Enbank docs
Privacy model
Which fields are sealed, which fields a public chain would see, and what this site actually stores.
Field split
Treat every field as one of three classes. The class is about the production system. The preview column says what this website does with the same field today.
| Field | Production class | This website |
|---|---|---|
| Account address | Public. Settlement names the account. | Stored in the clear. Shown shortened in the header. |
| Private key | Client-only. Never an MXE input. | Plaintext JSON in enbank.wallet.v1. |
| Asset amounts | Private inputs. Omitted from callback accounts. | Plaintext in enbank.preview.v1. Masked in the UI until reveal. |
| Recipient or card destination | Private input. | Send stores a short address in the activity detail. No card field exists. |
| Settled bit | Public result. | A status string on the activity row. |
| Preview rates | Would be circuit outputs or sealed parameters. | Hard-coded strings. Not computed. |
Browser threats
The preview's secrecy is the screen, not the storage. These are in scope for this site:
- Another person with the unlocked profile can read both storage keys and reveal every amount.
- An extension or XSS on this origin can read the private key. The key is not encrypted at rest.
- Reveal is a boolean. Flipping it does not decrypt anything, because nothing was encrypted.
- CSV export writes the word
sealedin the amount column when reveal is off, and the raw number when reveal is on. The file is created on the device. - The dev server and a production host receive the page request. They do not receive the ledger. The ledger is written by the browser to its own storage.
Resetting the preview restores sample data. It does not delete enbank.wallet.v1. New wallet clears the key and leaves the ledger. Clearing site data is the way to drop both.
Production guarantees
A production deployment would move secrecy from CSS masks to the MXE. The guarantee is conditional, and Arcium states the conditions in its own docs:
- Inputs are encrypted to the MXE before the Solana transaction is built. Arcium documents X25519 and the Rescue cipher for that step.
- The circuit runs across a cluster of Arx nodes using Cerberus, a dishonest-majority, detect-and-abort MPC protocol. A detected abort stops the computation rather than returning a forged result.
- Each MXE is bound to one cluster at a time. The authority can migrate it. Migration is a trust event: the new cluster must receive key material through the recovery procedure.
- The callback is the privacy boundary. Any field the MXE program writes into a public account becomes public, even if the circuit computed it on ciphertext.
Enbank does not claim that Arcium hides data the application chooses to publish, and it does not claim the preview inherits those guarantees. The Arcium page names the accounts and offsets involved.
Reveal
Reveal exists so the holder of the device can read their own vault. It is not a sharing feature. There is no link that grants another address a view of the amounts. On the production path, the equivalent is client-side decryption of outputs the circuit returned still encrypted to the user, which is a different mechanism from the boolean stored at desk.revealed.
Search does not bypass the mask. It filters positions, markets, and activity by text. Amounts stay masked in the rows it returns. See Create a private vault for the balance record reveal sits on.
