CIPHERPLATFORM GUIDE

CIPHER / PRIVACY

Privacy, precisely.

Sealed bids, public wallets and operator identity are different privacy questions. This preview does not offer anonymous transactions.

Design in progress. Live deposits are closed.

The first release targets a 24-hour SOL auction for a Solana token through Pump.fun. Broader destinations are a roadmap, not available launch services.

What this preview protects

The application requests no name, email or social login. It uses local artwork and fonts, with no application advertising or analytics SDK. The public deployment disables persisted Worker logs and traces and sends no referrer header to linked sites. Hosting infrastructure still processes connection information.

Rate limiting stores a short-lived, secret-keyed identifier rather than a raw IP address. New sandbox sessions expire after 24 hours. Wallet ownership challenges and proofs expire separately. An hourly cleanup removes expired application rows; provider backups can retain earlier copies.

Wallet proof stores the public wallet address and an origin-bound challenge temporarily. Disconnecting or clearing that proof removes its application record. This is pseudonymous access, not an anonymous identity system.

Launch intake stores up to five briefs, including project terms and public treasury and destination wallet addresses, in server-side session storage. The session holder and operator can read them. They expire 24 hours after session creation; creators can delete them or export a copy they keep themselves. This storage is not operator-blind or end-to-end encrypted.

What remains visible

Demo operator
The sandbox server owns the demonstration decryption key and can read demo bids. Authenticated operator-blind MPC is not connected.
Public chains
SOL deposits, balances, token creation, distribution and EVM claims can link wallets and amounts. A new wallet alone does not unlink its funding history.
Infrastructure
Hosting, registrar, RPC, routing and wallet providers can see their portion of the interaction. Domain registration privacy hides eligible public contact fields; it does not hide the customer from the registrar.
Cross-chain routing
Shielded ZEC does not make a transparent bridge endpoint or Solana payout private. Current route quotes expose their input and recipient to the quote provider.

The release requirement

Before marketing confidential bidding, publish the threat model, audit the encrypted computation and prove that operators cannot decrypt bids early. Address deposit-size and timing leakage, relayer metadata, recipient linkage, selective aborts and refund privacy. A guarantee of anonymity from every observer is not supported.

Review launch gates