Confidential · Compliant · For regulated institutions only
Prove everything. Reveal nothing.
In plain terms: a family office, crypto-native fund or on-chain treasury holds serious money on a public blockchain, where anyone can watch every move. PROVA is a confidential vault that keeps their holdings hidden from competitors and bots, while still letting them prove to a regulator that the vault admits no listed counterparty to its perimeter — without handing anyone a key to their book. Built for the desks that actually hold crypto on-chain — family offices, crypto-native hedge funds and trading desks, large swing traders who move size a few times a year and sit on the position in between, DAO and protocol treasuries, and tokenization / RWA issuers. These holders don't keep everything in one place: their assets live on different blockchains — strkBTC on Starknet, wstETH on Ethereum and Arbitrum, tokenized US Treasuries and RWAs wherever they're issued — and they answer to different regulators in different countries. PROVA is built to meet each asset where it already lives: the same vault runs on Starknet and Arbitrum today, with Solana on the way, and screens against whichever sanctions list a given jurisdiction requires. One product, every chain the client's money is on — no bridges, no moving assets around. How the compliance boundary works, in one breath: only addresses the client approves can deposit (the client runs the guest list — no stranger can drop assets into the vault), every deposit and every withdrawal is checked against the sanctions list — both on the way in and on the way out (screening on entry is something almost nobody in crypto does, yet it's exactly what tokenized Treasuries and RWAs require), and each holding carries a certificate of provenance — proof that it derives from the institution's own declared association set, settled on-chain. No listed counterparty is admitted to the perimeter, and every holding carries provenance anyone can verify. And to an observer watching the chain, a withdrawal can't be tied back to any particular deposit — who exited, when and to where doesn't read off the public trail. But this is privacy inside an already-screened perimeter: both entry and exit passed the sanctions check and provenance is proven by certificate, so breaking the trail isn't a way to hide sanctioned value — it's how a screened holder's strategy stays shielded from onlookers.
PROVA is a confidential, compliant treasury-vault for regulated institutions — built on a first-rank zero-knowledge stack: STARK-secured Starknet, settled to Ethereum, UltraHonk proofs verified on-chain. Your treasury stays sealed from the market, with a sanctions boundary that is cryptographically provable to a regulator. Asset-agnostic by design — tokenized treasuries, yield-bearing wrappers, near any count-preserving token. Custody never leaves your keys. One audited-once ZK core, portable to the chain your assets already live on — the same circuits and verification keys deploy natively on any EVM chain, so PROVA comes to the asset instead of bridging the asset to PROVA.
Deposit → hold → withdraw, live
Two views of one vault. Only one of them can read it.
Below is a working model of the PROVA vault, computed right now in your browser. Deposit seals an amount into a note — the chain records the commitment and its denomination, never who can spend it or where it will exit. Withdraw proves the note and releases funds without ever linking exit to entry. Switch to the chain observer to see exactly what a competitor sees.
computing…
The problem
A public chain shows your competitors everything. The usual fixes make it worse.
An institutional treasury on a public chain publishes its balances, counterparties, and flows to anyone with a block explorer — competitors, front-running bots, chain-analysis vendors. For a regulated desk that is not transparency; it is a standing disclosure of position and strategy.
Each classical fix answers a different question — or surrenders something. A custodian takes the asset. A mixer buys privacy by destroying compliance. And disclosure tools — viewing keys — answer the auditor's question, who may look at what happened, but not the question that comes first for a compliance officer: how to be certain that no listed address ever enters or exits at all. After-the-fact visibility cannot un-accept a deposit that should have been refused at the gate.
PROVA puts prevention where it belongs — at the gate. Custody stays with the institution: the vendor holds no key over a deployed vault. Disclosure is per-transaction, when lawfully requested. Every value-bearing path is gated by a zero-knowledge OFAC non-membership check — on the depositor at entry, on the recipient at exit — enforced by the contract before any token moves. And each note earns an affirmative source-of-funds attestation that settles on-chain as a certificate: proof of provenance from the institution's declared association set, checkable by a counterparty or auditor, never a brake on exit.
Confidential from the market. Provable to the regulator. Never handed to a custodian.
Why now · the cost of the status quo
Transparency is not neutral. On a public chain it is a standing tax on every position you hold.
The question is not whether confidentiality is nice to have. It is what a transparent, retrospective-compliance treasury already costs you — today, on every deposit, every exit, every audit cycle. Three costs, each of which compounds.
Your book is priced against you
A transparent ledger publishes size, timing and counterparties to anyone with a block explorer. Every large position becomes a signal — front-run by bots, faded by counterparties, mapped by chain-analysis desks. This is not a breach; it is the default behaviour of the chain. It shows up as worse fills and eroded edge on every move, and it scales with the size of your book.
