When people talk about compliance, they often treat KYC like just a plug-in—but ZhuZhu thinks the question has been wrong from the very beginning.

The design idea behind Citadel really opened my eyes. It’s not a KYC plug-in at all; it’s a self-sovereign identity plus license-based infrastructure. Through the issuance, verification, and revocation processes of license contracts, a compliant identity shifts from being stored as a file on a platform to becoming a verifiable credential held by the user.

More importantly, there’s selective disclosure. Users only need to prove that they “meet a certain attribute” (qualified investor status, residential region, age range, for example) without exposing their full identity.

Paired with Phoenix/Zedger, identity proof and asset transfer are completely decoupled—compliant and privacy-preserving at the same time.

What ZhuZhu is most interested in, though, is the underlying logic: compliance shouldn’t be a burden on the platform; it should be the user’s right. In a sense, this ordering explains better whether Citadel is truly serving institutions than the concept of “privacy KYC” itself.

But ZhuZhu also can’t pretend this mechanism has already been sufficiently validated. No matter how clever the license contract design is, we’ll only know how useful it is once real scenarios start running. There aren’t many publicly available deployment cases yet. Whether this capability can truly support institution-level compliance needs may only become clear after more contracts go live.

What do you think—long term, between the path of “user-held verifiable credentials” and the path of “the platform stores a file,” which one will be more likely to be accepted by institutions?

ZhuZhu thinks no matter which path is chosen, @Dusk Foundation will be redefining compliance infrastructure with $ DUSK—this is the real native compliance!
#dusk $DUSK