The most important thing I found about Dusk’s privacy model is that it does not remove issuer control. Dusk’s current mainnet docs explicitly list access controls such as allowlists, plus forced transfers for regulated assets.

I initially assumed XSC meant confidentiality first and permissionless transfer underneath.

Dusk’s own XSC self-custody material says otherwise: security tokens can be restricted to registered, vetted holders, while issuers can freeze or force-transfer tokens in certain circumstances.

That changes the interpretation. Privacy here is mainly about limiting who can see sensitive transaction information; it does not mean removing compliance authority from the asset itself.

For tokenized securities, that distinction matters. Eligibility requirements, asset recovery, and other legal obligations can demand controls that ordinary bearer-style crypto does not.

The detail I’d watch now is where Dusk draws the boundary between protocol-standardized controls and issuer-configurable rules, especially as current docs describe Hedger as the evolution of Zedger. That boundary may determine what “confidential securities” actually mean in practice.

@Dusk $DUSK #dusk