Idea 03
Private Payroll
Settle salaries on Stellar without publishing every employee’s pay.
- Category
- ZK × Payments
- Difficulty
- Advanced
- Theme
- Privacy + Compliance
- Soroban
- USDC
- BN254
- Poseidon
Treat confidential-token components as experimental. They are in developer preview, not a production payroll rail today. The MVP should stand on commitments plus a ZK verifier.
Problem
A normal onchain payroll shows “Company → Alice: $8,000” and “Company → Bob: $3,000”. Anyone can read the amounts. Stellar calls payroll out as a case where public transaction visibility is a problem.
Idea
The company funds a private payroll pool. Employees receive payment commitments. A ZK proof shows the batch was authorized and fully allocated, without revealing individual salaries. Employees withdraw against their own commitment.
Why now
Stellar’s privacy stack includes native ZK primitives: BN254 and Poseidon / Poseidon2. Confidential tokens are in developer preview.
User story
Payroll uploads a batch. Observers can see that the pool was funded and that the proof verified. Alice and Bob each withdraw their own salary. Neither amount is written in the clear.
Architecture
01
Company treasury funds a private payroll pool
02
Employer uploads a payroll batch of commitments
03
ZK proof checks that the distribution is authorized and sums to the funding
04
Each employee withdraws against their commitment
MVP
- Employer creates a payroll batch of employee commitments.
- Pool is funded in USDC for the batch total.
- A ZK proof validates the authorized distribution.
- Employees withdraw without the contract logging individual amounts.
- Public state shows funding and execution, not salaries.
Soroban contracts
Payroll pool
Holds the batch funding and records that it executed.
Commitment tree
Stores Poseidon commitments to each payment.
Verifier
Checks a BN254 proof that the batch is authorized and conserves value.
Withdraw
Lets an employee claim a commitment they can open.
Stellar features
- BN254 pairing checks for proof verification
- Poseidon / Poseidon2 for commitments and nullifiers
- SAC transfer of the pooled USDC
Suggested integrations
- USDC
- An offchain prover
- HR export that produces the batch
Build sequence
01
Pool + batch
Fund a contract and store a list of payment commitments.
02
Proof
Prove the commitments sum to the deposit and were signed by payroll.
03
Withdraw
An employee opens their commitment and receives USDC once.
04
Public view
A page that shows funded and executed, and hides amounts.
Stretch goals
- Swap the demo commitments for confidential-token transfers once that preview is stable.