- On-ramp from fiat balance
- Off-ramp to fiat balance
- A confidential balance of each asset you support, such as USDC, SOL, or any SPL or Token-2022 token. See Confidential Assets and Inventory.
- Users with a Private Wallet.
Confidential Assets and Inventory
To fund your on/off-ramp confidential balance, deposit from a public balance you already hold, for example a hot wallet or custody account.- Deposit to your on/off-ramp confidential balance. You deposit SPL tokens and receive a confidential balance of the same token. Topping up from a public balance reveals the deposited asset and amount.
- Serve on-ramps and off-ramps. You send private transfers from your confidential balance to users for on-ramps, and receive private transfers from users for off-ramps. These transfers do not reveal the asset or amount.
- Withdraw from your on/off-ramp confidential balance. You spend your confidential balance and receive the SPL tokens in your public balance. Withdrawals reveal the withdrawn asset and amount.
Compliance Considerations
A confidential on-ramp or off-ramp does not change common compliance flows.- You screen, match, and record against the same public Solana addresses as today, since a confidential Ring encrypts the asset and amount, not the sender or recipient.
- We recommend that you check the following against your existing compliance flows.
What You Can See
Wallet Screening
Wallet screening does not change:- Screen the user’s Solana address with your existing screening provider before you accept an order, and cancel the order if the address is flagged.
- In a confidential Ring, the sender and recipient of every private transfer are public onchain, so who a user transacts with stays auditable. Only the asset and amount are encrypted.
Travel Rule
The Travel Rule does not change for confidential transfers. For transfers to or from a self-hosted wallet, you verify that your customer owns or controls the address. Originator and beneficiary information is exchanged offchain between service providers, not onchain, so encrypting the asset and amount onchain does not affect it. A private wallet’s address is the user’s Solana address, and in a confidential Ring the same Solana key authorizes private transfers. Both common verification methods work unchanged:- Message signing – the user signs a message you define with their Solana key.
- Predefined amount – the user sends a predefined amount to your on/off-ramp confidential balance by private transfer. You decrypt the transfer and check the amount.
Map Your Existing Flow
Records and Audits
You decrypt every transfer you send or receive, so your records hold the same data as for public transfers. To disclose a transfer you sent, share its transaction viewing key. A transaction viewing key grants read-only access to one transaction and no spending authority.Transaction Flows
1. On-Ramp
An on-ramp credits a private balance: the user pays fiat offchain; the provider sends a private transfer onchain from its on/off-ramp confidential balance to the user’s Private Wallet.- The user deposits fiat.
- The provider matches the user’s fiat deposit to a Private Wallet in the internal ledger.
- The provider syncs its on/off-ramp confidential balance, then sends a private transfer to the user’s Private Wallet.
2. Off-Ramp
An off-ramp is a private transfer from the user’s Private Wallet to the provider’s on/off-ramp confidential balance and an update of the provider’s internal ledger to pay out fiat to the user. The steps to complete a private off-ramp include:- The user syncs their private balance and sends a private transfer to the provider’s on/off-ramp confidential balance.
- In a confidential Ring the provider can match the transfer by the visible user wallet address. In an anonymous Ring the public ledger does not reveal sender or recipient; match via the off-ramp request in the internal ledger.
Start Integrating
1
Understand User Flows
Launch Demo
Try confidential transfers and swaps on devnet.
2
Create a Private Wallet
Native Wallet Integration
Add privacy support with your own key management. For providers that want to manage encryption keys and run state sync.
Embedded Private Wallet
Use an embedded wallet with private and public balances directly in your product. For companies and apps without their own key management.
3
Integrate On-Ramp and Off-Ramp Flows
Deposit
Fund your on/off-ramp confidential balance from a public balance.
Private Transfer
Send private transfers to users for on-ramps and receive them for off-ramps.