Private payments. Non-custodial. On Robinhood Chain.

Private payments. Non-custodial.

2-of-3 Threshold Custody

Send, receive, and swap USDC and USDT privately with a signing key split into three independent shards.

Network
Robinhood Chain
PRIVATUM gradient background
Overview

Why choose Privatum for private self-custody?

A 2-of-3 wallet architecture built for private stablecoin payments, graceful recovery, and open developer tooling.

Single-Key Hot Wallet

Stores the complete private key in one browser or device, so one compromise can authorize every transaction.

Hardware Wallet

Improves offline key isolation but adds hardware cost, firmware trust, shipping friction, and seed backup burden.

2-of-3 Threshold Wallet

Splits signing authority across desktop, co-signer, and passkey shards so no single party can move funds.

Highlights

Private stablecoin payments built for real financial activity

Privatum delivers non-custodial USDC and USDT payments with threshold security, passkey recovery, and a privacy focused roadmap.

Person with short brown hair and glasses talking on a phone against a white background.PRIVATUM desktop command center
Overview

Build and launch private payment flows with confidence

Create threshold-secured payment workflows for users, teams, and developers using a native desktop app and open SDK.

Private send and stealth receive

Send USDC and USDT to handles or raw addresses, then receive payments through one-time stealth destinations.

In-wallet swaps

Route supported stablecoin swaps through Robinhood Chain liquidity with clear quote and slippage controls.

2-of-3 threshold signing

The desktop client signs locally, the co-signer validates policy, and partial signatures combine without assembling the full key.

Native desktop command center

Manage balances, shard health, recovery, policy controls, swaps, and private payment activity from one desktop surface.

Overview

Reliable custody that continuously verifies itself

Continuously monitor shard readiness, policy checks, activity, and recovery paths before funds move.

Shard health monitoring

Check client, co-signer, and passkey readiness before a transaction reaches the signing pipeline.

Co-signer policy enforcement

Validate session, transaction intent, spending limits, velocity, and anomaly signals before the second signature.

Activity and recovery visibility

Track settlement history, export activity, rehearse recovery, and rotate a lost client shard without a seed phrase.

Try our live demo

Discover the full potential of Privatum Live

See how threshold custody coordinates private send, stealth receive, swaps, policy checks, and recovery in one operational flow.

Dashboard flow ready.
Check the wallet details and try again.
Integrations

Connect every payment touchpoint effortlessly

Private Send

Phone

Transfer stablecoins through a two-shard signing flow with policy checks.

Stealth Receive

Black pixelated checkmark on a light gray background.

Share one handle while incoming payments arrive at one-time addresses.

In-Wallet Swaps

Minimalistic whale illustration with two eyes and a star-like shape above its head.

Swap supported stablecoins with route, quote, and slippage visibility.

Open SDK

Icon showing an opening angle bracket, a forward slash, and a closing angle bracket symbolizing code or HTML.

Embed threshold wallets into applications with a Viem based TypeScript SDK.

Robinhood ChainSettlement layer
MPC / TSS 2-of-3Threshold signing
ERC-5564 StealthOne-time addresses
Passkeys / WebAuthnDevice auth
Viem + TypeScript SDKDeveloper surface
USDC / USDTSupported assets
Shamir RecoveryShard restore
Policy EnginePre-signing checks
Robinhood ChainSettlement layer
MPC / TSS 2-of-3Threshold signing
ERC-5564 StealthOne-time addresses
Passkeys / WebAuthnDevice auth
Viem + TypeScript SDKDeveloper surface
USDC / USDTSupported assets
Shamir RecoveryShard restore
Policy EnginePre-signing checks
Robinhood ChainSettlement layer
MPC / TSS 2-of-3Threshold signing
ERC-5564 StealthOne-time addresses
Passkeys / WebAuthnDevice auth
Viem + TypeScript SDKDeveloper surface
USDC / USDTSupported assets
Shamir RecoveryShard restore
Policy EnginePre-signing checks
Compliance & Security

Enterprise security for every private payment

Purple shield icon with a keyhole in the center representing security.

Data Protection

Protect local shards with encrypted storage, OS keychains, isolated environments, and strict session controls.

