Protocol
Architecture
Updated 1 October 202610 min read
Redacted is built from a few pieces around one idea. Secrets live in your browser, value lives on-chain and everything in between only transports. This page puts the whole system on one map, follows the money through it and then takes each piece in turn.
The system map
Read the map from the middle out. The core lives on THORChain, where the Reserve holds the funds as private notes, your Spending accounts act from it and they reach all of Rujira. The entry doors are the ways money gets in, which are a direct deposit from your public wallet and coins from other chains through a pay-in account.
The nodes are independent, bonded operators. They carry your sealed actions to the chain, approve deposits, release them after the wait and vote on the brakes, and what a node checks is up to that node. Ozone is the reference screener. It signs answers about addresses tied to known hacks or sanctions lists and decides nothing. Governance sets the public rules through token holders (the DAO until the relaunch), the upgrade timelock and Bōheki, a capped brake. You hold the keys, and your browser proves every action and sends it, sealed, to a node picked at random.
How money moves
Money comes in three ways. A direct deposit comes from your public wallet, and a node may check the source before it approves. Money someone else sends to a Spending account can be traced before it enters the Reserve. Coins from other chains arrive through a pay-in account and never at a Spending account. All new money waits about two hours, which breaks the timing link between a deposit and what you do next and gives the nodes time to send back money they decide not to accept. Coins tied to known hacks or sanctions lists don't enter the Reserve, and a rejected deposit goes back only to the address it came from. See New money waits briefly.
Once your money is in the Reserve, you can move it to a Spending account, use any Rujira product and bring it back without waiting, and your own money comes back from Spending at once (see Returns from Spending). Withdrawals are always open. No vote, pause or delay applies to them, and if no node is active for 7 days the emergency exit opens by itself (see The emergency exit).
The browser
Your keys are derived from one wallet signature and exist only in your browser. It decrypts your notes, rebuilds your balances from public chain data and generates the zero-knowledge proofs that authorize every action, and nothing secret ever leaves it.
That is why there is no database. Your account state isn't stored with us. It is rebuilt each time from the chain plus your keys, and any browser can do that, including ours.
The Reserve contract
The Reserve holds all users' assets and applies its rules through zero-knowledge verification.
- Each deposit becomes a commitment in a Merkle tree, together with an encrypted note that only the owner can read.
- Spending requires a Groth16 proof that you own an unspent note in the tree, without revealing which one.
- A nullifier retires each spent note forever, so a note can't be spent twice.
- The contract's own books always balance, because it continuously accounts for every asset it owes against every asset it holds.
There is no admin backdoor into these rules. The contract has no sweep function, no owner override and no switch that can stop a withdrawal. Its message surface is the user actions you see in the app, a time-locked and hard-capped fee governance path and, with the node network, the rules for bonded relayer nodes, whose brakes can only pause money coming in.
The Spending account
Each Spending account is a minimal smart-contract account with a single master, the Reserve acting on your proofs. It is created without any migration admin, so it is immutable from the moment it exists. It executes your call plans (trades, swaps, stakes and THORChain deposits) and nothing else, for no one else.
The relayer
The relayer carries your sealed actions to the chain and pays the network fee. Every proof binds the action, the amounts, the destination, the fee, the specific relayer and an expiry, so changing a single bit makes the proof worthless. The relayer can therefore deliver your sealed action or decline to, and that is the full extent of its power. It never sees a key, a note or a choice.
Today one relayer carries the actions. With the node network, the relayer is one of many independent, bonded nodes, picked at random for each action, and if none is live for 7 days you can submit your own withdrawal. See How the node network works.
Governance and safety
The pieces above sit inside a layer of public, capped governance.
- Token holders (the DAO until the relaunch) decide the fees, the wait, bond sizes, screening policy and code upgrades. Fees, the wait and bond sizes change only after an on-chain notice.
- Staking lets holders back a node with the bond currency. Stake counts toward the node's bond, so where holders stake helps decide which nodes run. See Staking behind a node.
- The upgrade timelock holds every code upgrade for about 3 days, in public, so anyone who disagrees can withdraw first. The emergency lane, which needs all three emergency signers, can run an upgrade the DAO already scheduled at once.
- Node votes control five switches, which are the deposit pause, the deposit cap per hour, pausing new private accounts, strict screening and incident mode. Two thirds of the active nodes, and at least three, decide.
- Bōheki is a capped brake, a 2-of-3 multisig that can pause deposits or start incident mode once, for about 3 days at most. Only the DAO can re-arm it.
Every brake acts only on money coming in, on everyone at once, and none of them touches a withdrawal. See Security and upgrades, How the node network works and How it all fits together.
The note tree
Every deposit and every private action mints a note, which is a Poseidon commitment appended to a Merkle tree next to a ciphertext sealed to its owner with AES-256-GCM. The chain stores everything and understands nothing. To every observer, including us and the relayer, it is envelopes stacking up in a tree 4.3 billion slots deep.
Three properties of the tree are worth knowing. The cost is constant, because appending note four billion costs exactly what note four cost, which is thirty-two hashes, and proofs are the same size on day one and on day ten thousand. The tree doesn't slow down or degrade as it fills.
Nothing is ever deleted. The tree is append-only and every note stays where it landed, which is part of how the privacy works, because every new deposit joins everyone who came before it and the crowd you blend into only grows.
Capacity is not a practical limit either. 4.3 billion notes is a million private actions a year for two thousand years, and if it ever mattered, a fresh tree could stand up beside the old one with the same math, the same ceremony-verified circuits and the same one-signature access.
The ciphertexts that travel with the commitments are also why there is no database anywhere in the system. Any browser holding your keys, and only your keys, can rebuild your entire account from public chain data alone, so the chain serves as the backup and the ledger, and your signature is the only index into it.
The cryptography
| Purpose | Design |
|---|---|
| Ownership and authorization | Groth16 zero-knowledge proofs over BN254 |
| Note privacy | Poseidon commitments, one-time nullifiers |
| Note and backup encryption | AES-256-GCM, PBKDF2-SHA256 (600k iterations) for backups |
| Key derivation | Deterministic wallet signature, scoped to wallet + chain + deployment |
| Trust setup | Community ceremony, where one honest participant is enough |
What can be replaced
Every component can be replaced except the one you control. If you lose the frontend, any client can rebuild your account from chain data. If you lose the relayer, another one can carry your proofs. If you lose your device, your backup restores everything through any supported wallet. The one irreplaceable piece is your keys, and those never leave your hands.
For more detail, see Relayer, Security and upgrades and the Integration guide.