Cryptographic commitments with scheduled release — a shadow ledger where the server holds nothing but ciphertext. The parties identify each other through the transaction; everyone else sees only a hash and a notarized timestamp. "Universal privacy" means exactly that: the platform is the least-informed participant by design.
The parties agree the deal off-platform (and identify each other in it). The vault turns those terms into a tamper-evident commitment: a hash you can cite, an encrypted envelope only the passphrase can open, and a scheduled release.
2 Commitment sealed
Commitment ID
Notarized. The server attests this hash existed at the time below — it never saw the terms (only ciphertext).
Vault ledger
No commitments yet. The scheduler below shows when each one opens for settlement.
3 Verify a commitment
Anyone can prove a terms document matches a commitment hash — tamper-evidence without revealing the document's other contents to the server.
Hashes don't match — the document differs from what was committed.
4 Open a commitment
Wrong passphrase or damaged envelope. The live server never knows either.