Aztec and Privacy
Oro uses Aztec because the protocol needs confidential ownership and privacy-preserving user actions around gold-backed value.
Privacy does not mean everything is invisible. A useful protocol must also expose enough public information to stay safe, auditable, and operable.
Oro aims to keep user activity confidential while keeping system-level safety visible.
Privacy map
| Area | Confidential | Public or operational |
|---|---|---|
| Gold exposure | ZGLD balances and transfers on Aztec | EVM-side bridge deposits and exits |
| Debt position | Private token movements used by position actions | Current CDP owner, collateral and debt accounting |
| ORO usage | ORO balances and transfers on Aztec | Global supply and protocol accounting where required |
| Bridge | User activity after value enters Aztec | Message commitments, bridge boundaries, and settlement events |
| Oracle | No user portfolio details | Gold price, update rounds, and freshness |
| Services | No user intent should be made public by default | Service health and availability signals |
What should be confidential
These user-level details are intended to stay confidential:
ZGLDbalances.ORObalances.- confidential transfers.
- token transfers used to deposit, mint, repay, or withdraw.
The current testnet does not yet provide fully private CDP positions. Position ownership, collateral and debt are stored in public contract state. Migrating position accounting to private notes is planned work and must not be treated as a current guarantee.
What is public or operational
Some information is public by design:
- EVM vault deposits and unlocks.
- bridge message commitments and consumption paths.
- global supply and backing constraints where needed.
- oracle prices, rounds, and freshness.
- risk parameters such as the minimum collateral ratio.
- pause state and role-governed actions.
- current CDP position ownership, collateral and debt.
- service health exposed by the backend.
This public layer is what allows the system to prove that collateral, messages, and supply rules are respected.
Practical privacy boundary
The clean mental model is:
Confidential today: ZGLD and ORO note balances and private token transfers.
Public today: CDP position accounting, system-level safety data, bridge boundaries, oracle freshness, and EVM-side settlement.
Users should also assume that timing, wallet connections, EVM deposits, service requests, and cross-chain amounts may create metadata that links activity across systems.