Related · tier-1 reading. For the privacy story end-to-end — FHE + STARK proof + portable artifact, see Privacy Layer.
The only privacy infrastructure designed for regulated institutions.
Banks, custodians, ETF providers, and stablecoin issuers need privacy for competitive reasons and compliance for regulatory reasons. These have always been in tension. H33 resolves both simultaneously.
The concept is owned by the Privacy Layer — this page is a supporting expression, not a redefinition.
H33-74 attests each proof with three post-quantum signature families and anchors a 32-byte commitment.
A combination of STARK zero-knowledge proof (ZK), minimization, and selective disclosure. Where encrypted compute is genuinely in the workflow, FHE may participate — but that is a distinct data-in-use mechanism.
Any regulator or auditor confirms an attestation with the public verifier — see Verification — without trusting H33 or the institution.
Competitors see your positions. Counterparties front-run your trades. Client lists become public. Compliance satisfied, competitive advantage destroyed.
Tornado Cash, mixers, privacy chains. Regulators cannot verify compliance. Enforcement actions follow. Institutional adoption impossible.
STARK proofs verify that regulatory requirements are satisfied. The regulator sees a cryptographic attestation that the institution passed AML, holds adequate reserves, or screened against OFAC. The regulator never sees the underlying positions, counterparties, or transaction details.
Process transactions privately while proving every transfer passes AML screening.
Prove you hold what you claim without revealing positions.
File reports and satisfy regulatory requirements without front-running risk.
Meet FinCEN and FATF travel rule requirements without transmitting personally identifiable information between counterparties.
The regulator learns that a specific compliance statement is true. "This institution passed AML screening." "Reserves exceed liabilities." "OFAC screening completed within 24 hours." The claim is verified. The underlying data is not.
No transaction details, counterparty lists, portfolio positions, or client identities leave the institution's boundary. The proof is enough. The data stays home.
Every byte of data shared beyond what compliance requires is unnecessary risk. PII liability. Breach surface. Competitive intelligence leakage. Compliant Privacy eliminates all of it.
The HATS verifier is open source. Regulators verify attestations without trusting H33, the institution, or any third party. Mathematics replaces trust.
Identity verification attestation. Client re-verification at standard regulatory intervals. Auto-expiry enforced on-chain.
Sanctions screening refreshed daily. Matches real-world OFAC list update cadence. Stale screening automatically invalidates compliance status.
Accredited investor status valid for 12 months per SEC guidance. Institutional eligibility verified without revealing financial statements.
Every counterparty runs independent due diligence. Banks submit the same compliance documentation to dozens of counterparties. Each submission creates a new data exposure point. Each is a breach target.
Institution attests once. 32-byte proof on-chain. Every counterparty verifies the same commitment. Zero document duplication. Zero PII exposure. Compliance travels with the institution.
The HATS verifier is open source. No API key. No vendor cooperation. No platform dependency. Read the HATS standard.
Selective disclosure of a regulatory claim: the claim is proven and verifiable; positions, counterparties, and client data are not revealed.
The claims themselves — AML, OFAC, reserve adequacy, accreditation — and their refresh cadences are specific to regulated finance. The proof machinery is shared.
The 74-byte post-quantum attestation: three-family PQ signatures, signer set, timestamp, authority scope, governance link. See H33-74.
A combination: STARK ZK proof, minimization, and selective disclosure. FHE only where encrypted compute is genuinely in the workflow — a distinct data-in-use mechanism.
The chain gives permanence and public ordering for the 32-byte commitment only — an anchoring surface the evidence anchors to. It provides no privacy, no attestation, no compliance determination.
Recompute the commitment and check all three PQ signatures with the public verifier — no vendor trust. See Verification.
Prefer FHE when the requirement is computation over data that stays encrypted end to end, rather than proving a claim about it.
Use compliant privacy when a regulator, auditor, or counterparty must be shown that a specific requirement is satisfied — AML, sanctions screening, reserve adequacy, accreditation — while competitive positions and client data stay inside the institution. It supports a compliance program; it does not replace the institution's own compliance determination.
Do not use it when the need is computation over data that stays encrypted end to end — route to /fhe/, a different (data-in-use) mechanism. Do not read an attestation as a statement that an organization "is compliant" — it proves a bounded claim; the compliance conclusion belongs to the institution and its regulators.
Compliant privacy is the expression of the Privacy Layer in which a regulatory-relevant claim is proven and post-quantum attested without disclosing the underlying positions, counterparties, or client data. The regulator sees that the claim holds; the data stays inside the institution. It supports a compliance program — it does not by itself make an organization compliant.
No. An attestation proves a bounded claim — for example that AML screening was completed or that reserves exceeded liabilities at a point in time. Whether the organization is compliant overall is a separate determination made by the institution and its regulators. The privacy techniques here provide verifiable evidence that supports that determination; they do not replace it.
Primarily a STARK zero-knowledge proof plus minimization and selective disclosure, attested by H33-74. Where the workflow genuinely requires computing on data that stays encrypted end to end, fully homomorphic encryption may participate — but FHE is a distinct data-in-use mechanism documented at /fhe/. If encrypted compute is your actual need, start there.
The chain contributes permanence and public ordering for a 32-byte commitment only — an anchoring surface the evidence anchors to, never owns. It provides no privacy or compliance of its own. The evidence is verified independently by recomputing the commitment and checking the three post-quantum signatures with the public verifier, described at Verification — no trust in H33 or the institution required.
Compliance without custody. Privacy without opacity. Verification without trust.
Schedule DemoH33.ai, Inc. · Patents Pending · HATS Standard