What the employer app lets you do
Fund a private balance
Bring USDC into your confidential balance with the test-USDC faucet, a CCTP bridge from another chain, or a deposit of classic USDC you already hold.
Manage contractors
Add people one at a time or by CSV, track who has registered, and keep pay rates in one searchable table.
Run confidential payroll
Select recipients and amounts, review the batch, and settle many private payouts in one run. Each amount is hidden on-chain.
Track, prove, and report
Follow payout history, issue per-cycle payslips, and produce a verifiable disclosure for an audit when you need one.
The end-to-end workflow
You use these screens in order the first time, and return to them each pay cycle.Fund your balance
Move USDC into your confidential balance so payroll has something to spend. Use the one-click test-USDC faucet, bridge from Base Sepolia over CCTP, or deposit classic USDC. See Fund your balance.
Add contractors
Add the people you pay and invite them to register. Each contractor connects a wallet and self-registers once so payouts can be encrypted to their viewing key. See Contractors.
Run payroll
Pick contractors and amounts, review the total against your available balance, and run. Your browser proves each payout privately, you approve each in your wallet, and Confiroll fee-bumps every settlement. See Run a payroll.
Track, prove, and report
Watch settlement in payout history, issue payslips for the cycle, and produce a compliance disclosure that proves an amount without exposing the rest.
Key things to know
You keep a private ledger
Amounts are hidden on-chain and Confiroll is blind to them, so the record of who received how much is your private ledger, kept encrypted on your side. On-chain confirms that a payout settled. Your ledger holds what.
You hold the disclosure key
The escrow key that can reveal a specific amount for an audit lives on your device, not on Confiroll. You can prove any payout, and Confiroll cannot read one.
One approval per payout
Each payout is a transfer you sign as the transaction source. A run of twelve payouts is twelve quick wallet approvals, sequenced for you by the run screen.
Only Ready contractors are payable
A contractor becomes payable once they connect a wallet and register their confidential account. Until then they show as Invited or Onboarding and stay out of runs.
Every action is 0 gas
Depositing, merging, and every payout are fee-sponsored. You sign, Confiroll fee-bumps, and your account pays 0 XLM even when it holds no XLM at all.
Confiroll is blind by design
Your balance is decrypted in your browser with your viewing key. The number never travels to a server, and Confiroll cannot move your funds.
Every employer screen
Dashboard
Your home screen: available balance, quick stats, recent activity, and the first-run checklist.
Contractors
Add and manage the people you pay, track registration status, and keep pay rates in one table.
Fund your balance
Faucet, CCTP bridge, and classic-USDC deposit, plus how available and pending balances work.
Run a payroll
The Select, Review, Run, Done wizard, with live per-payout progress and retries.
Payout history
Every run and payout, with status and explorer links for public settlement proof.
Payslips
Per-cycle documents, end-to-end encrypted to each contractor and anchored on-chain.
Compliance
Disclose a specific amount for an audit and export a verifiable proof.
Settings
Organization profile, keys, team and roles, defaults, network transparency, and notifications.
New here? Start with How it works for the model behind confidential payroll, then Getting started to sign in and reach this app.