All Case Studies

01 / CASE STUDY · SOLANA · GROTH16 · NILLION TEE · MAGICBLOCK

Civitas

Four-layer confidential payroll on Solana.

Civitas product interface
256 BGROTH16 PROOF FOOTPRINT

Paired with a 580-byte verification key embedded in BPF; fits comfortably inside Solana’s single-packet 1,232-byte MTU without Address Lookup Tables.

~175k CUON-CHAIN VERIFICATION COST

Executes SpongePoseidon(10) input reconstruction + 4-pairing alt_bn128_pairing check well inside Solana’s 1.4M compute unit ceiling.

~0.3sWARM SEV-SNP ENCLAVE LATENCY

Nillion nilCC V4 long-lived CVM replaces 2–5 minute per-job cold VM boots while keeping Ed25519-signed manifest attestation.

5× SplitTEMPORAL & AMOUNT UNLINKABILITY

MagicBlock TEE dispatcher fragments every USDC payout into 5 randomized sub-transfers delayed across a [500ms, 30s] window.

ClientCivitas Protocol
RuntimeSolana Devnet · V4 Warm Workload
Releasev3.1 · May 2026
On-Chain ArtifactCQW3TnN4...V6e24y
02 / EXECUTIVE THESIS

Designing for the real constraint.

Every architectural decision begins by isolating the structural failure modes of existing solutions and engineering directly against them.

01 / THE PROBLEM

Vulnerability & Friction Surface

Public blockchains turn a single payroll run into a permanent intelligence leak: one transfer exposes individual compensation to peers, headcount and burn rate to competitors, and a high-value transaction graph to extortionists. Point solutions fail in production: a standalone ZK claim pool still leaks the plaintext salary roster to the database operator and links withdrawals by identical amounts. Meanwhile, Solana’s native Token-2022 ElGamal ConfidentialTransfer extension remains disabled on devnet and mainnet pending its 2026 security audit.

02 / OUR APPROACH

Protocol & Product Strategy

We decomposed payroll privacy across four cooperating layers where each layer consumes only the cryptographic output of the layer before it. Employee tags and vouchers are secret-shared across a 3-of-3 Nillion nilDB MPC cluster, while batch commitments and a depth-20 Poseidon Merkle root are computed inside a hardware-attested AMD SEV-SNP confidential VM (nilCC V4) in ~0.3s. Employees prove voucher ownership in-browser via a 5-constraint Circom 2.1.6 Groth16 circuit verified via Solana’s alt_bn128_pairing syscall, and final USDC payout is decoupled through MagicBlock’s TEE Private Payments splitter.

03 / DELIVERED

Shipped Production System

An end-to-end confidential payroll protocol deployed on Solana Devnet (CQW3Tn...6e24y) featuring a 219-line custom Groth16 BN254 verifier in Rust, a 10-field SpongePoseidon public-input commitment, an append-only Nullifier PDA registry, a warm nilCC V4 enclave workload, and a dual-portal Next.js 16 employer/employee command center with zero mocks.

SYSTEM ARCHITECTURE

Four-layer confidential payroll pipeline.

Hover any node for technical detail
01Employee BrowserLocal ZK Witness
02Nillion nilDB3-of-3 MPC Storage
03Nillion nilCC V4SEV-SNP Enclave
04Solana ProgramGroth16 Verifier
05MagicBlock TEE5× Payout Splitter
VERIFICATION LOOP

Asynchronous settlement attestation returns from MagicBlock TEE to the Solana Nullifier PDA.

TECHNICAL ARCHITECTURE & PROOF

Architecture & verification.

Explore the defense-in-depth matrix, formal cryptographic equations, end-to-end execution trace, and systems engineering trade-offs.

03 / FOUR-LAYER PRIVACY STACK

Why a single primitive is never enough.

Each layer consumes the cryptographic output of the layer before it. Dropping any single boundary re-opens a concrete inference vector across storage, compute, claim verification, or token settlement.

LAYER 01

Confidential Storage

Nillion nilDB · @nillion/secretvaults v2.0 (3-of-3 MPC)
THREAT ELIMINATED

Eliminates single-operator database read access to the organizational salary table and voucher records via 3-of-3 additive secret shares (%allot).

IF OMITTED (LEAK VECTOR)

Any infrastructure operator or compromised cloud snapshot can dump the entire payroll roster in plaintext.

LAYER 02

Confidential Compute

Nillion nilCC V4 · AMD SEV-SNP Hardware-Attested CVM
THREAT ELIMINATED

Prevents the employer’s browser or an API server from acting as a trusted party when computing voucher commitments and the depth-20 Merkle root.

IF OMITTED (LEAK VECTOR)

Whoever computes the Merkle tree observes every (employee_tag, amount) pair simultaneously in unencrypted memory.

LAYER 03

Zero-Knowledge Anonymous Claim

Circom 2.1.6 · snarkjs 0.7 · Solana alt_bn128_pairing
THREAT ELIMINATED

Breaks the on-chain link between an employee’s identity leaf in the payroll Merkle tree and the destination wallet claiming funds.

IF OMITTED (LEAK VECTOR)

The on-chain settlement contract must know which employee index is claiming, trivially deanonymizing the recipient.

LAYER 04

Unlinkable TEE Settlement

MagicBlock Private Payments · tee.magicblock.app + SPL Token-2022
THREAT ELIMINATED

Eliminates amount-correlation and timing-graph heuristics linking the ZK claim transaction to the USDC payout via 5-way randomized splitting.

IF OMITTED (LEAK VECTOR)

Block explorers trivially correlate the exact USDC transfer amount and timestamp back to the claim_payment transaction.

HAVE A RELATED CHALLENGE?

Let's make
it ship.

Whether you are architecting zero-knowledge circuits, formally verified DeFi primitives, or a 250-builder ecosystem hackathon, you work directly with our founders and senior engineers.