Stickybit.← VerificationPortuguêsConfidentiality · verification · 2026
Confidentiality · checking without opening

Checking without opening the data.

Almost every audit hits the same wall: to check, the auditor needs to see, and the audited party cannot show. Confidentiality agreements, health data, trade secrets, votes. There are four ways to reach a verdict without opening the data, from simplest to strongest. Each one answers one kind of question, and none answers them all.

Specimen · what does the auditor need to know?
the technique that answersthe one that comes along
The auditor sees
Stays hidden
What it costs
The limit
Where to see it

The costs quoted are our own measurements: the age proof and the other proofs on the 0k-proof bench (Apple M2), the encrypted vote on the FHE section's demonstration server. The rest are descriptions, without numbers.

The ladder

Four rungs, each stronger and more expensive.

The four ways do not compete; they are rungs. The bottom one is almost free and answers a narrow question: "did this change?". The top one answers almost any question with a yes-or-no answer, and takes real work to set up.

The practical rule is to climb only as far as needed. If a receipt settles it, you do not need a proof. If the question is about a total, encrypted computation settles it without anyone seeing the parts. Zero-knowledge proof comes in when the question is a specific statement ("is over 18", "followed the rule") and the data that answers it cannot leave where it is.

On every rung the same care from this section applies: each technique has a blind spot, and the report says which before it says the result.

ReceiptLeakEncryptedcomputationZero-knowledgeproof changed?stopped?what total?is the statementtrue? MORE QUESTIONS ANSWERED · MORE COST TO SET UP the auditor never sees the confidential data, on any rung
Sketch. Height is qualitative: it shows the order of strength and cost, not a measurement.
Rung 1

The receipt: the file's fingerprint.

At delivery, a cryptographic digest of the file is computed: 32 bytes that change completely if a single comma changes. That digest gets a signed timestamp. The file can stay with the vendor; the receipt goes to whoever will check.

Months later, in a dispute, any third party recomputes the digest of the file presented and compares. It matches: it is the same file from that day. It does not: someone changed it. No opinion is involved.

The limit is clear and must be said: the receipt proves it did not change, not that it was right. And, to last decades, the stamp's signature must resist quantum computers, the subject of the post-quantum section.

AT DELIVERY a3f9 … 71c2 30 SEP2026 32-byte digeststamp MONTHS LATER a3f9 … 71c2 = match recomputed by any third party, without trusting whoever kept it
Sketch. The digest and date are illustrative.
Rung 2

The leak: what the system does not choose to show.

Every system that sends data also emits things nobody chose: the size of each packet after compression, the time it arrived. A live sensor trembles a little, even at rest, and that tremor does not compress below a floor. A frozen sensor repeats the same number and fits in almost nothing.

An auditor who receives only sizes and times can refute "the sensor worked all month" without reading a single measured value. That is the property we care about: the verdict leaves without the data leaving.

We measured the limits, and they are serious. As a detector, packet size was no better than a simple rule on the signal itself. Invented noise passes: absence convicts, presence does not acquit. And a coarse sensor at rest leaks nothing: there the honest verdict is undecidable. Details in judge what leaks.

WHAT THE AUDITOR RECEIVES floor 10:0010:40 No measured value leaves. Only size and time, stamped. Verdict: refuted, from 10:40 on.
Sketch, with the same drawing as the notebook entry.
Rung 3

Encrypted computation: adding without seeing the parts.

When the question is about a total (the sum of sales, the vote count, a group's average), the whole calculation can be done with the numbers locked. Each part arrives encrypted, whoever adds works on what they cannot read, and only the total is opened, by whoever holds the key.

In the encrypted ballot box of our FHE section, the server tallied without needing to see a single vote. The price is space: each locked vote takes about 1.5 MB, against a few bytes for the open vote.

And there is a trap: hiding is not guaranteeing. Encrypted computation alone does not stop someone from depositing a false part, like a vote "worth 100". That is why it almost always comes with a proof, the next rung.

