# Incognitee Docs

Welcome to the documentation of Incognitee, the privacy transaction hub built on the Integritee Network protocol.&#x20;

The wiki is divided into sections to cater to each of these different groups:

#### Why Incognitee? <a href="#why-incognitee" id="why-incognitee"></a>

Privacy matters, but we won’t get it. neither from credit cards nor from crypto - so far.

#### Want to get started? <a href="#want-to-get-started" id="want-to-get-started"></a>

* ​​[Get started](/2.-get-started/2.1-get-started-with-incognitee-live-net) with Incognitee Live Net
* ​​[Get started](/2.-get-started/2.2-get-started-with-incognitee-test-net) with Incognitee Test Net
* [Learn more](/2.-get-started/2.3-learn-more-about-incognitee) about Incognitee
* [Learn more ](/2.-get-started/2.4-learn-more-about-integritee)about Integritee

#### Want to integrate or build? <a href="#want-to-integrate-or-build" id="want-to-integrate-or-build"></a>

* ​[ Integration Guide ](/3.-want-to-integrate-or-build/3.1-integration-guide)- Tools, libraries, and resources to help you integrate.
* ​ [Build Guide](/3.-want-to-integrate-or-build/3.2-build-guide) - Overview on how to get started building your own Sidechain.

#### Want to join or support Incognitee? <a href="#want-to-join-or-support-incognitee" id="want-to-join-or-support-incognitee"></a>

* ​ [Become a Validateer](/4.-want-to-join-or-support-incognitee/4.1-become-a-validator) - Information about running a validateer node for Incognitee.
* ​ [Become a Nominator](/4.-want-to-join-or-support-incognitee/4.2-become-a-nominator) - Information how to nominate a Validator on Incognitee.
* ​ [Become a Partner](/4.-want-to-join-or-support-incognitee/4.3-become-a-partner) - Information how to collaborate with the Incognitee team.
* ​ [Become a Bug Hunter](/4.-want-to-join-or-support-incognitee/4.4-become-a-bug-hunter) - Information how to hunt for Incognitee bugs.
* &#x20;[Get TEERdays ](/4.-want-to-join-or-support-incognitee/4.5-get-teerdays)-  Information about what TEERdays are and how to earn them.

#### Technology <a href="#resources" id="resources"></a>

* ​ [Technology](#resources) - Information about the underlying tech, the concepts and architecture.&#x20;

#### Resources <a href="#resources" id="resources"></a>

* ​ [Community](/6.-resources/community) - List of community rooms and channels to talk to others about Incognitee and Integritee.

#### Roadmap <a href="#roadmap" id="roadmap"></a>

* ​ [Roadmap](/7.-roadmap) - See what we are planning for Incognitee


# Get Started

**Want to get started?**

* ​​[Get started](/2.-get-started/2.1-get-started-with-incognitee-live-net) with Incognitee Live Net
* ​​[Get started](/2.-get-started/2.2-get-started-with-incognitee-test-net) with Incognitee Test Net
* [Learn more](/2.-get-started/2.3-learn-more-about-incognitee) about Incognitee
* [Learn more ](/2.-get-started/2.4-learn-more-about-integritee)about Integritee


# Get started with Incognitee Live Net

### Incognitee on Integritee Network Wallet <a href="#incognitee-cli-tutorial" id="incognitee-cli-tutorial"></a>

The first beta version of Incognitee is now live on Integritee Network. \
Follow the link : <https://app.incognitee.io/>

Once you enter the website, you will see the Incognitee wallet, where you can connect your wallet from one of the providers mentioned.&#x20;

1. The first step is to connect your wallet.&#x20;

<figure><img src="https://3529530876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHGQkGlOxedyndchi5TU4%2Fuploads%2Fu4IWBdfgLe5V7JL05QJd%2Fimage.png?alt=media&amp;token=df52f1b7-94ff-41b5-883d-2897255fdfdc" alt=""><figcaption></figcaption></figure>

2. Once you are connected, you will see your wallet in the bottom left corner.&#x20;

<figure><img src="https://3529530876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHGQkGlOxedyndchi5TU4%2Fuploads%2F84EmiHXEDAyTQZ6Mp6Ol%2Fimage.png?alt=media&amp;token=ed38df9a-95fc-4a26-8c7f-bfcfc7a784aa" alt=""><figcaption></figcaption></figure>

3. You can now also close the pop-up screen and continue interacting with the wallet. Now you can also see on the top, that you are currently active on the Integritee Network. In the center of the screen, you can see your current public transferable balance. From here you can now either shield your balances to the private L2 or switch to your private balance.

<figure><img src="https://3529530876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHGQkGlOxedyndchi5TU4%2Fuploads%2FWo9DPsJPZ89pm6DEUQOg%2Fimage.png?alt=media&amp;token=30649be1-26d1-4d6e-88a9-d7d653456e21" alt=""><figcaption></figcaption></figure>

4. By selecting "Shield" you can now transfer your TEER to the private L2 layer.

<figure><img src="https://3529530876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHGQkGlOxedyndchi5TU4%2Fuploads%2FVWP5ikttWS3Ix41VspFk%2Fimage.png?alt=media&amp;token=d02f2257-4654-4309-936a-98ef85cd8f22" alt=""><figcaption></figcaption></figure>

5. Switching now to the private balance, you can either send or receive TEER tokens privately and instantly without leaving any trace on chain. Or you can unshield the TEER tokens anytime back to layer 1.

### Under the hood <a href="#under-the-hood" id="under-the-hood"></a>

**Check sidechain activity**

Visit the [Integritee Network explorer](https://polkadot.js.org/apps/?rpc=wss%3A%2F%2Fkusama.api.integritee.network#/explorer) where you can see events whenever sidechain blocks get finalized:

<figure><img src="https://3529530876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHGQkGlOxedyndchi5TU4%2Fuploads%2FPSB9BdLCHBbSGbK5c3Tb%2Fimage.png?alt=media&amp;token=f0b8965d-16e2-4962-a3a4-8291937e8d7b" alt=""><figcaption></figcaption></figure>

As privacy is our main feature, you can’t see much more here. The `BlockHeaderHash` helps you proving that you sent funds to someone. By default, recipients just observe a change in their balance but they have no clue where the funds come from unless you tell them and provide a merkle proof for the sidechain block inclusion of your transfer.

However, as shielding and unshielding events are publicly happening on Integritee, you can observe shielding/unshielding activity on the vault account on [subscan](https://integritee.subscan.io/account/2KBaZn1mvdp6oJbSWJ5ffRWmTZ44STuqgm8Zbau4oaLRKR1u?tab=transfer).

The balance of the vault account will always exactly match the total supply on the respective sidechain shard.

**What are shards and mrenclaves?**

Each instance of an Incognitee sidechain is identified by a *shard identifier* and we’ll need to tell the validators which shard we’d like to talk to. Think of it like the genesis hash of a L1 blockchain.

