From static analysis of structure to evaluation via simulation.

Today Sunspot reasons statically about a model of a transaction. Next it dry-runs the real transaction against a mainnet fork and machine-checks the proof wiring — then extends the same lens to Arcium's encrypted compute and to ZK-compressed state, the confidential-compute and scaling layers arriving on Solana. Each stage adds reach without changing what Sunspot is: the check you run on a confidential transfer before it ships.

Stages
available now · Analysis

In-browser analysis of confidential transfers

Give Sunspot a structural model of a Token-2022 confidential transfer — the six worked examples, or your own as JSON — and it decodes the instruction and CPI flow into the ZK ElGamal Proof program, checks each transfer carries all three proofs (equality, ciphertext-validity, range) in a fresh, closed context, tracks the public / pending / available balance model, traces every confidential value to the sinks that make it observable, and reports the three-observer view alongside CT findings with a fix for each. It runs entirely client-side: nothing is decrypted, no keys are held, and no source ever leaves the browser.

CLI · CI · SARIF

Command line, merge-gate, and SARIF

The same engine as a command-line tool and a GitHub Action that fails a pull request the moment a change introduces a new leak or drops a required proof, emitting SARIF so each finding appears inline in code review and in the repository's Security tab — the confidentiality check, run automatically where the work already happens.

live simulation · trace

Live simulation and trace

Dry-run a confidential transfer against a mainnet fork through a same-origin RPC proxy, then analyze the real instruction flow and proof-context accounts rather than a model — the same lens Sunspot applies statically today, now over a live transaction, with nothing signed and nothing broadcast.

soundness proofs

Machine-checked soundness

SMT-backed non-interference over the information-flow graph, and explicit Fiat-Shamir transcript checks over proof construction, turning the pattern matches behind CT-4 and CT-6 into checks that return a proof or a concrete counterexample.

Arcium · ZK compression

Arcium circuits and ZK compression

Extend the same lens beyond Token-2022: Arcium's Arcis circuits and encrypted multi-party compute (the reserved MXE rule family), and Light Protocol's ZK-compressed accounts and validity proofs (the ZC family). Confidential compute and confidential scaling, analyzed with one tool.

programmable compliance

Verifiable programmable compliance

An auditor console for selective disclosure: attest that a transfer satisfies a policy without revealing amounts, and give auditors a verifiable view scoped to exactly what the mint intends. The compliance boundary, made checkable.