Confidential transfer
B2B settlement with encrypted sender and receiver balances. Groth16 proof binds to on-chain ciphertext hashes.

Shield is a transfer standard on Stellar that encrypts every balance with additive ElGamal on BN254. Amounts stay invisible on-chain — yet fully auditable via view keys for parties you authorize.
Platform
Register, mint, transfer, and audit — modular dashboard sections for each step of the shielded lifecycle.
B2B settlement with encrypted sender and receiver balances. Groth16 proof binds to on-chain ciphertext hashes.
Admin-minted encrypted supply for demo institutions. Freighter-signed, verifier-checked mint proofs.
Decrypt shielded holdings locally. Dashboard activity from Soroban events — amounts stay private.
Witness + prove on the backend; Freighter signs unsigned XDR. Frontend on Vercel, keys stay with you.
Flow
Freighter on Stellar testnet. Generate a BabyJub view key; save the backup in your browser.
Admin mints encrypted supply, or deposit public units into your shielded balance.
Backend builds the Groth16 proof; you sign in Freighter. Counterparty must be registered.
Dashboard reveals balances with your view key only — never sent to the prover API.
Open the dashboard — register, mint, and settle with your demo counterparty on live testnet.