Stickybit.← 0k-proofPortuguêsApplications · 0k-proof · 2026
Applications · 0k-proof

Seven uses, with what stays hidden.

Every proof without showing has three roles: who attests the data at the source, who proves and who checks. What changes from one use to another is what each one knows, what stays hidden and whom you still have to trust. Below, seven uses with those three roles, the cost we measured and how ready each one is.

Specimen · pick a use and see who knows what

stays hidden
measured cost
maturity

Costs come from our bench (gnark v0.16.3, Groth16, BN254 curve, Apple M2), on the proof closest to each use. Where we did not measure, the page says so. "In use" means in use by someone in the world, not by us in production.

The three roles

Who attests, who proves, who checks.

A zero-knowledge proof does not create trust out of nothing. It carries trust: the checker comes to trust a statement because they trust whoever signed the source data, and the math guarantees the statement follows from that data.

That is why every use starts with the same question: who signs the data? If nobody does (the person types in their own date of birth), there is nothing to prove: the proof would only confirm that the person typed something. If someone trustworthy signs it, the proof lets the data stay with its owner and sends on only the answer.

The seven uses below range from what is already out in the world (age, voting) to what is still research for us (sensor, audit). For each one, we say what stays hidden and whom you still have to trust.

Who attestssigns onceand steps away Who proveskeeps the dataand makes the proof Who checksreceives the claimand the proof signed data164 bytes the checker trusts whoever attests,not whoever proves
Trust goes around: the checker never has to trust the prover, only whoever signed the source data and the rule written as arithmetic.
The seven uses

From the phone wallet to auditing without opening.

I am over 18Age

"I am 18 or older"

in use
Who attests
Identity agency: knows everything: name, ID number, date of birth
Who proves
You, on your phone: holds the signed document
Who checks
The website or app: sees only: over 18, yes, and that the document is genuine
Stays hidden
name, ID number, exact date, photo, address
Who has to trust whom
The website trusts the issuing agency, not you. You do not have to trust the website with your document.
Measured cost
26 ms to prove · 1.4 ms to check · 164 bytes
In practice
Since 17 March 2026, Brazil's Digital Statute of Children and Adolescents (Law 15,211/2025) requires reliable age verification on social networks, games, app stores and adult content, bans plain self-declaration and limits the data collected to that purpose. The European Commission published a blueprint app using this kind of proof in July 2025, updated in October, piloted in 2026 in France, Denmark, Greece, Italy, Spain, Cyprus and Ireland. Google announced age proofs in its digital wallet in May 2025 and open-sourced the code (Longfellow ZK, Apache 2.0 license) in July.

My balance is over R$ 10,000Income or balance

"The balance signed by my bank is over R$ 10,000"

ready for a pilot
Who attests
The bank: knows the exact balance and the full statement
Who proves
Whoever wants to rent or borrow: holds the balance signed by the bank
Who checks
The letting agent or lender: sees only: over R$ 10,000, yes
Stays hidden
exact balance, statement, employer, other debts
Who has to trust whom
The letting agent trusts the bank. Nobody emails a bank statement or keeps a copy in a shared folder.
Measured cost
25 ms to prove · 1.4 ms to check · 164 bytes
In practice
The arithmetic is as simple as it gets: comparing a number against a threshold. What is missing is outside the proof: the bank signing the balance in a format the phone can use. Until that exists, the proof has nowhere to start from.

I am on the list, without saying whoBeing on a list

"My name is among the one million on this list"

ready for a pilot
Who attests
Whoever keeps the list: knows every name; publishes only the list's summary
Who proves
One of the members: knows their own place on the list
Who checks
The front desk, the forum, the service: sees only: one of the members, yes
Stays hidden
which of the one million names
Who has to trust whom
The front desk trusts whoever keeps the list. To stop the same person using it twice, the proof can carry a single-use mark that does not reveal who they are.
Measured cost
220 ms to prove · 1.9 ms to check · 164 bytes
In practice
It works for members of an association, voters in an internal ballot, accredited guests at an event, a whistleblowing channel that needs to know the speaker is an employee without knowing which. The list is summarized as a tree, and only its top is public.

I applied the agreed ruleThe calculation was done right

"Each person's bonus came from the contract rule, over the signed data"

ready for a pilot
Who attests
The source system: signs the inputs: salaries, orders, hours
Who proves
Whoever calculates (the supplier): has all the inputs and the result
Who checks
The client or auditor: sees the total and the guarantee that the rule was followed
Stays hidden
each person's or order's individual values
Who has to trust whom
The auditor trusts the source system and the rule written as arithmetic, which needs its own review. They do not have to redo the calculation or see the data.
Measured cost
grows with the calculation: the heaviest on our bench took 1.6 s and needed a 51 MB key
In practice
Payroll, shipping, commission, royalty payouts: any calculation where one party computes and the other has to believe it. Small calculations are cheap. Big ones get expensive fast: proving you know the text behind a single SHA-256 hash already takes 200 thousand steps, 1.6 s on the fastest system and 40.6 s on the other.

