Architecture Overview
Cyphron is a confidential payments layer for people and the software working on their behalf. It runs on Robinhood Chain, and its privacy primitive comes from Cyphron's own confidential token contracts: an ERC-20 with encrypted balances in the Zether tradition. Because the EVM has nothing like this built in, the contract layer was written in-house and verified on-chain. Unlike a typical fintech, Cyphron also maintains no settlement ledger of its own. The ledger is Robinhood Chain, and Ethereum sits beneath it.
Responsibilities of this layer
- Custody and signing. Every account is an ERC-4337 smart account controlled by a keypair created on the client. Cyphron never receives the keys.
- Confidential transfers. The token contracts encrypt amounts, and the client generates the proofs.
- Gas abstraction. Each account keeps a small ETH float that tops itself up through an internal swap whenever it runs low, so users only ever think in USDG. Gas is reduced to an implementation detail.
- Agent policy. The agent's client checks spend policies while signing, and the
AgentControllercontract enforces them on-chain. - Indexing. An off-chain indexer consumes contract event streams and drives both the live feed and the webhook system, with no polling involved.
Anything that requires trust (who owns which funds, whether a transfer is valid) is decided by Robinhood Chain and Cyphron's on-chain contracts, and the rollup's fraud-proof settlement ultimately backs that correctness with Ethereum. Everything else, such as rendering, notifications, and indexing, is a convenience built on top. Keeping those two apart is the core of the design.
Layers
+-------------------------------------------------+
| Applications |
| Web . Mobile (iOS/Android) . SDK |
+---------------------+---------------------------+
|
+---------------------v---------------------------+
| API surface |
| REST + WebSocket . Agent API . Webhooks |
+---------------------+---------------------------+
|
+---------------------v---------------------------+
| Core services |
| |
| Wallet Engine Privacy Engine Agent Engine |
| (keys, (ZK proofs, (policies, |
| tx building) client-side) x402) |
| |
| Indexer (contract event streams + PostgreSQL) |
+---------------------+---------------------------+
|
+---------------------v---------------------------+
| Robinhood Chain Mainnet |
| Confidential Tokens . ZK Verifier . x402 |
+-------------------------------------------------+
Trust, component by component
- Funds: no one has to trust Cyphron. Keys are created and stored on the device, and the servers only ever see signed transactions, never a private key.
- Amounts: no one has to trust Cyphron. Proof generation and decryption run on the client, and the backend only ever touches ciphertext.
- Agents: limits are enforced when the agent signs and again on-chain by
AgentController, never left to Cyphron's judgment after the fact. A transaction that breaks policy never gets created.
Related pages
- Smart Contracts: how on-chain state is laid out
- Security and Threat Model: security at each layer