engineering team inside a business, not a public chain user. Contracts can be written in Java and other JVM languages, and the platform itself is written in Kotlin targeting the JVM. If your team already ships Kotlin or Java services, the language surface is familiar. If your team works in Go or Rust, nothing here meets you halfway.

The privacy claim has a concrete mechanism behind it. The README describes a peer-to-peer network of nodes plus a notary infrastructure that validates uniqueness and sequencing of transactions without global broadcast. That is the design decision that separates Corda from ledgers that replicate a full history to every participant: transaction contents go to the parties involved, and the notary is used to settle ordering and double-spend questions rather than to publish data.

## How the node, flows and notaries fit together

Four pieces do the work. Nodes form a peer-to-peer network. Flows manage communication and negotiation between participants, so a multi-step business process (propose, counter, sign, record) lives in code rather than in an out-of-band email thread. Smart contracts define the rules a transaction must satisfy. Notaries validate uniqueness and sequencing without a global broadcast.

The README also names the deployment unit: distributed apps called CorDapps. A CorDapp is what you actually build and ship; the node is the runtime that hosts it. The repository layout reflects that split. There are separate top-level directories for core, node, node-api, client, serialization, finance, testing and tools, plus a samples directory containing working demos such as attachment-demo, bank-of-corda-demo, notary-demo, trader-demo and simm-valuation-demo. A team evaluating the platform can read those samples instead of guessing at the intended shape of a CorDapp.

One structural detail matters for anyone planning upgrades. The README states that the code in this repository reflects the first version of the Corda architecture, covering versions 1 through 4, and that the second and current version lives in a separate repository, corda-runtime-os, forming the basis of Corda 5. The repository also carries legacy411 and legacy412 directories alongside the active release branches. Read that as a codebase that is maintained for the 4.x line while the architecture work happens elsewhere.

## Installing Corda 4.x and running the Example CorDapp

The README does not give a package install command. Its Getting started list points to four documentation pages: Getting Started, the Example CorDapp tutorial, Key Concepts, and the Hello, World tutorial. That is where the project says to begin, and it is the honest answer to "how do I install Corda".

The repository does give you a Gradle build. The top level contains build.gradle, settings.gradle, gradlew and gradlew.bat, and BUILD.md. The README does not spell out a build invocation, so the wrapper scripts named in the repository layout are the entry point to check first, and BUILD.md is the local document to read. The build targets the JVM, so a JDK is required; the README does not state a version, and the repository files given here do not either, so check the docs before picking one.

The wrapper scripts are the only build entry point the repository layout names, and BUILD.md is the only local build document in it. Treat those two as where to start, and the Getting Started page as the place where the actual commands live.

For a first real use, the README's step two is the Example CorDapp tutorial. The samples directory is the local counterpart, with demos such as bank-of-corda-demo and notary-demo. Running one of those, following the tutorial's run configuration, is how you see a flow execute between nodes and a notary settle a transaction. The repository does not document a single command that launches a demo network, so treat the tutorial as the instruction source and the samples as the code to read alongside it.

## Where Corda 4.x is the wrong choice

The clearest limitation is written into the README itself: this repository is the first architecture version, and the current version is elsewhere. A team starting a new Corda deployment today is choosing between a 4.x codebase and a project whose next major release does not live here. That is not a defect, but it changes the cost of the decision. You are adopting a maintained line, not the direction of travel.

Second, privacy by design costs you the properties that make public chains useful. There is no global broadcast, so there is no single public record anyone can audit independently. If your use case depends on public verifiability, or on permissionless participation, Corda's model is the opposite of what you want. The README's phrase "designed for business from the start" is a description of that boundary, not a boast.

Third, the language constraint is real. Contracts in Java and other JVM languages, flows in the same stack, a Kotlin codebase, and a Gradle build. A team without JVM experience will spend its first weeks on tooling rather than on ledger design. The samples directory softens that, but it does not remove it.

Finally, the documentation surface is external. Installation, first run and key concepts all live on docs.r3.com rather than in the repository. The README is a signpost. If you need a self-contained repository where the build instructions and the architecture explanation sit next to the code, this is not that project, and BUILD.md is the only local build document named in the layout.

