Private payroll · Robinhood Chain

Pay people.
Show no one.

sUSD is a sealed dollar. Stream salaries, send invoices and hand out signed receipts, and the ledger records no sender, no recipient and no amount. Your team gets paid. Your treasury stays yours to know.

How streams work
S
to
from
sUSD price
$—
collateral ratio
reserve
streamed to date
sealed
The desksUSD · 4663
USDG
SEAL
sUSD · visible
streams in
sUSD · sealed
000000revealledger key
Quiet Yield · earned while sealed
01 · streams

Salary, rent, retainers. On a schedule, under seal.

Pick an address, an amount, a period and a count. SEAL pays it from your sealed balance every period, on time, as a sealed send. Each payment is one nullifier and one commitment on the ledger, and each one carries a signed receipt. If the balance runs dry the stream pauses and resumes when you top up. Cancel any time.

streams live
payments made
sUSD streamed
fee per payment
02 · invoices

Get paid by a link. The payer stays unnamed.

Create an invoice for an amount and a memo. It becomes a link. Whoever opens it pays from their sealed balance straight into yours, and neither of you appears on the ledger. Both sides get a receipt. Contractors invoice DAOs, DAOs pay contractors, and nobody outside learns the rate.

invoices paid
invoiced to date
03 · sealed receipts

Proof it happened. Nothing else.

Every stream payment and invoice produces a receipt: an id, an amount, a time and an HMAC-SHA256 signature from the SEAL ledger. It carries no sender and no recipient. Give it to an accountant, a landlord or an auditor and they verify it at /verify without learning who paid. This is how you prove payroll ran without publishing payroll.

ID

Unique

One receipt per payment, generated the instant it settles.

SIG

Signed

Forged receipts fail verification. Real ones verify from any device.

Ø

Blank

Amount, kind and time only. No names, ever.

receipts issued
04 · quiet yield

Sealed balances earn the fees.LIVE

40% of every protocol fee streams to the people holding sealed sUSD, pro-rata, the instant it is paid. Every stream payment, invoice, send and Blind Desk trade pays a fee, so a payroll running through SEAL is paying its own holders. No staking, no lock, no claim. Nothing is printed: the fee is sUSD that is already collateral-backed. The rest buys $SEAL and burns it.

share of every fee
paid to sealed holders
last 24h
running APR · from fees
payouts
wallets earning
you have earned
05 · what the ledger sees

Every entry below is public. That is the whole footprint.

06 · blind desk

Treasury exposure, unobserved.

positions open
notional inside
000000
volume
fees

Commit sealed sUSD to tokenized stocks, long or short at 1x, priced off the live exchange tape. Ticker, size, side and P&L stay sealed. Orders fill only while the tape is live.

07 · bonds · cryo · the window

$SEAL below market. Reserve above.

bond price · $SEAL
market price
capacity today
bonded so far
cryo price · $SEAL
in cryo
window APY · in $SEAL
sUSD staked
reward pool left
window closes in
stakers

Bonds: deposit USDG, take $SEAL at 20% below market, vesting over 5 days. USDG goes to the reserve and mints nothing. Cryo: lock the bond 48 hours at 30% below market and earn 80% APY in $SEAL while locked. The Window: a fixed-pool staking period with a hard end date. Nothing printed.

08 · the burn

Every fee buys $SEAL and removes it.

$SEAL burned
bought back
queued · next cycle
cycles
09 · relays

Bring a team in. Earn 20% of their fees, forever.

Anyone who opens your envelope or invoice, or arrives through your relay link, is bound to you. From then on 20% of every fee they pay lands in your sUSD. The rest is split between Quiet Yield and the burn.

wallets you relayed
earned from their fees
10 · answers

Asked plainly.

What is sUSD?
A dollar you can seal. sUSD is a fractional-algorithmic stablecoin on Robinhood Chain: each unit is minted from USDG, most of which is held as collateral while the remaining share buys and burns $SEAL. The protocol moves that ratio to hold the price at $1.
What is a stream?
A scheduled sealed payment: X sUSD to one address every minute, hour, day, week or month, N times. The first payment goes out the moment you start it. Each payment is a sealed send, so the ledger shows one nullifier and one commitment and never the recipient. Each payment carries a signed receipt. If your sealed balance cannot cover the next payment the stream pauses and you can resume it after topping up. You can cancel at any time. 30 bps per payment.
What is an invoice?
A request for sUSD as a link. You set an amount and a memo; whoever opens the link pays from their sealed balance into yours. The payer is never named on the ledger and the invoice page shows only the amount and memo. One payment per invoice, and both sides receive a receipt.
What is a sealed receipt and how do I verify one?
Every stream payment and invoice creates a receipt: an id, the amount, the time and an HMAC-SHA256 signature from the SEAL ledger. It contains no sender and no recipient. The sender or recipient fetches it from the Receipts tab and shares a link; anyone who opens /verify with that link sees whether the signature is real and what the amount and time were, and nothing else.
How does the peg hold?
Below $1 the collateral ratio rises, so more USDG backs each new sUSD and redeeming pays more hard collateral. Above $1 the ratio falls. Redemption is always open, so arbitrage pulls the price back to $1. The ratio is shown live at the top of this page.
What does “seal” actually do?
It moves sUSD from your visible balance into the shielded pool and writes a note encrypted only to you (x25519) plus a commitment in the Merkle tree. Your balance is unreadable to everyone but you.
What can an observer see when I pay sealed?
One nullifier spent and one new commitment added. No amount, no sender, no recipient.
What is Quiet Yield?
40% of every protocol fee, paid to sealed sUSD holders. Each time anyone streams, pays an invoice, sends, redeems or trades on the Blind Desk, 40% of the fee is split pro-rata across every sealed balance and credited as sUSD, in the same instant. No staking, no lock, nothing to claim. It is paid from fees that are already collateral-backed sUSD, so nothing is printed and it has no end date.
What is $SEAL for?
$SEAL is the share token. A slice of every mint and 60% of the non-referral fee buys $SEAL and burns it, and bonds and the Window pay out in it. Demand for private payroll flows into $SEAL. Holders govern the protocol parameters.
Is my USDG actually deposited?
Yes. A deposit is a real USDG transfer on Robinhood Chain to the treasury. The server reads the receipt, checks the Transfer log runs from your wallet to the treasury, and only then credits your desk.
How do I get USDG back out?
Redeem sUSD for USDG, then Withdraw. Withdrawals enter a queue the treasury pays from a cold wallet, usually within 24 hours, with the payout hash written next to your request. There is deliberately no hot key on the server.
What is a ledger key?
A view key: an HMAC over your address with a server salt. It reads your sealed balance and history on a read-only page and has no spending power. Give it to an accountant, and to nobody else.
What is the Blind Desk?
Private exposure to tokenized stocks for a treasury: long or short at 1x, priced off the live tape, settled in sealed sUSD. Positions are capped per wallet and protocol-wide; shorts stop out at a 95% loss.
Which chain and which wallet?
Robinhood Chain (chainId 4663). Connect any EVM wallet such as MetaMask or Rabby; the site switches the network for you. USDG is the collateral asset.
How is risk handled?
The collateral ratio is published live, redemption is always open, yield programs have fixed pools and end dates, and Blind Desk exposure is capped. Withdrawals are paid from a cold wallet. Sealed notes are encrypted to your keys alone, so keep your keys.