Architecture
A UTXO-style ledger of encrypted notes, with modules around it. What each part does and what it can see.
Status: design. XEROPAY is being built. These pages describe intended behaviour. Nothing here is claimed as live mainnet. Details can change. See What's live.
XEROPAY is specified as a note-based shielded pool — commitments and nullifiers, in the tradition of Zcash-style designs — with modules for yield routing, spend settlement, payroll batching, and controlled disclosure. Zero-knowledge proofs let a contract verify that a transaction is valid (notes exist, are unspent, and balance) without learning what it contains. No chain, circuit, or address is claimed live.
Components
| Component | Role | Sees |
|---|---|---|
| Shielded pool | Holds assets; records commitments and nullifiers; verifies proofs | Commitments, nullifiers, proof validity — not amounts, owners, or assets |
| Edge screener | Gates shield and unshield; publishes association sets | Deposit and withdrawal addresses |
| Yield router | Allocates pool capital; credits returns per note | Pool-level allocation only |
| Settlement module | Settles spend-rail batches from the pool | Batch totals |
| Batcher | Builds payroll batches | Nothing; runs in the client |
| Disclosure | Viewing keys and attestations | Proof validity |
| Relayer + paymaster | Submits proofs; pays gas | That a proof was submitted |
| Client | Keys, decryption, proofs, dashboard, exports | Everything, locally |
A transaction, end to end
- The client selects notes to spend, builds new notes for recipients (and change), and generates a proof that inputs equal outputs, inputs are unspent, and the signer owns them.
- The relayer submits the proof. The pool checks it, records new commitments, and records nullifiers so spent notes cannot be spent again.
- Recipients scan for notes encrypted to their key and add them to their balance.
Where privacy comes from
- Commitments hide note contents; nullifiers prevent double-spends without revealing which note.
- Stealth addresses unlink payments to the same handle.
- Pool-level yield and settlement mean the chain sees the pool act, not the account.
- Time decorrelation and consolidation break timing and amount links between entry and exit.
Where compliance comes from
- Edge screening at shield and unshield.
- Association sets so withdrawals can prove hygiene.
- Viewing keys and attestations issued by the account holder only.
See Security model for what this does and does not protect against.
