Proof Lab
StartEcosystem
Explore (579)Live Systems (52)Pricing
Log InGet API Key✓ Verify It Yourself
Compliant Privacy

Compliance Without Custody.

Related · tier-1 reading. For the privacy story end-to-end — FHE + STARK proof + portable artifact, see Privacy Layer.

The only privacy infrastructure designed for regulated institutions.

Banks, custodians, ETF providers, and stablecoin issuers need privacy for competitive reasons and compliance for regulatory reasons. These have always been in tension. H33 resolves both simultaneously.

STARK proves. H33-74 attests. 32 bytes anchor. HATS verifies.
Schedule Demo Privacy Layer
Banks | Custodians | ETF Providers | Stablecoin Issuers | Regulated Exchanges
Definition
What compliant privacy is.
Compliant privacy is the thematic expression of the Privacy Layer in which a regulatory-relevant claim is proven and attested — "AML screening passed," "reserves exceed liabilities," "OFAC screening completed" — without disclosing the underlying positions, counterparties, or client data. The privacy property is selective disclosure: the claim is verifiable, the data is not.
Why this exists: traditional compliance forces institutions to reveal everything so a regulator can verify anything, which builds surveillance infrastructure and a permanent breach surface. Compliant privacy exists to verify only the claim that matters and minimize every other disclosure. The privacy techniques here support compliance programs; they do not, on their own, make an organization compliant — regulatory compliance is a separate determination made by the institution and its regulators.
Owner

The concept is owned by the Privacy Layer — this page is a supporting expression, not a redefinition.

Attestation by H33-74

H33-74 attests each proof with three post-quantum signature families and anchors a 32-byte commitment.

Mechanism

A combination of STARK zero-knowledge proof (ZK), minimization, and selective disclosure. Where encrypted compute is genuinely in the workflow, FHE may participate — but that is a distinct data-in-use mechanism.

Independent verification

Any regulator or auditor confirms an attestation with the public verifier — see Verification — without trusting H33 or the institution.

The Institutional Dilemma
Privacy and compliance have always been enemies.
Institutions need privacy to protect competitive positions -- trading strategies, portfolio allocations, client relationships, counterparty networks. But regulators need visibility to enforce AML, sanctions screening, investor protections, and market integrity. Every existing solution forces a choice between the two. H33 eliminates the choice.
Full Transparency

Reveal everything

Competitors see your positions. Counterparties front-run your trades. Client lists become public. Compliance satisfied, competitive advantage destroyed.

Privacy Tools

Hide everything

Tornado Cash, mixers, privacy chains. Regulators cannot verify compliance. Enforcement actions follow. Institutional adoption impossible.

H33 Compliant Privacy

Prove compliance without revealing competitive information.

STARK proofs verify that regulatory requirements are satisfied. The regulator sees a cryptographic attestation that the institution passed AML, holds adequate reserves, or screened against OFAC. The regulator never sees the underlying positions, counterparties, or transaction details.

How It Works
Four steps. No data exchange.
The institution generates a STARK proof that a compliance statement is true, without revealing the data behind it. H33-74 attests the proof with three post-quantum signature families. A 32-byte commitment anchors on-chain. The HATS verifier confirms independently.
1
STARK proves
Compliance statement verified
2
H33-74 attests
Three PQ families sign
3
32 bytes anchor
On-chain commitment
4
HATS verifies
Independent confirmation
Who Needs This
Every regulated institution holding digital assets.
Banks

Transaction Privacy + AML Compliance

Process transactions privately while proving every transfer passes AML screening.

  • Wire transfers without counterparty exposure
  • AML compliance proof per transaction
  • Sanctions screening without revealing parties
  • Correspondent banking privacy
  • Regulatory reporting without data leakage
Custodians

Holdings Privacy + Reserve Proof

Prove you hold what you claim without revealing positions.

  • Proof of reserves without balance disclosure
  • Client segregation attestation
  • Asset-under-custody verification
  • Insurance coverage proof
  • Audit-ready evidence packages
ETF Providers

Portfolio Privacy + Regulatory Reporting

File reports and satisfy regulatory requirements without front-running risk.

  • NAV proof without position disclosure
  • Rebalancing attestation without timing data
  • SEC 13F compliance without public exposure
  • Authorized participant verification
  • Creation/redemption privacy
Stablecoin Issuers

Travel Rule Compliance Without PII Exchange

Meet FinCEN and FATF travel rule requirements without transmitting personally identifiable information between counterparties.

  • Originator/beneficiary attestation without PII
  • Reserve backing proof without portfolio detail
  • Cross-border compliance without data residency issues
  • Continuous monitoring attestation
The Principle
Compliance without surveillance.
Traditional compliance requires institutions to reveal everything so that regulators can verify anything. This creates surveillance infrastructure masquerading as regulatory compliance. Compliant Privacy inverts the model: verify the claims that matter, minimize the exposure that does not, and avoid every unnecessary disclosure.
Verify Claims

The regulator learns that a specific compliance statement is true. "This institution passed AML screening." "Reserves exceed liabilities." "OFAC screening completed within 24 hours." The claim is verified. The underlying data is not.

Minimize Exposure

No transaction details, counterparty lists, portfolio positions, or client identities leave the institution's boundary. The proof is enough. The data stays home.

Avoid Disclosure

Every byte of data shared beyond what compliance requires is unnecessary risk. PII liability. Breach surface. Competitive intelligence leakage. Compliant Privacy eliminates all of it.

Independent Verification

The HATS verifier is open source. Regulators verify attestations without trusting H33, the institution, or any third party. Mathematics replaces trust.