The `MRENCLAVE` identifies the validator code which is executed in Intel SGX enclave (it’s basically the hash of the enclave binary). Your call will only execute if the validator runs the code you expect it to run.

**Why should I trust validators?**

Because they can’t cheat and they can’t see your data. That’s what TEEs guarantee. But how should you know that the validators actually run the correct code in a TEE? You can authenticate validators thanks to Integritee’s remote attestation registry at [enclaves.integritee.network](https://enclaves.integritee.network).

There you can find the validator for this tutorial if you search for the url you’re using `wss://integritee-1.cluster.securitee.tech:2000` and it will tell you the verified MRENCLAVE which has been remotely attested using [our decentralized DCAP process](https://docs.integritee.network/4-development/4.5-attesteer).

### **Incognitee Portal**  <a href="#incognitee-portal" id="incognitee-portal"></a>

The portal has separate sections with privacy-supported features:&#x20;

* Wallet
* Vouchers
* Messages
* TEERdays

**Wallet:**\
\
In this section, you can select the asset you want to transfer. After connecting your wallet via the bottom left button “Connect Wallet”, you can start transferring assets from public Layer 1 to the confidential Layer 2.\
\
Actions that are available:\
\
**Shielding:**\
Shielding is the process of transferring an asset from an origin chain like TEER on Integritee to Incognitee, which is still public. Thereby your wallet is sending the amount to a vault on the source chain, and the same amount will be available on the same wallet address on Incognitee.\
\
**Private Transfer:**\
A private transfer, is a transfer between two Incognitee wallets which is done completely in private.

**Unshielding:**\
You can transfer your asset back from L2 to L1 anytime if you would like to continue on the transparent ledger.&#x20;

&#x20;


# Get started with Incognitee Test Net

## Incognite Paseo Test Wallet  <a href="#incognitee-cli-tutorial" id="incognitee-cli-tutorial"></a>

You can already test a simple version of the Incognitee Wallet on Paseo. \
\
Follow the link : <https://try.incognitee.io>

Once you enter the website, you will see the Incognitee wallet, which is already generating new wallet for you.&#x20;

1. The first step is to obtain free PAS tokens on Paseo via the button below in the window. There you should copy the address into your clipboard and go to the Paseo faucet. \ <br>

<figure><img src="https://3529530876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHGQkGlOxedyndchi5TU4%2Fuploads%2FxUNQyAWgJaTs6Fb7Skpd%2Fimage.png?alt=media&amp;token=56611337-515e-479f-8813-ac6ffab1ccb7" alt="" width="563"><figcaption></figcaption></figure>

2. Enter your copied wallet address in the faucet to get your first 100 free PAS. After this, you can close this window and return to the Incognitee web wallet.&#x20;

<figure><img src="https://3529530876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHGQkGlOxedyndchi5TU4%2Fuploads%2Fpe8eKDsUrS7x95g6kEE4%2Fimage.png?alt=media&amp;token=92591115-cc3d-4eae-acd6-94e5acd778b9" alt="" width="563"><figcaption></figcaption></figure>

3. You can now also close the pop-up screen and continue interacting with the wallet. Now you can also see on the top, that you are currently active on the only available test network Paseo with one available Token PAS.  \
   In the center of the screen, you can see your current public balance,  as you just retrieved 100 PAS from the faucet.  From here you can now either shield your balances to the private L2 or switch to your private balance.&#x20;

<figure><img src="https://3529530876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHGQkGlOxedyndchi5TU4%2Fuploads%2FhzOG9D8xUMIgZanUiR7j%2Fimage.png?alt=media&amp;token=0264fb03-1df5-4829-8a88-07fb73b2e574" alt="" width="563"><figcaption></figcaption></figure>

4. By selecting "Shield" you can now transfer your PAS to the private L2 layer.&#x20;

<figure><img src="https://3529530876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHGQkGlOxedyndchi5TU4%2Fuploads%2F198CeNspJN0uL0mXXlmU%2Fimage.png?alt=media&amp;token=c59b1576-08ad-4fa3-a2a5-f13786e94104" alt="" width="563"><figcaption></figcaption></figure>

5. Switching now to the private balance, you can either send or receive PAs tokens privately and instantly without leaving any trace on chain. Or you can unshield the PAS tokens back to layer 1.&#x20;

<figure><img src="https://3529530876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHGQkGlOxedyndchi5TU4%2Fuploads%2FMqPHzDPbra4Lpw2G8PtD%2Fimage.png?alt=media&amp;token=b2462039-9894-411c-b6e1-93b08264dc39" alt="" width="563"><figcaption></figcaption></figure>

## Under the hood

#### Check sidechain activity

Visit the [Integritee Network on Paseo explorer](https://polkadot.js.org/apps/?rpc=wss%3A%2F%2Fpaseo.api.integritee.network#/explorer) where you can see events whenever sidechain blocks get finalized:<br>

<figure><img src="https://hackmd.io/_uploads/rJsCT-uFT.png" alt=""><figcaption></figcaption></figure>

As privacy is our main feature, you can’t see much more here. The `BlockHeaderHash` helps you proving that you sent funds to someone. By default, recipients just observe a change in their balance but they have no clue where the funds come from unless you tell them and provide a merkle proof for the sidechain block inclusion of your transfer.

However, as shielding and unshielding events are publicly happening on Paseo, you can observe shielding/unshielding activity on the vault account on [subscan](https://paseo.subscan.io/account/5CBWPstfcW7dPYGdUG4kVDZSQq9Q9Ed65LT2Eu1inhJRoY8e?tab=transfer).

The balance of the vault account will always exactly match the total supply on the respective sidechain shard.

#### What are shards and mrenclaves?

Each instance of an Incognitee sidechain is identified by a *shard identifier* and we’ll need to tell the validators which shard we’d like to talk to. Think of it like the genesis hash of a L1 blockchain.

The `MRENCLAVE` identifies the validator code which is executed in Intel SGX enclave (it’s basically the hash of the enclave binary). Your call will only execute if the validator runs the code you expect it to run.

#### Why should I trust validators?

Because they can’t cheat and they can’t see your data. That’s what TEEs guarantee. But how should you know that the validators actually run the correct code in a TEE? You can authenticate validators thanks to Integritee’s remote attestation registry at [enclaves.integritee.network](https://enclaves.integritee.network/?rpc=wss%3A%2F%2Fpaseo.api.integritee.network).

There you can find the validator for this tutorial if you search for the url you’re using `wss://integritee-1.cluster.securitee.tech:2000` and it will tell you the verified MRENCLAVE which has been remotely attested using [our decentralized DCAP process](https://docs.integritee.network/4-development/4.5-attesteer).


# Learn more about Incognitee

Incognitee is a product based on an Integritee [L2 sidechain](https://docs.integritee.network/3-our-technology/3.1-software-development-kit/3.1.1-sidechains) and built with the [Integritee SDK](https://docs.integritee.network/4-development/4.4-sdk)  to conduct private transfers on substrate-based chains.

