Four rungs, each stronger and more expensive.
The four ways do not compete; they are rungs. The bottom one is almost free and answers a narrow question: "did this change?". The top one answers almost any question with a yes-or-no answer, and takes real work to set up.
The practical rule is to climb only as far as needed. If a receipt settles it, you do not need a proof. If the question is about a total, encrypted computation settles it without anyone seeing the parts. Zero-knowledge proof comes in when the question is a specific statement ("is over 18", "followed the rule") and the data that answers it cannot leave where it is.
On every rung the same care from this section applies: each technique has a blind spot, and the report says which before it says the result.
The receipt: the file's fingerprint.
At delivery, a cryptographic digest of the file is computed: 32 bytes that change completely if a single comma changes. That digest gets a signed timestamp. The file can stay with the vendor; the receipt goes to whoever will check.
Months later, in a dispute, any third party recomputes the digest of the file presented and compares. It matches: it is the same file from that day. It does not: someone changed it. No opinion is involved.
The limit is clear and must be said: the receipt proves it did not change, not that it was right. And, to last decades, the stamp's signature must resist quantum computers, the subject of the post-quantum section.
The leak: what the system does not choose to show.
Every system that sends data also emits things nobody chose: the size of each packet after compression, the time it arrived. A live sensor trembles a little, even at rest, and that tremor does not compress below a floor. A frozen sensor repeats the same number and fits in almost nothing.
An auditor who receives only sizes and times can refute "the sensor worked all month" without reading a single measured value. That is the property we care about: the verdict leaves without the data leaving.
We measured the limits, and they are serious. As a detector, packet size was no better than a simple rule on the signal itself. Invented noise passes: absence convicts, presence does not acquit. And a coarse sensor at rest leaks nothing: there the honest verdict is undecidable. Details in judge what leaks.
Encrypted computation: adding without seeing the parts.
When the question is about a total (the sum of sales, the vote count, a group's average), the whole calculation can be done with the numbers locked. Each part arrives encrypted, whoever adds works on what they cannot read, and only the total is opened, by whoever holds the key.
In the encrypted ballot box of our FHE section, the server tallied without needing to see a single vote. The price is space: each locked vote takes about 1.5 MB, against a few bytes for the open vote.
And there is a trap: hiding is not guaranteeing. Encrypted computation alone does not stop someone from depositing a false part, like a vote "worth 100". That is why it almost always comes with a proof, the next rung.
The proof: the statement leaves, the data stays.
A zero-knowledge proof convinces that a statement is true without handing over the data that makes it true. "This person is over 18" without the date of birth. "This calculation followed the agreed rule" without the input data. The auditor receives the statement and a short proof they check on their own.
We measured it on our bench: the age proof takes 26 ms to generate, 1.4 ms to check and takes 164 bytes. Larger proofs cost more: being in a list of a million takes 220 ms; the text behind a SHA-256 digest, 1.6 seconds.
The limit brings us back to the start of this section: the proof guarantees that a program was followed, not that the program is right. The proven program is a yardstick, and needs its own audit. The 0k-proof section shows how it works inside.
What each one shows, hides and costs.
| Technique | Answers | The auditor sees | Stays hidden | Cost | Blind spot |
|---|---|---|---|---|---|
| Stamped receipt | changed or not | a 32-byte digest and a date | the contents, if not handed over | almost none | does not say whether it was right |
| Leak | stopped or fabricated | sizes and times | all values | no new instrumentation | invented noise passes; a coarse sensor does not leak |
| Encrypted computation | totals, counts, averages | only the final result | each part | high in space~1.5 MB per vote | does not stop a false part |
| Zero-knowledge proof | yes-or-no statements | the statement and the proof | the data that makes it true | from 26 ms to 1.6 s to prove1.4 to 3.3 ms to check | worth what the issuer and the program are worth |
The costs with numbers are our measurements: proofs on the 0k-proof bench, the encrypted vote in the FHE section's demonstration. The other cells describe, without measuring.
In practice, the rungs go together.
The ballot box: sum, proof and receipt
Encrypted computation hides each vote; a proof per vote guarantees it marks exactly one candidate; the chained record gives each voter a receipt to check the vote went in. It is the FHE section's ballot box, working.
Telemetry: receipt and leak
Each batch of measurements gets a stamped receipt on arrival; the packet sizes and times, which the auditor may see, say whether the sensor stayed alive. No measured value leaves the company.
The calculation: receipt and proof
The input data gets a receipt first; then a proof shows that the agreed program, run on exactly that data, produced that result. The auditor checks both without seeing the data.
Always: the yardstick on top
No rung dispenses with this section's question: can the yardstick fail? A proof of a slack program, or a receipt for a wrong report, is certainty about the wrong thing.
Where this can mislead.
Context leaks even when the data does not
Whoever checks does not see the value, but sees who asked, when and how often. That trail can reveal as much as the data, and needs care of its own.
The channel that checks also watches
The same leak that proves a machine ran reveals when it ran, even in "anonymised" data. Whoever sells the check has to treat that as a declared privacy cost.
Confidentiality is not integrity
Hiding well does not guarantee that nobody cheated. Encrypted computation needs a proof; the receipt needs a yardstick worth something; the proof needs an audited program.
Everything depends on who attested the input
An age proof is worth what the document issuer checked. A receipt is worth something from the moment it was registered, not before. Checking without opening does not replace checking at the source.
To go deeper.
Does this apply to your case?
Tell us in two lines what you need to decide or measure. The first conversation is to see whether measurement solves your case, and if it does not, we say so.
- Zero-knowledge proofs: our own bench, September 2026, gnark v0.16.3 in Go, BN254 curve, Apple M2 with 8 GB; method on the 0k-proof bench.
- Encrypted computation: the FHE section demonstration, with the Lattigo library; locked-vote size measured on the demonstration server.
- Leak: our own measurements on the public LeRobot ALOHA dataset, with prediction and losing criterion registered beforehand; notebook entry judge what leaks.
- Receipt: SHA-256 digest (32 bytes); timestamps and quantum-resistant signatures in the post-quantum section.