Skip to main content

Context

A bolt-on privacy feature looks like if (shielded) callZcashService(): a second payment system with its own state, its own books and its own failure modes, reconciled with the first by hand.

Decision

Privacy is the zcash_ironwood venue in the one route graph. privacy: "shielded" is a constraint on the path (it must end in a shielded venue), not a separate subsystem.

Consequences

  • Shielded and public payouts share every guarantee: exactly-once booking, compensation, reconciliation.
  • Disclosure is built in: a viewing key per (customer, period).
  • The console shows shielded balances only to the customer and key holders.

Alternatives rejected

  • A separate privacy service: duplicated state and a reconciliation problem between systems.
  • A private L2 or mixer: weaker disclosure semantics and no per-period audit scoping.