Detection cannot un-accept a dirty deposit
Sanctions liability is strict — intent is not a defence. Viewing keys and monitoring answer who may look at what already happened; they cannot stop tainted value from entering or leaving in the first place. Once a bad deposit settles, the exposure is booked. Detection is not prevention — and supervisors increasingly expect the latter, at the gate, not in the quarterly report.
Regulated capital is arriving on-chain — unsolved
Tokenized treasuries, money-market wrappers and institutional stablecoins are moving on-chain now. The piece still missing is a way to hold them that is confidential to the market and provable to the regulator at once. The desks that solve this first hold their positions without publishing them — while the rest are still choosing between disclosure and compliance.
Every day on a transparent vault is a day your strategy is public and your compliance is retrospective. PROVA closes both — at the gate, inside the same transaction.
What is PROVA
Seven deliberate choices — each removes a problem instead of adding a feature.
A regulated institution holds its on-chain treasury inside its own isolated vault — confidential from the market, provable to a regulator, never handed to a custodian. The design is defined by what it refuses as much as by what it does.
Confidential, not private
PROVA protects what and how much — balances, counterparties, flows — from external observers. It does not chase a large anonymity set hiding who participates. The threat model is the competitor and the front-running bot, not the state. That is the confidentiality a treasury needs — and the axis on which anonymity-set size is simply not the game.
Compliant
Entry is restricted to counterparties the institution approves — a controlled, provable perimeter, never an open pool. On EVM deployments, where depositor and recipient share OFAC's address space, this is reinforced by an on-chain zero-knowledge OFAC non-membership check on entry and exit. On Starknet, where account addresses fall outside that designation space, compliance is enforced at the perimeter and made auditable through selective disclosure. No listed counterparty is admitted, and a regulator can verify the boundary without a standing audit key. This is not a mixer.
Treasury-vault
A place to hold, not a venue to trade through. The product is a vault assets rest in between moves — you keep trading wherever you already do, and hold the position here, sealed from the market.
Yield-bearing assets
Yield accrues inside the asset — accruing-in-price wrappers, tokenized treasuries whose value rises in the token's own rate — so capital is not idle while held. No external contract call, no DeFi integration, no composability required.
Held-only
Deposit → hold → withdraw. No internal transfer graph, no swaps. The smallest sufficient surface — which is also the smallest surface to leak, and to audit.
No composability — by design
Wiring the held asset into external DeFi costs the confidentiality of amounts: swap sizes hit public AMM state — precisely the property the institution is paying to protect. PROVA declines that trade: the vault is where a position rests between moves, not the venue you execute through. Trade wherever you already do — hold the resulting position here, sealed.
With zkSoF — an affirmative proof of source of funds
Provenance from a declared association set, bound to a specific note. Six choices subtract risk; this one adds a property no blacklist can give: the proof attests which declared set the funds derive from, not merely that an address is absent from a list. It is cryptographic evidence for a source-of-funds file — timestamped and independently checkable — not a substitute for the AML judgment itself.
The protocol
Deposit. Hold. Withdraw.
Deposit
Before any token moves, the contract enforces three checks: membership in
your own whitelist — the operator is the client, so only addresses you approve can
ever deposit (a random passer-by cannot put anything into your perimeter, so tainted
assets never appear inside it in the first place); an OFAC non-membership proof bound
to the caller's address — sanctions screening enforced on the way in, which
almost nothing in the industry does, yet is exactly what a tokenized-Treasury or RWA
program needs; and a proof that the note's commitment opens to
exactly the deposited amount. A deposit claiming a different amount is
structurally impossible.
Hold
The note rests in your own vault. Yield accrues inside the asset itself — no DeFi calls, no rebalancing, no oracle. Balances, counterparties and flows are invisible to observers; only commitments touch the chain.
Withdraw
A zero-knowledge proof — verified by the contract inside the transaction —
authorizes exit. The nullifier prevents replay; the recipient is sanctions-screened
in the same atomic transaction. Exit never waits on any third-party compliance service.
What defines the design
Three properties you can check in the contracts — not a brochure.
Affirmative source of funds
AML asks "prove the source of these funds." A blacklist answers only
"not on this list." PROVA's zkSoF is a positive proof that a note derives from an
approved association set — and it runs as a parallel attestation, never as a
withdrawal gate: the money path never waits on a compliance operator. The attestation
settles on-chain as a certificate — ProvenanceAttested,
timestamped, bound to the note — and anyone can confirm it via
is_sof_attested. The set is the institution's own, committed on-chain:
the proof establishes derivation from a declared set, not a legality verdict —
evidence inside your compliance program, not a replacement for it.
