Went looking for how Dusk actually resolves the "privacy AND compliance" claim at a mechanical level, since regulators generally need to see what's happening even when the public can't. The docs point to selective disclosure the idea that a confidential transaction can be revealed to an authorized party, like a regulator or auditor, without exposing it to everyone else on-chain.
That's the right design goal. But selective disclosure only works if someone actually holds the key or credential that unlocks the hidden data on request. Whoever holds that key becomes a real point of trust and a real point of failure lose it, and disclosure obligations can't be met; centralize it too tightly, and you've quietly recreated the custodial trust model the chain was supposed to remove.
I couldn't find a clear, public answer to who holds that key in practice. Is it the issuer of the security? A regulator directly? Some multisig or threshold scheme distributed across parties? The materials describe the capability confidently but stay vague on the custody model behind it which is a strange gap for a project whose entire pitch to institutions is "we've already solved the hard compliance question."
Cryptographic capability and operational custody are two different problems, and only one of them is usually shown off in the pitch deck.
Does Dusk publish who actually holds selective-disclosure keys for its confidential contracts, or is that detail still unspecified?
@Dusk #dusk $DUSK
That's the right design goal. But selective disclosure only works if someone actually holds the key or credential that unlocks the hidden data on request. Whoever holds that key becomes a real point of trust and a real point of failure lose it, and disclosure obligations can't be met; centralize it too tightly, and you've quietly recreated the custodial trust model the chain was supposed to remove.
I couldn't find a clear, public answer to who holds that key in practice. Is it the issuer of the security? A regulator directly? Some multisig or threshold scheme distributed across parties? The materials describe the capability confidently but stay vague on the custody model behind it which is a strange gap for a project whose entire pitch to institutions is "we've already solved the hard compliance question."
Cryptographic capability and operational custody are two different problems, and only one of them is usually shown off in the pitch deck.
Does Dusk publish who actually holds selective-disclosure keys for its confidential contracts, or is that detail still unspecified?
@Dusk #dusk $DUSK

