Banknote-style engraving of a postmaster in a peaked cap, holding up an envelope closed with a wax seal.

For finance and treasury teams paying on-chain

Move money. Show no one.

Aroko is registered mail for money. Every payment is sealed, delivered, and receipted on public rails. Prove it to anyone with the right to ask.

Built on the confidential-finance stack

  • ERC-7984
  • ZAMA
  • OPENZEPPELIN
  • INCO
  • BRIDGE.XYZ
The problem

Your payroll is on a billboard.

A finance team that pays 50 people on-chain publishes 50 salaries. Pay a supplier and every competitor reads the terms. This is not a privacy preference. It is a trade-secret leak, a labor-law exposure, and the reason CFOs say no to the rail.

Public chain · anyone can read
RecipientAmount
0x7f…3ab2$8,250.00
0x9c…41e0$12,400.00
0x21…d90c$6,100.00
0xe4…77a1$14,900.00
0x5b…08f3$9,700.00
0xa0…c2e7$21,300.00
Aroko · amount sealed
RecipientAmount
0x7f…3ab2Sealed
0x9c…41e0Sealed
0x21…d90cSealed
0xe4…77a1Sealed
0x5b…08f3Sealed
0xa0…c2e7Sealed
  • $9T

    settled in stablecoins over the last twelve months

  • 1.5M

    workers paid through platforms that now settle in USDC

  • 100%

    of those payments are public. To everyone. Forever.

  • 0

    of those platforms seal the amount.

Deel, Rise, Bitwage and Request Finance moved payroll on-chain in 2025–26. The rails are ready. The envelope is missing.

Who it’s for

Built for the people who sign the payout run.

You already moved payouts on-chain. Now every number is public. Aroko seals them before the next run, without a cryptography team.

  • Start here

    B2B settlement

    Supplier paid. Your terms stay yours.

  • Payroll

    Everyone paid. No salary on a public feed.

  • Contractor and cross-border payouts

    Contractors paid on schedule. Rates stay private.

What you keep

  • Trade secrets
  • Margins
  • Salaries
  • Supplier terms

What you prove

  • Delivery
  • Compliance
  • Every amount, on lawful request

Run a payroll or payout platform? Offer your customers a confidential mode.

The alternatives

Four ways to pay on-chain. Only one is private and compliant.

The cryptography exists. Shipping it means owning keys, proofs and an auditor path. Aroko ships all three.

  1. Exposed

    Stay on public rails.

    Easy to run. Every amount broadcast, to everyone, forever.

  2. Anonymous

    Privacy coins and mixers.

    Amounts sealed, counterparties anonymous. Compliance says no, and so does your CFO.

  3. You build it

    Build it yourself on FHE.

    Powerful math. Now it is your math.

    What you’d own
    • Encrypt every amount client-side and generate input proofs
    • Grant and track decryption permissions per address
    • Integrate a relayer and key management
    • Authorize operators with expiries
    • Run two-phase redemption: burn now, finalize later
    • Build the KYC gate
    • Issue receipts
    • Build a disclosure path for auditors
  4. Sealed

    Aroko

    Sealed to the crowd. Open to the law. One call.

Build it yourself

on-chain today · client · contract · keys
const input = instance.createEncryptedInput(contractAddress, userAddress)
input.add64(amount)
const { handles, inputProof } = await input.encrypt()
euint64 amt = FHE.fromExternal(encryptedAmount, inputProof);
FHE.allowThis(balance); FHE.allowTransient(amt, msg.sender);
token.setOperator(operator, until)
requestRedeem(stable, maxStableOut, encryptedAmount, inputProof)
finalizeRedeem(redeemId, cleartextBurned, decryptionProof)
const { publicKey, privateKey } = instance.generateKeypair()
await instance.userDecrypt(handles, privateKey, publicKey, signature, …)
// + KYC gate, receipts, auditor disclosure, key custody …

With Aroko

Sandbox
await aroko.transfers.create({
  to: "0x7f…3ab2", amount: 8250.00
})
→ { status: "settled", nota: "#42" }

// the SDK seals the amount on your machine · on-chain today: confidentialTransfer(to, handle, inputProof)
One call. DeliveredAmount sealed
What each option makes your team own
Public rails Privacy coins and mixers Build it yourself on FHE Aroko
Amounts sealed No Yes Yes Yes
Counterparties identified (KYC passport) Yes No You build it Yes
Regulator opens any amount on lawful request n/a, already public No You build it Yes
Proof of delivery (.nota receipt) No No You build it Yes
Cryptography your team must own None Some All of it None
Keeps your stablecoin, wallet and Ethereum Yes No Yes Yes
Show all four options
The other two options
Privacy coins and mixers Build it yourself on FHE
Amounts sealed Yes Yes
Counterparties identified (KYC passport) No You build it
Regulator opens any amount on lawful request No You build it
Proof of delivery (.nota receipt) No You build it
Cryptography your team must own Some All of it
Keeps your stablecoin, wallet and Ethereum No Yes
  1. We ship the two layers the cryptographers don’t: the .nota receipt and the compliance passport.

  2. Confidential, not anonymous. Every sender and receiver holds a KYC passport.

  3. Features get copied in two weeks. A KYC-gated confidential rail on a live standard does not.

How it works

What switching looks like.

Upload the payout run you already have. Approve it. Your team never touches keys or encryption.