**L2 Sidechain:**

Sidechains are L2 blockchains connected to our public Integritee Network parachain (L1). Scalability is one of any blockchain projects' toughest challenges. Sidechains emerged to tackle that issue. Moreover, they provide confidential state and processing of transactions.

But how does it tackle the scalability problem, exactly? Transactions to different sidechains (or shards) can be processed in parallel leading to much higher throughput over the entire network. TEEs allow for a simplified consensus algorithm which yields very fast block times, leading to low transaction latency. Another benefit of TEE-based sidechains is the fact that they can provide a very high degree of privacy in executed business logic.

While [Polkadot ](https://polkadot.network/)itself already offers highly competitive scalability and flexibility compared to other L1 protocols, Integritee multiplies this potential on L2 and offers much lower latency. One other matter is Polkadot’s transparency: this feature might not be beneficial for everyone, especially if there is information one wants to keep confidential. Integritee’s sidechain allows a high degree of privacy. Performance is yet another issue. Although Polkadot is one of the fastest blockchains, some projects need even more. Responsiveness is key for many industries, such as gaming.<br>

**Direct Invocation**

With direct invocation, a requester chooses one of the sidechain validators to send her trusted call to over an encrypted channel. The validator produces a sidechain block, executing pending transactions. The block gets finalized on the Integritee parachain and the state diff is broadcast to the other validators, who simply apply the diff to their copy of the state. The sidechain validators produce blocks with a customizable block time T and broadcast them to the other validators. Should a validator fail to broadcast a block (or the block doesn’t reach the next validator) that validator is skipped after a timeout.

**Finality**

Sidechain blocks are produced asynchronously to layer one at a higher block rate. Despite the integrity guarantees provided by the TEEs, these blocks are not final because forks on the sidechain can happen. Every sidechain block hash is anchored to the layer-one blockchain and gets finalized on layer one along with the block that includes its anchoring extrinsic.

**Architecture of Incognitee**<br>

<figure><img src="https://lh7-us.googleusercontent.com/pPJf8fXrZ63hkG0eomfA0bEuLbe3CF8UqulkalTg7ccQfPa2fQc3jiqHqnybDao7yIanJlyW7BJrf8-TMKvlf0u95gGd7B6ej8pqe4Mc60AfelYV6eF6yLrAPNLuJQ46TN8VBCuyJUrBT9_kaD3Uzmgr70SeVz201ZviLvkHHzPd4PMD9WD8KIXzf9mLcg" alt=""><figcaption></figcaption></figure>

**Process:**\
\
Alice would like to transfer funds from her account to Bob's privately. She sends DOT tokens to the sidechain’s vault account. The sidechain's light client will subscribe to all transfers to its vault account and will endow the sender’s account with the amount received. Then, Alice can trigger all kinds of transactions on L2. In our example, she directly transfers tokens from her shielded account to Bob's. Bob can then trigger unshielded tokens to his L1 account. After this process, there is no way to directly link information on L1.

In order to gain practical unlinkability, one has to avoid the linkability of amounts or timing of the process. Mixers can be used to hide the exact time and amount of transfers. This means that the degree of privacy enhancement depends on the number of users that are simultaneously active on our sidechain. The more users sending similar amounts, the better the k-anonymity.&#x20;

Thanks to the Trusted Execution Environments (TEE) technology, not even the operators of the sidechain “validateers” can learn anything about L2 transactions on our sidechains. Validateers are validators operating our second-layer sidechains – the block production and validation happen inside TEEs. This means validateers can trust each other based on remote attestation and the consensus protocol is greatly simplified.<br>

In this example, the fees to be paid by the user are:&#x20;

1. Shielding fee \[DOT]: a percentage of the shielded amount plus the extrinsic fee on L1
2. Private-tx fee \[DOT]: a fixed fee
3. Unshielding fee \[DOT]: a fixed fee, enough to cover L1 extrinsic fees for unshielding plus markup

Fees to be paid by the sidechain validateers (mostly unrelated to user traffic) are:

1. Remote attestation fee \[TEER]
2. Sidechain block finality fee \[TEER] depending on block period


# Learn more about Integritee

Integritee is the fastest, most scalable and secure Web3 network bringing the vision of a trustless, decentralized future for all. You can find more about Integritee on their [website](https://www.integritee.network/) or their offical [docs](https://docs.integritee.network/).


# Want to integrate or build?

**Want to integrate or build?**

* ​[ Integration Guide ](/3.-want-to-integrate-or-build/3.1-integration-guide)- Tools, libraries, and resources to help you integrate.
* ​ [Build Guide](/3.-want-to-integrate-or-build/3.2-build-guide) - Overview on how to get started building your own Sidechain.


# Integration Guide

We invite wallet teams and dApp devs to integrate with Incognitee to enhance privacy for their users. This guide will help you get started.

## Rust API

Please check our [cli client code](https://github.com/integritee-network/worker/tree/master/cli) with many demo scripts to learn how to interact with the Incognitee API using Rust.

## Javascript API

The following sample code shows you how to perform the most common actions using the Incognitee API. The relevant library comes in typescript, so we encourage you to use typescript even if this example is js.

To run it, do:

```bash
nvm use 20
yarn add @encointer/worker-api
node index.js
```