#▒▓░▓#░▒░▒#▓▒░▓#▓▒#░▒▓ sum, still locked total opened only here,with the key LOCKED PARTS
Sketch. In the FHE section's demonstration, the sum is of real votes, cast by visitors.
Rung 4

The proof: the statement leaves, the data stays.

A zero-knowledge proof convinces that a statement is true without handing over the data that makes it true. "This person is over 18" without the date of birth. "This calculation followed the agreed rule" without the input data. The auditor receives the statement and a short proof they check on their own.

We measured it on our bench: the age proof takes 26 ms to generate, 1.4 ms to check and takes 164 bytes. Larger proofs cost more: being in a list of a million takes 220 ms; the text behind a SHA-256 digest, 1.6 seconds.

The limit brings us back to the start of this section: the proof guarantees that a program was followed, not that the program is right. The proven program is a yardstick, and needs its own audit. The 0k-proof section shows how it works inside.

STAYS WITH THE PROVER nameIDbornphoto over 18: yes 164-byte proof GOES TO THE AUDITOR 1,4 ms for the auditor to check, withouttalking to the prover
Numbers from the 0k-proof bench: Groth16, BN254 curve, Apple M2.
Side by side

What each one shows, hides and costs.

TechniqueAnswersThe auditor seesStays hiddenCostBlind spot
Stamped receiptchanged or nota 32-byte digest and a datethe contents, if not handed overalmost nonedoes not say whether it was right
Leakstopped or fabricatedsizes and timesall valuesno new instrumentationinvented noise passes; a coarse sensor does not leak
Encrypted computationtotals, counts, averagesonly the final resulteach parthigh in space~1.5 MB per votedoes not stop a false part
Zero-knowledge proofyes-or-no statementsthe statement and the proofthe data that makes it truefrom 26 ms to 1.6 s to prove1.4 to 3.3 ms to checkworth what the issuer and the program are worth

The costs with numbers are our measurements: proofs on the 0k-proof bench, the encrypted vote in the FHE section's demonstration. The other cells describe, without measuring.

Combining

In practice, the rungs go together.

  1. The ballot box: sum, proof and receipt

    Encrypted computation hides each vote; a proof per vote guarantees it marks exactly one candidate; the chained record gives each voter a receipt to check the vote went in. It is the FHE section's ballot box, working.

  2. Telemetry: receipt and leak

    Each batch of measurements gets a stamped receipt on arrival; the packet sizes and times, which the auditor may see, say whether the sensor stayed alive. No measured value leaves the company.

  3. The calculation: receipt and proof

    The input data gets a receipt first; then a proof shows that the agreed program, run on exactly that data, produced that result. The auditor checks both without seeing the data.

  4. Always: the yardstick on top

    No rung dispenses with this section's question: can the yardstick fail? A proof of a slack program, or a receipt for a wrong report, is certainty about the wrong thing.

Limits

Where this can mislead.

Context leaks even when the data does not

Whoever checks does not see the value, but sees who asked, when and how often. That trail can reveal as much as the data, and needs care of its own.

The channel that checks also watches

The same leak that proves a machine ran reveals when it ran, even in "anonymised" data. Whoever sells the check has to treat that as a declared privacy cost.

Confidentiality is not integrity

Hiding well does not guarantee that nobody cheated. Encrypted computation needs a proof; the receipt needs a yardstick worth something; the proof needs an audited program.

Everything depends on who attested the input

An age proof is worth what the document issuer checked. A receipt is worth something from the moment it was registered, not before. Checking without opening does not replace checking at the source.

The section

To go deeper.

Talk to us

Does this apply to your case?

Tell us in two lines what you need to decide or measure. The first conversation is to see whether measurement solves your case, and if it does not, we say so.

Talk on WhatsApp algorithms@stickybit.com.br Stickybit · Porto Alegre, Brazil, since 2004

← Verification

Sources