SatyaStack
Privacy-preserving zero-knowledge compliance infrastructure for India
Founder & Software Architect2025 — Present
The Problem
India's Digital Personal Data Protection Act conflicts with AML/KYC requirements — businesses must verify compliance without storing or exposing personal data. Traditional solutions leak PII across trust boundaries.
Overview
Built to verify regulatory compliance (KYC, sanctions, solvency) without exposing PII, addressing the conflict between India's DPDP Act and AML/KYC requirements. Uses PLONK/KZG proofs with Noir circuits for on-chain and off-chain verification.
Architecture
Trust boundary model with zero PII crossing verification boundary. Dual Sparse Merkle Tree for revocation, QLDB for audit trail, DynamoDB for state. Path-triggered CI/CD with per-service deployments.
Mobile Vault
DigiLocker
Issuer Service
Noir Circuits
Verifier (Rust)
Sparse Merkle Tree
DynamoDB
QLDB Audit
AWS Infra
Key Highlights
- 1Designed ZK circuit architecture using PLONK (KZG) with Noir for KYC membership, sanctions, and age-range proofs
- 2Built issuer service (Java/Spring Boot) and verifier service (Rust/Axum) with strict PII isolation
- 3Implemented mobile credential vault in Flutter with native FFI to Rust prover
- 4Multi-language SDK suite (TypeScript, Java, C#, Python) auto-generated from OpenAPI specs
- 5Infrastructure provisioned via Terraform across dev/stage/prod AWS environments
Tech Stack
NoirRustSpring BootFlutterAWSTerraformDynamoDBQLDBWASM