Protocol

Architecture

Updated 1 October 202610 min read

Redacted is built from a few pieces around one idea. Secrets live in your browser, value lives on-chain and everything in between only transports. This page puts the whole system on one map, follows the money through it and then takes each piece in turn.

The system map

The Redacted system map The entry doors lead into the Reserve of private notes. The Reserve, the Spending accounts and the Rujira products sit on THORChain. Independent nodes relay your actions, approve deposits after their own checks and vote on the safety switches, and Ozone is the reference screener they can use. Token holders and the DAO set the public rules, with an upgrade timelock and the Bōheki brake. The Reserve Private notes of all users, held together. Only your proofs can spend yours. Spending accounts Your private accounts, where money acts at once. Rujira products Trade, swap, stake, borrow and more. Entry doors Your public wallet Direct deposit Other chains Via a pay-in account You Your browser Keys, notes and proofs stay here. It sends sealed actions to a random node. Independent nodes Bonded operators Relay your actions Approve deposits after their own checks Release them when the wait is over Vote a deposit back, to its sender only Vote on five safety switches Confirm your own returns Ozone The reference screener signs answers about public lists and decides nothing. Emergency exit If no node is active for 7 days, the exit opens by itself. can check addresses Governance Token holders and the DAO They set fees, the wait, bonds and the screening policy, and admit, back or remove nodes. The DAO acts until the relaunch. Upgrade timelock Code upgrades wait about 3 days, in public. An emergency lane, with all three emergency signers, can run a scheduled upgrade at once. Bōheki A capped 2-of-3 brake that pauses new deposits or starts incident mode, once, for about 3 days at most. Only the DAO re-arms it. Relay, approve, release Five safety switches Rules, upgrades, one brake

Read the map from the middle out. The core lives on THORChain, where the Reserve holds the funds as private notes, your Spending accounts act from it and they reach all of Rujira. The entry doors are the ways money gets in, which are a direct deposit from your public wallet and coins from other chains through a pay-in account.

The nodes are independent, bonded operators. They carry your sealed actions to the chain, approve deposits, release them after the wait and vote on the brakes, and what a node checks is up to that node. Ozone is the reference screener. It signs answers about addresses tied to known hacks or sanctions lists and decides nothing. Governance sets the public rules through token holders (the DAO until the relaunch), the upgrade timelock and Bōheki, a capped brake. You hold the keys, and your browser proves every action and sends it, sealed, to a node picked at random.

How money moves

How money flows through Redacted Money reaches Redacted through a direct deposit, through coins that someone sends to a Spending account, or through coins from other chains that arrive at a pay-in account. New money settles for about two hours, and nodes may check where it came from. Coins tied to known hacks or sanctions lists do not enter the Reserve and can go back to where they came from. Once your money is in the Reserve, you can move it to a Spending account, trade on Rujira and bring it back without waiting, and you can always withdraw. Three ways in Direct deposit From your public wallet. A node may check the source before it approves. Sent to a Spending account Anyone can send coins to its address. Nodes can trace them before they enter the Reserve. From other chains Native coins arrive at a pay-in account and never at a Spending account. New money settles for about 2 hours Nodes may check where it came from. The wait means a deposit cannot be matched to what you do next. Each node decides what it checks. Inside Redacted The Reserve Private notes of all users, held together. Spending accounts Your private accounts, where money acts at once. Rujira products Trade, swap, stake, borrow. Way out Withdrawals You can always withdraw, with no delay, and no vote or pause applies. Coins tied to known hacks or sanctions lists They do not enter the Reserve and can go back to where they came from. In a Spending account they stay, and no one can redirect or keep them. known hack or sanctions list Returns from Spending Your own money comes back at once. Money someone else sent waits like a deposit. A mixed return is split.

Money comes in three ways. A direct deposit comes from your public wallet, and a node may check the source before it approves. Money someone else sends to a Spending account can be traced before it enters the Reserve. Coins from other chains arrive through a pay-in account and never at a Spending account. All new money waits about two hours, which breaks the timing link between a deposit and what you do next and gives the nodes time to send back money they decide not to accept. Coins tied to known hacks or sanctions lists don't enter the Reserve, and a rejected deposit goes back only to the address it came from. See New money waits briefly.

Once your money is in the Reserve, you can move it to a Spending account, use any Rujira product and bring it back without waiting, and your own money comes back from Spending at once (see Returns from Spending). Withdrawals are always open. No vote, pause or delay applies to them, and if no node is active for 7 days the emergency exit opens by itself (see The emergency exit).

The browser

Your keys are derived from one wallet signature and exist only in your browser. It decrypts your notes, rebuilds your balances from public chain data and generates the zero-knowledge proofs that authorize every action, and nothing secret ever leaves it.

That is why there is no database. Your account state isn't stored with us. It is rebuilt each time from the chain plus your keys, and any browser can do that, including ours.

