Privacy + Compliance

Idea 03

Private Payroll

Settle salaries on Stellar without publishing every employee’s pay.

Category
ZK × Payments
Difficulty
Advanced
Theme
Privacy + Compliance
  • Soroban
  • USDC
  • BN254
  • Poseidon

Treat confidential-token components as experimental. They are in developer preview, not a production payroll rail today. The MVP should stand on commitments plus a ZK verifier.

Problem

A normal onchain payroll shows “Company → Alice: $8,000” and “Company → Bob: $3,000”. Anyone can read the amounts. Stellar calls payroll out as a case where public transaction visibility is a problem.

Idea

The company funds a private payroll pool. Employees receive payment commitments. A ZK proof shows the batch was authorized and fully allocated, without revealing individual salaries. Employees withdraw against their own commitment.

Why now

Stellar’s privacy stack includes native ZK primitives: BN254 and Poseidon / Poseidon2. Confidential tokens are in developer preview.

User story

Payroll uploads a batch. Observers can see that the pool was funded and that the proof verified. Alice and Bob each withdraw their own salary. Neither amount is written in the clear.

Architecture

  1. 01

    Company treasury funds a private payroll pool

  2. 02

    Employer uploads a payroll batch of commitments

  3. 03

    ZK proof checks that the distribution is authorized and sums to the funding

  4. 04

    Each employee withdraws against their commitment

MVP

  • Employer creates a payroll batch of employee commitments.
  • Pool is funded in USDC for the batch total.
  • A ZK proof validates the authorized distribution.
  • Employees withdraw without the contract logging individual amounts.
  • Public state shows funding and execution, not salaries.

Soroban contracts

  • Payroll pool

    Holds the batch funding and records that it executed.

  • Commitment tree

    Stores Poseidon commitments to each payment.

  • Verifier

    Checks a BN254 proof that the batch is authorized and conserves value.

  • Withdraw

    Lets an employee claim a commitment they can open.

Stellar features

  • BN254 pairing checks for proof verification
  • Poseidon / Poseidon2 for commitments and nullifiers
  • SAC transfer of the pooled USDC

Suggested integrations

  • USDC
  • An offchain prover
  • HR export that produces the batch

Build sequence

  1. 01

    Pool + batch

    Fund a contract and store a list of payment commitments.

  2. 02

    Proof

    Prove the commitments sum to the deposit and were signed by payroll.

  3. 03

    Withdraw

    An employee opens their commitment and receives USDC once.

  4. 04

    Public view

    A page that shows funded and executed, and hides amounts.

Stretch goals

  • Swap the demo commitments for confidential-token transfers once that preview is stable.

Resources