Orbital, the first onchain privacy layer in Orbio's orbit

The first onchain privacy layer for Orbio.

Prove the code is safe. Eclipse the rest.

Orbital gives Orbio agents a private audit. An AI auditor agent runs through Orbio with zero data retention, reads your source alone and signs what it found. Eight fixed checks run on your bytecode, and the seal goes on Robinhood Chain. Nobody else ever reads a line, human or agent.

0
bytes of source kept
8
fixed checks
1
agent, then it forgets
Eclipse a contractexample
  • Sourceread once, then deleted
  • Agentclaude-opus-5 via Orbio
  • Retentionzero, on Orbio's ZDR routes
  • Sealcodehash on Robinhood Chain
Eclipse my code
$ORBITALpre-launch on Pons, CA posted here firstRegistry0xeaDd…FeEAOrbital Protocol v1 · agent on Orbio · Robinhood Chain

Built on Orbio. The agent forgets by design.

Orbio gives agents one key to every model and routes only to zero data retention endpoints. That is the missing piece for a private audit: the only reader of your source is a model that keeps nothing. Orbital is the privacy layer on top.

  1. Your repo→
  2. Orbital agent→
  3. Orbio · ZDR→
  4. Claude→
  5. Signed seal→
  6. Robinhood Chain
  • Zero data retention

    The review runs only on Orbio's ZDR routes. Prompts and responses pass through and are not written anywhere, so your source exists in one place for one call.

  • Pay with your credits

    Orbio holders earn inference credits from the token's fees. Bring your key and the agent's review is paid from them, used once and never stored.

  • Straight relay, on the record

    Orbio sends the request to the model it names, unchanged. The seal records which model wrote the review and that it went through Orbio.

Hold $ORBIO? Your credits pay for your review.

Paste your Orbio key when you send the contract. It is used for one call, never stored, and the seal says the review ran through Orbio.

One protocol. Three layers. No one reads the code.

Privacy onchain has meant hiding balances and transfers. Orbital, the first onchain privacy layer for Orbio, hides the other thing people keep private: the code itself. Each layer does one job, and the source never crosses from one to the next.

The layers are separate on purpose: what is proven, what an agent thinks, and what is at stake are never mixed into one green tick.

  1. LAYER 01deterministic

    The proof layer

    Eight fixed checks run on the compiled bytecode: mint, drain, tax, blacklist, pause, upgrade, sell path, self-destruct. The answers are yes or no, the same for everyone, bound to the hash of the code.

    • 8 checks
    • bytecode hash
    • zkVM target
  2. LAYER 02agentic

    The agent layer

    An AI auditor agent reads the source in isolation through Orbio, with zero data retention. It describes what the code does and who holds which powers, scores the risk, and never quotes a line. The auditor signs its output, labelled as an opinion.

    • AI auditor
    • via Orbio
    • zero retention
    • signed review
    • never quotes
  3. LAYER 03onchain

    The settlement layer

    The registry on Robinhood Chain writes the seal against the code hash, holds the auditor's stake behind it, splits the fee and pays the cover pool when a claim passes.

    • registry
    • stake + bond
    • cover pool
    • Robinhood Chain

One file. The auditor reads it. The chain reads the bars.

Every audit so far has asked the same price: publish the code, then we will tell people it is safe. Orbital keeps the security check and leaves the privacy where it was. Here is the line, exactly.

What stays private: the source, the repo, you. A loop, not data.

Becomes public

  • The hashkeccak256 of the runtime bytecode, which anyone can recompute from the chain.
  • Eight answersWhich checks passed, with the proof that they ran on that hash.
  • The reviewThe auditor's signed text about what the code does. It describes, it does not quote.
  • The auditorTheir key and the stake locked behind this seal.

Stays private

  • The sourceRead by one auditor from a read-only grant. Never stored past the review, never published.
  • The repoIts name, its history, its other branches. The seal records a commit hash, not a link.
  • YouNo account on this site. The wallet that pays the fee is the only identity, and it can be a fresh one.

Connect the repo. Get the review. Wear the seal.

Eclipse my code
  1. 01

    Connect GitHub, name the contract

    A read-only grant on one repo, at one commit. Nothing else is asked for.

  2. 02

    The review runs, behind the bars

    The repo is compiled and matched to the chain byte for byte. Eight fixed checks run, then a model reads the source and the auditor signs what it says.

  3. 03

    Sealed against the hash

    The seal follows the bytecode wherever it is deployed, and anyone can read it without asking.

The code goes in. Only the seal comes out.

What the chain receives is a hash, a proof and a signature. It never receives the source, and the proof does not contain it either. A launchpad, a wallet or a marketplace can show the mark without asking anyone.

Checks
8
Proven
8
Opinions
1
SourcezkVMSeal
A loop, not data.

Eight checks. Fixed, public, the same for everyone.

What each one looks for
  • 01
    No hidden mint

    No path creates supply after deployment other than the ones declared in the interface.

  • 02
    No owner drain

    No function lets one address move balances that are not its own.

  • 03
    Tax under the cap

    If there is a tax, it is fixed or bounded, and the bound is ten percent.

  • 04
    No blacklist

    No function can stop a specific address from selling.

  • 05
    No pause on transfer

    Transfers cannot be switched off after launch.

  • 06
    Not upgradeable

    No proxy, no delegatecall to an address that can change.

  • 07
    Sell path clears

    A buy followed by a sell completes, from a fresh address, on a fork.

  • 08
    No self-destruct

    Nothing can remove the code once it is sealed.

Built for agents. On both sides of the seal.

Agents already write contracts, launch tokens and trade them. None of them can read a stranger's source, and none of them should have to publish their own. Orbital gives them a trust signal a machine can read: a hash in, a verdict out.

AGENTS THAT BUILD

Seal before you ship

A coding agent that deploys a token or a strategy asks for a review of its own repo, and launches with the mark without handing out its edge.

repo + commit → review bytecode hash → seal
AGENTS THAT TRADE

Read before you buy

A trading agent checks the seal of any contract in one call before it buys. No source to parse, no report to trust: a hash, eight answers, a score.

badge(codehash) → score, passed, ran, standing
THE AUDITOR AGENT

The only reader

The one agent that sees the source. It works in isolation, its review is signed by a staked auditor, and the tree is deleted when it is done.

source → agent → signature source → deleted

A seal is not a promise. It is a list.

It says these checks ran on this code and passed, and that someone locked money behind saying so. It does not say the code is good, and it cannot see what the checks do not look for.

Read the rules

Every seal pays a fee in $ORBITAL. This is where it goes.

  • 50%
    The auditorWhoever ran the press and signed the review. Paid when the seal is written.
  • 25%
    The cover poolHeld with the auditors' stakes. Paid out to holders of a sealed contract that is exploited.
  • 15%
    BuybacksBuys the platform token on the market. What it buys is burned.
  • 10%
    OrbitalWhat the platform earns.

Who you are trusting, and with what.

  • Your sourceNobody. It is encrypted in your browser to one auditor's key. The site never sees it and the chain never gets it.
  • The checksMathematics. The proof says they ran on your hash and passed. Anyone can verify it, and the registry does before writing a seal.
  • The reviewThe auditor, as a signed opinion. It can be wrong. The seal labels it as an opinion, apart from the proof.
  • The stakeThe registry. An auditor's tokens are locked behind every seal they sign, and a passed claim takes them.

Launch with the mark, before the reveal.

A Pons launch, a bot, a strategy for sale: get it reviewed before anyone sees the code. The seal follows the bytecode wherever it is deployed.