Fintech and vault products
Add a confidential settlement layer to a fintech or digital-asset product without replacing its wallet, ledger, compliance programme, or public funding rails.
Availability: the client journey is available for testnet evaluation. Embedded integration remains preliminary and should not be presented as production-ready.
Who this is for
- Fintech and digital-bank product teams
- Digital-asset account and vault providers
- Wealth and treasury-management products
- Web3 applications using institution-controlled wallets or smart accounts
The problem
Many financial products combine several public and private systems:
- Users fund an account through an on-ramp or public-chain transfer.
- An institution or smart account controls assets on-chain.
- The product moves value between strategies, counterparties, or account functions.
- Assets eventually return to a public wallet, off-ramp, or spend rail.
If every on-chain movement uses an ordinary token transfer, observers may reconstruct balances, internal movements, counterparties, and product usage from known addresses.
How Tenebrae helps
Tenebrae can provide confidential settlement between the product's public entry and exit points.
A typical product flow is:
- Public funding. A user or institution funds an existing wallet or smart account.
- Deposit into Tenebrae. Supported assets enter private Protocol settlement.
- Private movement. The product coordinates supported transfers inside private Protocol state.
- Public exit. Assets return to a wallet, off-ramp, or spend rail when required.
Tenebrae supplies the private settlement layer. The product continues to own its customer experience, custody or wallet model, internal ledger, permissions, KYC, screening, and regulatory responsibilities.
Example: confidential vault movement
A digital-asset account lets a customer hold stablecoins, allocate part of the balance to a managed strategy, and pay an external counterparty.
Without a privacy layer, the movement between the customer's known wallet, strategy addresses, and counterparty may be visible on-chain. With Tenebrae, supported movements can occur inside private Protocol state before value returns to a public destination.
This does not hide card authorisations, bank transfers, on-ramp records, application telemetry, or the public deposit and withdrawal boundaries.
Product architecture
| Component | Responsibility |
|---|---|
| Fintech or vault product | Customer experience, account model, permissions, records, support, and compliance |
| Existing wallet or smart account | Key control and transaction signing |
| Tenebrae client or integration surface | Private balance view, operation preparation, and local proof generation |
| Tenebrae Protocol | Proof verification and private settlement state |
| Host chain and external rails | Public execution, funding, withdrawal, and downstream settlement |
Tenebrae is not the product's general ledger. Product teams must reconcile public transactions, private Protocol state, and their own customer records according to their operating model.
Privacy boundaries
| Information | Visibility |
|---|---|
| Public funding and deposit | Public |
| Supported movement inside Tenebrae | Private at the Protocol data layer |
| Transaction sender, timing, and gas | Potentially observable |
| Product application and customer records | Controlled by the integrating product |
| Withdrawal and downstream spend rail | Public or visible to the relevant rail |
Tenebrae does not conceal information collected by the product, wallet provider, RPC provider, on-ramp, off-ramp, card network, or other external service.
Adoption paths
Evaluate with the Tenebrae client
Use the testnet client to validate the deposit, private transfer, and withdrawal journey before committing to an embedded product design.
Embed the settlement journey
An embedded experience would keep the product's interface and use Tenebrae's integration surface for private settlement. This path is preliminary and requires technical and commercial scoping; it is not currently a self-service production integration.
Operational fit
This model is most relevant when:
- The product already uses supported EVM assets and wallets.
- Public transaction graphs create a meaningful customer or commercial privacy problem.
- The product can preserve explicit public deposit and withdrawal disclosures.
- The product retains responsibility for customer records and compliance.
- Testnet evaluation is appropriate for the current stage of adoption.