Enygma Sovereign

Private, auditable settlement for banks and central banks

Rayls Enygma Sovereign settles payments privately between the Rayls Sovereign chains institutions run, built on the published Rayls design for central bank digital currencies (CBDCs). It is in production today, with read-only access for the designated regulator.

Banks, each on its own Rayls Sovereign chain
Bank A
Other banksCan’t see the transfer
Bank B
Rayls EnygmaChecks every transfer, sees no balances or counterparties
read-only view key
Regulator
Each bank runs its own Rayls Sovereign chain. A transfer goes from Bank A to Bank B through Rayls Enygma on a shared chain, which checks it is valid without seeing balances or counterparties. Other banks see nothing, and the designated regulator reads exactly what it supervises.
In production
in the Rayls Sovereign chains institutions run
408 ms
under half a second to generate the zero-knowledge proof for a transfer, per the Rayls II paper
Auditor View
read-only access for the designated regulator, scoped to what it supervises

The problem: A shared chain shows every bank’s book to every other bank

Central banks and commercial banks want the speed and simplicity of a shared chain for central bank digital currency (CBDC) and interbank settlement. But a transparent chain publishes every balance, payment and counterparty to every participant. Regulators need to see; competitors must not.

Most blockchains

A transparent chain

  • Every balance public
  • Every payment traceable
  • Counterparties exposed

Visible to every participant

Institutions

Regulated settlement

  • Confidential balances
  • Private counterparties
  • Regulator oversight

Cannot publish their book

A stand-off: banks and central banks want a shared chain for CBDC and interbank settlement, but cannot put their books on a chain every competitor can read.

The solution: Rayls Sovereign chains, settled privately with Enygma

Enygma Sovereign runs on Rayls Sovereign chains. Each bank keeps its clients on its own Rayls Sovereign chain, and between banks Enygma sends one sealed transaction to a shared chain, which checks it with a zero-knowledge proof (a mathematical proof that the transfer is valid, which reveals nothing else) before it settles.

Rayls Sovereign chain Bank A
ClientClient
Payments between its own clients stay on the bank’s own chain
Shared commit chain Administered by the central bank in a CBDC
  • Proof checked
  • Nothing spent twice
  • No money created from nothing
Payer, payee and amount sealed
Rayls Sovereign chain Bank B
ClientClient
Bank B credits its clients, then applies its own rules
RegulatorView key: reads transfers on the chain, can never move funds
  • Private between banks

    Payer, payee and amount are hidden from other banks and the public. Each transfer sits among a set of banks, so no one can tell who paid whom.

  • Verifiable by anyone

    Every transfer carries a zero-knowledge proof anyone can check, so no bank can spend the same money twice or create money from nothing.

  • Built for national scale

    Hundreds of millions of users can be grouped into about 400 Rayls Sovereign chains. Between banks, one transaction can pay several banks at once and carry many client payments inside it.

  • Compliant and sovereign

    The central bank issues the currency and administers the shared chain, each bank applies its own rules, and the regulator can hold a view key that opens every transfer but never moves funds.

Enygma Sovereign runs on Rayls Sovereign chains. Every bank in the network runs its own, and Enygma settles privately between them.

Explore Rayls Sovereign

Described in Rayls II: Fast, Private, and Compliant CBDCs, in production with one of the largest clearing houses in the world and being tested by a central bank in a CBDC pilot.

What institutions settle with Enygma

Interbank payments, CBDC distribution and delivery-versus-payment, each settled on a shared chain without exposing balances or counterparties.

Interbank

Interbank payments

Settle payments between banks on a shared chain without showing balances, amounts or counterparties to the other participants.

CBDC

CBDC distribution

Issue a central bank digital currency (CBDC) and distribute it through commercial banks, with every transfer private and the designated regulator able to audit its scope.

