blog / 6 min read

Signed reports and selective disclosure

What a signed report proves, what it leaves visible and how to share one with care.

Selective disclosure means showing a counterparty some of your payment history, not all of it. ZeroShade expresses this as a signed report. The word signed is doing specific work, and it is easy to misread.

What a signature gives you

What it does not give you

A signature does not hide anything. The report payload can be read by anyone who can see it. Think of a signed postcard: the signature shows the key holder signed it and detects edits, without naming a real person, but the postman can still read it.

What sharing stores

When you share a report through the hosted API, the signed payload is stored so the recipient can open it. Anyone who obtains the link can read it. If a report contains something you would not post publicly, do not share it by link.

Practical guidance

  1. Include only the payments the counterparty needs to see.
  2. Assume the link is readable by anyone who has it.
  3. Verify a report you receive before relying on it.
  4. Do not treat verification as proof the underlying facts are complete. It proves integrity, not completeness.

Where the line is

Verification checks the signature on what was shared. It says nothing about what was left out, and it cannot make a shared payload private afterward.

Back to all articles

Next to readWhat the hosted API stores, field by fieldNext to readReading the simulated demo: what is real and what is not