The Reserve contract

The Reserve holds all users' assets and applies its rules through zero-knowledge verification.

  • Each deposit becomes a commitment in a Merkle tree, together with an encrypted note that only the owner can read.
  • Spending requires a Groth16 proof that you own an unspent note in the tree, without revealing which one.
  • A nullifier retires each spent note forever, so a note can't be spent twice.
  • The contract's own books always balance, because it continuously accounts for every asset it owes against every asset it holds.

There is no admin backdoor into these rules. The contract has no sweep function, no owner override and no switch that can stop a withdrawal. Its message surface is the user actions you see in the app, a time-locked and hard-capped fee governance path and, with the node network, the rules for bonded relayer nodes, whose brakes can only pause money coming in.

The Spending account

Each Spending account is a minimal smart-contract account with a single master, the Reserve acting on your proofs. It is created without any migration admin, so it is immutable from the moment it exists. It executes your call plans (trades, swaps, stakes and THORChain deposits) and nothing else, for no one else.

The relayer

The relayer carries your sealed actions to the chain and pays the network fee. Every proof binds the action, the amounts, the destination, the fee, the specific relayer and an expiry, so changing a single bit makes the proof worthless. The relayer can therefore deliver your sealed action or decline to, and that is the full extent of its power. It never sees a key, a note or a choice.

Today one relayer carries the actions. With the node network, the relayer is one of many independent, bonded nodes, picked at random for each action, and if none is live for 7 days you can submit your own withdrawal. See How the node network works.

Governance and safety

The pieces above sit inside a layer of public, capped governance.

  • Token holders (the DAO until the relaunch) decide the fees, the wait, bond sizes, screening policy and code upgrades. Fees, the wait and bond sizes change only after an on-chain notice.
  • Staking lets holders back a node with the bond currency. Stake counts toward the node's bond, so where holders stake helps decide which nodes run. See Staking behind a node.
  • The upgrade timelock holds every code upgrade for about 3 days, in public, so anyone who disagrees can withdraw first. The emergency lane, which needs all three emergency signers, can run an upgrade the DAO already scheduled at once.
  • Node votes control five switches, which are the deposit pause, the deposit cap per hour, pausing new private accounts, strict screening and incident mode. Two thirds of the active nodes, and at least three, decide.
  • Bōheki is a capped brake, a 2-of-3 multisig that can pause deposits or start incident mode once, for about 3 days at most. Only the DAO can re-arm it.

Every brake acts only on money coming in, on everyone at once, and none of them touches a withdrawal. See Security and upgrades, How the node network works and How it all fits together.

The note tree

Every deposit and every private action mints a note, which is a Poseidon commitment appended to a Merkle tree next to a ciphertext sealed to its owner with AES-256-GCM. The chain stores everything and understands nothing. To every observer, including us and the relayer, it is envelopes stacking up in a tree 4.3 billion slots deep.

The note tree A Merkle tree with 32 levels of hashing between one root hash and a row of sealed notes. A proof walks one path from your note up to the root without revealing which leaf is yours. thirty-two levels of hashing … … the root one hash the contract trusts your note your proof walks this path it shows your note connects to the root without revealing which leaf is yours

Three properties of the tree are worth knowing. The cost is constant, because appending note four billion costs exactly what note four cost, which is thirty-two hashes, and proofs are the same size on day one and on day ten thousand. The tree doesn't slow down or degrade as it fills.

Nothing is ever deleted. The tree is append-only and every note stays where it landed, which is part of how the privacy works, because every new deposit joins everyone who came before it and the crowd you blend into only grows.

Capacity is not a practical limit either. 4.3 billion notes is a million private actions a year for two thousand years, and if it ever mattered, a fresh tree could stand up beside the old one with the same math, the same ceremony-verified circuits and the same one-signature access.

The ciphertexts that travel with the commitments are also why there is no database anywhere in the system. Any browser holding your keys, and only your keys, can rebuild your entire account from public chain data alone, so the chain serves as the backup and the ledger, and your signature is the only index into it.

The cryptography

PurposeDesign
Ownership and authorizationGroth16 zero-knowledge proofs over BN254
Note privacyPoseidon commitments, one-time nullifiers
Note and backup encryptionAES-256-GCM, PBKDF2-SHA256 (600k iterations) for backups
Key derivationDeterministic wallet signature, scoped to wallet + chain + deployment
Trust setupCommunity ceremony, where one honest participant is enough

What can be replaced

Every component can be replaced except the one you control. If you lose the frontend, any client can rebuild your account from chain data. If you lose the relayer, another one can carry your proofs. If you lose your device, your backup restores everything through any supported wallet. The one irreplaceable piece is your keys, and those never leave your hands.

For more detail, see Relayer, Security and upgrades and the Integration guide.