Settlement

Private delivery-versus-payment

Exchange a tokenised asset, such as a bond, for payment in one atomic settlement: both legs complete or neither does, and the price and parties stay confidential.

How Enygma Sovereign compares

Enygma Sovereign against the privacy approaches banks and central banks are weighing today, compared on what other participants can see, who can verify the chain and how a regulator gets access.

Scroll sideways to compare →

  Rayls Enygma SovereignZK privacy between Rayls Sovereign chains, with post-quantum auditor keys Canton NetworkNeed-to-know privacy across a network of Daml ledgers ZKsync PrividiumA private chain run by one operator, proven to Ethereum ZamaFully homomorphic encryption (FHE) for confidential contracts
Hides balances from other participants
Yes, held in commitments
Yes, each party sees only the contracts it is a stakeholder in
Yes, kept off-chain in the operator’s database
Yes, encrypted with FHE
Hides balances from the network operator
Yes, the shared chain holds only commitments: even the central bank that runs it cannot read balances without a view key
Partly: synchronizer operators see only encrypted messages, but the validator hosting a party stores that party’s data in the clear
No, the operator keeps the full state in its own database and sees every balance
Partly: coprocessors see only ciphertexts, but 9 of the 13 key-management nodes together can decrypt
Hides counterparties
Yes, inside an anonymity set of participants
Yes, non-stakeholders see neither payload nor metadata
From the public, but not from the operator
No, addresses stay visible
Every participant can verify every transfer
Yes, every node checks a zero-knowledge proof for each transfer
Each party validates only the parts it is a stakeholder in
Validity proofs are checked on Ethereum, for a chain one operator runs
FHE runs on off-chain coprocessors, checked by majority consensus
Who can see the data
Only the parties to a transfer, and the regulator within its scope
Only the stakeholders in each part of a transaction
The operator sees everything; others see what it permits
A threshold key-management network decrypts on request: 9 of its 13 nodes must cooperate
Regulator access
Scoped, read-only view key: one transaction, a time window or an account
Added as an observer on the contracts it audits
Selective disclosure of approved data through read-only endpoints
Per-value access rules set by each contract
Recorded data safe from a future quantum computer
Yes, post-quantum key agreement, with ML-KEM, the NIST post-quantum standard, for auditor keys
No, elliptic-curve encryption (ECIES) by default; post-quantum support is only a proposal
Data is not published on-chain; it stays in the operator’s database
Yes, lattice-based FHE, which Zama describes as post-quantum
Atomic delivery-versus-payment
Yes, native atomic swaps
Yes, multi-leg transactions settle atomically
Within one chain; across chains through ZKsync bridges
Can be built as contracts; no delivery-versus-payment primitive
EVM compatible
Yes, Rayls Sovereign chains and the shared chain both run the EVM
No, contracts are written in Daml; Zenith, a separate EVM layer, is still in testing
Yes, it is a ZKsync chain: Solidity contracts and Ethereum tooling
Yes, Solidity contracts on existing EVM chains
Proof system
Groth16 zero-knowledge proofs
No zero-knowledge proofs; stakeholders confirm their own views
Zero-knowledge validity proofs
TFHE, plus proofs of correct encryption

Terms used. ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism) is a post-quantum way for two parties to agree a secret key, standardised in 2024 by NIST, the US National Institute of Standards and Technology; it rests on lattice maths that quantum computers are not known to break. Daml is Canton’s smart-contract language, and a stakeholder is a party to a contract. A validity proof shows every state change followed the rules without revealing the data behind it. Fully homomorphic encryption (FHE) lets computers work on data while it stays encrypted. Threshold key management splits a decryption key across many nodes so no single one can use it. ECIES is a standard elliptic-curve encryption scheme, the kind of classical cryptography a large quantum computer could break. A Canton synchronizer orders and routes encrypted messages between nodes, and a validator is the node that hosts a party’s data. The EVM (Ethereum Virtual Machine) runs Ethereum-style smart contracts, so Solidity code and Ethereum tools work unchanged.

