> ## Documentation Index
> Fetch the complete documentation index at: https://www.helius.dev/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Encryption and Privacy Guarantees

> Learn what is public and what is encrypted in a private transaction, and how the shielded keypair encrypts and decrypts private balances.

<a id="private-wallet" />

<a id="shielded-keypair" />

<a id="creation-of-a-private-wallet" />

## Privacy Guarantees

Each party in a private transaction sees only what it needs to.
In this example, Alice pays Bob, then Bob pays Charlie. Both are private transfers.

<Tabs>
  <Tab title="Default Ring">
    The Default Ring is the permissionless confidential Ring.
    Sender and recipient addresses are public onchain. Asset and amount are encrypted.
    Only the sender and the recipient can decrypt the transaction, each with their own viewing key. Each can decrypt only their own balance.

    <img src="https://mintcdn.com/helius/ITnDOhn5GRfQ1FQW/images/privacy/who-sees-what-confidential.svg?fit=max&auto=format&n=ITnDOhn5GRfQ1FQW&q=85&s=345de01ce5c5b51451c72f28fb852433" alt="Alice pays Bob, then Bob pays Charlie in a Confidential Ring. Each party's view shows the amounts it can decrypt; the addresses are public to everyone." width="960" height="586" data-path="images/privacy/who-sees-what-confidential.svg" />

    | Party | Sees | Does not see |
    | - | - | - |
    | Alice | Her payment to Bob. That Bob paid Charlie. | The asset and amount of Bob's payment to Charlie |
    | Bob | Alice's payment to him. His payment to Charlie. | Alice's balance |
    | Charlie | Bob's payment to him. That Alice paid Bob. | The asset and amount of Alice's payment to Bob |
    | RPC and Solana | Sender and recipient addresses, commitments, and ciphertexts | Any asset or amount |
  </Tab>

  <Tab title="Custom Rings">
    A Custom Ring

    * can be configured to be confidential, or anonymous
    * can customize compliance controls, and
    * can declare an auditor that can decrypt balances of that Ring.

    <Tabs>
      <Tab title="Confidential Custom Ring">
        Sender and recipient addresses are public onchain. Asset and amount are encrypted.

        <img src="https://mintcdn.com/helius/ITnDOhn5GRfQ1FQW/images/privacy/who-sees-what-confidential.svg?fit=max&auto=format&n=ITnDOhn5GRfQ1FQW&q=85&s=345de01ce5c5b51451c72f28fb852433" alt="Alice pays Bob, then Bob pays Charlie in a Confidential Ring. Each party's view shows the amounts it can decrypt; the addresses are public to everyone." width="960" height="586" data-path="images/privacy/who-sees-what-confidential.svg" />

        | Party | Sees | Does not see |
        | - | - | - |
        | Alice | Her payment to Bob. That Bob paid Charlie. | The asset and amount of Bob's payment to Charlie |
        | Bob | Alice's payment to him. His payment to Charlie. | Alice's balance |
        | Charlie | Bob's payment to him. That Alice paid Bob. | The asset and amount of Alice's payment to Bob |
        | Ring auditor | The Ring activity the policy defines | Activity outside the Ring |
        | RPC and Solana | Sender and recipient addresses, commitments, and ciphertexts | Any asset or amount |
      </Tab>

      <Tab title="Anonymous Custom Ring">
        A relayer submits the transaction. Sender and recipient are not visible onchain. Only the recipient can see which private wallet sent the payment.

        <img src="https://mintcdn.com/helius/ITnDOhn5GRfQ1FQW/images/privacy/who-sees-what-anonymous.svg?fit=max&auto=format&n=ITnDOhn5GRfQ1FQW&q=85&s=8c2c1ee021abe1117743b0ee1de56363" alt="Alice pays Bob, then Bob pays Charlie in an Anonymous Ring. Each party's view shows only its own counterparties and amounts." width="960" height="510" data-path="images/privacy/who-sees-what-anonymous.svg" />

        | Party | Sees | Does not see |
        | - | - | - |
        | Alice | Her payment to Bob | Bob's payment to Charlie, or that Charlie exists |
        | Bob | Alice's payment to him, including which private wallet sent it. His payment to Charlie. | Alice's balance |
        | Charlie | Bob's payment to him, including which private wallet sent it | Alice, or her payment to Bob |
        | Ring auditor | The Ring activity the policy defines | Activity outside the Ring |
        | RPC and Solana | The relayer, commitments, and ciphertexts | Sender, recipient, asset, or amount |
      </Tab>
    </Tabs>
  </Tab>
</Tabs>

<Info>
  This example models private transfers. Deposits and withdrawals reveal more onchain:

  * A deposit from a public balance reveals the source, asset, and amount.
  * A withdrawal reveals the destination, asset, and amount.

