Business
Shielded payroll
Pay hundreds of employees or contractors from one private treasury in a single transaction. Each recipient can read only their own line.
Status: pre-launch. Noirpay is being built. This page describes the design as specified in the whitepaper; nothing on it is live on Robinhood Chain yet, and details can change before launch. See What's live today.
How a batch works
- Finance uploads or syncs the roster: handle, amount, memo, optional schedule.
- The batch is approved under the treasury's policy (caps, thresholds, co-signers).
- Noirpay builds one transaction that spends from the treasury's notes and mints one new note per recipient, each delivered to a fresh stealth address and encrypted to that recipient's key.
- The chain sees a single proof verified inside the pool. It does not see the number of recipients, any amount, or any identity.
- Each recipient's app decrypts their own note. They see their line; nobody sees anyone else's.
What each party sees
| Party | Sees |
|---|---|
| The chain | One transaction in the pool |
| An employee | Their own payment, with memo |
| Finance staff with a seat | The full batch, inside the app, under their role |
| The accountant | Whatever a viewing key scoped to payroll and a date range allows |
| A competitor with an explorer | Nothing |
Recurring payroll and retainers
A batch can be scheduled (weekly, fortnightly, monthly). Each run is a separate transaction from consolidated notes, so there is no repeating pattern on-chain (private recurring payments).
Milestones and escrow
For contractors paid per deliverable, fund a shielded escrow per milestone. Amount and counterparty stay hidden until release; release on both-party sign-off or a deadline.
Recipients outside Noirpay
A line can be paid to a plain Robinhood Chain address. That line is an unshield from the treasury: screened, and the recipient sees a withdrawal from the pool rather than from your company.