Security
What Privatly protects, and what it does not.
Privatly is programmable confidentiality on Solana. It reduces what the public chain reveals about balances and transfers. It does not make you anonymous, and it is not a mixer.
01Architecture
The interface talks to a PrivacyProvider contract. The live provider is Umbra: encrypted token accounts on Solana whose updates are computed by Arcium's encrypted computation network, with zero-knowledge proofs generated in your browser. Swaps go through Jupiter. Agents use Squads v4 smart accounts.
- No custom cryptography. We use established open source libraries (@noble) and third-party protocols, and deploy no on-chain programs of our own.
- The client is never trusted for pricing. Fees come from server quotes, and reported executions are verified on-chain before they settle into the ledger.
- Every server route validates input with strict schemas and rejects anything else.
- Fees are paid to a public treasury wallet, so anyone can audit what was collected.
02Threat model
Per mechanism: what it protects, what stays visible, and what you have to trust.
Encrypted balances
Runs on: Umbra encrypted token accounts (Arcium)
- Protects
- Token balances held in the encrypted account
- Amounts moving between encrypted balances
- Stays visible
- That your wallet has an encrypted account
- Deposits (shield) and withdrawals (unshield) from public wallets: amounts, wallets and timing
- Fee payments to the treasury, and Solana transaction fees
- You trust
- Umbra's on-chain programs and Arcium's encrypted computation network compute on ciphertext. You rely on their correctness and on the network's honesty assumptions.
- Your private keys are derived from one wallet signature over a fixed message. Sign it only on this site.
Claimable private transfers
Runs on: Umbra receiver-claimable transfers (Groth16)
- Protects
- The direct on-chain link between sender and recipient
- The amount, when the transfer is funded from an encrypted balance
- Stays visible
- That a transfer entered the pool, and that a claim happened, with their timing
- The amount, when the transfer is funded from a public balance
- Unique amounts and close timing can still link sender and recipient
- You trust
- Zero-knowledge proofs are generated in your browser. Claims are submitted by Umbra's relayer, which sees the claim it submits.
View keys
Runs on: Umbra compliance grants (X25519)
- Protects
- Nothing by themselves: a grant deliberately lets a named viewer decrypt your activity
- Stays visible
- The grant exists on-chain, with the granter and grantee public keys
- You trust
- Revocation stops future decryption. It cannot take back what the viewer already saw.
- Grants have no on-chain expiry. An expiry date in the app is a reminder to revoke.
Swaps
Runs on: Jupiter routing, settled on Solana
- Protects
- Nothing. Swaps are ordinary public Solana transactions.
- Stays visible
- Wallet, input and output amounts, route and timing
- The platform fee paid to the treasury token account
- You trust
- Quotes and transactions are built by Jupiter through our server. Both see the request. Shield the output afterwards if the balance should be encrypted.
Agents
Runs on: Umbra private agent accounts (default) or Squads vaults with onchain spending limits
- Protects
- Spending beyond your limits: Squads spending limits are the hard, on-chain cap per token per day
- Your wallet key, which the agent never holds
- Stays visible
- Vault balances, spending limits, every swap and payment, and their timing
- You trust
- Agent keys are generated and held on our server, encrypted at rest with AES-256-GCM. The encryption key lives in server configuration, not in the database.
- Policy rules are enforced by our server. Someone who controlled the server and that key could move funds up to the on-chain daily limit, and no further.
- Fund a vault only with what the agent may spend. You can pause, withdraw and delete at any time.
Encrypted messaging
Runs on: X25519 + XChaCha20-Poly1305, end to end
- Protects
- Message contents between people, end to end
- Private notes on agent objectives, sealed on your device
- Stays visible
- To our server: who talks to whom, when, how often, and message sizes
- You trust
- The server distributes public keys. There is no out-of-band key verification yet, so a compromised server could substitute a key.
- Agent reports are sealed with an agent key the server holds, so the server can read them.
Sign-in, sessions and records
Runs on: Ed25519 signature, server session
- Protects
- Your wallet keys: sign-in is a free message signature, never a transaction or a seed phrase
- Stays visible
- To our server: your wallet address, IP address and request timing, like any web service
- Activity records you report, with public fields in plain text and private details encrypted on your device
- You trust
- The revenue ledger stores a keyed hash of your wallet, not the address. Admin analytics show aggregates only.
Beyond every mechanism: a compromised device or wallet defeats all of the above. Privacy cannot outlast the keys that control it.
03Key management
- Wallet keys never leave the wallet. Signing happens through Wallet Standard. We never ask for, transmit or store seed phrases.
- Privacy and messaging keys are derived on your device from a wallet signature and are never sent to us.
- Agent keys are generated on the server and stored encrypted at rest (AES-256-GCM, key in server configuration, bound to each agent).
- Sessions are signed tokens in an httpOnly cookie, valid for 7 days.
- API keys are stored as SHA-256 hashes and shown in full only once.
04Audits
Privatly itself has not been audited. The protocols it builds on are operated by third parties and publish their own security reviews.
| Scope | Status | Note |
|---|---|---|
| Privatly application | Not audited | Web app, API routes, agent runtime and messaging. Internal review only. |
| Umbra (encrypted balances, transfers, view grants) | Third-party protocol | See their published audits. |
| Arcium (encrypted computation behind Umbra) | Third-party protocol | See their published audits. |
| Squads v4 (agent smart accounts, spending limits) | Third-party protocol | See their published audits. |
| Custom on-chain programs | None deployed | Privatly deploys no programs of its own. |
05Dependencies
Every runtime dependency this build declares, with its version range.
- @neondatabase/serverless ^1.2.0
- Postgres over HTTP (Neon)
- @noble/ciphers ^2.4.0
- XChaCha20-Poly1305 for messages and notes
- @noble/curves ^2.4.0
- X25519 key agreement, Ed25519 sign-in verification
- @noble/hashes ^2.4.0
- Hashing and key derivation
- @solana-program/system ^0.15.0
- System program instructions
- @solana-program/token ^0.17.0
- Token program instructions
- @solana/kit ^8.4.0
- Solana RPC and transactions
- @solana/react ^8.4.0
- Wallet signing hooks
- @solana/spl-token ^0.4.15
- Token account helpers
- @solana/wallet-standard-features ^1.5.0
- Wallet Standard feature types
- @solana/web3.js ^1.99.0
- Required by the Squads SDK
- @sqds/multisig ^2.1.4
- Squads v4 smart accounts and spending limits
- @tanstack/react-query ^5.104.1
- Client data fetching
- @umbra-privacy/sdk 5.0.0-rc.10
- Umbra encrypted balances, transfers and grants
- @wallet-standard/app ^1.1.1
- Wallet discovery
- @wallet-standard/features ^1.1.1
- Wallet Standard features
- @wallet-standard/react ^1.0.3
- Wallet discovery in React
- @wallet-standard/ui-registry ^1.1.1
- Wallet account registry
- geist ^1.7.2
- Fonts
- jose ^6.2.12
- Session token signing (HS256)
- lucide-react ^1.52.0
- Icons
- motion ^14.0.0
- Interface animation
- next ^16.3.8
- Framework and server routes
- react ^19.3.0
- UI rendering
- react-dom ^19.3.0
- UI rendering
- server-only ^0.0.1
- Keeps server modules out of browser bundles
- snarkjs ^0.7.6
- Groth16 proof generation
- zod ^4.6.5
- Input validation on every server route
- zustand ^5.0.15
- Client UI state
06Responsible disclosure
If you find a vulnerability, email security@privatly.xyz. Include steps to reproduce and the impact you observed. Give us reasonable time to fix the issue before public disclosure, do not access data that is not yours, and do not move funds that are not yours. Issues in Umbra, Arcium, Squads or Jupiter belong with those teams; we will help route reports.