@Dusk_Foundation used to think "selective disclosure" was just a softer word for transparency.

Sat with Citadel's actual design for a while, and it isn't.

Full transparency, the kind Dusk explicitly builds against, means every observer sees every attribute tied to a transaction or identity, whether they need it or not. Citadel does something narrower, and I traced the actual mechanics: three distinct parties, not two. A User requests a license on-chain from a License Provider. Once issued, that license lets the User establish a private, off-chain connection with a Service Provider — who verifies the claim using only what's stored on-chain, never learning the User's underlying identity.

Hmm.

so what does the Service Provider actually learn when a check passes?

Just that one claim is true — residency, age bracket, accreditation, whatever the license covers. Not the underlying data behind it, not any other attribute the User holds, not a persistent identifier linking this check to a future one.

That's a much narrower promise than transparency makes. A fully transparent system tells everyone everything, permanently, whether it's relevant or not. Citadel's three-party structure tells one Service Provider one true thing, verified against an on-chain record, without that Service Provider ever touching the User's full profile.

Not saying transparency is wrong everywhere. Public coordination genuinely benefits from everyone seeing the same ledger. But identity-gated actions — proving eligibility without volunteering a full profile — needed a protocol with three separate roles, not two, to actually work.

Is proving one true thing through three separated roles a stronger privacy guarantee than transparency's "everyone sees everything, so no one's hiding anything"?

@Dusk_Foundation #dusk $DUSK
Stronger guarantee
100%
Transparency is simpler
0%
4 الأصوات • تمّ إغلاق التصويت