For teams

Run payroll and treasury without leaking the org chart

Businesses need private money that still integrates: APIs, roles, invoices, and checkout — without publishing salary bands or customer graphs.

XEROPAY privacy card

Compensation stays a note, not a public payslip.

Payroll

Compensation that isn't a public spreadsheet

On a public chain, payroll is a spreadsheet anyone can scrape. XEROPAY is designed so each employee receives into a stealth address, with roles for who can approve, and viewing keys for auditors.

Roles

Separates who can initiate from who can approve a run.

Thresholds

Large runs wait for a second operator.

Batch files

CSV in, shielded notes out — without a public payslip.

Treasury

Runway that isn't an explorer query

Competitors, journalists, and anyone with a block explorer can currently read a protocol's treasury in real time. A shielded treasury is designed so only operators and named auditors see the books.

Public treasury versus XEROPAY
Public treasuryXEROPAY
RunwayVisible to anyoneEncrypted notes
PayrollSalary graphStealth destinations
VendorsEvery invoice on-chainPrivate settlement, optional proof

API and webhooks

Integrate without a public webhook dump

REST-shaped endpoints for shield, unshield, and note queries. Events fire when a payment settles, fails, or a viewing key is disclosed. There is no public sandbox key yet — this is the intended surface, not a live contract list.

  • Auth is scoped per workspace, not a single shared wallet.
  • Webhooks retry on failure; payloads never include decrypted balances.
  • Idempotency keys on money-moving calls.

Intended surface

  • POST/v1/shieldCreate a shielded note for a named payee.
  • POST/v1/unshieldExit to a named destination after screening.
  • GET/v1/notesClient-side decrypt — never a server-side balance.
  • POST/v1/webhooksSubscribe to settled / failed / disclosed events.

Checkout

Accept payment without a public customer graph

Checkout is designed so a customer can pay from a shielded note or a one-time stealth address. You receive confirmation; you do not inherit a public list of every payer.

  • Session expiry so unpaid quotes do not linger.
  • Amount + asset locked at quote time.
  • Refunds as new notes — not a reverse of a public tx.
  1. 01QuoteCheckout session with amount, asset, and expiry.
  2. 02SettleCustomer pays from a shielded note or a fresh stealth address.
  3. 03ConfirmWebhook fires settled. The public graph does not list your customers.

Invoicing

Invoices that don't become a public ledger of clients

Issue an invoice to a handle. Each one gets a fresh destination. Paid invoices can export a proof for accounting without publishing the whole client list.

  • Line items stay local until you export them.
  • Partial payments attach to the same invoice, not a new public hash.
  • Voiding never leaves a public tombstone.

Draft

Internal only. Nothing on chain.

Issued

Payee handle + amount. Fresh destination per invoice.

Paid

Note lands in treasury. Optional viewing-key export.

Overdue

Local reminder. No public dunning trail.

Pricing

Pricing is not live. Access is.

There is no public fee table yet. Early teams get a seat, a support channel, and a written scope of what is actually live. When numbers exist, they will live here — not as a teaser.

  • No invented APR, spread, or per-tx fee.
  • Enterprise terms are written, not implied by a slider.
  • Usage reports stay with the workspace.

Starter

One operator, viewing keys, CSV export. For teams still mapping payroll.

Team

Roles, approval thresholds, and a named support channel.

Enterprise

SSO, custom screening policy, dedicated onboarding — scoped when you ask.