## Corda compared with Hyperledger Fabric

The comparison people reach for is Hyperledger Fabric, and the difference is architectural rather than cosmetic. Fabric's model centers on channels: a set of organisations shares a channel, and the ledger's contents are visible to the members of that channel. Privacy is achieved by choosing who is in the channel, and ordering is handled by an ordering service.

Corda takes the other route. The README describes a peer-to-peer network of nodes and a notary infrastructure that validates uniqueness and sequencing without global broadcast. Transaction details are shared with the parties involved rather than with a channel membership, and the notary exists to settle ordering and double-spend questions. In Fabric terms, the closest analogue to Corda's notary is the ordering service, but Corda's stated design keeps the transaction contents away from the ordering function.

Practically, that changes how you model a deal. In a channel-based design you ask who needs to be in the channel. In Corda you ask which parties are on this transaction and what the notary must confirm. The second question tends to produce finer-grained confidentiality, at the cost of a network where membership and notary trust have to be arranged deliberately. Both approaches run on the JVM, both are Apache-style open source projects aimed at enterprises, and the choice usually comes down to whether your confidentiality boundary is a consortium or a counterparty pair. The README does not make this comparison, and the documentation it points to is the place to confirm the operational details before you commit.

## Maintenance, licensing and what an upgrade costs

The repository is not archived, and the last push was on 2026-09-23, so the 4.x line is receiving commits. The default branch is release/os/4.15, which tells you where current work lands. The release history shown in the repository, however, is old: release/4.1 dates to 2019-06-14, release-V3.4 to 2019-03-14, and release-V3.3 to 2018-10-15. Branch activity and tagged releases are not the same signal, and anyone planning a version pin should look at the branches rather than at those tags.

The upgrade path is the part to think about before you write code. The README directs the current architecture to corda-runtime-os, which will form the basis of Corda 5. The presence of legacy411 and legacy412 directories at the top level shows that keeping older versions buildable has been an ongoing job. A CorDapp written against 4.x is therefore an investment in that line, and the migration question is a real one that the README does not answer.

Licensing is Apache 2.0, stated in the README and present as a LICENSE file at the top level. That is a permissive licence with a patent grant, and it is the same licence family used by most enterprise ledger projects. The repository also carries a TRADEMARK file, which is worth reading if you plan to use the Corda name in a product or service; a permissive code licence does not grant trademark rights. This is not legal advice, and the TRADEMARK and LICENSE files are the authoritative texts.

## Conclusion

Adopt Corda 4.x if you need a JVM-based ledger where only the parties to a transaction see its details, and you are prepared to track the 4.x line rather than the Corda 5 runtime. Do not adopt it if you want a public, permissionless chain or a platform whose next major version is in this repository. Before committing, read the Architecture Evolution section of the README, confirm which release branch matches your target, and run the Example CorDapp from the samples directory to see the flow and notary model in practice.

## FAQ

### What is Corda?

Corda is an open source blockchain project designed for business, written in Kotlin and targeting the JVM. The README describes it as a platform for building interoperable blockchain networks that transact in strict privacy, with smart contracts, a flow framework, peer-to-peer nodes and notary infrastructure.

### How do I use Corda?

The README's Getting started list says to read the Getting Started documentation, run the Example CorDapp, read the Key Concepts page and follow the Hello, World tutorial. The repository supplies a Gradle build with gradlew and a samples directory containing demos such as notary-demo and bank-of-corda-demo.

### Is Corda legit?

Corda is an Apache-2.0 licensed open source project hosted at github.com/corda/corda, with documentation at docs.r3.com and a project site at corda.net. The README also notes that the current architecture now lives in a separate repository, corda-runtime-os, which will form the basis of Corda 5.

### How does Corda compare with Hyperledger Fabric?

Corda uses a peer-to-peer network of nodes with a notary that validates uniqueness and sequencing without global broadcast, so transaction details go to the parties involved. Fabric's privacy model is built around channels and an ordering service, which is a different way of drawing the confidentiality boundary.

## Sources

- [corda/corda on GitHub](https://github.com/corda/corda)
- [License: Apache-2.0](https://github.com/corda/corda/blob/release/os/4.15/LICENSE)
- [Project website](https://www.corda.net)
- [README](https://github.com/corda/corda/blob/release/os/4.15/README.md)
- [Releases](https://github.com/corda/corda/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/corda-corda