Enygma’s Groth16 proofs keep data private but are not yet quantum-secure against forgery; moving to a quantum-secure proof system is on its roadmap.

Based on each project’s own public documentation as of September 2026: Canton privacy model, Canton synchronizer, Canton cryptographic schemes, Canton post-quantum proposal, ZKsync Prividium overview, Zama Protocol litepaper and the Zenith announcement.

Cutting-edge research, published in the open

Enygma is designed in the open: presented at two leading academic security conferences, IEEE Security and Privacy and Financial Cryptography, free to read on the IACR Cryptology ePrint Archive (the open archive of the International Association for Cryptologic Research), and open source. Every paper describes a quantum-private design, in which payer, payee and amount stay hidden even from an adversary with a quantum computer.

  1. May 2024
    IEEE Symposium on Security and Privacy · poster

    Rayls: A Novel Design for CBDCs

    The design for central bank digital currencies (CBDCs) is first presented publicly at one of the flagship conferences in computer security.

  2. 2025
    CoDecFin (Coordination of Decentralized Finance) workshop at Financial Cryptography 2025 · ePrint 2025/1639

    Rayls: A Novel Design for CBDCs Quantum-private

    Yaksetig and Xu. Private, auditable transfers between institutions, hidden inside anonymity sets (groups of possible participants), with post-quantum key agreement so that a quantum adversary cannot learn payer, payee or amount.

  3. 2025
    Financial Cryptography in Rome 2025 · ePrint 2025/1638

    Rayls II: Fast, Private, and Compliant CBDCs Quantum-private

    Yaksetig, Pereira, Yang, Nejadgholi and Xu. The design behind Enygma Sovereign, with proof generation cut from about four seconds to 408 milliseconds (under half a second) on a Mac mini.

  4. Today
    Rayls documentation · open source

    ML-KEM replaces CSIDH

    Key exchange is how two parties agree a secret key. For auditor keys it now uses ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism), the post-quantum standard published in 2024 by NIST, the US National Institute of Standards and Technology, built on lattice maths that quantum computers are not known to break. It replaces CSIDH (Commutative Supersingular Isogeny Diffie–Hellman, pronounced “seaside”), an earlier, more experimental post-quantum method used in the papers. The proof circuits and smart contracts are open source.

Bring private, auditable settlement to your institution

Take twenty minutes with the team on your CBDC or settlement use case, or read how Enygma works in the docs.

Questions about Enygma

Is Enygma quantum-safe?

Enygma Sovereign is quantum-private by design: the Rayls papers describe a system in which even an adversary with a quantum computer cannot infer the payer, the payee or the amount. Key agreement, the step where two parties agree a secret key, is post-quantum. Auditor key exchange uses ML-KEM, short for Module-Lattice-Based Key-Encapsulation Mechanism: a way to agree a secret key that quantum computers are not known to break, standardised in 2024 by NIST, the US National Institute of Standards and Technology. The zero-knowledge proofs currently use Groth16, a widely used proof system, which keeps transactions private but is not yet quantum-secure against forgery; moving to a quantum-secure proof system is on the roadmap.

How do auditors and regulators get access?

Through Auditor View. A designated auditor, typically a financial regulator, holds a view key that decrypts full transaction data, scoped to an account or to a period of time, and individual transactions can also be disclosed one at a time. A view key reveals history, but it cannot move or freeze funds.

Where is Enygma live today?

Enygma Sovereign is in production in the Rayls Sovereign chains institutions run, and the Rayls papers report it in production with one of the largest clearing houses in the world.

Can I read the research and the code?

Yes. The design is published on the IACR Cryptology ePrint Archive as Rayls: A Novel Design for CBDCs and Rayls II: Fast, Private, and Compliant CBDCs, was presented as a poster at IEEE Security and Privacy 2024, and the implementation is open source on GitHub.