{"id":51834981,"url":"https://github.com/anukulpandey/veilpay","last_synced_at":"2026-07-22T20:01:29.740Z","repository":{"id":371909413,"uuid":"1304179255","full_name":"anukulpandey/veilpay","owner":"anukulpandey","description":"🔏 Confidential payroll on Avalanche eERC — zk-SNARK encrypted salaries, on-chain encrypted payslips, auditor-ready compliance. Live on Fuji.","archived":false,"fork":false,"pushed_at":"2026-07-17T17:38:27.000Z","size":48938,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-07-17T18:23:00.073Z","etag":null,"topics":["avalanche","eerc","hackathon","payroll","privacy","zk-snarks"],"latest_commit_sha":null,"homepage":null,"language":"Circom","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/anukulpandey.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-07-17T16:21:20.000Z","updated_at":"2026-07-17T17:38:32.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/anukulpandey/veilpay","commit_stats":null,"previous_names":["anukulpandey/veilpay"],"tags_count":null,"template":false,"template_full_name":null,"purl":"pkg:github/anukulpandey/veilpay","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/anukulpandey%2Fveilpay","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/anukulpandey%2Fveilpay/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/anukulpandey%2Fveilpay/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/anukulpandey%2Fveilpay/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/anukulpandey","download_url":"https://codeload.github.com/anukulpandey/veilpay/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/anukulpandey%2Fveilpay/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35775334,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-07-20T02:08:10.276Z","status":"online","status_checked_at":"2026-07-22T02:00:06.236Z","response_time":124,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["avalanche","eerc","hackathon","payroll","privacy","zk-snarks"],"created_at":"2026-07-22T20:01:27.507Z","updated_at":"2026-07-22T20:01:29.730Z","avatar_url":"https://github.com/anukulpandey.png","language":"Circom","funding_links":[],"categories":[],"sub_categories":[],"readme":"# 🔏 VeilPay — Confidential Payroll on Avalanche\n\n\u003e **Payroll on-chain, salaries invisible.** VeilPay pays teams in an encrypted\n\u003e stablecoin using Avalanche's **eERC (Encrypted ERC)** standard. Salary amounts\n\u003e are sealed with zk-SNARKs + ElGamal homomorphic encryption — yet a designated,\n\u003e **rotatable auditor key** can decrypt everything for compliance.\n\u003e Private for the world. Provable for the regulator.\n\nBuilt for the **Team1 India Speedrun — Privacy on Avalanche** (July 2026).\n\n**🌐 Live product: [veilpay.notcool.in](https://veilpay.notcool.in)** — landing page,\n[docs](https://veilpay.notcool.in/#/docs), and the [app](https://veilpay.notcool.in/#/app)\nwith one-click demo roles on Fuji (no wallet needed).\n\n---\n\n## The problem\n\nCompanies want to run payroll on-chain (instant, borderless, programmable), but a\nnormal ERC-20 `transfer(alice, 2500e6)` publishes **everyone's salary, forever**.\nThat single leak kills the entire use case: no real company can pay employees\nwhere each colleague, competitor, and ex-partner can read comp on Snowtrace.\n\nPure privacy coins solve the leak but create the opposite problem: **regulators\nand auditors get nothing**, which is a non-starter for any Indian (or global)\nbusiness that files taxes.\n\n## The solution\n\nVeilPay uses **eERC converter mode** to wrap a stablecoin into `eUSDC`:\n\n| | Normal ERC-20 payroll | Mixer-style privacy | **VeilPay (eERC)** |\n|---|---|---|---|\n| Amounts hidden | ❌ | ✅ | ✅ (ElGamal + zk-SNARK) |\n| Auditor can decrypt | n/a | ❌ | ✅ (rotatable auditor key) |\n| Self-custody balances | ✅ | ⚠️ | ✅ (no relayers, no mixers) |\n| Payslips | off-chain | ❌ | ✅ **encrypted, on-chain, in the payment tx** |\n\n### What a payroll run looks like\n\n1. **Employer** shields treasury: `50,000 mUSDC → eUSDC` (one deposit).