Skip to content

feat: prove approvals without exposing private audit data - #9

Merged
renezander030 merged 2 commits into
masterfrom
feat/zk-private-approval-receipts
Sep 6, 2026
Merged

renezander030 merged 2 commits into
masterfrom
feat/zk-private-approval-receipts

Conversation

@renezander030

Copy link
Copy Markdown
Owner

Value

A customer or auditor can verify that a direct human approval met quorum without receiving the customer payload, reviewer identity, workflow name, timestamp, or vote counts.

What ships

  • draftcat zk-receipt key-id|prove|verify
  • BN254/Groth16 circuit with only key and receipt commitments public
  • HMAC validation before proving; policy approvals, altered rows, and under-quorum rows are refused
  • pinned instance-key verification and circuit-ID binding
  • prominent beginner-facing README explanation plus full threat model
  • embedded development proving artifacts and regeneration command

Evidence

  • go test ./...
  • go vet ./...
  • end-to-end SQLite -> signed row -> 164-byte proof -> pinned-key verification
  • negative tests for policy approval, insufficient quorum, wrong key, hidden-field leakage, and tampered commitment
  • focused local proof: 29 ms on this machine

Review boundary

This is explicitly labeled an experimental preview. The checked-in Groth16 keys come from a single-party development setup and the circuit has not been independently audited. The docs require a multiparty ceremony or suitable transparent system plus an audit before production reliance.

@renezander030
renezander030 merged commit 9ad1d90 into master Sep 6, 2026
1 check passed
@renezander030
renezander030 deleted the feat/zk-private-approval-receipts branch September 6, 2026 03:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant