Get your account
Under the hood

Architecture Overview

Beta. Parts of what these docs describe are still being built. The roadmap shows what is live today.

Cyphron is a confidential payments layer for people and the software working on their behalf. It runs on Robinhood Chain, and its privacy primitive comes from Cyphron's own confidential token contracts: an ERC-20 with encrypted balances in the Zether tradition. Because the EVM has nothing like this built in, the contract layer was written in-house and verified on-chain. Unlike a typical fintech, Cyphron also maintains no settlement ledger of its own. The ledger is Robinhood Chain, and Ethereum sits beneath it.


Responsibilities of this layer

  1. Custody and signing. Every account is an ERC-4337 smart account controlled by a keypair created on the client. Cyphron never receives the keys.
  2. Confidential transfers. The token contracts encrypt amounts, and the client generates the proofs.
  3. Gas abstraction. Each account keeps a small ETH float that tops itself up through an internal swap whenever it runs low, so users only ever think in USDG. Gas is reduced to an implementation detail.
  4. Agent policy. The agent's client checks spend policies while signing, and the AgentController contract enforces them on-chain.
  5. Indexing. An off-chain indexer consumes contract event streams and drives both the live feed and the webhook system, with no polling involved.

Anything that requires trust (who owns which funds, whether a transfer is valid) is decided by Robinhood Chain and Cyphron's on-chain contracts, and the rollup's fraud-proof settlement ultimately backs that correctness with Ethereum. Everything else, such as rendering, notifications, and indexing, is a convenience built on top. Keeping those two apart is the core of the design.


Layers

+-------------------------------------------------+
|                 Applications                    |
|      Web . Mobile (iOS/Android) . SDK           |
+---------------------+---------------------------+
                      |
+---------------------v---------------------------+
|                  API surface                    |
|   REST + WebSocket . Agent API . Webhooks       |
+---------------------+---------------------------+
                      |
+---------------------v---------------------------+
|                 Core services                   |
|                                                 |
|  Wallet Engine   Privacy Engine   Agent Engine  |
|  (keys,          (ZK proofs,      (policies,    |
|   tx building)    client-side)     x402)        |
|                                                 |
|  Indexer (contract event streams + PostgreSQL)  |
+---------------------+---------------------------+
                      |
+---------------------v---------------------------+
|            Robinhood Chain Mainnet              |
|  Confidential Tokens . ZK Verifier . x402       |
+-------------------------------------------------+

Trust, component by component

  • Funds: no one has to trust Cyphron. Keys are created and stored on the device, and the servers only ever see signed transactions, never a private key.
  • Amounts: no one has to trust Cyphron. Proof generation and decryption run on the client, and the backend only ever touches ciphertext.
  • Agents: limits are enforced when the agent signs and again on-chain by AgentController, never left to Cyphron's judgment after the fact. A transaction that breaks policy never gets created.