Privacy Architecture
Mathematical guarantees, zero-knowledge verification, and non-custodial privacy invariants across the Veil protocol stack.
1. Non-Custodial by Mathematical Invariant
Veil operates entirely through decentralized smart contracts on Robinhood Chain. When you swap or deposit funds into the shielded pool, your assets are cryptographically accounted for via a LeanIMT Merkle tree. Neither Veil, relayers, nor guardians hold custody of your assets. The VeilShieldRouter enforces a strict 0-held custody invariant, ensuring no user funds ever linger in router storage.
2. Client-Side Proving & Zero Server Logging
All cryptographic secrets, nullifiers, and notes are generated locally in your browser using cryptographically secure randomness. At no point are private notes, nullifiers, or secret keys transmitted to any external server or indexer. Proof payloads are assembled client-side; the onchain verifier is provisional for old notes only, with Groth16 live on the 0xbow paths.
3. Unlinked Relayer Settlements
Withdrawals are broadcast via an open relayer network or self-relayed. All transaction parameters (pool, minimum amount out, recipient address, and relayer fee) are cryptographically bound to the public input context hash of the ZK proof. Relayers cannot tamper with or redirect destination funds. On-chain observers see zero link between the initial depositor and the final receiving address.
4. Non-Blocking Withdrawal Invariant
Veil contracts guarantee immutable, censorship-resistant withdrawals. While protocol guardians may pause incoming deposits in an emergency, withdrawal mechanisms can never be paused, censored, or frozen under any circumstance.