I voted for one candidate, only oneValid vote

"This locked vote is for exactly one of the candidates"

in use
Who attests
The electoral authority: issues the credential of who may vote
Who proves
The voter: knows who they voted for
Who checks
The ballot box, and later anyone: sees that the vote is valid, without knowing for whom
Stays hidden
who the person voted for
Who has to trust whom
Nobody has to trust the voting terminal to know it did not slip a double vote or an invalid number into the tally.
Measured cost
live in the FHE section's ballot box, one proof per vote
In practice
The encrypted ballot box in the FHE section already uses a proof without showing for each vote: it guarantees the locked vote is a 1 for one candidate and zeros for the rest, without opening it. It is a public demonstration, not an official election.

It stayed within range all weekSensor within range

"Every signed reading this week stayed between 2 °C and 8 °C"

research
Who attests
The sensor itself: signs each reading as it measures
Who proves
The operator (the carrier, the plant): has the full series of readings
Who checks
The insurer, the client, the regulator: sees only: within range, yes
Stays hidden
the series of readings, which reveals routine, route and operating rhythm
Who has to trust whom
The checker trusts the sensor. If the sensor lies or was swapped, the proof proves the lie; that is why it is worth also looking at what the sensor leaks unintentionally.
Measured cost
not measured: depends on the number of readings
In practice
The idea fits the telemetry section, where every measurement already comes stamped. It is still research for us: we have not built or measured this proof, and the cost grows with the length of the series.

The rule held in every recordAuditing without opening the data

"None of this quarter's stamped records breaks the agreed rule"

research
Who attests
The audited system: stamps each record when it is created
Who proves
The audited company: has the complete records
Who checks
The external auditor: sees the verdict and the guarantee, without the records
Stays hidden
the records, which may hold personal data or trade secrets
Who has to trust whom
The auditor trusts the stamps and the rule written as arithmetic. When the proof is too expensive, there are lighter ways to check without opening, with weaker guarantees.
Measured cost
depends on volume; still expensive for large batches
In practice
This is where this section meets Verification: reaching a contestable verdict without seeing the confidential data. The zero-knowledge proof is the strongest way; sizes, stamps and encrypted computation are the cheaper ones.
Summary

All seven, in one table.

UseWhat is provenStays hiddenMeasured costMaturity
AgeI am over 18name, ID number, exact date, photo, address26 ms to prove · 1.4 ms to check · 164 bytesin use
Income or balanceMy balance is over R$ 10,000exact balance, statement, employer, other debts25 ms to prove · 1.4 ms to check · 164 bytesready for a pilot
Being on a listI am on the list, without saying whowhich of the one million names220 ms to prove · 1.9 ms to check · 164 bytesready for a pilot
The calculation was done rightI applied the agreed ruleeach person's or order's individual valuesgrows with the calculation: the heaviest on our bench took 1.6 s and needed a 51 MB keyready for a pilot
Valid voteI voted for one candidate, only onewho the person voted forlive in the FHE section's ballot box, one proof per votein use
Sensor within rangeIt stayed within range all weekthe series of readings, which reveals routine, route and operating rhythmnot measured: depends on the number of readingsresearch
Auditing without opening the dataThe rule held in every recordthe records, which may hold personal data or trade secretsdepends on volume; still expensive for large batchesresearch

Costs from our bench, on the proof closest to each use. "Ready for a pilot" means the arithmetic is cheap and well known, and what is missing lies outside the proof: someone signing the source data in a usable format.

When not to use it

Not every check needs a proof without showing.

  1. When the data is not confidential

    If showing the data is fine, show it, with a signature. An ordinary signature is cheaper, simpler and easier to audit than any proof.

  2. When nobody attests the source

    If the data is typed in by the prover, the proof only confirms that something was typed. First someone trustworthy has to sign the data; then the proof makes sense.

  3. When a signature on the answer is enough

    If the issuer is available on the spot and can answer "yes, over 18" directly, an answer signed by them solves it. The proof wins when the issuer should not learn where you are using the data.

  4. When the rule is not settled yet

    The proof guarantees a rule was followed, not that it is the right rule. If the threshold or the calculation is still under discussion, prove later; first, check the yardstick.

Limits

Where this can mislead.

Trust only moved

In every use, the checker still trusts someone: the issuing agency, the bank, the sensor. The proof takes the data out of the way, not the need for an honest issuer.

"Ready for a pilot" is not "ready"

In the uses marked that way, the arithmetic is cheap but the ecosystem is missing: the bank signing the balance, the list publishing its summary, the system stamping its records. That is where projects stall.

Cost grows with the rule

The low numbers on this page come from short rules. Large calculations get expensive fast, and the proof system chosen moves the cost from 1.6 s to 40.6 s on the same rule.

The trail still exists

The checker does not see the data, but sees that a proof happened, from where and when. In sensitive uses, that trail needs its own care.

The section

To go further.

Talk to us

Does this apply to your case?

Tell us in two lines what you need to decide or measure. The first conversation is to see whether measurement solves your case, and if it does not, we say so.

Talk on WhatsApp algorithms@stickybit.com.br Stickybit · Porto Alegre, Brazil, since 2004

← 0k-proof: proving without showing · stickybit.com.br

Sources