Run receipt
- Payments
- 4
- Amounts
- sealed
- Receipts
- 4 × .nota
- Status
- Delivered
For finance and treasury teams paying on-chain
Aroko is registered mail for money. Every payment is sealed, delivered, and receipted on public rails. Prove it to anyone with the right to ask.
Built on the confidential-finance stack
A finance team that pays 50 people on-chain publishes 50 salaries. Pay a supplier and every competitor reads the terms. This is not a privacy preference. It is a trade-secret leak, a labor-law exposure, and the reason CFOs say no to the rail.
| Recipient | Amount |
|---|---|
| 0x7f…3ab2 | $8,250.00 |
| 0x9c…41e0 | $12,400.00 |
| 0x21…d90c | $6,100.00 |
| 0xe4…77a1 | $14,900.00 |
| 0x5b…08f3 | $9,700.00 |
| 0xa0…c2e7 | $21,300.00 |
| Recipient | Amount |
|---|---|
| 0x7f…3ab2 | Sealed |
| 0x9c…41e0 | Sealed |
| 0x21…d90c | Sealed |
| 0xe4…77a1 | Sealed |
| 0x5b…08f3 | Sealed |
| 0xa0…c2e7 | Sealed |
settled in stablecoins over the last twelve months
workers paid through platforms that now settle in USDC
of those payments are public. To everyone. Forever.
of those platforms seal the amount.
Deel, Rise, Bitwage and Request Finance moved payroll on-chain in 2025–26. The rails are ready. The envelope is missing.
You already moved payouts on-chain. Now every number is public. Aroko seals them before the next run, without a cryptography team.
Supplier paid. Your terms stay yours.
Everyone paid. No salary on a public feed.
Contractors paid on schedule. Rates stay private.
Run a payroll or payout platform? Offer your customers a confidential mode.
The cryptography exists. Shipping it means owning keys, proofs and an auditor path. Aroko ships all three.
Easy to run. Every amount broadcast, to everyone, forever.
Amounts sealed, counterparties anonymous. Compliance says no, and so does your CFO.
Powerful math. Now it is your math.
Sealed to the crowd. Open to the law. One call.
const input = instance.createEncryptedInput(contractAddress, userAddress)
input.add64(amount)
const { handles, inputProof } = await input.encrypt()
euint64 amt = FHE.fromExternal(encryptedAmount, inputProof);
FHE.allowThis(balance); FHE.allowTransient(amt, msg.sender);
token.setOperator(operator, until)
requestRedeem(stable, maxStableOut, encryptedAmount, inputProof)
finalizeRedeem(redeemId, cleartextBurned, decryptionProof)
const { publicKey, privateKey } = instance.generateKeypair()
await instance.userDecrypt(handles, privateKey, publicKey, signature, …)
// + KYC gate, receipts, auditor disclosure, key custody …
await aroko.transfers.create({
to: "0x7f…3ab2", amount: 8250.00
})
→ { status: "settled", nota: "#42" }
// the SDK seals the amount on your machine · on-chain today: confidentialTransfer(to, handle, inputProof)
| Public rails | Privacy coins and mixers | Build it yourself on FHE | Aroko | |
|---|---|---|---|---|
| Amounts sealed | No | Yes | Yes | Yes |
| Counterparties identified (KYC passport) | Yes | No | You build it | Yes |
| Regulator opens any amount on lawful request | n/a, already public | No | You build it | Yes |
| Proof of delivery (.nota receipt) | No | No | You build it | Yes |
| Cryptography your team must own | None | Some | All of it | None |
| Keeps your stablecoin, wallet and Ethereum | Yes | No | Yes | Yes |
| Privacy coins and mixers | Build it yourself on FHE | |
|---|---|---|
| Amounts sealed | Yes | Yes |
| Counterparties identified (KYC passport) | No | You build it |
| Regulator opens any amount on lawful request | No | You build it |
| Proof of delivery (.nota receipt) | No | You build it |
| Cryptography your team must own | Some | All of it |
| Keeps your stablecoin, wallet and Ethereum | No | Yes |
We ship the two layers the cryptographers don’t: the .nota receipt and the compliance passport.
Confidential, not anonymous. Every sender and receiver holds a KYC passport.
Features get copied in two weeks. A KYC-gated confidential rail on a live standard does not.
Upload the payout run you already have. Approve it. Your team never touches keys or encryption.
