Every stablecoin payment is public by default. Salaries, supplier prices, your runway. Sotto seals the amounts and lets you decide who reads them.
Private books.Public chain.
The business account for companies that pay in stablecoins. Every payment settles on Solana. Only the people you hand a key to can read the numbers.
September payroll
Sample data. Public view: anyone can verify the payments, nobody can read the amounts.
Solana switched native confidential transfers back on in June 2026. Sotto is the business account built on top of them.
A confidential payment is one Solana transaction in Solflare.Measured on Solana devnet, September 2026
A 24 person payroll run takes 3 wallet approvals.Measured on a local Solana validator with a test wallet, September 2026
Verifying a proof of funds onchain costs about 13,000 compute units.The Sotto program on Solana devnet, September 2026
No amount or memo reaches Sotto's servers in plaintext.Checked by an end to end test on every build
Same payments. Two worlds.
On the left, what any block explorer reveals about a company today. On the right, the same account on Sotto. Drag to compare.
One ledger. Four views.
Addresses stay public, so anyone can verify you paid. Amounts open only for the people you choose.
Every way a business moves money.
Payouts
Pay thousands of creators and contractors in one run. Competitors can't see who your stars are.
Payroll
Maya sees her pay. Nobody sees anyone else's.
Suppliers
Negotiated prices stay between you and your supplier.
Treasury
Your accountant sees the runway. The market doesn't.
Prove it. Without showing it.
Pick a statement and who it's for. A zero-knowledge proof checks it against your sealed balance. They learn yes or no. Nothing else.
appears here
Three steps. No new habits.
Confidential, not anonymous.
Every Sotto payment is three things at once. Hover to see which part is which.
The engine is an SDK.
Everything the Sotto app does is built on @sotto/sdk: payroll in chunks, a sealed record for each reader, proofs of funds. It is a preview and not published yet.
import { payPayrollLines } from "@sotto/sdk/confidential"; // Pay a run. Every amount is encrypted onchain.const outcome = await payPayrollLines({ rpc, wallet, version: 1, sourceToken, mint: wrappedUsdc, payments, // one per line buildChunk, // proofs made in the browser onSignature: save, // kept before each send});Questions, answered.
The short version of everything we get asked about privacy, payments and compliance.
No. Addresses stay public, so anyone can see who paid whom and when. Only the amounts are encrypted, using Solana's native confidential transfers, and memos never go onchain. Funds are never pooled with anyone else's.
You, and anyone you hand a viewing key to. A key covers every amount, one period or payroll only. Revoking stops access from then on; it cannot erase what was already viewed.
Today they connect a Solana wallet. Email claim is coming.
During the beta, Sotto runs on Solana devnet with devnet USDC, wrapped one to one by a test deployment of Solana's Token Wrap program. Mainnet assets are not decided yet.
Businesses are verified before an account opens, every recipient is screened before a payment, and auditors or regulators can be given read access. During the beta, screening uses a deny list. Sotto never takes custody of funds.
Sotto builds on Solana's confidential transfers and adds no new cryptography. Its own program only checks proofs and writes records: it holds no funds and cannot move tokens. It gets an external audit before public mainnet.