No standing audit key required
Prove a specific fact about a specific transaction when lawfully requested — liability assessed by knowledge at the time of the transaction, as in ordinary law. And where a client's supervisory relationship calls for viewing-key disclosure, it layers cleanly on top: disclosure is policy; prevention stays at the gate.
Physical single-tenant isolation
Each client deploys and owns its own vault — a separate sovereign audit domain, not a
logical partition in a commingled pool. No neighbour-reputation risk. The vendor holds
no privileged key over a deployed instance: read owner on-chain and
confirm it is yours.
Positioning in the Starknet stack
Prevention at the gate. Disclosure on request. Two layers of one compliance stack.
Starknet's ecosystem is building a viewing-key standard for confidential assets — and it answers a real need. PROVA does not compete with it: the two answer different questions, and a regulated institution needs both answered.
An auditor or supervisor granted a key can read flows after the fact. This is the right tool for audit and supervisory relationships — accountability for what has already settled. PROVA composes with it: a client that adopts the ecosystem's viewing-key standard simply layers it on top of its vault, as policy.
Before value moves, the contract itself enforces an OFAC non-membership proof on the depositor at entry and on the recipient at exit. This is what makes an institution certain that no listed address either enters or exits — a guarantee no amount of after-the-fact viewing can provide, because visibility cannot un-accept a deposit that should have been refused at the gate. In parallel — never as a brake on exit — each note earns a zkSoF provenance attestation that settles on-chain as a certificate, bound to that note and checkable by anyone. The order matters: a blocked recipient is turned away at this compliance gate before any proof is even checked — which is what separates PROVA from a privacy mixer with screening bolted on. Confidentiality lives inside the compliance perimeter, not beside it.
Disclosure is a policy an institution chooses. Prevention is a property the contract enforces. PROVA adds the layer the stack was missing — and composes with the one it has.
Your jurisdiction, your list. PROVA screens against the sanctions regime you are actually accountable to — not a one-size-fits-all blacklist. The U.S. OFAC SDN List is live on the current deployments, and because the list is a pluggable input rather than a hard-wired assumption, your vault can be stood up quickly against the regime your regulator expects: the EU Consolidated Financial Sanctions List (European Commission), the UK Consolidated List of Financial Sanctions Targets (OFSI, HM Treasury), the United Nations Security Council Consolidated List, the Swiss SECO sanctions list (State Secretariat for Economic Affairs) — or several at once, one reproducible tree per jurisdiction. Same contracts, same proofs, your rules — a configuration of the pipeline, not a rebuild.
Roadmap: BTC-origin screening for strkBTC. A bridged asset has one moment when its origin exists as a screenable subject — before the bridge. On the roadmap, BTC deposit addresses are screened against the SDN's XBT entries (520 designated Bitcoin addresses on the current list) at the custody/bridge boundary, before strkBTC is minted — with a proof-carrying attestation of that screening to follow on the same attestor rail that governs the sanctions root today. Stated as roadmap, not as shipped: the gate lives where the subject lives, and for a bridged asset that is the mint boundary, not the vault.
The trust boundary
What PROVA proves — and what it does not.
- Proven, on a public network
- That the vault verifies both money-path proofs on-chain — deposit amount-binding and withdrawal. That a borrowed-address proof, a fabricated sanctions root, and a replayed nullifier each revert. That the full deposit→withdraw cycle has settled 111 automated runs with deterministic, bit-identical gas. Every claim maps to a transaction you can open.
- Not claimed — yet
- Mainnet operation and live yield-bearing assets are go-to-market scope, not a current claim: today's vault runs on Sepolia against a mock ERC-20 standing in for the production asset. PROVA is a pre-market MVP, and this page will never say otherwise.
The difference between PROVA and a pitch deck is that PROVA's claims come with transaction hashes.
Trust transferred from a name to a proof.
The vault is non-custodial and trust-minimized: PROVA never holds the asset and holds no privileged key over a deployed instance. Confidentiality rests on a zero-knowledge proof verified on-chain — not on trust in a hardware enclave, and not on trust in the vendor. A reviewer does not have to trust the founder's reputation: they read the source-verified contracts and re-run the adversarial checks themselves.
The capital here is verifiability, not a custodian's brand — don't trust, verify, applied to the business model, not only to the code.
Pure infrastructure: no token, no protocol fees, no custody. Each licensed institution deploys and owns its own vault, verifier, and compliance policy — B2B annual licensing.
Attack surface
What PROVA does not do — and why that is your security.
Read the post-mortem of almost any nine-figure protocol loss and you find the same precondition: the protocol was doing something with the money. Lending it, pricing it, swapping it, quoting it against an oracle, pooling it with strangers. Exploits need a moving mechanism to attack. A vault at rest does not offer one — because a vault at rest is not a mechanism. Confidentiality is what PROVA sells; a smaller attack surface is what the design costs you nothing to receive.
