Private transfer protocol · Stellar

Confidential Payments

Compliant by Design

Shield is a transfer standard on Stellar that encrypts every balance with additive ElGamal on BN254. Amounts stay invisible on-chain — yet fully auditable via view keys for parties you authorize.

Built on
StellarSorobanElGamal / BN254Groth16

Platform

Built for regulated B2B flows

Register, mint, transfer, and audit — modular dashboard sections for each step of the shielded lifecycle.

Confidential transfer

B2B settlement with encrypted sender and receiver balances. Groth16 proof binds to on-chain ciphertext hashes.

Enterprise mint

Admin-minted encrypted supply for demo institutions. Freighter-signed, verifier-checked mint proofs.

Corporate balances

Decrypt shielded holdings locally. Dashboard activity from Soroban events — amounts stay private.

Prover on Cloud Run

Witness + prove on the backend; Freighter signs unsigned XDR. Frontend on Vercel, keys stay with you.

Flow

How Shield works

  1. 01

    Connect & register

    Freighter on Stellar testnet. Generate a BabyJub view key; save the backup in your browser.

  2. 02

    Mint or deposit

    Admin mints encrypted supply, or deposit public units into your shielded balance.

  3. 03

    Transfer privately

    Backend builds the Groth16 proof; you sign in Freighter. Counterparty must be registered.

  4. 04

    Decrypt locally

    Dashboard reveals balances with your view key only — never sent to the prover API.

Ready to try a shielded transfer?

Open the dashboard — register, mint, and settle with your demo counterparty on live testnet.

Go to dashboard