Payout run
payout-run.csv · 4 payees
| Payee | Amount |
|---|---|
| 0x7f…3ab2 | sealed |
| 0x9c…41e0 | sealed |
| 0x2d…e7c1 | sealed |
| 0x51…08af | sealed |
Run receipt
The CSV or export you already have.
Your approvers, your roles. Nothing to install.
Each payment gets a .nota. Auditors open any amount on lawful request.
Design-partner preview. Roles, KYC passports and the .nota ledger in one workspace. No keys, no ciphertext, no math.
Pay supplier
To 0x7f…3ab2
Receipt #42
The amount is encrypted before it touches the chain. Only sender and recipient hold the key.
Settlement runs on public Ethereum like any transfer. Anyone can see it landed.
Anyone confirms delivery with one call. Only an authorized reader opens the amount.
Built on Zama’s fully homomorphic encryption (FHE) and the ERC-7984 confidential-token standard from OpenZeppelin, Zama and Inco. Zama built the code. Aroko built the phone.
Mint sealed dollars 1:1. Move them encrypted. Redeem to stables. Verify any payment by signature or by anchor.
Mint. Deposit stables, receive cAROUSD 1:1. The balance is sealed from the first block.
Transfer and redeem. Encrypted client-side, settled on-chain, redeemed in two phases: burn, then finalize.
Verify. Every payment returns a .nota. Check it by EIP-712 signature with no chain call, or by on-chain anchor with no trust in us.
POST /v1/deposits { "recipient": "0x9c…41e0", "stable": "USDC", "amount": "250000.00" } // the deposit is public USDC; the balance is sealed from mint // on-chain today: commitDeposit(recipient, stable, amount) → netAmount → 201 { "minted": "cAROUSD", "netAmount": "sealed", "backed": "1:1" }
const sealed = await aroko.encrypt(amount) // Zama FHE — encrypted client-side POST /v1/transfers { "to": "0x7f…3ab2", "amount": sealed.handle, "proof": sealed.inputProof } // on-chain today: confidentialTransfer(to, handle, inputProof) → 201 { "status": "settled", "nota": "#42" }
POST /v1/redemptions { "stable": "USDC", "maxStableOut": "250000.00", "amount": sealed.handle, "proof": sealed.inputProof } // on-chain today: requestRedeem(…) → redeemId — two-phase: burn, then finalize → 202 { "redeemId": "0x5d…", "phase": "burning" }
GET /v1/nota/42/verify // two ways to trust a receipt: // by signature — EIP-712, no chain required // by anchor — on-chain tokenId, no trust in Aroko required // on-chain today: tokenURI(42) + EIP-712 recover → 200 { "delivered": true, "phase": "sealed" }
REST + SDK ship with the sandbox · today: Solidity 0.8.27 on Sepolia · 12 contracts · 250 passing tests
Send a payment. Aroko returns a .nota: a signed, sealed receipt. The chain proves it settled. The amount stays sealed. Disclose only to a party with the right to ask.
.nota
Sample notas · sandbox
GET /v1/nota/42/verify
returns 200 { "delivered": true, "phase": "sealed" }
// on-chain today: tokenURI(42) + EIP-712 recover
Aroko is not privacy from the system. It is privacy from everyone who is not the system. Every sender and receiver holds a KYC passport. Every amount opens on lawful request.
| Who | What they see | What they keep |
|---|---|---|
| The business | Its own books | Trade secrets, margins, salaries |
| Regulators and auditors | Any amount, on lawful request | A named, identified ledger |
| Employees | Their own pay | Their salary off the feed |
| Competitors and scrapers | Delivery only | Nothing |
Aroko is a Yoruba word for a message sent as an object. A string of cowries, a folded leaf, a knotted cord, carried by a courier in the open. Everyone on the road saw the package. Only the person it was addressed to could read it.
Carried in the open.
Protected by law since the 1840s.
Sealed by Aroko. Receipted on-chain.
The category · Zama, Bron, OpenZeppelin, Inco
Proof, not a pitch
The rail Aroko builds on has settled real payroll on Ethereum mainnet. Our contracts are deployed, verified, and under internal review on Sepolia today. REST and SDK ship with the sandbox.
Aroko · shipped
Where this goes
Sealed B2B settlement and payroll.
Sealed invoices, sealed balances, sealed treasury reporting.
The confidential layer for every payment on every public chain. A rail a business uses without thinking about it.
Sandbox access
Join the sandbox waitlist. We are onboarding finance and treasury teams that run recurring on-chain payouts, B2B settlement first.
We’ll write when your sandbox is ready.
Envelope didn’t open? Send it to hello@aro.media