Compliant by default: privacy regulators can live with
Privacy and compliance are often framed as opposites: either the chain sees everything and the regulator is happy, or the chain sees nothing and the regulator reaches for sanctions. Both framings keep failing, and they fail in instructive ways.
Radical transparency fails the users. On a public ledger, a customer's balance, salary, counterparties and complete financial history are permanently readable by anyone: competitors, data brokers, phishing operations, an abusive ex. No regulated institution can put its clients in that position, which is why most of them are still watching from the sidelines.
Radical opacity fails everyone else. Mixers that break every link between sender and receiver do not distinguish between a private citizen and a sanctioned laundering operation, so regulators shut them down, and every legitimate user loses access overnight. Privacy without a disclosure path is a product with a countdown timer.
The false dichotomy
The mistake in both designs is treating visibility as global: either everyone sees a record, or no one does. Real-world finance has never worked that way. Your bank statement is not public, and it is also not invisible; your bank sees it, your auditor can request it, a court can subpoena it. Visibility is scoped, justified and logged.
That is exactly the property Bubble brings on-chain. Data is never decrypted during computation; the only disclosure path is the on-chain access list (ACL), through which authorized entities can request scoped decryption.
How selective disclosure actually works
Every encrypted record on Bubble is governed by an access list that lives on the chain itself. Whoever governs a record decides who may view it, and the network checks the list before any decryption happens. When an auditor needs transaction records for a reporting period, they get those records: not the customer list, not the strategy, not the rest of the book. Every access is on-chain, so the disclosure trail is itself auditable.
The result inverts the usual trade-off. The public chain sees nothing. The counterparty sees only their side. The auditor sees exactly what the engagement entitles them to. And the institution can prove, cryptographically, that this is all anyone saw.
Regulators are not the enemy of this design; they are the audience
Recent stablecoin legislation in the US demands KYC, transaction monitoring and suspicious-activity reporting from issuers. European supervisors expect audit access as a condition of operating. None of that is compatible with a mixer, and all of it is compatible with selective disclosure: the oversight hooks regulators require are the same scoped-access mechanism that protects customers from everyone who is not entitled to look.
Confidentiality for the market, transparency for oversight. That is not a compromise between privacy and compliance. It is what both of them look like when the system is designed for finance rather than against it.
See how the security and compliance model works, or talk to our team about what your auditor would actually see.