Soda Labs

NIST

The vocabulary that makes privacy claims testable

Regulator or standard-setterGlobalBuilds with privacy tech

The regime itself mandates, pilots or funds privacy-preserving technology.

What NIST actually says

A national agency rather than a global one, included because its output gets adopted internationally as reference material and because it does something no financial regulator has. NIST turns privacy claims into things a supervisor can check. SP 800-226 gives an evaluation method for differential privacy guarantees and names the implementation hazards that make a formally correct deployment leak anyway, which is exactly the gap between claiming a privacy property and demonstrating one. The multi-party threshold cryptography work under the IR 8214 series covers threshold signatures and the MPC constructions used in custody. Whatever position a regulator eventually takes on privacy-enhancing technology in finance, the measurement vocabulary it will use probably comes from here.

The instruments that matter

SP 800-226, March 2025
guidelines for evaluating differential privacy guarantees, setting out evaluation factors and cataloguing common implementation hazards
Privacy Framework 1.0, CSWP 10, 16 January 2020
version 1.1 was released as an initial public draft in April 2025 and remained in draft as of August 2026
Multi-party threshold cryptography, IR 8214 series
directly relevant to threshold signatures and MPC-based custody

What this means for confidential transactions

Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.

Compliant by default.

See how selective disclosure satisfies a supervisor without publishing your book to the world.