- What is it built on?
- The pool, entrypoint, verifiers and circuits are 0xbow's Privacy Pools, vendored unmodified apart from import paths. Those contracts and circuits were audited by Oxorio and Auditware (2025). The proving keys are the published outputs of the Privacy Pools trusted-setup ceremony (500+ contributors), pinned by hash. VeilSpeak's own board/router contract is not yet audited.
- Who can touch the funds?
- Only note owners (with a proof) and original depositors (exit). The Entrypoint is upgradeable by its owner, who can also change fees and stop new deposits; an upgrade could interfere with relayed withdrawals, so the owner key should be a multisig. Exits are paid by the pool directly to the depositor and cannot be blocked.
- Who approves deposits?
- VeilSpeak runs the association set provider. It can delay or refuse private withdrawal for a deposit, and publishes every decision with a content hash anchored on-chain. It cannot move funds: a refused deposit exits to its depositor.
- What if I lose my recovery phrase?
- Private withdrawals become impossible. The depositing wallet can still exit everything publicly.
- Is "token live" the same as "protocol live"?
- No. The token can trade on Pons before the pool opens. Deposits open only after contracts for that exact token are deployed, checked against the pinned ceremony keys and activated. The status above shows both.