Enclave · Built on Arc

The private financial stack, phase by phase.

FX
Live now
Invoice
Phase 01
Payroll
Phase 02
Allowance
Phase 03
Escrow
Phase 04
Stream
Phase 05
Reserve
Phase 06
Credit
Phase 07

Stablecoin trading

Enclave FX (USDC/EURC)

Live Private by design

Enclave FX lets you trade USDC and EURC privately: your order is encrypted directly to the attested enclave, filled against liquidity supplied by market makers at the live Chainlink oracle price, and only settles once the identical execution has been independently re-proven. Your deposit and withdrawal are never linked on-chain, so your trading activity stays private.

Good to know

Trades fill against liquidity that market makers supply, priced against the Chainlink oracle. Enclave does not automatically swap or rebalance against an external pool, such as Uniswap V3, to top up that liquidity. That is a separate feature and not part of the current plan.

Private payments

Enclave Invoice

In development Private by design

Enclave Invoice will let you send a payment request in USDC or EURC and get paid privately, with the same cryptographic settlement guarantee as an Enclave FX trade.

What you’ll be able to do

Issue an invoice, have it paid, and see it settle through the same deposit, private execution, and proof pipeline that already secures every trade.

Why it matters

Freelancers, vendors, and cross-border teams get a simple bill-and-pay flow without giving up the privacy Enclave already provides.

Where it stands

In development, and next in line to ship. It reuses Enclave’s existing deposit and settlement pipeline, so the custody and privacy guarantees you get today do not change.

Private payments · batched

Enclave Payroll

Planned Private by design

Enclave Payroll will let you pay many people at once: one authorization covering a whole team or vendor list, settled together instead of one payment at a time.

What you’ll be able to do

Submit a batch of recipients and amounts in one go, and have every payment in the batch settle together, with a receipt for each recipient.

Why it matters

Paying a team privately today means repeating a private payment many times over. Payroll turns that into a single, private, batched settlement.

Where it stands

Planned. It builds directly on Enclave Invoice’s payment path, so recipients still withdraw to addresses never linked to the funding deposit.

Spending policy

Enclave Allowance

Planned Private by design

Enclave Allowance will let you create a wallet with built-in spending rules, such as a fixed budget, an approved list of recipients, and an expiry date. That lets a team member or an autonomous agent spend within limits you set, instead of holding unrestricted access to funds.

How it’s expected to work

Your balance stays in the same Vault as everywhere else in Enclave. A new policy layer checks every payment against the rules you set before it settles.

  • The Vault remains the custodian: an allowance wallet holds real balances, never IOUs. Policy governs spending, not custody.
  • Deposits and withdrawals are meant to keep working the same private way as everywhere else in Enclave.
  • One open question we have not settled yet: how spending should be funded when the service being paid runs on a different network than Arc.

Circle’s agent marketplace (agents.circle.com/services) already lists hundreds of x402 services that agents can discover and pay for per request in USDC, with no accounts or API keys since the payment itself is the authentication. The examples below show the kind of spending an Enclave Allowance wallet could control once this is built.

Wave 1: the engine and the first examples we’re planning for

Market-data agent

Prices and monitors positions by paying per request for crypto metrics, funding and ROI data. Research spend that never exposes who is asking, bounded by a per-merchant cap and a daily budget.

Pays for: market-data endpoints (e.g. Messari, Allium)

On-chain analytics agent

Runs wallet-balance, PnL and explorer queries to produce treasury and portfolio reports, with every call settled from a policy-bound wallet instead of the treasury itself.

Pays for: wallet & explorer query endpoints (e.g. Allium)

Web-search agent

Retrieves and cross-checks research material on demand: documentation, counterparties, market context. Spend is bounded per call, with a session key that expires before the budget does.

Pays for: search & contents endpoints (e.g. Exa)

Team & vendor allowances

The human side of the same engine: per-seat budgets for team members and fixed retainers for vendors, each with a merchant allowlist and an expiry. The wallet sits in a person’s hands, not just an agent’s.

Policy: per-seat budget, payTo allowlist, session expiry

Wave 2: more examples we’re considering

News-monitor agent

Watches news, tickers and recap feeds continuously and alerts on events that matter to a position. A standing subscription paid per request, capped before it can run away.

Pays for: news & recap endpoints (e.g. itsGloria)

Marketing-intelligence agent

Tracks brand presence, competitive landscape, share-of-shelf and price positioning on a schedule. Competitive research whose spend pattern is itself commercially sensitive.

Pays for: marketing analytics endpoints (e.g. Syntalic)

Shopping & procurement agent

Sources purchases through best-price and deal-finder endpoints, then buys within policy: a per-transaction ceiling, an approved-merchant list, and nothing left to the agent’s discretion.

Pays for: shopper endpoints (e.g. Syntalic)

Booking agent

Discovers availability and books reservations on a user’s behalf, paying per job from an allowance that expires at the end of the trip. Spend that ends when the task does.