index.js:

```javascript
// A simple sample code for common use cases of the Incognitee API

const {IntegriteeWorker} = require("@encointer/worker-api");
const {Keyring} = require("@polkadot/keyring");
const {cryptoWaitReady, mnemonicToMiniSecret} = require("@polkadot/util-crypto");
const {hexToU8a} = require("@polkadot/util");
const bs58 = require("bs58");

// Adjust these for the shard you'd like to use
const INCOGNITEE_SHARD = "5wePd1LYa5M49ghwgZXs55cepKbJKhj5xfzQGfPeMS7d";
const INCOGNITEE_URL = "wss://scv1.paseo.api.incognitee.io:443";

async function main() {

    // Initialize the Incognitee API
    const api = new IntegriteeWorker(INCOGNITEE_URL);

    // Wait for crypto to be ready
    await cryptoWaitReady();

    // PublicGetters need no signature, can be queried by anyone
    const info = await api.parentchainsInfoGetter(INCOGNITEE_SHARD).send();
    console.log("[PublicGetter] Parentchains Info:")
    console.log(info.toHuman());

    const localKeyring = new Keyring({type: "sr25519", ss58Format: 42});
    const account = localKeyring.addFromUri('//Alice', {
        name: 'Alice',
    });

    // Make sure Alice is funded or use your own account instead:
    // 1. visit app.incognitee.io/pas
    // 2. create test account
    // 3. shield PAS to incognitee
    // 4. copy seed from url and insert it below

    // const account = localKeyring.addFromSeed("<seed>");

    // If you want to shield without using our dApp at app.incognitee.io/pas
    const shard_vault = await api.getShardVault()
    console.log("Send PAS to this shard vault on L1 for shielding: " + shard_vault.toString());

    // querying balance needs authentication (privacy!)
    const getter = await api.accountInfoAndSessionProxiesGetter(account, INCOGNITEE_SHARD);

    const response = await getter.send();
    console.log("[TrustedGetter] Account's free balance: " + response.toHuman().account_info.data.free);
    // check if a session proxy has been defined previously
    console.log("[TrustedGetter] Previously defined session proxy?:");
    console.log(response.toHuman().session_proxies[0]);

    // transfer funds privately on L2
    const fingerprint_hex = await api.getFingerprint();
    const fingerprint = bs58.encode(hexToU8a(fingerprint_hex.toString()));
    console.log("[TrustedCall] using enclave fingerprint:" + fingerprint);

    await api.trustedBalanceTransfer(
        account,
        INCOGNITEE_SHARD,
        fingerprint,
        account.address,
        "5FHneW46xGXgs5mUiveU4sbTyGBzmstUspZC92UhjJM694ty",
        100000000,
        "hello world"
    )

    // send a message to someone
    await api.trustedSendNote(
        account,
        INCOGNITEE_SHARD,
        fingerprint,
        account.address,
        "5FHneW46xGXgs5mUiveU4sbTyGBzmstUspZC92UhjJM694ty",
        "Hi Bob"
    )

    // unshield funds to L1
    await api.balanceUnshieldFunds(
        account,
        INCOGNITEE_SHARD,
        fingerprint,
        account.address,
        "5FHneW46xGXgs5mUiveU4sbTyGBzmstUspZC92UhjJM694ty",
        100000000
    )

    // register a session proxy: let delegate sign on behalf of account, but only for non-transfer actions and queries
    const delegateMiniSecret = mnemonicToMiniSecret("secret forest ticket smooth wide mass parent reveal embark impose fiscal company");
    const delegate = localKeyring.addFromSeed(delegateMiniSecret);

    await api.trustedAddSessionProxy(
        account,
        INCOGNITEE_SHARD,
        fingerprint,
        api.createType('SessionProxyRole', 'NonTransfer'),
        delegate.address,
        null,
        delegateMiniSecret
    )

    // now we can query the account balance using the delegate
    const res = await api.getAccountInfo(
        account.address, // we only pass the address here. no need to know the secret
        INCOGNITEE_SHARD,
        {delegate: delegate} // the delegate account will be used for signing
    )
    console.log("Account's free balance fetched using session proxy: " + res.toHuman().data.free);

    // or we can fetch recent messages and tx history for the account
    // first we fetch note buckets info:
    const noteBucketsInfoGetter = await api.noteBucketsInfoGetter(INCOGNITEE_SHARD);
    const noteBuckets = await noteBucketsInfoGetter.send();
    const lastBucket = noteBuckets.toHuman().last.index
  
    // then we create a reusable getter which we can poll regularly to check for new messages
    const notesGetter = await api.notesForTrustedGetter(
        account.address,
        lastBucket,
        INCOGNITEE_SHARD,
        {delegate: delegate}
    )
    // send getter each time you want to poll for new messages
    const notes = await notesGetter.send();
    console.log("Messages and TX history for account:");
    for (const note of notes) {
        if (note.note.isSuccessfulTrustedCall) {
          const call = api.createType(
            "IntegriteeTrustedCall",
            note.note.asSuccessfulTrustedCall,
          );
          console.log("Call: ", call.toHuman());
        }
    }
    
    // bye bye
    api.closeWs()
}

main();
```


# Build Guide

Incognitee is built on the [Integritee Sidechain SDK](https://docs.integritee.network/4-development/4.4-sdk/4.4.1-sidechain-sdk) which allows you to implement any substrate runtime with pallets of your choice or your own making. This runtime will be executed within TEE enclaves, providing a secure and private execution environment for your use case.

Would you like to

* check the Incognitee [code on github](https://github.com/integritee-network/worker) and contribute to Incognitee or the Integritee SDK?
* fork your own sidechain project and implement your [own custom sidechain logic](https://docs.integritee.network/4-development/4.4-sdk/4.4.4-custom-business-logic-stf)?

Please visit the [Integritee SDK docs](https://docs.integritee.network/4-development/4.4-sdk/4.4.1-sidechain-sdk).


# Want to join or support Incognitee?

#### Want to join or support Incognitee? <a href="#want-to-join-or-support-incognitee" id="want-to-join-or-support-incognitee"></a>

* ​ [Become a Validateer](/4.-want-to-join-or-support-incognitee/4.1-become-a-validator) - Information about running a validateer node for Incognitee.
* ​ [Become a Delegator](/4.-want-to-join-or-support-incognitee/4.2-become-a-nominator) - Information how to delegate TEER to a Validator on Incognitee.
* ​ [Become a Partner](/4.-want-to-join-or-support-incognitee/4.3-become-a-partner) - Information how to collaborate with the Incognitee team.
* ​ [Become a Bug Hunter](/4.-want-to-join-or-support-incognitee/4.4-become-a-bug-hunter) - Information how to hunt for Incognitee bugs.
* [Get TEERdays ](/4.-want-to-join-or-support-incognitee/4.5-get-teerdays)-  Information about what TEERdays are and how to earn them.


# Become a Validator

A validator on Incognitee has to operate a Intel SGX machine in a trustworthy datacenter setup.

To be considered as a validator in Incognitee Mainnet, you have to get whitelisted via the on-chain Governance mechanism and previously beeing active in the Test Net.

Every validator will earn from transactions. Validators will receive a proportional amount of every transaction that is beeing validated by the network based on the amount of TEERdays it has, creating an opportunity for continual rewards in line with Incognitee’s activity.\
\
The number of Incognitee validators will be limited and set by onchain Governance.<br>

**Technical & Operational requirements:**

* Run a Intel SGX based machine in a datacenter
* Machines that we recommend: \
  `Dell PowerEdge R340 Server`, where the CPU **must be** an Intel(R) Xeon(R) E-2276G CPU @ 3.80 GHz.
* Remote Attestation should be always valid and up to date, check [here ](https://docs.integritee.network/4-development/4.5-attesteer)how to set it up. <br>

**Get whitelisted via the Integritee Network on-chain-Governance:**\
\ <mark style="background-color:orange;">Coming soon!</mark>\
\
\
**Get some TEER Token and earn TEERdays to increase validation commission:**

You have multiple options to obtain TEER tokens. Check out available venues [here](https://docs.integritee.network/2-integritee-network/2.4-teer-token/2.4.3-how-to-get-teer).\
\
Earn TEERdays [here](https://teerdays.incognitee.io/). \
\
**Revenue Calculation:**

Lets take a set of 5 Validators that have the following amount of TEERdays:\
\
Validator 1: 5'000 TEERdays\
Validator 2: 10'000 TEERdays\
Validator 3: 15'000 TEERdays\
Validator 4: 20'000 TEERdays\
Validator 5: 25'000 TEERdays\
\
Total amount: 75’000 TEERdays \
\
The overall revenue via transaction fees on Incognitee is lets say 1’000’000 USD per month .\
\
In this case the share of transaction fees would be as following:\
\
Validator 1: 5'000 / 75’000 \* 1’000’000 = 66’666 USD\
Validator 2: 10'000 / 75’000 \* 1’000’000 = 133’333 USD\
Validator 3: 15'000 / 75’000 \* 1’000’000 = 200’000 USD\
Validator 4: 20'000 / 75’000 \* 1’000’000 = 266’666 USD\
Validator 5: 25'000 / 75’000 \* 1’000’000 = 333’333 USD

Once Nomination becomes available, you can attract even more TEERdays via nomination that can add up to your total locked amount.\
\
If you want to express interest in becoming a validator and need some help along the process, we encourage you to reach out to the Integritee core team via <hello@integritee.network> .


