Evidence-gated working capital for physical trade finance.
A financier locks USDG in a shipment-specific escrow facility. Tranches release only when multi-source sensor evidence satisfies an on-chain policy. An anomaly pauses the facility, a context-bound zero-knowledge proof of secondary evidence resumes it, and the buyer's invoice payment settles through a fixed waterfall.
PHYSICAL REALITY → CRYPTOGRAPHIC EVIDENCE → EVIDENCE CONFIDENCE → FINANCIAL RISK → AVAILABLE CAPITAL → USDG SETTLEMENT
Status: testnet prototype with production-grade engineering. Deployed and verified on Robinhood Chain Testnet with testnet USDG (no monetary value). Not audited, not a regulated financial product, and the ZK trusted setup is single-party (testnet only). See limits.
A 40,000 USDG facility against a 100,000 USDG invoice (5 milestones of 8,000, 3% fee):
sequenceDiagram
autonumber
participant X as Exporter
participant F as Financier
participant S as Sensors
participant B as Backend (evidence + AI monitor)
participant C as Contracts (Robinhood Testnet)
participant Y as Buyer
X->>C: register shipment, reveal policy, create facility
F->>C: deposit 40,000 USDG (escrowed in the vault)
loop each 8-reading epoch
S->>B: signed telemetry
B->>B: fuse sources, score evidence, fraud checks
B->>C: commit Poseidon root + score
C-->>X: release 8,000 USDG if evidence passes policy
end
S->>B: container overheats, probes disagree
B->>C: pause (reason code + AI audit)
Note over C: release now reverts
B->>B: Groth16 proof over the unaffected probe's hidden readings
B->>C: resumeWithProof (context-bound)
C-->>X: remaining milestones release
Y->>C: confirm delivery, pay 100,000 USDG
C-->>F: 40,000 principal + 1,200 fee
C-->>X: 58,800 residual
- Capital follows physical evidence. A shipment has a financial facility attached; a failed milestone changes what can be drawn, on-chain, not in a dashboard.
- No single oracle. Sources are fused with Dempster-Shafer and an explicit conflict factor, then scored with documented penalties. The same input always yields the same score.
- Privacy by construction. Raw telemetry never goes on-chain: only Poseidon Merkle roots, scores and proof verification status do. Recovery is proved in zero knowledge over readings that stay private.
- An AI that cannot move money. A language model may only ever make an outcome stricter (pause or ask for more proof), through a key that holds no other role. It never sees telemetry-derived text, and the policy gate decides alone whenever the model is absent, slow or wrong. See the AI monitor.
- Contracts hold final authority. Core contracts are immutable (no proxy). Pause is narrow and cannot withdraw funds. Eight invariants are fuzz- and invariant-tested.
All seven contracts are deployed and source-verified, and the full story has been run on the public chain: fund,
two milestones, thermal anomaly, pause, Groth16 recovery proof verified on-chain, remaining milestones,
delivery, settlement, with the AI monitor consulted at every epoch. 22 transactions, 116 seconds, each linked on
the explorer in docs/runbooks/testnet.md
(run at 1/2000 scale, 20 USDG against a 50 USDG invoice, because the faucet drip was 100 USDG).
| Contract | Explorer |
|---|---|
| FinancingController | 0xA2E7…E210 |
| ReceivableVault | 0x5298…6902 |
| EvidenceRegistry | 0x4aD4…6e66a |
| Groth16Verifier | 0x1BAa…0a8D |
| Chain | Robinhood Chain Testnet (ID 46630), RPC https://rpc.testnet.chain.robinhood.com |
| USDG | 0x7E955252E15c84f5768B83c41a71F9eba181802F (6 decimals) |
Needs Foundry, Go 1.24, Node 20+, Postgres and circom.
make anvil & # a local chain
make deploy-local # contracts + a mock USDG
createdb cargoflow
ENV_FILE=.env.local.example make serve & # API + indexer + evidence pipeline
ENV_FILE=.env.local.example make demo ARGS="-mint -pace 2s" # the whole story, real transactions, numbers checkedThe same make demo runs against the public testnet (ARGS="-divisor 2000" fits a 100 USDG faucet drip).
| Contract tests | 170 (unit, fuzz, invariants I1-I8, real-proof integration) |
| Backend | 19 Go packages with -race; integration tests run a real anvil chain and Postgres; the end-to-end test drives the full story through the running service |
| Circuit | 13,494 constraints; proves in about 1 s; 25 tests including tamper and wrong-context cases |
| ZK resume on-chain | ~0.25 M gas (real Groth16 verification) |
| Stylus vs Solidity (optional engine) | 128-reading epoch fusion: 611,945 vs 31,511 gas on Arbitrum Sepolia (19x; 32x cached); method and caveats |
| Static analysis | Slither triaged: docs/security/slither-triage.md |
Every figure is reproducible with make check, make bench and make slither; method and caveats are in
docs/benchmarks.md.
| Path | Purpose |
|---|---|
contracts/ |
Solidity core (Foundry): registry, policy, evidence, controller, vault, verifier |
backend/ |
Go service: ingestion, evidence engine, AI monitor, proof worker, API, indexer, reconciler, demo runner |
circuits/ |
Circom telemetry-epoch circuit and Groth16 tooling |
infra/ |
Hardened Dockerfile and compose stack |
scripts/ |
Key generation, funding, testnet deploy and explorer verification |
docs/ |
Architecture, runbooks, security, benchmarks, protocol knowledge base, design spec, roadmap |
stylus/ |
Optional Rust (Stylus) evidence engine for Arbitrum Sepolia, benchmarked against a Solidity reference |
frontend/ |
Planned: dashboard |
- Architecture: components, state machine, trust boundaries
- Backend service, API and guarantees
- Testnet runbook
- Benchmarks and Slither triage
- Protocol knowledge base, design spec, roadmap
- Changelog, Contributing, Security policy
- Testnet only. No audit. USDG here has no value.
- The Groth16 setup is single-party: it must be replaced by a public ceremony before any real use.
- Telemetry is simulated; there is no hardware. Source authentication is Ed25519 signatures, not attested hardware.
- The AI monitor's score weights and thresholds are design parameters, not statistically calibrated.
- One backend instance per database; recovery proving runs inside the HTTP request.
- The dashboard is not built yet, so the API, the demo command and the explorer are the interface today.
MIT. The generated Groth16 verifier is GPL-3.0 (see NOTICE).