Skip to content

Privacy ​

Some fields are not stored on the chain. The chain stores a commitment. The ciphertext sits on sidecars beside the validators. The full design is the spec docs/specs/privacy-layer.md.

What that spec commits to:

  • Plaintext, the salt, and the data key do not appear in a transaction, a log, contract storage, or Scan.
  • Four sidecars each store the ciphertext. The data key is split into 4 shares. Reading needs 3 of the 4 shares, the same quorum as a QBFT block.
  • The sidecar does not keep its own policy. On a read or a write it calls the collection contract at a finalized block and follows that answer.
  • UMBRO-ORG stays the organization standard (members, roles, hasRole, isAdmin). The privacy layer does not replace it.

The public edge routes sealed shares. It cannot open them. Scan's API does not return plaintext.

Wallet and Scan screens for this layer, and the host deploy, are tracked in that spec. This page does not add a second set of rules.

Testnet coin T-RAIN · chain 20261003