Shield and unshield
Money is checked at the boundary, then encrypted. Leaving is checked again — to a named destination, not a hop.
Status: design. XEROPAY is being built. These pages describe intended behaviour. Nothing here is claimed as live mainnet. Details can change. See What's live.
Shield
A shield is a deposit into the pool. Sources are licensed ramps and bridges. Screening runs before notes are created. What the chain can see is that the pool received funds. What it should not see is which account grew, by how much, in which asset.
Failed screens never become notes. There is no “retry inside the pool” for a refused source.
Unshield
An unshield is an exit to a destination you name. It is screened again. Amounts can be split and delayed so clock and size are weaker links between entry and exit. The destination is not supposed to be “another mixer.”
Identity-separated ramps
KYC belongs with the licensed partner. That record is not supposed to sit next to your note history inside XEROPAY. Joining those halves would be a product bug, not a feature. See Edge screening.
What this is not
It is not a tumbler, not a delay-and-hope mixer, and not an anonymous cash-out with no destination. If you need the money to remain an account — earning, paying, proving — stay shielded. Unshield when you actually need to leave.
