Private payroll is live.

See how

How it works

Proofs

Your money in Gloam is private by default. A proof lets you show one fact about it to one person you choose: a balance, that you hold at least an amount, that you were paid, or what a payroll run paid in total. They check it themselves, in their browser, against the live vault.

Exact balance
one balance, shown
At least
a minimum, balance hidden
Payment
the amount, or a minimum
Payroll total
a run's total, each pay hidden

Four proofs

All four are made on your device from records only you hold, and none of them can be used to move your money. Open Prove in the app and pick one. A payroll total is made from a finished run on the Payroll page.

Exact balance

Shows one of your private balances exactly: the asset and the amount. Use it when the number itself is the point, for example a lender asking what is in one account. It covers one balance, never your total.

At least (proof of funds)

Shows that you hold at least an amount you name, such as at least 10,000 USDG, without showing how much you really hold. Up to four of your balances in the same asset can back it, and the app picks the fewest that cover the amount. If it would take more than four, prove a smaller amount or combine balances first.

Payment (proof of payment)

Shows that you received a private payment. You choose whether it shows the exact amount, or only that it was at least a figure you pick. It works for payments sent to your Gloam address, claim links and payroll payouts, once you have claimed them.

Payroll total

Shows that a payroll run you sent paid exactly a total to a number of people, such as 21,500 USDG to 5 people, without showing what any one of them got. It is for your accountant, an auditor or a tax office: the figure on the books, backed by the vault. On a finished run, or under Past runs, choose Prove the total.

The checker confirms that every payment in it is a private payment inside the vault that you sent from your own balance. A deposit, a trade, the change from a payment, or a payment someone sent you cannot be counted, and no payment can be counted twice.

What each one shows and hides

ProofThey seeThey never see
Exact balanceThe asset and that one amountYour wallet, other balances, history
At leastThe asset and the minimum you namedYour real balance, which balances back it, your wallet, history
PaymentThe asset, the amount or a minimum, and when it landedYour balance, your other payments, your wallet
Payroll totalThe asset, the run's total, how many people were paid, and when the payments landedWhat each person got, their names and addresses, your balance

Proofs of funds, payments and payroll totals also carry two things you set: who the proof is for, and when it expires.

Made for one person

When you make an at least, payment or payroll total proof, you say who it is for, like "Acme Bank" or "my landlord", and how long it is good for: 1, 7 or 30 days. Both are sealed into the proof. Anyone can still read a forwarded copy, but it will say who it was made for and when it ran out, and changing either one breaks it.

How checking works

What the verifier does
Step 1Checks the mathThe zero-knowledge proof is checked in the browser with Gloam's published checking key. Nothing is sent to Gloam.
Step 2Checks who it is forThe name, expiry, network and vault must match what was sealed into the proof.
Step 3Checks the live vaultIt reads the vault on Robinhood Chain or Tempo directly: the state the proof was made against, for a payment that the payment is there, and for a payroll total that every payment in it is a private payment the sender made.
Step 4Checks it is still currentFor at least, that none of the backing balances has been spent since. For all of them, that the proof has not expired.

Each check is listed on the result with a plain pass, fail or could not check. A proof only reads as verified when every check passes. If the network cannot be reached, the result says so instead of guessing.

Limits worth knowing

  • Testnet only. Proofs run on Robinhood Chain and Tempo testnets with play money, using proving keys from a development ceremony. A production ceremony and an external audit come before mainnet. See the production gate.
  • At least publishes spend markers. A proof of funds carries a marker for each balance behind it, so the verifier can tell none were spent. The flip side: if you later spend one of those balances, whoever holds the proof can see that it was spent. Not where it went or how much.
  • At least means "can open at least this much". Strictly, a proof of funds shows the holder knows the keys to unspent balances worth at least the amount. A balance someone paid you was created by them, so until you move it, the sender knows its key too and could count it in a proof of their own. Balances you added yourself, or change left over after you pay someone, are yours alone.
  • A payment proof points at its record. They can find the transaction that delivered it and when it landed. That transaction never shows the amount. It shows the sender's wallet only if they paid without Hide my wallet.
  • Up to four balances can back one proof of funds.
  • A payroll total proves a sum, not a staff list. It does not show who the people were or that they work for you. It also cannot tell whether two payments went to the same person, or whether one of them went back to you. It counts payments, each one a real private payment you sent.
  • Up to 32 people per proof. A larger run is proven in even parts, sealed together in one proof. Each part shows its own subtotal, over 16 to 32 people, so no part is one person's pay. A run of one person proves that person's pay, so the app warns you.
  • A payroll total points at its payments. The checker sees the transaction behind each payment and when it landed. Those never show amounts or who received them. They show your wallet only if you paid without Hide my wallet.
  • Made in the browser that ran the payroll. Proving a total needs each payment's key, which the run keeps encrypted on that device. Runs paid before Gloam kept those keys cannot be proven, unless every payee was sent a claim link.
  • Expired is not the same as false. An expired proof may have been true when it was made. Ask for a fresh one.

How to check a proof

  1. Open gloam.trade/verify. No wallet or account needed.
  2. Paste the proof. It starts with gloamfunds1:, gloampay1:, gloamroll1: or gloamdisc1:. If you were sent a link, opening it fills the proof in for you. The proof travels after the # in the link, so it never reaches a server.
  3. Read the verdict, who it was made for and when it expires, then the list of checks.