Receipt #42
- Recipient
- 0x7f…3ab2
- Amount
- sealed
- Anchor
- tokenId 42
- Signature
- EIP-712 verified
Sandbox waitlist open
Aroko is registered mail for money. Every payment is sealed, delivered, and receipted on public rails. Prove it to anyone with the right to ask.
Built on the confidential-finance stack
A finance team that pays 50 people on-chain publishes 50 salaries. Pay a supplier and every competitor reads the terms. This is not a privacy preference. It is a trade-secret leak, a labor-law exposure, and the reason CFOs say no to the rail.
| Recipient | Amount |
|---|---|
| 0x7f…3ab2 | $8,250.00 |
| 0x9c…41e0 | $12,400.00 |
| 0x21…d90c | $6,100.00 |
| 0xe4…77a1 | $14,900.00 |
| 0x5b…08f3 | $9,700.00 |
| 0xa0…c2e7 | $21,300.00 |
| Recipient | Amount |
|---|---|
| 0x7f…3ab2 | Sealed |
| 0x9c…41e0 | Sealed |
| 0x21…d90c | Sealed |
| 0xe4…77a1 | Sealed |
| 0x5b…08f3 | Sealed |
| 0xa0…c2e7 | Sealed |
settled in stablecoins over the last twelve months
workers paid through platforms that now settle in USDC
of those payments are public. To everyone. Forever.
of those platforms seal the amount.
Deel, Rise, Bitwage and Request Finance moved payroll on-chain in 2025–26. The rails are ready. The envelope is missing.
Every payment is a sealed envelope. One call opens it, for the right reader only.
Pay supplier
To 0x7f…3ab2
Receipt #42
The amount is encrypted before it touches the chain. Only sender and recipient hold the key.
Settlement runs on public Ethereum like any transfer. Anyone can see it landed.
Anyone confirms delivery with one call. Only an authorized reader opens the amount.
Built on Zama’s fully homomorphic encryption (FHE) and the ERC-7984 confidential-token standard from OpenZeppelin, Zama and Inco. Zama built the code. Aroko built the phone.
Mint sealed dollars 1:1. Move them encrypted. Redeem to stables. Verify any payment by signature or by anchor.
Mint. Deposit stables, receive cAROUSD 1:1. The balance is sealed from the first block.
Transfer and redeem. Encrypted client-side, settled on-chain, redeemed in two phases: burn, then finalize.
Verify. Every payment returns a .nota. Check it by EIP-712 signature with no chain call, or by on-chain anchor with no trust in us.
POST /v1/deposits { "recipient": "0x9c…41e0", "stable": "USDC", "amount": "250000.00" } // on-chain today: commitDeposit(recipient, stable, amount) → netAmount → 201 { "minted": "cAROUSD", "netAmount": "sealed", "backed": "1:1" }
const sealed = await aroko.encrypt(amount) // Zama FHE — encrypted client-side POST /v1/transfers { "to": "0x7f…3ab2", "amount": sealed.handle, "proof": sealed.inputProof } // on-chain today: confidentialTransfer(to, handle, inputProof) → 201 { "status": "settled", "nota": "#42" }
POST /v1/redemptions { "stable": "USDC", "maxStableOut": "250000.00", "amount": sealed.handle, "proof": sealed.inputProof } // on-chain today: requestRedeem(…) → redeemId — two-phase: burn, then finalize → 202 { "redeemId": "0x5d…", "phase": "burning" }
GET /v1/nota/42/verify // two ways to trust a receipt: // by signature — EIP-712, no chain required // by anchor — on-chain tokenId, no trust in Aroko required // on-chain today: tokenURI(42) + EIP-712 recover → 200 { "delivered": true, "phase": "sealed" }
REST + SDK ship with the sandbox · today: Solidity 0.8.27 on Sepolia · 12 contracts · 250 passing tests
Send a payment. Aroko returns a .nota: a signed, sealed receipt. The chain proves it settled. The amount stays sealed. Disclose only to a party with the right to ask.
.nota
Sample notas · sandbox
GET /v1/nota/42/verify
returns 200 { "delivered": true, "phase": "sealed" }
// on-chain today: tokenURI(42) + EIP-712 recover
Aroko is not privacy from the system. It is privacy from everyone who is not the system. Every sender and receiver holds a KYC passport. Every amount opens on lawful request.
| Who | What they see | What they keep |
|---|---|---|
| The business | Its own books | Trade secrets, margins, salaries |
| Regulators and auditors | Any amount, on lawful request | A named, identified ledger |
| Employees | Their own pay | Their salary off the feed |
| Competitors and scrapers | Delivery only | Nothing |
Aroko is a Yoruba word for a message sent as an object. A string of cowries, a folded leaf, a knotted cord, carried by a courier in the open. Everyone on the road saw the package. Only the person it was addressed to could read it.
Carried in the open.
Protected by law since the 1840s.
Sealed by Aroko. Receipted on-chain.
The category · Zama, Bron, OpenZeppelin, Inco
Proof, not a pitch
The rail Aroko builds on has settled real payroll on Ethereum mainnet. Our contracts are deployed, verified, and under internal review on Sepolia today. REST and SDK ship with the sandbox.
Aroko · shipped
Where this goes
Sealed B2B settlement and payroll.
Sealed invoices, sealed balances, sealed treasury reporting.
The confidential layer for every payment on every public chain. A rail a business uses without thinking about it.
Sandbox access
Join the sandbox waitlist. We are onboarding finance and treasury teams that run recurring on-chain payouts, B2B settlement first.
We’ll write when your sandbox is ready.
Envelope didn’t open? Send it to hello@aro.media