Private payroll is live on testnet.

See how

How it works

How Gloam compares

Privacy onchain splits into two jobs. Some apps share secrets between many people. A payment has one owner. Gloam does the second job, and that choice decides who can see your money.

Who holds a key
only you
Proofs made
on your device
Networks
Tempo · Robinhood Chain (testnet)
New cryptography
none, by design

Two jobs, two kinds of privacy

A sealed auction, a private order book or a lending pool has to work on many people's hidden data at once. Somebody has to do that work. So FHE networks like Zama and MPC networks like Arcium use a committee of nodes that hold the keys together.

A payment is different. It has one owner. The owner can prove the payment is valid on their own device with a zero-knowledge proof, and nobody else ever holds a key. That is the job Gloam does.

Who holds the key
ACommittee modelZama, Arcium, Tempo Zones. A committee or an operator holds the key, or sees inside.
BOwner modelGloam. Your device makes the proof. Nobody else holds a key, including us.

What a breach exposes

If a committee or an operator is breached, everyone who used it can be exposed, past payments included. If one owner's device is breached, one person is exposed. That is the whole argument for doing payments the owner way.

It also means Gloam never needs your secrets on a server. Proofs are made on your device, never on our servers.

Not new cryptography

Gloam does not invent new maths. It uses the zero-knowledge proofs of the Zcash lineage: notes, nullifiers, a Merkle tree and Groth16 proofs. Then it builds the payments product on top, the way Stripe built on card networks. What is new is the product layer. See what is new and what is not.

Side by side

"Not found" means we did not find it in their public docs as of October 2026. It does not mean it cannot be built.

ProductWho can see your paymentsIf they are hackedLive on Tempo or Robinhood ChainProve one fact to one personPrivate payrollAgent payments
GloamOnly youOne person is exposedYes, both testnetsYes, a proof for one reader that expiresYes, with a payroll total proofYes: x402, an MPP method, MCP
ZamaA 13-node committee shares one global keyEveryone, past data includedNot foundDecryption rights for a valueNot foundNot found
ArciumA node cluster, private while one node stays honestEveryone on that cluster, if every node fallsNot found (Solana)Not foundNot foundNot found
Tempo ZonesThe zone operator sees everything in the zoneEveryone in the zoneTempo, limited previewNot foundNot foundNot found
Helius PrivacyHelius's server receives the full secret inputs, amounts includedWhatever reached the serverNot found (Solana devnet)Not foundNot foundNot found
RailgunOnly youOne person is exposedNot found (Ethereum and L2s)Viewing keys that show your whole historyNot foundNot found

Gloam and each of them

Zama

Zama uses fully homomorphic encryption. Tokens stay encrypted and a coprocessor network computes on them. A 13-node key management committee shares one global key. Zama has raised over $170M, including a token sale.

Where they win: computing on shared data, like sealed auctions and lending. Where Gloam differs: a payment has one owner, so there is no committee and no global key.

Arcium

Arcium uses multi-party computation on Solana. Clusters of nodes compute on secret shares, and data stays private while at least one node in the cluster stays honest. Clusters are admitted by an authority.

Where they win: private shared state on Solana. Where Gloam differs: no cluster to trust, and it runs on Tempo and Robinhood Chain.

Tempo Zones

Zones are operator-run private chains on Tempo. The operator sees everything inside its zone, and deposits and withdrawals are public. Zones are in a limited preview.

Where they win: enterprises that want an operator in the loop. Where Gloam differs: self-custody with no operator, open to anyone a Zone does not serve.

Helius Privacy

Helius Privacy is on Solana devnet. Helius's server generates the proofs, so it receives the full secret inputs, amounts included.

Where they win: speed on weak phones, and reach on Solana. Where Gloam differs: proofs are made on your device, never on our servers.

Railgun

Railgun is the closest to Gloam in design: client-side zero-knowledge proofs, on Ethereum and L2s. It holds about $113M and charges 0.25% in and out. Its viewing keys show your whole history to whoever holds them.

Where they win: years live, a public multi-party ceremony, and external audits. Where Gloam differs: proofs for one reader that expire, payroll total proofs, agent payments, and Tempo and Robinhood Chain.

Others worth knowing

  • Payy ($6M seed) runs a private stablecoin wallet and a Visa card on its own ZK chain. Where they win: consumer users and a card today.
  • Cloak is a client-side ZK pool with payroll, on Solana.

The short version

We found no other product on Tempo or Robinhood Chain that combines owner-only privacy, proofs for one reader, and payroll and agent rails.

Where Gloam is behind

  • Testnet only. Proving keys come from a single-contributor dev ceremony. A multi-party ceremony comes before real money.
  • Internal audits only. Two rounds, with fixes deployed. An external audit comes before mainnet.
  • Small crowd. The testnet anonymity set is small, so treat unlinkability as weak for now.
  • Forwarded proofs. A reader can still pass a proof on. It will say who it was for and when it expired. A designated-verifier mode is next.
  • Rule changes. There is no admin withdraw, and rule changes are timelocked: the owner can swap verifiers only after a 3-day public delay.

The full list is on the production gate and in what stays private.