\n2. **Run payroll**: for each employee the browser generates a **Groth16 transfer\n   proof**; the amount is encrypted **three ways** in one transaction —\n   ElGamal for sender + receiver balances, Poseidon for the employee's history,\n   Poseidon for the **auditor**. An **encrypted payslip** (org, period, gross)\n   rides along as encrypted metadata in the same tx.\n3. **Employee** decrypts their balance + payslips locally (key derived from one\n   wallet signature — no new seed phrase), and can withdraw back to plain mUSDC.\n4. **Auditor** decrypts every amount from the `AuditorPCT` ciphertexts across\n   the full chain history and exports a CSV compliance report — **without any\n   employee's cooperation and without seeing anyone's keys**.\n\n## Architecture\n\n```\n┌──────────────────────────── Browser (React + wagmi) ───────────────────────────┐\n│  Employer view        Employee view        Auditor view                        │\n│  roster / run payroll  balance + payslips  full-history decrypt + CSV          │\n│        │                    │                    │                             │\n│  @avalabs/eerc-sdk (snarkjs Groth16 proving, wasm/zkey self-hosted)            │\n│  + custom PCT/metadata decryption (@zk-kit) — no 1000-block audit window       │\n└───────┬───────────────────────┬─────────────────────┬──────────────────────────┘\n        │ zk proofs             │ reads               │ log scans\n┌───────▼───────────────────────▼─────────────────────▼──────────────────────────┐\n│                        Avalanche Fuji C-Chain                                   │\n│  Registrar ── EncryptedERC (converter mode) ── 5 Groth16 verifiers (prod set)   │\n│                   │            │                                                │\n│            SimpleERC20     PayrollManager                                       │\n│            (mock USDC)     (orgs / rosters / run log — never sees amounts)      │\n└─────────────────────────────────────────────────────────────────────────────────┘\n```\n\n**Contracts** are the audited [ava-labs/EncryptedERC](https://github.com/ava-labs/EncryptedERC)\nprotocol (Registrar, EncryptedERC converter, production trusted-setup verifiers)\nplus one thin addition:\n\n- [`PayrollManager.sol`](contracts/contracts/payroll/PayrollManager.sol) — org \u0026\n  roster registry and payroll-run log. **Salaries never touch this contract**;\n  they exist only as eERC ciphertexts. It records the public facts (who works\n  where, when a run happened) and nothing else.\n\n### Deep-tech highlights (what we're proud of)\n\n- **Real Groth16 proofs in the browser** for register / transfer / withdraw,\n  against the repo's production trusted-setup artifacts (we verified the\n  `contracts/prod` verifiers match the shipped zkeys before deploying).\n- **Encrypted on-chain payslips**: eERC's encrypted-metadata channel\n  (`transfer(..., bytes message)`) carries a Poseidon-ECDH-encrypted payslip in\n  the salary transaction itself. The employee's browser decrypts it locally.\n- **Signature-derived keys**: one `personal_sign` deterministically derives the\n  BabyJubJub key pair (SDK-compatible grindKey → Blake512 pruning). Same wallet,\n  same key, any device — reproduced bit-for-bit in our Node tooling\n  ([`eerc-client.ts`](contracts/scripts/lib/eerc-client.ts)) so deploy scripts,\n  e2e tests, and the browser all interoperate.\n- **Full-history auditor console**: we re-implemented PCT decryption client-side\n  (`mulPointEscalar(authKey, scalar)` + Poseidon decrypt via @zk-kit) so the\n  auditor scans from deployment block with no window limits, survives **auditor\n  key rotation** (we rotate the auditor to a fresh key post-deploy), and exports\n  CSV for filings.