Privacy boundaries
What is private inside Tenebrae Protocol — and what stays public at the boundary.
Public on the way in. Private on the way through. Ceiling: Stack · FAQ.
What stays private
| Surface | Private by design |
|---|---|
| Balances | Holdings stay out of public wallet view |
| Transfers | Amounts and counterparties stay out of public settlement inputs |
| DeFi | Who you are stays private through venue flows |
What stays public
| Surface | Public by design |
|---|---|
| Deposit | Amounts moving from public wallet into Tenebrae Protocol |
| Withdraw | Amounts leaving Tenebrae Protocol to a public wallet |
| DeFi | Token · amount · market stay public at the host venue |
| Proof verification | Proofs verify on-chain · private inputs stay on the client |
| Discovery | Only you can tell which discovery keys are yours · for balances and activity |
What stays unlinked
Deposit ↔ withdraw — cannot prove which deposit funded which withdraw.
Still possible · Distinctive amounts can still re-link — transfers and DeFi alike.
Detail: Quickstart · Stack.
Who can see what
| Party | Can see |
|---|---|
| Your wallet | Signs only · no Protocol private view |
| Tenebrae client | Private view after unlock · builds and proves locally |
| Tenebrae Protocol | Proof verification · not private inputs |
| Indexer / cloud | Discovery and receipts · not private details |
Depth: Stack · Compliance.
Privacy and compliance
Policy is checked in every settlement proof without publishing screening details on-chain. Your institution owns upstream KYC and screening. Detail: Compliance.