Payout run

payout-run.csv · 4 payees

Imported payout run, every amount sealed
PayeeAmount
0x7f…3ab2sealed
0x9c…41e0sealed
0x2d…e7c1sealed
0x51…08afsealed
Approve run

Run receipt

Payments
4
Amounts
sealed
Receipts
4 × .nota
Status
Delivered
Delivered Amounts sealed
  1. Import the payout run

    The CSV or export you already have.

  2. Approve

    Your approvers, your roles. Nothing to install.

  3. Every amount sealed. Every payment receipted.

    Each payment gets a .nota. Auditors open any amount on lawful request.

Design-partner preview. Roles, KYC passports and the .nota ledger in one workspace. No keys, no ciphertext, no math.

Built on Zama’s fully homomorphic encryption (FHE) and the ERC-7984 confidential-token standard from OpenZeppelin, Zama and Inco. Zama built the code. Aroko built the phone.

For your engineers

Four calls. That’s the whole rail.

Mint sealed dollars 1:1. Move them encrypted. Redeem to stables. Verify any payment by signature or by anchor.

  • Mint. Deposit stables, receive cAROUSD 1:1. The balance is sealed from the first block.

  • Transfer and redeem. Encrypted client-side, settled on-chain, redeemed in two phases: burn, then finalize.

  • Verify. Every payment returns a .nota. Check it by EIP-712 signature with no chain call, or by on-chain anchor with no trust in us.

Get sandbox access
POST /v1/deposits Sandbox
POST /v1/deposits
{
  "recipient": "0x9c…41e0",
  "stable": "USDC",
  "amount": "250000.00"
}
// the deposit is public USDC; the balance is sealed from mint
// on-chain today: commitDeposit(recipient, stable, amount) → netAmount

→ 201 { "minted": "cAROUSD", "netAmount": "sealed", "backed": "1:1" }

REST + SDK ship with the sandbox · today: Solidity 0.8.27 on Sepolia · 12 contracts · 250 passing tests

The .nota receipt

Prove the payment. Not the amount.

Send a payment. Aroko returns a .nota: a signed, sealed receipt. The chain proves it settled. The amount stays sealed. Disclose only to a party with the right to ask.

Engraved illustration of a sealed envelope with a wax seal, floating on a violet-to-pink gradient.

.nota

Receipt #42

Recipient
0x7f…3ab2
Amount
sealed
Anchor
tokenId 42
Signature
EIP-712 verified
Delivered Amount sealed

Sample notas · sandbox

  1. #45 · Payroll 50 recipients · delivered Amount: sealed just now
  2. #44 · Supplier settlement delivered Amount: sealed 4 min ago
  3. #43 · Contractor payout delivered Amount: sealed 11 min ago
  4. #42 · B2B invoice delivered Amount: sealed 26 min ago
Verify a .nota Sandbox
GET /v1/nota/42/verify
returns 200 { "delivered": true, "phase": "sealed" }
// on-chain today: tokenURI(42) + EIP-712 recover
Who sees what

Regulators get a cleaner ledger than they have ever had.

Aroko is not privacy from the system. It is privacy from everyone who is not the system. Every sender and receiver holds a KYC passport. Every amount opens on lawful request.

  • Confidential, not anonymous
  • Soulbound KYC passport
  • Travel Rule–ready
Envelope access
Who What they see What they keep
The business Its own books Trade secrets, margins, salaries
Regulators and auditors Any amount, on lawful request A named, identified ledger
Employees Their own pay Their salary off the feed
Competitors and scrapers Delivery only Nothing
Why the name

The post office solved this in 1840. West Africa solved it earlier.

Aroko is a Yoruba word for a message sent as an object. A string of cowries, a folded leaf, a knotted cord, carried by a courier in the open. Everyone on the road saw the package. Only the person it was addressed to could read it.

Aroko · Yoruba, n.
A coded message sent as an object. Everyone sees the package. Only the recipient can read it.
  • The cord of cowries

    Carried in the open.

  • The sealed letter

    Protected by law since the 1840s.

  • The .nota

    Sealed by Aroko. Receipted on-chain.

The category · Zama, Bron, OpenZeppelin, Inco

  • Jan 2026 First confidential payroll on Ethereum mainnet, executed live by Zama and Bron.
  • ERC-7984 The confidential-token standard, jointly authored by OpenZeppelin, Zama and Inco.
  • $57M Series B Zama’s institutional round, led by Pantera Capital.
  • OTC trade First confidential institutional OTC trade settled on Ethereum, on the same rail.

Proof, not a pitch

The hard part is already on mainnet.

The rail Aroko builds on has settled real payroll on Ethereum mainnet. Our contracts are deployed, verified, and under internal review on Sepolia today. REST and SDK ship with the sandbox.

Aroko · shipped

  • 12 contracts deployed on Sepolia
  • 250 passing tests, incl. encrypted mint, transfer, redeem
  • 4 API calls. Mint, transfer, redeem, verify.

Where this goes

Every business ledger, sealed by default.

  1. Today

    Sealed B2B settlement and payroll.

  2. Next

    Sealed invoices, sealed balances, sealed treasury reporting.

  3. Then

    The confidential layer for every payment on every public chain. A rail a business uses without thinking about it.

Sandbox access

Seal your first payment.

Join the sandbox waitlist. We are onboarding finance and treasury teams that run recurring on-chain payouts, B2B settlement first.

What you get in the sandbox

  • Sealed transfers on Sepolia
  • .nota receipts on every payment
  • A KYC passport test flow
  • Workspace preview for design partners

No backend yet. This opens your mail app, addressed to hello@aro.media.