Treasury operations
Use public chains without publishing every operating payment, counterparty relationship, and treasury movement.
Availability: available for evaluation on supported testnets. Tenebrae is not yet a mainnet production system. See Stack for current networks and capabilities.
Who this is for
- Corporate and institutional treasury teams
- Digital-asset and tokenised-asset operations teams
- Finance teams making stablecoin payments
- Trading and fund operations teams managing public-chain liquidity
The problem
Public-chain settlement gives treasury teams direct ownership, rapid finality, and programmable assets. It also creates a durable public record of operating activity.
Anyone monitoring known treasury addresses may be able to infer:
- Current and historical balances
- Vendor and counterparty relationships
- Payment amounts and cadence
- Rebalancing activity
- Changes in liquidity requirements or operating strategy
Using additional wallet addresses can make analysis less convenient, but it does not provide a dependable privacy boundary.
How Tenebrae helps
Tenebrae adds confidential settlement between public funding and public withdrawal. The institution continues to use its existing wallet and host chain.
A typical treasury flow is:
- Fund private settlement. An operating wallet deposits a supported asset into Tenebrae Protocol.
- Move value privately. The treasury transfers value inside private Protocol state.
- Return to public rails. A recipient withdraws to a public wallet when liquidity or disclosure is required.
The institution remains in control of its keys throughout the flow. Tenebrae does not custody treasury assets or replace the institution's wallet, accounting system, approval policy, or compliance programme.
Example: vendor settlement
An institution needs to make recurring stablecoin payments to several service providers.
With ordinary token transfers, observers can associate each provider with the institution and monitor payment amounts and frequency. With Tenebrae, the institution can fund Protocol settlement publicly and then make the individual transfers inside private state. Each provider can later withdraw to a public wallet.
This reduces disclosure of the internal payment graph. It does not make the deposit, withdrawal, transaction sender, timing, or all surrounding metadata private.
Privacy boundaries
| Information | Visibility |
|---|---|
| Deposit transaction and amount | Public |
| Wallet submitting an on-chain transaction | Public |
| Private transfer amount | Not published as a plaintext Protocol input |
| Private transfer recipient relationship | Not published as a plaintext Protocol input |
| Withdrawal amount and destination | Public |
| Timing, gas, RPC, and wallet metadata | Potentially observable |
Distinctive amounts, closely timed deposits and withdrawals, or external information may allow an observer to infer relationships. Tenebrae provides a Protocol privacy boundary, not a guarantee against every form of traffic analysis.
Operational fit
Tenebrae is most relevant when:
- Assets already move on supported public EVM chains.
- The institution wants to retain its existing custody model.
- Counterparty and payment-graph disclosure creates commercial or operational risk.
- Public deposits and withdrawals are acceptable.
- The institution can continue to run upstream identity, screening, approval, and accounting controls.
Tenebrae is not designed to conceal regulated issuance, subscription, redemption, or other activity that must remain public or auditable under the institution's legal and operational model.
Current scope
The testnet product supports evaluation of the core deposit, private transfer, and withdrawal journey. Mainnet readiness, supported assets, chain availability, service levels, and institutional deployment requirements must be assessed separately.