# Become a Nominator

If you are a loyal TEER holder and you would like to let your TEER working for you, you should start earning TEERdays now by bonding TEER [here](https://teerdays.incognitee.io/) and join the Nominator Program <mark style="background-color:orange;">Coming soon!</mark> to nominate your TEERdays to an active Incognitee Validator to help securing Incognitee’s backbone.

As validators receive a share of the transaction fees generated by Incognitee, they can share them with TEER holders via Nomination.

If you want to express interest in becoming a nominator and want to be informed about the launch of the nominator program, we encourage you to reach out to the Integritee core team via <hello@integritee.network> or join Integritee Social Media channels for further announcements.


# Become a Partner

We are activly looking for partner in differnet segments like wallet provider, exchanges, vaildator operators, financial services companies and others.

If you want to express interest in becoming a Partner and learn more about the possiblilites to collaborate, we encourage you to reach out to the Integritee core team via <hello@integritee.network>.


# Become a Bug Hunter

If you are a professional bug hunter, you should check out our open bug bounties.&#x20;

You can read more about our active campaign in collaboration with Immunefi here:

<https://medium.com/integritee/bug-bounty-programs-how-outsourcing-can-help-your-project-644539de575a>\
\
or go directly to the Bug Bounty Portal: \
\
<https://immunefi.com/bug-bounty/integriteenetwork/information/>


# Get TEERdays

## **TEERdays: Profiting from Privacy**

What do TEERdays have to do with Incognitee? In the future, our privacy-enabling sidechain will be operated by multiple validators, who will, in turn, share the revenue generated by the solution itself.

This revenue share will be determined by the amount of TEERdays assigned to Incognitee. Although not everyone has the expertise to be a validator, all TEER holders can become nominators – they will be nominating their TEERdays to a validator to also be able to participate in the revenue share of Incognitee.\
\
TEERdays as a unit will be calculated on top of the bonded TEER to determine the final share.

## **What are the TEERdays?**

TEERdays aims to reward the most loyal TEER holders who get in the race first. We designed a mechanism where the ones who bond their TEER tokens earlier, get more rewards in the future. TEERdays are a unit that can be accumulated by token holders now by bonding their TEER for the launch of Incognitee – in a way, you’re buying your position in the game.

TEERdays are calculated by multiplying the amount of TEER by the number of days bonded. Example:

* 1 TEER bonded over 7 days would result in 7 TEERdays.
* 20 TEER bonded over 10 days would result in 200 TEERdays.

Your accumulated TEERdays will be used as a unit to determine your future revenue share of Incognitee. Let’s say Incognitee generates 100,000 USD a day. If the total number of all TEERdays is 100,000, and you accumulated 1,000 TEERdays, your eligible revenue share would be 100,000 USD x 1,000 TEERdays / 100,000 Total TEERdays = 1'000 USD. Your share would be 1'000 USD.\
\
Validator operators can additionally charge a commission from nominators, which will be a fraction of the nominated amounts for their efforts to operate hardware and contribute to the solution's decentralization and availability.

However, TEERdays isn’t just about determining your revenue share – it’s also about including our loyal community in the Incognitee governance system, which means that all the TEERdays participants will have a say in what happens within the project. Your TEERdays will be applied to the revenue share, but also to your governance voting power for important things regarding Incognitee. Using TEERdays for governance will also increase the security of Incognitee because it adds inertia to the electorate. A (potentially hostile) takeover by some whale jumping into the game at a later stage is much harder because money alone won’t buy TEERdays. Committed time is factored in as well, which gives weight to loyalty.

### **Important details**

* You can unbond your TEER within seven days (at a pro-rata) loss of a % of accumulated TEERdays if you partially unlock bonded funds ( e.g. 30% unbond will result in 30% loss of TEERdays). If you unbound all your TEER, you will lose 100 % of your TEERdays).
* During the unlock period, you're not accumulating TEERdays for the unbonded amount.
* TEERdays are non-transferable

### **Examples**

<figure><img src="https://3529530876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHGQkGlOxedyndchi5TU4%2Fuploads%2FHWrL08D9aAo0QoG82RrF%2Fimage.png?alt=media&amp;token=22883c92-e7ed-4342-8d66-52881595af7a" alt=""><figcaption></figcaption></figure>

&#x20;\
**Left:** Example how TEERdays accumulate and diminish based on bonding and unbonding TEER over time. \
\
**Right:** Bonding your TEER locks them and makes them non-transferrable. When you unlock, you’ll need to wait for 7 days before you can withdraw your TEER and make them transferrable again.

## **Why participate and collect TEERdays?** <a href="#why-participate-and-collect-teerdays" id="why-participate-and-collect-teerdays"></a>

TEERdays are the best way to both contribute to and earn rewards on Incognitee. Participating in this will allow you to be part of our network, and to have a say in important matters related to Integritee’s privacy sidechain.

TEERdays can be used to increase your revenue share for the launch of Incognitee on Polkadot/Kusama and will also increase your governance voting power for future decisions related to Incognitee. ​

## **How to participate**  <a href="#how-to-participate" id="how-to-participate"></a>

Go to the Incognitee TEERday page [here](https://app.incognitee.io/teerdays-lp/) and follow the steps:

1. First, you need to possess some TEER. Grab them at one of the avenues like [Kraken](https://www.kraken.com/prices/integritee?quote=usd\&interval=24h), [Gate](https://www.gate.io/de/trade/TEER_USDT) or [Basilisk](https://app.basilisk.cloud/trade?assetIn=1\&assetOut=17). ​
2. Download one of the supported wallets like Nova, Talisman, Subwallet or PolkadotJs and connect your wallet. ​
3. Transfer TEER to your wallet. ​
4. Bond your TEER [here](https://app.incognitee.io/teerdays-lp/).
5. Start automatically collecting TEERdays.
6. Refer a friend <mark style="background-color:orange;">Coming soon!</mark>.

