Why Confi.cash exists
Public blockchains make transaction amounts, wallet relationships, and trading behavior easy to inspect. That transparency supports verification, but it can also expose treasury activity, payment flows, portfolio rebalancing, and trading strategy. Stellar AMMs provide liquidity and price execution. They do not create a shielded balance layer or hide each user’s swap amount. Confi.cash adds that privacy-preserving execution layer without creating a new bridge or taking custody of your spend keys.What you can do
Hold and transfer shielded assets
Create a shielded balance and send notes to another
cb1... address without publishing the transfer amount on-chain.Swap through Stellar AMMs
In a shared batch, swap through Soroswap, Aquarius, and other supported AMMs while only the aggregate net flow reaches public liquidity.
Withdraw to Stellar
Move a standard amount from the shielded pool to a public Stellar wallet when you need on-chain funds.
Test an anchor payout flow
Explore a mock testnet flow that shows how a shielded balance could fund a compliant payout without publishing a direct history link on-chain.
How it works
Your browser creates the proofs and secrets needed to control your shielded notes. Soroban contracts verify note ownership, value conservation, nullifier freshness, valid batch clearing, and withdrawals without receiving your spend key. For a shared swap, Confi.cash groups eligible shielded orders and clears them at a shared batch price. Only the aggregate net flow is routed through an adapter to the selected public AMM. When you choose Others in the app, that external liquidity can come from Soroswap, Aquarius, or another supported Stellar AMM. Your proceeds return as a fresh shielded note. In solo settlement, your order is the batch net and becomes inferable from public settlement.Others is a liquidity-route choice, not a separate privacy mode. The same batch privacy boundaries apply to every supported external AMM route.
How a compliant payout can work
In a production integration, the same shielded balance could fund an individual payout through a regulated Stellar anchor. The anchor would perform the identity and destination checks required for its payout rail, then deliver fiat, mobile money, or another supported form of value. In that production flow, the public chain would see a withdrawal from the shielded pool to a destination assigned for the payout session. It would not receive a direct record of your internal transfers or individual swap history. The production anchor would still see your verified identity, payout amount, destination, and session details, and public timing or amount correlation could reveal additional links. The current Confi.cash offramp is a testnet simulation. Its mock anchor receives simulated identity data and does not deliver real fiat.The privacy boundary
Confi.cash is designed to keep shielded balances and internal transfer amounts from being directly published to public chain observers. An individual swap leg is not directly published when a shared batch contains other real orders. Timing, boundary amounts, and the public batch net can still support inference.- Deposits and withdrawals remain public, including their asset and amount.
- The chain records batch timing, clearing price, and aggregate net flow.
- A solo swap makes the individual order equal to the public batch net.
- The operator can observe network metadata such as IP address and timing and associate a request with the public pool action it relays.
- Confi.cash operates the threshold committee and can reconstruct individual swap amounts with quorum-level administrative access.
Explore the protocol
How Confi.cash works
Follow value through shielded notes, browser proofs, batch settlement, and withdrawal.
Privacy model
See what chain observers, AMMs, anchors, recipients, and the operator can learn.
Create a shielded balance
Connect a testnet wallet, derive your shielded identity, and deposit a supported asset.