Skip to main content

Treasury operations

Use public chains without publishing every operating payment, counterparty relationship, and treasury movement.

Availability: available for evaluation on supported testnets. Tenebrae is not yet a mainnet production system. See Stack for current networks and capabilities.

Who this is for

  • Corporate and institutional treasury teams
  • Digital-asset and tokenised-asset operations teams
  • Finance teams making stablecoin payments
  • Trading and fund operations teams managing public-chain liquidity

The problem

Public-chain settlement gives treasury teams direct ownership, rapid finality, and programmable assets. It also creates a durable public record of operating activity.

Anyone monitoring known treasury addresses may be able to infer:

  • Current and historical balances
  • Vendor and counterparty relationships
  • Payment amounts and cadence
  • Rebalancing activity
  • Changes in liquidity requirements or operating strategy

Using additional wallet addresses can make analysis less convenient, but it does not provide a dependable privacy boundary.

How Tenebrae helps

Tenebrae adds confidential settlement between public funding and public withdrawal. The institution continues to use its existing wallet and host chain.

A typical treasury flow is:

  1. Fund private settlement. An operating wallet deposits a supported asset into Tenebrae Protocol.
  2. Move value privately. The treasury transfers value inside private Protocol state.
  3. Return to public rails. A recipient withdraws to a public wallet when liquidity or disclosure is required.

The institution remains in control of its keys throughout the flow. Tenebrae does not custody treasury assets or replace the institution's wallet, accounting system, approval policy, or compliance programme.

Example: vendor settlement

An institution needs to make recurring stablecoin payments to several service providers.

With ordinary token transfers, observers can associate each provider with the institution and monitor payment amounts and frequency. With Tenebrae, the institution can fund Protocol settlement publicly and then make the individual transfers inside private state. Each provider can later withdraw to a public wallet.

This reduces disclosure of the internal payment graph. It does not make the deposit, withdrawal, transaction sender, timing, or all surrounding metadata private.

Privacy boundaries

InformationVisibility
Deposit transaction and amountPublic
Wallet submitting an on-chain transactionPublic
Private transfer amountNot published as a plaintext Protocol input
Private transfer recipient relationshipNot published as a plaintext Protocol input
Withdrawal amount and destinationPublic
Timing, gas, RPC, and wallet metadataPotentially observable

Distinctive amounts, closely timed deposits and withdrawals, or external information may allow an observer to infer relationships. Tenebrae provides a Protocol privacy boundary, not a guarantee against every form of traffic analysis.

Operational fit

Tenebrae is most relevant when:

  • Assets already move on supported public EVM chains.
  • The institution wants to retain its existing custody model.
  • Counterparty and payment-graph disclosure creates commercial or operational risk.
  • Public deposits and withdrawals are acceptable.
  • The institution can continue to run upstream identity, screening, approval, and accounting controls.

Tenebrae is not designed to conceal regulated issuance, subscription, redemption, or other activity that must remain public or auditable under the institution's legal and operational model.

Current scope

The testnet product supports evaluation of the core deposit, private transfer, and withdrawal journey. Mainnet readiness, supported assets, chain availability, service levels, and institutional deployment requirements must be assessed separately.

Next