Attestation Epochs
Compliance cadences built into the protocol.
Different compliance requirements have different refresh cadences. Attestations are time-bound, revocable, and automatically enforced. When an attestation expires, the institution must re-verify to maintain compliance status.
90 days
KYC Identity

Identity verification attestation. Client re-verification at standard regulatory intervals. Auto-expiry enforced on-chain.

24 hours
OFAC Screening

Sanctions screening refreshed daily. Matches real-world OFAC list update cadence. Stale screening automatically invalidates compliance status.

1 year
Accredited Investor

Accredited investor status valid for 12 months per SEC guidance. Institutional eligibility verified without revealing financial statements.

Portable Compliance
Verify once. Use across protocols.
A single compliance attestation works across every protocol, chain, and counterparty that supports the HATS standard. Institutions verify once. Counterparties check the same 32-byte commitment. No repeated due diligence. No redundant data collection.
Today

Every counterparty runs independent due diligence. Banks submit the same compliance documentation to dozens of counterparties. Each submission creates a new data exposure point. Each is a breach target.

With Compliant Privacy

Institution attests once. 32-byte proof on-chain. Every counterparty verifies the same commitment. Zero document duplication. Zero PII exposure. Compliance travels with the institution.

Regulator Verifiable
No vendor trust required.
The HATS verifier is public and open source. Regulators, auditors, counterparties, and courts can independently verify any attestation without trusting H33, the institution, or any intermediary.
regulator terminal
$ cargo install hats-verifier $ hats verify compliance-attestation.json VALID -- All checks passed Checks: 24 passed, 0 failed Attestation: aml-screening-v1 Institution: [redacted] Expiry: 2026-11-15T00:00:00Z Duration: 83us PQ Sigs: ML-DSA-65 + FALCON-512 + SLH-DSA-128f

The HATS verifier is open source. No API key. No vendor cooperation. No platform dependency. Read the HATS standard.

Boundary Questions
Where compliant privacy begins and ends.
Seven questions that fix the boundary of this expression against the owner that defines it, the mechanisms it uses, and the chains it references.
1 · Privacy property

Selective disclosure of a regulatory claim: the claim is proven and verifiable; positions, counterparties, and client data are not revealed.

2 · What is context-specific

The claims themselves — AML, OFAC, reserve adequacy, accreditation — and their refresh cadences are specific to regulated finance. The proof machinery is shared.

3 · Supplied by H33-74

The 74-byte post-quantum attestation: three-family PQ signatures, signer set, timestamp, authority scope, governance link. See H33-74.

4 · Mechanism

A combination: STARK ZK proof, minimization, and selective disclosure. FHE only where encrypted compute is genuinely in the workflow — a distinct data-in-use mechanism.

5 · What the chain does NOT provide

The chain gives permanence and public ordering for the 32-byte commitment only — an anchoring surface the evidence anchors to. It provides no privacy, no attestation, no compliance determination.

6 · Independent verification

Recompute the commitment and check all three PQ signatures with the public verifier — no vendor trust. See Verification.

7 · When to prefer another mechanism

Prefer FHE when the requirement is computation over data that stays encrypted end to end, rather than proving a claim about it.

Decision Guidance
When to use this, and when not to.
When to use this

Prove a regulatory claim without disclosing the data behind it.

Use compliant privacy when a regulator, auditor, or counterparty must be shown that a specific requirement is satisfied — AML, sanctions screening, reserve adequacy, accreditation — while competitive positions and client data stay inside the institution. It supports a compliance program; it does not replace the institution's own compliance determination.

When NOT to use this

Not an encrypted-compute engine, not a compliance verdict.

Do not use it when the need is computation over data that stays encrypted end to end — route to /fhe/, a different (data-in-use) mechanism. Do not read an attestation as a statement that an organization "is compliant" — it proves a bounded claim; the compliance conclusion belongs to the institution and its regulators.

FAQ
Compliant privacy, in plain terms.
What is compliant privacy?

Compliant privacy is the expression of the Privacy Layer in which a regulatory-relevant claim is proven and post-quantum attested without disclosing the underlying positions, counterparties, or client data. The regulator sees that the claim holds; the data stays inside the institution. It supports a compliance program — it does not by itself make an organization compliant.

Does an H33 attestation mean my institution is compliant?

No. An attestation proves a bounded claim — for example that AML screening was completed or that reserves exceeded liabilities at a point in time. Whether the organization is compliant overall is a separate determination made by the institution and its regulators. The privacy techniques here provide verifiable evidence that supports that determination; they do not replace it.

Is the mechanism ZK or FHE?

Primarily a STARK zero-knowledge proof plus minimization and selective disclosure, attested by H33-74. Where the workflow genuinely requires computing on data that stays encrypted end to end, fully homomorphic encryption may participate — but FHE is a distinct data-in-use mechanism documented at /fhe/. If encrypted compute is your actual need, start there.

What does the blockchain contribute, and how is the evidence verified?

The chain contributes permanence and public ordering for a 32-byte commitment only — an anchoring surface the evidence anchors to, never owns. It provides no privacy or compliance of its own. The evidence is verified independently by recomputing the commitment and checking the three post-quantum signatures with the public verifier, described at Verification — no trust in H33 or the institution required.

Related
Explore the privacy infrastructure.
EXPLORE
50 Live Systems 44 ZK Use Cases
Polygon Optimism Avalanche Hyperliquid

Privacy infrastructure for the institutions that cannot afford to get it wrong.

Compliance without custody. Privacy without opacity. Verification without trust.

Schedule Demo

H33.ai, Inc. · Patents Pending · HATS Standard