Most blockchains solve compliance by outsourcing it entirely: bolt a third-party KYC vendor onto the front end, store personal data off-chain somewhere, and hope the 2 systems stay in sync. Dusk Network's team made a different call in January 2023, launching Citadel, a self-sovereign identity protocol built directly into the network using zero-knowledge proofs, rather than treating identity as someone else's problem to solve around the edges.

The mechanics matter here. Citadel lets a user prove they hold a valid credential, an eligibility check, an accreditation status, a jurisdiction requirement, without revealing the underlying document or handing a service provider a copy of personal data to store and eventually leak. A concert-ticket comparison from the original research paper sticks with me: buying a ticket online today means a website collects card details, browsing data, sometimes a face scan, just to prove 1 narrow fact, that you're allowed in. Citadel is built to prove that 1 fact and nothing else.

Building this in-house rather than integrating a vendor was the harder, slower choice. It's also the only choice that let compliance logic run as a native primitive on Dusk Network rather than as a dependency on some external company's uptime, pricing, and data practices. The cost is that Dusk Network now owns the maintenance and audit burden for identity infrastructure most chains never have to think about at all, including keeping the underlying zero-knowledge circuits audited and current as cryptographic best practices evolve, an ongoing cost with no natural end date.

More than 2 years on, Citadel remains more of a foundational primitive than a widely deployed consumer product. Whether institutions actually build KYC flows on top of it at meaningful volume, rather than citing it as proof of technical seriousness, is still the open question this design decision has to answer.

#dusk $DUSK @Dusk