\n- **One-click demo roles**: a custom wagmi connector wraps viem local accounts\n  as EIP-1193 providers — judges can switch Employer → Alice → Bob → Auditor\n  instantly, no wallet extension required.\n\n## Live on Avalanche Fuji (chain 43113)\n\n| Contract | Address |\n|---|---|\n| EncryptedERC (converter) | [`0xCB9aB1F20d1d5Cf990694e60470FB28B23041D1b`](https://testnet.snowtrace.io/address/0xCB9aB1F20d1d5Cf990694e60470FB28B23041D1b) |\n| Registrar | `0x91Ee29CF99EC38f5fe35FB00480cc2240845E6c8` |\n| PayrollManager | `0x515bA9A35A496FC3FC5595c8A06C1343Da26a763` |\n| Mock USDC (open mint) | `0x55b14Cf06F3E4856EaC195D682d738DD279D63f5` |\n| Transfer verifier (prod set) | `0x1F1416F0F2b0E2eD3370A0230492601B08d3E125` |\n\nFull manifest: [`contracts/deployments/fuji.json`](contracts/deployments/fuji.json).\nSample **encrypted payroll transactions** (amounts are ciphertext — try to find the salary):\n[`0xa894…9994`](https://testnet.snowtrace.io/tx/0xa8947a8be30a166def3b625557a2aeded3f479588a84467474f8b0964f6d9994)\n*(Alice, gross 2,500.00 — only she and the auditor can know that)* and\n[`0xac99…d31f`](https://testnet.snowtrace.io/tx/0xac99f555228fa7debf2978b53e0d1facc4ee2b2481d2adf7e7d998f1848cd31f)\n*(Bob)* — demo identities in `contracts/deployments/fuji-demo.json`.\n\n- **E2E proof of the whole flow** (local): `contracts/scripts/e2e-local.ts` —\n  registers 4 users, shields 50k, runs encrypted payroll, decrypts payslips,\n  withdraws, audits. Every step asserted.\n\n## Run it yourself\n\n```bash\n# 0. Node \u003e= 22\n# 1. Contracts\ncd contracts\nnpm install --ignore-scripts      # prebuilt circuits + verifiers ship in-repo\nnpx hardhat compile\n\n# 2. Local end-to-end (fresh terminal: npx hardhat node)\nnpx hardhat run scripts/deploy.ts    --network localhost\nnpx hardhat run scripts/e2e-local.ts --network localhost   # full payroll story, asserted\n\n# 3. Fuji\necho \"PRIVATE_KEY=\u003cfunded key, no 0x\u003e\" \u003e .env\nnpx hardhat run scripts/deploy.ts    --network fuji\nnpx hardhat run scripts/fund-demo.ts --network fuji        # demo roles + auditor rotation\n\n# 4. Frontend\ncd ../web\nnpm install\nnpm run sync                      # pulls addresses + ABIs from contracts\nnpm run dev                       # http://localhost:5173\n```\n\n## Judging criteria mapping\n\n- **Value proposition**: payroll is the on-chain use case blocked *only* by\n  privacy; VeilPay unblocks it while staying auditor-friendly (the version of\n  privacy a real business can adopt).\n- **Technical complexity**: browser-side Groth16 proving, three-layer amount\n  encryption, encrypted metadata payslips, SDK-compatible key derivation\n  reimplemented server-side, full-history auditor decryption with key rotation.\n- **Avalanche usage**: eERC standard (converter mode) + official\n  `@avalabs/eerc-sdk` + production verifier set, deployed on Fuji C-Chain;\n  PayrollManager composes with, not around, the standard.\n\n## Repo layout\n\n```\ncontracts/   ava-labs/EncryptedERC + PayrollManager + deploy/e2e tooling\nweb/         React + wagmi + @avalabs/eerc-sdk frontend (3 role views)\ndeck/        pitch slides\n```\n\n## Security notes\n\n- eERC contracts/circuits: audited upstream (Circom + Gnark audits, 2025).\n- Demo private keys in the frontend are throwaway testnet identities, by design.\n- `PayrollManager` stores employer-chosen display labels; use pseudonyms if the\n  roster itself is sensitive (a production version would encrypt labels to the\n  org members' keys — the eERC metadata channel already supports this).\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fanukulpandey%2Fveilpay","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fanukulpandey%2Fveilpay","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fanukulpandey%2Fveilpay/lists"}