Docs

Architecture

A UTXO-style ledger of encrypted notes, with modules around it. What each part does and what it can see.

Status: design. XEROPAY is being built. These pages describe intended behaviour. Nothing here is claimed as live mainnet. Details can change. See What's live.

XEROPAY is specified as a note-based shielded pool — commitments and nullifiers, in the tradition of Zcash-style designs — with modules for yield routing, spend settlement, payroll batching, and controlled disclosure. Zero-knowledge proofs let a contract verify that a transaction is valid (notes exist, are unspent, and balance) without learning what it contains. No chain, circuit, or address is claimed live.

Components

ComponentRoleSees
Shielded poolHolds assets; records commitments and nullifiers; verifies proofsCommitments, nullifiers, proof validity — not amounts, owners, or assets
Edge screenerGates shield and unshield; publishes association setsDeposit and withdrawal addresses
Yield routerAllocates pool capital; credits returns per notePool-level allocation only
Settlement moduleSettles spend-rail batches from the poolBatch totals
BatcherBuilds payroll batchesNothing; runs in the client
DisclosureViewing keys and attestationsProof validity
Relayer + paymasterSubmits proofs; pays gasThat a proof was submitted
ClientKeys, decryption, proofs, dashboard, exportsEverything, locally

A transaction, end to end

  1. The client selects notes to spend, builds new notes for recipients (and change), and generates a proof that inputs equal outputs, inputs are unspent, and the signer owns them.
  2. The relayer submits the proof. The pool checks it, records new commitments, and records nullifiers so spent notes cannot be spent again.
  3. Recipients scan for notes encrypted to their key and add them to their balance.

Where privacy comes from

  • Commitments hide note contents; nullifiers prevent double-spends without revealing which note.
  • Stealth addresses unlink payments to the same handle.
  • Pool-level yield and settlement mean the chain sees the pool act, not the account.
  • Time decorrelation and consolidation break timing and amount links between entry and exit.

Where compliance comes from

  • Edge screening at shield and unshield.
  • Association sets so withdrawals can prove hygiene.
  • Viewing keys and attestations issued by the account holder only.

See Security model for what this does and does not protect against.