### How to use Polkadot.js

1. Download [Polkadot.Js](https://polkadot.js.org/extension/). ​
2. Go to [TEERdays page](https://app.incognitee.io/teerdays-lp/) and click on "connect wallet"
3. Allow the app connection request with one of your wallets and click "connect account"
4. Select the wallet on the TEERdays page and enter an amount.&#x20;
5. Push the button "Bond" and sign with the extension.&#x20;

### How to use Talisman&#x20;

1. Download [Talisman](https://chromewebstore.google.com/detail/talisman-ethereum-and-pol/fijngjgcjhjmmpcmkeiomlglpeiijkld) . ​
2. Go to [TEERdays page](https://app.incognitee.io/teerdays-lp/) and click on "connect wallet"
3. Allow the app connection request with one of your wallets and click "connect account"
4. Select the wallet on the TEERdays page and enter an amount.&#x20;
5. Push the button "Bond" and sign with the extension.&#x20;

### How to use Subwallet

1. Download [Subwallet](https://chromewebstore.google.com/detail/subwallet-polkadot-wallet/onhogfjeacnfoofkfgppdlbmlmnplgbn) . ​
2. Go to [TEERdays page](https://app.incognitee.io/teerdays-lp/) and click on "connect wallet"
3. Allow the app connection request with one of your wallets and click "connect account"
4. Select the wallet on the TEERdays page and enter an amount.&#x20;
5. Push the button "Bond" and sign with the extension.&#x20;

### How to use Novawallet

1. Download [Nova Wallet](https://novawallet.io/). ​
2. Within the Nova mobile app, go to Browser and enter the TEERdays page Url: \
   <https://app.incognitee.io/teerdays-lp/>
3. Dismiss the Warning and click "Open anyway".
4. Click "connect wallet".
5. Allow the Integritee Dapp to access your account.&#x20;
6. Select the wallet and enter an amount.&#x20;
7. Push the button "Bond" and sign with the extension.&#x20;


# Technology

Incognitee is a sidechain technology leveraging the Integritee Network and Trusted Execution Environments. It builds on the [Integritee SDK](https://github.com/integritee-network/worker). In this chapter we will introduce the main concepts of Incognitee and how it works.


# Sidechain

Incognitee is a shardable sidechain validated by trusted execution environments. Each shard is a separate L2 connecting to exactly one L1 chain and its native token.

The following diagram shows the Incognitee shards which are currently live:

<figure><img src="https://3529530876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHGQkGlOxedyndchi5TU4%2Fuploads%2FxVYfJ8qo3dugAe3XAb6y%2Fincognitee-shard-overview.drawio%20(2).svg?alt=media&amp;token=ce8d899e-cb7f-45ef-bcea-55759d425ef9" alt=""><figcaption></figcaption></figure>

Multiple shards could be deployed on the same L1, enabling horizontal scalability.

The Integritee Network is necessary to get finality for sidechain blocks and to verify remote attestation of validateer TEEs.

The IncogniteeDOT shard also supports bridged assets from Ethereum mainnet like USDC, USDT

Learn more about Sidechain technology on [Integritee SDK docs](https://docs.integritee.network/3-our-technology/3.1-software-development-kit/3.1.1-sidechains)


# Private Token Transfers

Incognitee enhances your privacy while dealing with digital assets. But what does privacy mean and how does incognitee improve privacy?

First, let's explore why digital assets are generally **not** private. When dealing with crypto assets, your account is a pseudonym on a public ledger, much like a bank account number. Every single transaction this account does will be stored publicly forever and you have no right for deletion of the trace you left. If, at a certain point in time your pseudonym can be linked to your identity - i.e. because you send tokens to someone else - your entire behavioral history is revealed as is your balance.

Incognitee is a privacy-enhancing technology that allows you to shield your assets and transfer them privately. This means that you can send tokens to someone else without revealing your balance or transaction history. The recipient will not be able to see your balance or transaction history either. This is achieved by using a technology called [trusted execution environments (TEE)](https://docs.integritee.network/2-integritee-network/2.7-privacy-technology-trusted-execution-environments) . The TEEs we use are a hardware feature of server CPU's called *Intel SGX*. In addition, the [Integritee Network](https://docs.integritee.network/2-integritee-network) , a Polkadot parachain, performs independent, decentralized remote attestation of TEEs. Moreover, it gives finality to Incognitee sidechain blocks.

Incognitee is a layer 2 solution, maintaining a private ledger secured by TEE. All your transactions are confidential, only known to and the person your transacting with. Sender, recipient and amount are invisible to the public and even to the operators of Incognitee infrastructure.

For maximal privacy, we suggest to shield your assets to incognitee and from then on transact them on incognitee only. If you need to unshield back to L1, you can still benefit from k-anonymity: the public just sees that someone out of *k* individuals is the originator of an unshielding event. If *k* is large enough, you can plausibly deny it was you. You can influence the size of *k* by choosing popular amounts and timing.


# Private Vouchers

## Private Vouchers

Vouchers are a way to share tokens with friends who may not even have a wallet set up yet.

The Incognitee dApp lets you create unique links which you can share as vouchers, either as url or as QR code.

The recipient can open that link and immediately has access to the funds. A voucher is a temporary wallet only and everyone who knows the link can spend the funds. Therefore, we suggest to withdraw the funds to a secure wallet swiftly.

## How it works

The app creates a fresh keypair client-side and encodes the private key into the voucher link. The creator of the voucher funds it with a private transfer on Incognitee.

For convenience, all created vouchers are persisted in your browser storage until you delete them manually. Should the voucher get lost on the way to the recipient, you can recover it.

Notice that the dApp will store and show all vouchers you created on the same machine (with the same browser), irrespective of the account you used to fund it.


# Private Messaging

The Incognitee messenger has been designed with privacy by default. The unique features of this specialized messenger are:

* metadata-frugal: Thanks to its design, the amount of metadata which operators of validateers are able to collect is close to nothing. The operator does not learn *when* *who* *communicates* with *whom*.
* blockchain-addressing: Write e2e encrypted messages to blockchain wallet addresses
* auto-delete: Messages are automatically deleted after a certain time
* decentralized: The messenger is a decentralized application (dApp) running on the Incognitee sidechain which is operated by an unpermissioned set of validateers (restrictions apply during beta phase)
* private token transfers: As part of the Incognitee sidechain, the messenger can transfer tokens along with private messages.

## How it works

Incognitee sidechains host a ringbuffer of all messages up to a limited buffer size. The more messages are sent, the earlier the messages get purged from the buffer. This design allows us to solve multiple difficult challenges at once:

* data availability: As the message buffer is part of the sidechain state it has to be replicated by every validateer who wants to produce blocks and earn rewards.
* strong privacy: The entire message buffer fits the confidential enclave memory. This allows querying messages to self or sending messages to others without leaving any traces beyond the TLS connection you establish into the enclave.

should the messanger enjoy wide adoption, retention time may become impractically short. In that case the message buffer can be used as a short-time cache and users can pay extra for off-shard encrypted retention.

