Protocol overview
The protocol is a shielded payment pool on an EVM contract with a hold state machine. Every transition carries a wallet proof and, where a regulated party is involved, a policy proof wrapped by a universal circuit. The pool checks both by plain equality on public inputs and never hashes.
Accept and reject are one resolve circuit with a witness-selected branch. The chain sees one nullified hold and one new commitment either way.
BN254, Grumpkin, Poseidon2 with domain tags, Schnorr, UltraHonk flavors, and the salt rule.
The hold state machine, the consent model, and why reclaim is the only distinguishable resolution.
The one object policies judge: four regions, additive schema evolution, type-level knowability.
One verification key for every institution and every phase. Verifies any policy under a witnessed VK.
What the contract checks by equality, how state is serialized, and what is provisional.
Normative table of what the public, each FI, and the recipient learn per transition.
Reading order
Start with notes and the lifecycle, then the context tree, which everything else refers to. The registry, policy ABI, and wrapper describe the policy side. Pool welds and main circuits close the loop. The security invariants each name a test.