What is left, stated without softening.
Four things: deposit, withdraw, a commitment tree, and an on-chain proof verifier. That is the whole surface. The residual risk is real and we name it — the code may be wrong: smart-contract risk, circuit risk, prover and verifier implementation risk, and the risk of a protocol that is new. PROVA carries no external audit and no mainnet volume today, and this page will say so until the day that changes.
But notice what that risk is. A custodian carries a class of risk you cannot inspect: an insider, a compromised vendor, an operational decision, a court order, an insolvency. You close it with a contract, an insurance policy and a name. A vault carries a class of risk you can inspect: source-verified contracts, adversarial tests you re-run yourself, a verifier your engineers read line by line. Trust does not disappear here — it changes from the kind you must take on faith to the kind your diligence can actually reach.
Which is why nobody should move nine figures into an unaudited protocol, and we will never ask. The path is a pilot at a sum whose loss is immaterial, your own engineers breaking it, an external audit before real capital, and then a slice of the cold layer — not the balance sheet. Don't trust, verify is not a slogan here; it is the sequence.
Diligence · for the buying committee
The questions a compliance officer, a GC and a CIO each ask first.
Circulate this to your committee. Every answer below maps to a contract you can read or a property you can verify on-chain — not a promise, and not a claim this page can't back with a transaction hash.
The right next step is not a signature — it is a pilot where your own engineers verify every claim on this page against your own instance.
On-chain, today · two chains
Don't trust the vendor. Read the chain — either chain.
The canonical M5 stack, deployed and verified on two independent testnets: Starknet Sepolia and Arbitrum Sepolia. Every wiring claim — which verifier the vault calls, which binding the compliance module routes to, which roots are registered — is confirmed by reading the deployed contracts' getters, and the adversarial checks are reproducible by any reviewer. The same Noir circuits and the same verification keys power both deployments; a single audit is designed to cover every chain. All contracts source-available under BUSL-1.1, converting to MIT on 2029-07-12.
Starknet Sepolia
Testnet canonical M5 · STARK-secured, settled to Ethereum · Garaga UltraHonkArbitrum Sepolia
Testnet same core, ported to the EVM · BN254 precompiles native (EIP-196/197), no wrapping layershared sanctions root · 0x15bdf63fc7b1413813d7cbbab3112e5fce031724de214caaa9185381d3c53130
Who holds what
Hold on-chain without publishing your book.
Your book's structure and your counterparties stay sealed from competitors and front-running bots while yield accrues inside the asset — no DeFi wiring, no oracle, no rebalancing. Custody never leaves your keys: the vendor cannot pause your vault, rotate your roots, or move your funds. Not "agrees not to" — is technically unable to.
Certain at the gate. Accountable on request.
Sanctions screening enforced on both entry and exit — so no listed address can either come in or go out — an affirmative source-of-funds attestation for every note, and disclosure measured in single transactions, proven in zero knowledge when lawfully requested. Your compliance policy, your whitelist, your audit domain — with the ecosystem's viewing-key standard available on top where your supervisor expects it.
Licensing
Annual licenses. You own the vault — we never can.
PROVA is infrastructure, not a custodian. Each licensee deploys and owns its own vault, verifiers and compliance policy — the owner key is yours, verifiable on-chain. We never hold your assets, your keys, or a privileged key over your deployment.
Pilot
- Single-tenant vault deployment on testnet
- Full circuit set: withdrawal, OFAC, zkSoF, amount-binding
- Compliance policy workshop — whitelist & association sets
- Direct engineering support
Standard
- Production deployment — owner key handed to you
- Sanctions-root update service behind your 24h timelock
- Association-set indexer & attestation tooling
- Adversarial acceptance run on your own instance
Enterprise
- Multi-vault estates, custom compliance predicates
- Legal-team integration & SLA
- Dedicated circuit review with your auditors
- Jurisdiction-specific disclosure support
Pilots run in weeks, not quarters
The treasury you seal today is the position nobody front-runs tomorrow.
Write to us with your asset, jurisdiction and compliance profile — we answer with a deployment plan and the contracts to verify before you sign anything.
[email protected]Capital · selectively open
We are raising the way we build: verifiable first.
PROVA is opening its first outside round. The pitch is unusually short, because most of it is already on this page and on-chain: a live vault on a public network, an adversarial attacker model with settled transactions, a no-token, no-custody B2B licensing model, and a defined gate to mainnet — external audit, first pilots, first licenses. If your thesis is infrastructure where verification replaces trust — in the product and in the diligence — we should talk.
Request the investor memoPrivate conversations with qualified investors. Nothing on this page is an offer of securities or a solicitation to purchase any instrument.