What the receipt proves
Commitment inclusion + payer attestation
A portable receipt proves that the disclosed line resolves to the public Merkle root and that the payer signed a binding to the finalized STRK20 transaction reference.
ShadowLedger separates publicly auditable aggregate facts from confidential payroll rows. Timing and voluntary disclosure still matter.
| Stage | Public | Hidden or selectively disclosed |
|---|---|---|
| Shield/deposit | Address, token, amount, timing | Future in-pool note ownership |
| Private payroll batch | A STRK20 pool interaction occurred | Sender-to-recipient links, recipients, individual allocations |
| Payroll registry | Token, aggregate, count, hashes, timestamps | Addresses and amounts for individual rows |
| Recipient receipt | Nothing unless voluntarily shared | Exactly one disclosed row and proof; all other rows |
| Auditor package | Nothing—the file stays local | Nothing from the chosen auditor; the complete book is disclosed to them |
What the receipt proves
A portable receipt proves that the disclosed line resolves to the public Merkle root and that the payer signed a binding to the finalized STRK20 transaction reference.
What it does not prove
The MVP does not expose a viewing key or cryptographically reveal the private note amount to a public verifier. The signed receipt is selective disclosure, not note decryption.
Residual risk
Shield early, avoid funding and paying in one obvious sequence, use only registered recipients, and never paste claim keys or private audit packages into public tools.