Security

Qietr ships under audit. No mainnet deploy without a clean review.

Audit status

In progress. At least one Anchor firm and one circuit specialist review before mainnet. Reports published here when complete.

Trusted setup

Current status (devnet): the live verifier uses a single-contributor development verifying key marked “do not deploy.” A trapdoor holder could forge proofs, so do not use with funds you can’t lose. A multi-party ceremony with published contributions replaces it before any mainnet launch.

The verifying-key upgrade path is gated by a 48-hour time-lock that thewithdraw instruction enforces against the on-chain verifying-key hash, providing notice and protection against an admin swapping the circuit.

Bug bounty

Terms publish after audits land. Disclosure: security@qietr.com.

Sanctions screening

The optional gasless relayer can screen a configured sanctions list at the relay layer (fail-closed: it refuses to start if the list can’t load). Screening applies only when you route through such a relayer; the shielded pool itself is permissionless and non-custodial, and direct (self-paid) withdrawals do not pass through any relayer.

User responsibilities