  See [what stays private in each flow](/docs/privacy/concepts/overview#deposit-to-a-private-balance).
</Info>

## Encryption

A private wallet consists of a Solana keypair for signing, a nullifier key, and a viewing key for encryption. Together these keys form the shielded keypair. A shielded keypair signs, encrypts and decrypts transactions.

* **Signing key:** The wallet's Ed25519 Solana keypair to sign transactions. In Anonymous Custom Rings, the private wallet's P-256 key signs instead.
* **Viewing key:** A P-256 keypair, used to encrypt and decrypt transactions.
* **Nullifier key:** A key used to derive nullifiers, which prevent a private balance from being spent twice.

The Shielded Address is the shielded keypair's public keys. Transfers encrypt to it.

```
ShieldedAddress = (signing_pk, nullifier_pk, viewing_pk)
```

To learn how transactions are encrypted, see [ViewingKey](https://github.com/helius-labs/zolana/blob/a3ddedda42b40d4951ae8fcdde2500374c4f2125/docs/spec.md#viewingkey) and [AES Key derivation](https://github.com/helius-labs/zolana/blob/a3ddedda42b40d4951ae8fcdde2500374c4f2125/docs/spec.md#aes-key-derivation) in the spec.

### Integrating a Shielded Keypair

A wallet can hold the shielded keypair itself via the native [Wallet Integration](/docs/privacy/integration/wallet).
With the [Embedded Privacy Wallet](/docs/privacy/integration/embedded-wallet), a Wallet Provider holds the shielded keypair and runs its key operations instead.

| Key management | Who holds the shielded keypair | Where its operations run |
| - | - | - |
| Native [Wallet Integration](/docs/privacy/integration/wallet) | The wallet | On the device |
| [Embedded Privacy Wallet](/docs/privacy/integration/embedded-wallet) | A Wallet Provider | In the Wallet Provider's infrastructure |

### Decryption Modes

The owner decrypts their private balance with the viewing key.

Confidential rings (the Default Ring and confidential Custom Rings) support local and delegated decryption.
Anonymous rings (Custom Rings only) support only delegated decryption.

| Mode | Where decryption happens | Who has view access | Wallet tradeoff | Who uses this |
| - | - | - | - | - |
| Local | Inside the wallet | Wallet only | Best privacy but requires local state and sync lifecycle | Confidential rings: the Default Ring and confidential Custom Rings |
| Delegated | Authorized RPC provider | Wallet + provider | Less local sync work but provider can view balances and history | Any ring; the only mode in anonymous Custom Rings |

#### Local Decryption

In local decryption mode, the wallet decrypts and syncs balances and history locally.
Local decryption keeps the viewing key on the device.

#### Delegated Decryption

In delegated decryption mode, the wallet and selected provider share a viewing key.
This lets the provider decrypt balances and history, but it does not grant spending authority.
A wallet may also share prior viewing keys when it authorizes the provider to sync historical activity.

Auditor access is separate from delegated decryption.
An auditor receives policy-defined Ring visibility, while a delegated provider receives wallet-scoped sync access.

#### Selective Disclosure

The owner can share the viewing key to grant read access, for example with an auditor for compliance or with a delegated decryption provider.

* To disclose a single transaction, the sender shares the transaction viewing key, which decrypts only that transaction.
* Custom Rings can also set a separate auditor key. It decrypts the Ring activity the policy defines. Learn more in [Custom Enterprise Rings](/docs/privacy/integration/enterprise).

## Learn More

<CardGroup cols={2}>
  <Card title="Overview" icon="book" href="/docs/privacy/concepts/overview">
    Rings, privacy guarantees, and transaction flow.
  </Card>

  <Card title="Architecture" icon="diagram-project" href="/docs/privacy/concepts/architecture">
    How wallets, RPC services, and Solana programs interact.
  </Card>

  <Card title="Private State and UTXOs" icon="database" href="/docs/privacy/concepts/utxo">
    How private balances are stored and spent.
  </Card>

  <Card title="Custom Enterprise Rings" icon="building" href="/docs/privacy/integration/enterprise">
    Learn how to configure a custom Ring.
  </Card>
</CardGroup>

## Didn't find what you were looking for?

<Callout type="info">
  Reach out! [Telegram](https://t.me/tilo_light) | [E-Mail](mailto:sales@helius.xyz) | [Contact](https://www.helius.dev/contact)
</Callout>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.