Skip to main content

Privacy boundaries

What is private inside Tenebrae Protocol — and what stays public at the boundary.

Public on the way in. Private on the way through. Ceiling: Stack · FAQ.


What stays private

SurfacePrivate by design
BalancesHoldings stay out of public wallet view
TransfersAmounts and counterparties stay out of public settlement inputs
DeFiWho you are stays private through venue flows

What stays public

SurfacePublic by design
DepositAmounts moving from public wallet into Tenebrae Protocol
WithdrawAmounts leaving Tenebrae Protocol to a public wallet
DeFiToken · amount · market stay public at the host venue
Proof verificationProofs verify on-chain · private inputs stay on the client
DiscoveryOnly you can tell which discovery keys are yours · for balances and activity

What stays unlinked

Deposit ↔ withdraw — cannot prove which deposit funded which withdraw.

Still possible · Distinctive amounts can still re-link — transfers and DeFi alike.

Detail: Quickstart · Stack.


Who can see what

PartyCan see
Your walletSigns only · no Protocol private view
Tenebrae clientPrivate view after unlock · builds and proves locally
Tenebrae ProtocolProof verification · not private inputs
Indexer / cloudDiscovery and receipts · not private details

Depth: Stack · Compliance.


Privacy and compliance

Policy is checked in every settlement proof without publishing screening details on-chain. Your institution owns upstream KYC and screening. Detail: Compliance.


Next