<figure><img src="https://3529530876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHGQkGlOxedyndchi5TU4%2Fuploads%2FcdJ0TtptMFqiZ2kD9qnW%2Fincognitee-docs-messaging.drawio.svg?alt=media&amp;token=2fd50924-0bf9-4b58-add5-38a6c254993c" alt=""><figcaption></figcaption></figure>

## Comparison

The landscape of messengers is vast and diverse. In order to show where we place the Incognitee messenger, we provide a few comparative comments to popular messengers:

* WhatsApp, Signal, Threema: centralized e2e encrypted messengers. They are metadata-rich as operators can collect when you communicate with whom, even if messages are (usually) e2e encrypted. With the exception of Threema you need a phone number to register.
* Telegram: Not private in any practical sense. Unencrypted by default. Centralized. Enables chat groups with large number of members
* [SimpleX](https://simplex.chat/): federated e2e encrypted messenger which generates minimal metadata. Very good choice for bilateral and small group chats. Doesn't support blockchain addressing or token transfers.
* [Bitmessage](https://en.wikipedia.org/wiki/Bitmessage) The OG in blockchain messaging. Also works as a ringbuffer for encrypted messages, but the buffer is public and leaks pseudonyms. For query privacy, users need to download the entire bitmessage chain which is not necessary for Incognitee.


# Session Proxies

Session proxies enable smooth UX even when Incognitee requires authentication for querying balances and messages.

For good security, we encourage users to protect their private keys in signer extensions for browsers or mobile wallets. These, however, come with a lot of user interaction if many actions require individual digital signatures.

Incognitee not only authenticates users when they want to perform state transitions (transactions, sending tokens or messages) but also when they query their balance or check incoming messages. This is necessary for privacy reasons.

To make the user experience smoother, we introduce the concept of session proxies.

## How it works

A session proxy is a keypair which is generated client-side and stored in Incognitee's sidechain state. Each session proxy has one of the following roles which defines what actions can be performed by the proxy on behalf of the owner without signer extension interaction:

* `ReadBalance`: Query the balance of the owner
* `ReadAny`: Query balance, messages and transaction history
* `NonTransfer`: Can send messages, but can't transfer tokens
* `Any`: Has full authority on behalf of the owner

These roles only apply to the Incognitee shard you register the session proxy on. They have no effect on other chains or shards.

As session proxies are stored on encrypted sidechain state, you can use them across devices and browsers. Just authenticate each new session with your owner account using the extension or mobile app and you can use the session proxy from then on.

## Why do I need to pay a deposit?

Your session proxy is stored on the Incognitee shard. Onchain storage is costly and we need to prevent state-bloat. Therefore, we ask for a tiny deposit for each session proxy you register (currently limited to one per owner account). Once you unregister the session proxy, the deposit is returned.


# Private Swaps

<mark style="background-color:orange;">Coming soon!</mark>

Whenever you use a centralized exchange (CEX), you trust them to operate a fair market and protect your data. Even worse, you hand over custody over your assets to them. The upside is: fast trading and something like privacy (in the best case your exposing your data and behavior to one entity only, not to the public)

If you need more autonomy, you may want to use decentralized exchanges (DEX). There, you keep custody over your assets and no single entity has the power to deny you access to the trading platform. However, this freedom comes with downsides: High latency and front-running

Incognitee can support shielding of various digital assets and offer automated market makers (AMM, similar to uniswap) on L2. This will prevent front-running because no one can see the transactions before they are executed. It also offers enhanced speed because of subsecond block times on Incognitee


# Private Voting

<mark style="background-color:orange;">Coming soon!</mark>

If you participate in OpenGov on Polkadot and Kusama or onchain governance on any of their parachains, you inevitably expose your voting preferences to the world. While your account can be a pseudonym, all your actions will be linkable and eventually reveal your identity. Knowing this will likely affect your voting behavior and promote conformity, obedience and submission. Vote privacy, on the other hand, rather promotes creativity, exploration and dissent.

Integritee will allow you to vote with enhanced privacy in web3 governance. This will enable you to vote freely and without fear of repercussions.

With great power comes great responsibility. For web3 governance to be legitimate, we need to strike a balance between privacy and accountability. Dominant voting power should never come with absolute privacy.


# Compliance

Balancing Privacy and Compliance

Incognitee is committed to privacy-by-default while ensuring compliance with regulatory requirements. Striking this balance remains largely uncharted territory in Web3. Opinions on this matter are highly polarized: some projects refuse to engage in anti-money laundering (AML) efforts entirely, while others introduce explicit backdoors for authorities. Integritee rejects both extremes.

The key requirement for compliance is enabling law enforcement to access specific data when there is a reasonable and legitimate suspicion of serious crime. While this is necessary for compliance in many jurisdictions, it is not always sufficient. Instead of conforming to traditional national models, we propose a novel approach and argue why nation-states should accept it:

**Law enforcement must have necessary tools in a functioning society, but mass surveillance must be avoided.**

Since blockchains do not inherently fit within national jurisdiction models, we must design a solution from first principles.

***Disclaimer**: This document does not constitute legal advice. The compliance measures outlined here are based on our current understanding and may not ultimately meet all regulatory requirements. Individuals and businesses must conduct their own research to determine whether they can legally use Incognitee in their respective jurisdictions.*

## Incognitee Compliance Requirements

To establish compliance, we first outline the key stakeholders and their requirements:

### Individuals

* Expect privacy by default
* Oppose mass surveillance by both state and private actors
* Want the freedom to use Incognitee for legitimate purposes without legal risks
* Require a maximum retention period for sensitive data ("right to be forgotten")

### Validateer Operators

* Seek the ability to operate nodes for profit without legal risk

### Law Enforcement Detectives

To investigate crimes, law enforcement may need:

* The ability to trace funds from an input (shielding) event to their destination

### AML Compliance Departments

Banks and exchanges must verify asset origins. They may require proof of beneficial ownership to determine:

* The source of funds for an output (unshielding) event

### National Governments

Governments may enforce sanctions on nations, individuals, or entities:

* Preventing specific jurisdictions from:
  * Using the service
  * Sending tokens to sanctioned entities

### Secondary Requirements

* **Preventing account poisoning:** Attackers must not be able to taint accounts by sending illicit funds
* **Selective disclosure:** Voluntary disclosure by one account holder must not compromise others; read keys must only reveal information about the disclosing subject

## Assumptions

To transition from an abstract framework to a practical implementation, we assume:

* Each Incognitee shard operates under a single jurisdiction (e.g., Switzerland)
* All validateers (nodes) within a shard are physically located in the jurisdiction
* A designated court represents the jurisdiction on-chain, acting via a multisig account or DAO

Different jurisdictions may impose distinct compliance requirements.

## Suggested Solutions

### Beta Stage: Limiting Shielding Amounts

A simple but effective AML measure is capping the value of shielded transactions. Until more sophisticated compliance mechanisms are in place, this will serve as an initial deterrent.

