Post-payroll privacy
Give workers an optional privacy layer after they receive a public stablecoin payout.
Availability: the worker-initiated flow can be evaluated on supported testnets. Tenebrae does not currently provide employer-driven private batch payroll.
Who this is for
- Payroll and employer-of-record platforms exploring stablecoin privacy features
- Product teams supporting workers who receive stablecoins
- Workers who want to reduce exposure of subsequent wallet activity
- Design partners evaluating optional post-payout settlement
The problem
A stablecoin payroll payment usually arrives as a public transfer to a worker-controlled wallet. Once that wallet is associated with the worker, later on-chain activity may reveal:
- The wallet's balance
- Transfers to other addresses
- Payment and spending patterns
- Interactions with public protocols
- Relationships between linked wallets
The payroll provider may complete its obligations correctly while the worker still inherits a long-lived public transaction graph.
How Tenebrae helps
Tenebrae gives the worker an explicit, self-custodial choice after the payroll payment is complete.
The current flow is:
- Public payroll payout. The payroll provider sends stablecoins to the worker's existing wallet.
- Worker opt-in. The worker chooses whether and how much to deposit into Tenebrae.
- Private settlement. Supported transfers take place inside private Protocol state.
- Public withdrawal. The worker returns assets to a public wallet or other supported rail when needed.
Tenebrae does not silently redirect payroll funds. The worker initiates the deposit and retains control of the signing wallet.
What this use case is
| This use case is | This use case is not |
|---|---|
| Optional privacy after a completed public payout | Private employer-to-worker payroll |
| Worker-controlled and self-custodial | Automatic capture of payroll funds |
| A private settlement layer for later activity | A replacement payroll platform or wallet |
| Compatible with upstream payroll KYC and controls | Transfer of employment or compliance responsibility to Tenebrae |
Employer-funded, multi-recipient private disbursement is a separate roadmap direction. See Batch private disbursement.
Example: worker-controlled privacy
A worker receives a monthly stablecoin payment to a self-custodial wallet. The payout remains visible, but the worker does not want every later payment or transfer to become part of the same public graph.
The worker deposits a chosen amount into Tenebrae, uses private transfers for supported activity, and withdraws to public rails when necessary. The worker, not the employer or payroll provider, chooses whether to use Tenebrae.
Privacy boundaries
| Information | Visibility |
|---|---|
| Employer or payroll-provider payout | Public |
| Worker deposit into Tenebrae | Public |
| Supported transfer inside Tenebrae | Private at the Protocol data layer |
| Transaction timing and submitting wallet | Potentially observable |
| Worker withdrawal and destination | Public |
| Payroll, employment, and platform records | Controlled by the relevant provider |
Distinctive amounts and timing may allow correlation between public events. Tenebrae does not hide information already known to an employer, payroll provider, wallet provider, RPC provider, or other external service.
Responsibilities
The payroll or employment platform remains responsible for:
- Employment and payroll obligations
- Identity verification and sanctions screening
- Source-of-funds and transaction policies
- Required records and disclosures
- Product support and customer communications
Tenebrae provides the private settlement layer after payout; it does not assume these responsibilities.
Current scope
The worker-initiated deposit, private transfer, and withdrawal journey can be evaluated on supported testnets. Product integration, production deployment, supported assets, disclosures, recovery procedures, and service commitments require separate assessment.