Skip to content
Deploier

Deploier litepaper

Version 0.1, October 2026. How Deploier keeps the terms of a deal between its parties while the proof that it settled stays public on Robinhood Chain.

Abstract and the problem

Why settlement on a transparent ledger leaks positions, and why consortium ledgers trade that for trust in an operator.

Read more

Two layers

A private record held by the parties and a public commitment, both anchored to Robinhood Chain blocks rather than a new chain.

Read more

Commitments and view keys

How a salted keccak256 hash proves a deal without revealing it, and how one key discloses one record and nothing else.

Read more

Signed intent and lifecycle rules

Plain-language signatures with one-time nonces, one named counterparty, a 24-hour expiry and withdrawal before acceptance.

Read more

The contracts and the token

The escrow, the issuance factory and the commitment registry as written, and the intended roles of the token.

Read more

Risks, limits and roadmap

Where practice mode depends on one server, what stays public on any chain, and the order in which the pieces ship.

Read more

1. Abstract

Deploier is a privacy settlement layer on Robinhood Chain. It separates each settlement into a private record held by the parties and a public commitment that anyone can verify. The goal is settlement that is final and verifiable like a public ledger, and confidential like a bilateral agreement.

This paper describes the design as it runs in practice mode, the contracts that make it move real assets, and the risks that remain. It makes no claim that any institution uses Deploier.

2. The problem

A transparent ledger exposes balances, counterparties and timing. For a fund, a broker or a payment company, that exposure is a cost: others trade ahead of known flows, read client relationships off the chain and reconstruct strategies from history.

Permissioned ledgers avoid exposure by keeping data inside a consortium, at the price of trusting the consortium and splitting liquidity across networks that cannot settle with each other.

3. Two layers

The private layer holds the record: both wallet addresses, both legs, a memo and a salt. The public layer holds a commitment to that record, its status and the Robinhood Chain block at which each status was reached.

Deploier is not a blockchain. Robinhood Chain provides ordering, time and the assets. This choice avoids a new validator set and bridges, and puts settlements next to the tokenized equities and the USDG dollar token already on that chain.

4. Commitments

A commitment is keccak256 over the canonical JSON of the terms, a separator and a 16-byte random salt. Canonical means keys sorted at every depth, lowercase addresses and normalised decimal amounts, so the same terms always give the same hash.

The salt prevents guessing: without it, an observer could hash likely terms and compare. With it, the commitment reveals nothing, yet anyone given the terms and salt can confirm the match.

5. View keys and selective disclosure

Each record has its own 32-byte view key, given to the creator once. The server keeps only its SHA-256. Presenting the key opens that record and no other. A desk answering a review request hands over the keys of the trades in question, and nothing else about its book becomes visible.

6. Signed intent

Every action is a plain-language message signed with personal_sign: the domain, the action, the wallet, chain id 4663, a one-time nonce and an expiry. The server burns the nonce atomically before verifying, so a signature cannot be replayed, and it applies the action it stored with the nonce rather than anything the browser sends later.

7. Lifecycle rules

  • A proposal names one counterparty; only that wallet can accept it, once.
  • An unaccepted proposal expires after 24 hours; the maker may withdraw it before acceptance.
  • The two legs must be different assets with positive amounts.
  • An issuance lists between one and five eligible holders in practice mode, and names its class, units, face value and maturity.

8. The contracts

Three contracts take the design from practice to real assets. SettlementEscrow takes leg A when the maker proposes and releases both legs in the transaction where the named taker delivers leg B; the maker can cancel before that, and after the expiry anyone can return leg A. AllowlistTokenFactory lets any wallet issue a whole-unit token that only allowlisted wallets can hold; the issuing wallet alone manages that list, and a maturity date stops transfers and opens redemption. CommitmentRegistry records hashes and statuses so the public tape is the chain itself.

What the code does and does not contain: no owner, no admin key, no pause, no fee and no upgrade path in any of the three; no deposit limits either. Incoming tokens are measured by balance difference and must arrive in full. Their source, tests and a script that checks deployed code byte for byte are published with the site.

9. The $DEPLOIER token

$DEPLOIER is the project token on Robinhood Chain. Its intended roles are operator bonding and fee discounts once an operator programme exists; the settlement contracts themselves charge no fee and do not use it. It carries no claim on revenue or assets and is not an investment product. The contract address will be published on the token page at launch.

10. Risks and limits

  • Practice mode depends on one server to store records and serve the tape.
  • Losing a view key means losing the ability to open that record; there is no recovery by design.
  • Timing and frequency of commitments are public and can leak patterns even when content does not.
  • Token transfers on Robinhood Chain are public. A first escrow contract can keep terms and memos private, but hiding amounts on-chain needs a shielded design, which is a larger, separate milestone.
  • Contracts can hold bugs, and these cannot be patched after deployment because there is no upgrade path.
  • Stock tokens can be paused or blocked by their issuer; a settlement involving one then cannot complete until the issuer allows it.
  • Regulatory treatment of private settlement differs by jurisdiction and is unresolved.

11. Roadmap

  1. Now: website, live chain data, practice desk for settlements and issuances.
  2. Next: token launch and deployment of the escrow, registry and issuance contracts.
  3. Then: integrations that read the on-chain tape, and a shielded design for hidden amounts.
  4. Later: operator programme, compliance hooks and integrations with custodians.