Pays for: reservation endpoints (e.g. agentres.dev)

Communications agent

Runs outreach from inboxes and drafts under a policy-bound identity, so the account doing the talking is never the account holding the treasury.

Pays for: mail endpoints (e.g. AgentMail)

Enrichment agent

Enriches records for CRM and KYC preparation through per-request enrichment calls. Sensitive lookups paid from a wallet with no link back to the funding deposit.

Pays for: enrichment endpoints (e.g. Paysponge)

Social-listening agent

Searches social and contact data for sentiment and brand tracking, with a fixed monthly allowance that makes monitoring spend predictable instead of open-ended.

Pays for: social endpoints (e.g. SocialIntel)

Content-publishing agent

Uploads media and captions to publish on schedule across platforms. A publishing wallet with a per-platform budget and a key that can be revoked the moment a campaign ends.

Pays for: media & caption endpoints (e.g. X, TikHub)

Conditional settlement

Enclave Escrow

Planned Aiming for private by design

Enclave Escrow will hold a payment until an agreed condition is met, then release it, so two parties can transact without needing to trust each other or a middleman.

What you’ll be able to do

Fund an escrow, have it release automatically once the condition you defined is met, or get refunded if it is not.

Why it matters

Useful for freelance milestones, marketplace deals, or any payment that should only complete once both sides deliver.

Where it stands

Planned. Escrow needs new release logic that does not exist yet. While funds sit in escrow, they are intended to remain real Vault balances, never IOUs, the same way every other balance in Enclave works today.

Scheduled settlement

Enclave Stream

Planned Aiming for private by design

Enclave Stream is intended for scheduled and vesting payments: value released over time on a set schedule, instead of all at once in a single transfer.

What you’ll be able to do

Set up a payment that unlocks gradually, for example a salary that vests monthly or a grant that releases on a schedule, and let the recipient claim what has unlocked so far.

Why it matters

Vesting and recurring payments are common for salaries, grants, and investor unlocks. Stream is meant to make that possible without one large, traceable lump-sum transfer.

Where it stands

Planned. It needs a new time-based release mechanism that does not exist yet. We intend for it to use the same private deposit and withdrawal model as the rest of Enclave, but that compatibility has not been built or proven yet.

Permissioned assets

Enclave Reserve (USYC + USDC)

Exploring Privacy model under evaluation

Enclave Reserve is an early exploration into offering USYC, a yield-bearing, permissioned asset, alongside USDC in the Vault, for institutions that want yield on idle cash.

Why this is still exploratory

USYC can only be held by non-US institutions above a $100,000 minimum, and every receiving address must be individually approved by Circle in advance; a transfer to any other address simply fails. Enclave’s privacy model normally relies on withdrawing to a fresh address that was never linked to your deposit. Because USYC requires pre-approved addresses, we have not yet worked out a withdrawal and privacy model for Reserve that matches the rest of Enclave.

Until that is resolved, we cannot promise Reserve will offer the same withdrawal privacy as Enclave FX or the other planned products. We would rather say that plainly now than promise a guarantee we cannot yet back up.

Private credit

Enclave Credit (cirBTC + USDC)

Planned Aiming for private by design

Enclave Credit is planned to let you borrow USDC against cirBTC as collateral, so you can access liquidity without selling your position or exposing it on-chain.

This is a new product for Enclave: collateralization, liquidation, and interest do not exist in the Vault today, and all three need to be designed and built before Credit can ship.

What you’ll be able to do

Deposit cirBTC, borrow USDC against it, and repay to release your collateral, the same way any collateralized loan works, settled through Enclave’s pipeline.

Why it matters

You get credit against your holdings without a lender seeing your full position or your other activity.

Where it stands

Planned. Collateral ratios, liquidation rules, and interest still need to be designed and built. We are aiming to carry over the same private deposit and withdrawal model used elsewhere in Enclave, but that has not been built or verified yet.

At a glance

The whole roadmap in eight rows

Product Phase What it’s for Privacy Status
Enclave FX (USDC/EURC) Live Private stablecoin trading Deposits and withdrawals are unlinkable Live
Enclave Invoice 01 Private one-off payments Same private model as Enclave FX In development
Enclave Payroll 02 Batched private payouts Same private model as Enclave FX Planned
Enclave Allowance 03 Spending-policy wallets for people and agents Same private model as Enclave FX Planned
Enclave Escrow 04 Conditional, milestone-based payments Aiming for the same private model as Enclave FX Planned
Enclave Stream 05 Scheduled and vesting payments Aiming for the same private model as Enclave FX Planned
Enclave Reserve (USYC/USDC) 06 Yield-bearing reserve for eligible institutions Withdrawal and privacy model still being evaluated Exploring
Enclave Credit (cirBTC/USDC) 07 Private, collateral-backed borrowing Aiming for the same private model as Enclave FX Planned