STANDARD

Privacy claims you can check.

PF-1 is an open disclosure standard — a privacy label that states what a protocol hides, from whom, under which assumptions, and what still leaks. It doesn't make anything more private; it makes privacy claims comparable and falsifiable.

Correction — 1 September 2026. This post originally illustrated the HIDDEN-C example with a 79-of-100 committee threshold. The deployed figure is 24-of-100 in production ceremonies; 79-of-100 remains the design target. Whitepaper §7.1 states both figures and the path between them. The text below has been updated; this note records what changed.

Every privacy protocol makes the same kind of claim: private, anonymous, confidential, untraceable. And every one of those words is doing a lot of unaccountable work, because privacy is the one property you can't verify by looking. If a chain is slow, you measure it. If it's expensive, you feel it. But if it says your data is hidden, you have no way to check — the whole point is that the data isn't there to inspect. That gap between the claim and anything you can test is exactly where marketing lives.

PF-1 is our attempt to close it. It's an open disclosure standard — a privacy label — that forces a protocol to state, in a fixed machine-readable format, what it actually protects: which data items are hidden, from which adversaries, under which assumptions, and, crucially, what still leaks. It doesn't make anything more private. It makes privacy claims comparable and falsifiable, which is a different and more useful thing.

Privacy you can't verify is indistinguishable from privacy you don't have.

01 /The distinction marketing erases

If PF-1 did only one thing, it would be this: force protocols to separate two claims that get sold as identical.

HIDDEN-U
Private, period

Hidden against unbounded operator collusion. Only cryptographic assumptions stand between an attacker and your data — even if every node colludes, they learn nothing.

HIDDEN-C
Private, conditionally

Hidden unless a named trust set colludes — a threshold committee, a TEE maker, an MPC quorum. The condition must be disclosed: the set, the threshold, rotation, detection.

"Private, period" and "private unless a threshold quorum of committee seats colludes" are different products at different risk levels. A user putting real money on-chain deserves to know which one they're buying — and today the marketing copy for both reads the same. PF-1 makes the difference show up in a single cell.

02 /An empty leakage section is a red flag

The second thing PF-1 forces is a mandatory, non-empty residual-leakage section. Every real system leaks something — transaction timing, a gas or fee tier, call targets, boundary amounts, metadata. A label that claims zero leakage isn't describing a perfect system; it's describing one whose authors either haven't looked or won't say. So PF-1 treats an empty residual section as prima facie evidence of non-conformance.

That inverts the usual incentive. Normally, admitting a weakness is a marketing cost, so nobody does it. Under PF-1, failing to admit one is the disqualifier — which makes honest disclosure the credible signal and turns "we leak nothing" from a selling point into a warning sign.

03 /Nutrition labels for privacy

The closest analogy is the nutrition label. It didn't make food healthier — it made food comparable and accountable. You can line two products up and see the difference, and a manufacturer can be held to what's printed on the box. PF-1 does that for privacy: a fixed set of data items (amount, balance, sender, recipient, outcome, call target, timing, boundary amounts, supply, self-access) against a fixed set of adversary columns, per tier, plus that non-empty residual section.

Two protocols with PF-1 labels can be compared cell by cell. A protocol that publishes one can be audited against its own claims. And because self-certification only goes so far, PF-1 is challengeable: anyone can dispute a cell, and a cell under unresolved challenge for more than 30 days is displayed as DISPUTED by aggregators. The standard assumes people will lie or err, and builds in a correction path.

04 /We go first — including the parts that don't flatter us

A standard nobody adopts is just a document. So Celar publishes its own PF-1 label — including its unflattering cells. Celar's confidential-state tier is strong: amounts, balances, and contract state are FHE-encrypted and hidden even from the validators executing the code. But the label marks call targets EXPOSED, timing EXPOSED, and boundary amounts EXPOSED, because in v1 they are.

Volunteering your weak cells in a fixed, checkable format is a costly, hard-to-fake signal — which is exactly why it's worth more to a serious user or auditor than any "fully private" banner. It reframes the category: instead of competing on adjectives, you compete on claims someone can falsify. The standard converts marketing into commitments, and the first commitment is ours.

05 /The honest caveat

PF-1 only matters if it's adopted and if challenges actually get raised. A standard that only Celar uses is a well-designed way to grade our own homework. Its real value shows up when a second and third protocol publish labels and the comparisons start to bite — which is why the standard is open (CC-BY), lives in a neutral public repo, and explicitly invites reference labels from ZK rollups, TEE networks, and mixers.

If you build a privacy protocol, we'd rather you publish a label that competes with ours than that nobody publishes one at all. Privacy you can't verify is indistinguishable from privacy you don't have — and PF-1 is a bet that the industry is ready to be held to claims it can be checked against.


CONTACT — press@celar.network · LIVE METRIC — celar.network/health · $CELAR