What we solve

Rational privacy, applied.

Private by default, provable on demand. Prove the property, keep the fact. Your data stays yours: when a regulator, an auditor or a counterparty needs an answer, you answer their exact question. Not with your database, with a proof. Four problems clients bring us, each with something shipped behind it.

Accountable AI agents

Deploy an AI agent that can prove it followed the rules, without exposing the data it read.

An agent approves a claim, prices a contract, makes a purchase. The auditor, the buyer, the counterparty all want the same things: proof it followed the rules, spent within budget, and is who it claims to be. Today that means the logs, and the logs are the data the agent read. Proving compliance leaks exactly what compliance is meant to protect.

Stays with the operator
  • The records the agent read
  • The purchases and the owner behind them
  • The agent's full reasoning
one proof
What the auditor sees
  • Which policy applied, and that its conditions were met
  • That spending stayed within budget
  • That the agent is who it claims to be
What leaves, and what stays

What changes when you can prove it without revealing it

The decision carries a proof it followed the policy: which rule applied, that the inputs met its conditions, that the output stayed in bounds. The auditor checks the proof; the inputs never leave. And an agent inherits the rest of this page: verified identity, certified assets, payments that stay private. It can act for a buyer through a signer it does not control, so it never holds the secret.

Where the work stands

Still open, and where our work is going. Two things have to hold: proof of what the agent ran, and proof it was allowed to do it. Confidential computing answers the first, with hardware attestation vouching for the code without opening the data it read. Open wallet standards answer the second, gating every signature on a policy before the key is decrypted, so the agent never holds the secret. What is linked below is the ground we build on.

The technology underneath

Proofs of policy compliance on Midnight; a pluggable signer so an agent never holds a user's secret; documentation and skills delivered as Claude Code plugins.

Tokenized assets

Move a real asset on-chain with its compliance intact, then put it to work as collateral.

A bond, a receivable, a carbon credit, collateral behind a loan: to move it on-chain you have to answer who may hold it, what must be proved before it transfers, and which parts of that proof are anyone's business. And an asset that just sits there is not the point. It has to work: collateral in DeFi, settlement on private rails, reserves a counterparty can check without opening the books.

Stays with the holder
  • The holder's identity and the documents behind a credential
  • The portfolio and the holder's other positions
one proof
What a counterparty sees
  • That the asset is what it claims to be, and who vouches for it
  • That this transfer is permitted, and by which rule
  • That a position is covered by eligible collateral
What leaves, and what stays

What changes when you can prove it without revealing it

The rules travel with the asset. It is listed publicly, bought privately, and stays auditable. A holder proves they qualify without showing the documents. A transfer proves it is permitted, and by which rule. A borrower proves a position is fully collateralized without revealing the portfolio behind it.

Where the work stands

The RWA framework we are building is the base new projects start from: composable modules, contracts and services on Midnight. It is early and private, so it is described here and not linked. The recorded sessions on ZK identity for RWA show the pattern end to end.

The technology underneath

Composable Compact modules on Midnight; selective disclosure over credentials.

Identity & credentials

Verify once, prove everywhere. No organization holds a copy of the documents.

A person or a company gets verified once, then again by the next bank, the next platform, the next regulator. The same documents are handed over each time, to another party who now has to store and protect them. The holder repeats the work; every verifier holds the liability.

Stays with the holder
  • The documents behind the credential
  • The birthdate, the file, the full identity
  • Where else the credential has been used
one proof
What each organization sees
  • That the holder meets the requirement
  • Who vouched for it, and when
What leaves, and what stays

What changes when you can prove it without revealing it

One trusted party verifies once and vouches with a credential. The customer carries their own proof, and each organization sees only the property it needs: over eighteen without the birthdate, licensed without the file, sanctions-clear without the statement. No one holds a copy of the documents.

Where the work stands

The method is being built in the open on Midnight: did:midnight is the reference implementation of the identifier, with verifiable credentials beside it, so a verifier learns the property and never the document behind it. It is early, far enough along to build against and still open enough to shape. Our part runs on two tracks: teaching it, and connecting it to real solutions to find where it holds. The sessions below walk through the pattern, including how a contract gates itself on a credential it never reads.

The technology underneath

Credentials issued once, proofs derived per verifier; ZK, MPC and TEE as the underlying stack, chosen after the problem.

Certification & ESG

Issue certificates people can trust, backed by proof instead of paperwork.

A buyer wants to know the energy was renewable, the material recycled, the survey flown to standard. Today, proving it means opening the books: suppliers, volumes, routes, raw imagery. Everyone ends up holding everyone else's business, and the paperwork proves less every year.

Stays with each party
  • The supplier list and the volumes behind a certificate
  • Raw imagery, coordinates and sensor logs
  • Which buyer holds or retired which certificate
one proof
What the market sees
  • That the certificate was issued by a named issuer
  • The claim: source, region, scale, standard
  • That it was sold or redeemed
What leaves, and what stays

What changes when you can prove it without revealing it

The certificate carries the claim and a proof it was issued by someone entitled to issue it. Where a measurement backs the claim, the device signs what it captures and a verifier vouches for the record. The buyer checks the proof, not the books. Suppliers, volumes, coordinates and raw data never leave.

Where the work stands

Karbonity, a marketplace for renewable-energy certificates, and Pickers, a marketplace for recycling credits, both built with the Midnight Solutions Team; prototypes on Midnight preview. ZkyProof, designed in Midnight Build Club Cohort 1, does the same for aerial survey data: the public record is a card, everything else is shielded.

The technology underneath

Compact contracts on Midnight; shielded ownership with a public listing; a device-signed capture path with an attestation-gated verifier where measurement backs the claim.

If one of these is yours.

The first step is a conversation, and often a spec and a mockup for your case before anything is built.

edda logo
youtubetwittergithublinkedin
© 2026 Edda Labs · All rights reserved