The envelope
envelope = { epk_eph, ct_user, ct_fi }
plaintext = shared leaves ‖ payload leaves ‖ sender_private_root ‖ attestation preimage
ct_user is encrypted to the recipient's pk_d (Sapling-style ECDH with
an ephemeral key). ct_fi is encrypted to the recipient FI's epk. Both
carry the same plaintext. The attestation preimage is included so the
recipient FI can check attestation_in.is(kind) (§5.6) without an
out-of-band channel. The sender FI receives the plaintext directly from the
sender; it is never on chain for the sender FI.
Non-custodial recipients work: the recipient decrypts ct_user, and their
FI decrypts ct_fi. Neither needs the other.