* Small transaction limits discourage money launderers and sanctioned entities
* Even with sybil attacks, large amounts cannot achieve meaningful k-anonymity

### Beta Stage: KYB (Know Your Business)

To accommodate businesses requiring higher shielding limits, Integritee, as the operator of Incognitee in its beta stage, can provide whitelisting subject to KYB verification.

### Enforced Selective Disclosure and Freezing

#### Immutable Event Log with Per-Account Encryption

* Validateers log each financial transaction as encrypted ciphertext in a public and tamper-resistant event log (e.g. [EventStore](https://www.eventstore.com/))
* Each account has a unique symmetric log key stored securely within Incognitee
* Only account holders can decrypt their transaction history
* Courts, authorized by their jurisdiction and authorized on an Incognitee shard, may grant law enforcement access to an account’s log key when legally justified

#### Voluntary Disclosure (Proof-of-Innocence)

Users can provide proof-of-origin to AML compliance departments without revealing unnecessary details:

* By generating read-keys, users can trace funds back to shielding events
* Zero-knowledge proofs (ZKPs) ensure only relevant transaction links are disclosed, preserving privacy of behavioral details which are not relevant for AML

#### Handling Sanctions

Sanctions can be enforced through:

* **Blacklist mechanisms:** Validateers can block attempts to shield funds from sanctioned addresses
* **Account freezing:** Courts may be authorized to freeze Incognitee accounts

#### Mitigating Backdoor Risks

To prevent courts from abusing their authority (e.g., mass freezes or universal disclosure):

* Court actions are **rate-limited** (e.g., limited interventions per day)
* Court interventions are logged transparently and published by validateers

## Secure Event Logging and Data Retention

To prevent account poisoning and excessive data exposure:

* A **quarantine mechanism** ensures receivers actively accept incoming transactions
* Logs are encrypted per account and only accessible to the respective owner (unless legally disclosed by the court)
* Log retention is jurisdiction-dependent, after which:
  * Log-keys are rotated at fixed intervals
  * Deleting an encryption key equates to deleting the log content

<figure><img src="https://3529530876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHGQkGlOxedyndchi5TU4%2Fuploads%2F6q8YDEjmOvC8P4bOdgIq%2FELIAS-eventlog.drawio.svg?alt=media&amp;token=ed0566af-23a2-413e-86ff-e45c1621c838" alt=""><figcaption><p>Event Log with per-account encryption, enabling selective disclosure of transaction history</p></figcaption></figure>

## Cryptographic Considerations

To ensure security and efficiency:

* The symmetric encryption algorithm must be **quantum-safe** and **ZK-friendly**
* Potential candidates include:
  * [Poseidon](https://www.poseidon-hash.info/)
  * [Rescue Prime](https://eprint.iacr.org/2020/1143)
  * [MiMC](https://eprint.iacr.org/2016/492)

This approach balances privacy and compliance while maintaining decentralization and user control. By leveraging cryptographic techniques and trusted execution environments, Incognitee ensures lawful oversight without enabling mass surveillance.


# Resources

Community


# Community

Check out the Incognitee and Integritee community list via [Community Info & Links](https://docs.integritee.network/6-misc/6.3-community-info-and-links) .


# Roadmap

**Stage 1: Prototype of Sidechain on Paseo with simple front-end support** ✅\
At this stage, we created a functional sidechain running on Paseo which supported a narrow use case to run a public user testing campaign with a specific action flow. A simple web campaign page as UI supported the actions performed by end users. On Paseo, we can already demonstrate the ability to do transfers on L2 fully private.

**Stage 2: Fully functional Sidechain deployed on Paseo with a nice UI** ✅\
At this stage, we were able to demonstrate a fully functional sidechain running on Paseo with a nice UI to perform all the actions necessary to do transfers and check account balances with authentication.

**Stage 3: Test Emergency Interventions on Paseo** ✅\
We ran different emergency scenarios on Paseo to show that recovery is possible and working as designed. Among the scenarios, we put the shard into maintenance mode (temporarily pausing state transitions) and shard retirement (force-unshielding all balances back to L1).

**Stage 4: Battle-Test the Basics on Integritee Network** ✅\
The first productive incarnation is a functional privacy-preserving sidechain for transactions of TEER tokens only. Moreover, at this stage, we will only allow shielding of limited amounts. This is a precaution in the beta phase against both potential loss and legal issues. Limits are set high enough to endow accounts and be active, but low enough to hinder money laundering.

**Stage 5: Beta Release on Polkadot  Assethub** ✅\
After successful operations on the Integritee Network, we will deploy Incognitee on Polkadot Asset Hub. This will enable not only the support for DOT and also for other Parachain tokens on Assethub.

**Stage 6: API Integration ✅**\
Our sidechain API can be already used to integrate with other dapps in the ecosystem.\
The integration guide can be found in our [docs](https://docs.incognitee.io/3.-want-to-integrate-or-build/3.1-integration-guide) for interested teams.&#x20;

**Stage 7: Sidechain Governance, Nomination, and External Validateers ⏳**\
We will soon introduce a Sidechain Governance mechanism that will allow a decentralized governance of several Incognitee sidechains independently from Integritee Network. Additionally, we will open up the permissionless operation of TEE-based Validateers for Incognitee sidechains with nominations from token holders. This will allow the distribution of Incognitee fees collected from operations in a decentralized way.

**Stage 8: Security Audit 🏳️**\
Our implementation will be audited by a specialized and independent team before lowering the limitations of the beta version.

## Future Stages 🏳️ <a href="#bd06" id="bd06"></a>

**Remove Limitations and add new features**\
Finally, we will remove certain limitations and add other features like private voting on Polkadot and Kusama and private token swaps.

**API Integration**\
At this point, our sidechain API will be compatible with js/api json-rpc, and integrate well with established wallets. This may involve upstreaming our authentication procedure for queries, so we will be looking for collaborations with wallet teams to make private transactions as smooth as can be.

**Release for other ecosystems**\
We are planning to expand to other ecosystems and offer the Incognitee solution to a broader user base.

**Enabling Law Enforcement Access**\
We shall allow law enforcement to request selective disclosure of certain data concerning certain accounts. A governance process needs to be specified to ensure due auditing.

**Snowbridge integration**\
We already leverage Snowbridge to bridge over assets from Ethereum like ETH, USDC, USDT and WBTC. But we want to improve the user experience and therefor directly integrate the bridging process  into Incognitee via API.&#x20;

**AI private inference & payment**

A new feature should allow Polkadot users to use AI services like ChatGPT or other LLMs with private crypto payments to overcome linkability between service usage and payment for the service in a first phase. In a second phase we would even extend this to offer private Inference.\
\
**AI Agents private payments**\
Our cutting-edge technology is uniquely designed to serve as the foundation for private transactions between AI agents, ensuring a decentralized, highly secure, and completely private payment infrastructure.

\ <br>