Orange lightning bolt icon representing energy or power.

Policy Controls

Enforce daily limits, velocity checks, anomaly detection, and transaction intent validation before co-signing.

Purple shield icon with a keyhole in the center representing security.

High Availability

Maintain co-signer availability with monitored infrastructure, failover planning, and operational alerts.

Orange lightning bolt icon representing energy or power.

Secure Access Control

Use passkeys, session checks, and quorum rules to manage access without giving any one party custody.

Connected

Reach users across every payment surface

Privatum connects desktop, SDK, Robinhood Chain, stablecoin swaps, stealth receive, and recovery surfaces in one custody model.

Roadmap

Roadmap to native privacy.

Phase 1
shipped

Robinhood Chain Custody MVP

ERC-4337 smart accounts, 2-of-3 threshold sharding and passkey recovery, live on Robinhood Chain mainnet with a Tauri v2 desktop client.

ERC-4337 accountsThreshold shardingPasskey recoveryDesktop client
Phase 2
in progress

Open SDK launch

A public, typed TypeScript toolkit built on viem, with guides, sample apps and audit-ready threshold primitives under MIT licensing.

npm SDKviem APIsDeveloper guidesMIT licensed
Phase 3
in progress

DEX swap aggregation

Low-slippage USDC and USDT routing with transparent quotes, slippage controls and policy-checked execution across desktop and SDK.

Aggregated routesQuote previewsSlippage controlsSDK swaps
Phase 4
next

Privacy Plane One

Threshold ECDSA and blind co-signing with ZK policy proofs, so signatures look standard and policy runs without profiling.

Threshold ECDSABlind co-signingZK policy proofsInvisible setup
Phase 5
planned

Privacy Plane Two

ERC-5564 stealth addresses, receiver unlinkability and screened privacy pools with association-set proofs for compliance-aware privacy.

Stealth addressesUnlinkabilityPrivacy poolsProvenance checks
Phase 6
planned

Multichain expansion

Additional EVM adapters and new L2 networks with one shard model, a portable co-signer and a consistent desktop experience everywhere.

EVM adaptersNew L2sPortable co-signerUnified recovery

Security and custody research

No single party, not even Privatum, can move user funds.

Smiling man with curly dark hair and beard wearing a dark shirt over a white tee.
Anette Lõhmus
Marketing Manager at Finbite

Security and custody research

"Compromise of one shard gives an attacker zero spend authority. Loss of one shard still allows complete recovery."

Young man with curly brown hair wearing an olive jacket and white shirt, smiling at the camera.
Ryan Patel
Operations Manager

Security and custody research

"The private key is never assembled or stored in one location. Spending requires cooperation from any two shards."

Portrait of a young man with black hair wearing a striped shirt, smiling against a gray background.
Jessica Morgan
Planneder Success Director
FAQ

Common Questions

What does Privatum do?

Privatum lets users and developers manage, send, receive, and swap USDC and USDT on Robinhood Chain with threshold security and privacy focused design.

How does 2-of-3 custody work?

The signing key is split into desktop, co-signer, and recovery passkey shards. Any two can approve or recover. One shard alone cannot spend.

How does a transaction sign?

The desktop client signs with Shard A, the co-signer validates policy and signs with Shard B, then partial signatures combine and settle through ERC-4337 infrastructure.

What happens if I lose my computer?

The recovery passkey and co-signer can rotate the lost client shard and restore access without exposing a seed phrase.

Does Privatum have custody of funds?

No. Privatum operates only the co-signer shard. Because every transaction requires two shards, Privatum cannot unilaterally move assets.

Which network does Privatum use first?

Privatum is built first for Robinhood Chain, an Ethereum-compatible Layer 2 with ETH gas, ERC-4337 support, and chain ID 4663.

When will native privacy launch?

The roadmap moves from custody MVP and SDK launch to swaps, invisible setup, confidential activity, and multichain expansion.

Build private payments on Robinhood Chain

Read the developer docs, explore the architecture, and follow the roadmap to native privacy.

Dashboard flow ready.
Check the wallet details and try again.
PRIVATUM gradient background