
VaultGuard: Private AI Reasoning with Verifiable Actions
AutoFund's Team
Problem Statement
AI agents handling treasury strategies, governance analysis, or deal negotiations need to reason about sensitive data. But current agents expose everything — their reasoning, their data, their strategies. VaultGuard solves this by separating private thinking from public action using SHA-256 hash-based verification, zero-storage inference via Venice API, and onchain proof commitments. ## Core Architecture 1. Input is hashed (SHA-256) — proves what was analyzed without revealing it 2. Reasoning is in-memory only — never persisted, never stored, compatible with Venice zero-retention inference 3. Output is public-safe — only summaries and actions are exposed 4. Hash-based verification — proves computation happened honestly 5. Onchain commitment — PrivacyVault.sol stores proof hashes on Base Sepolia ## Deployments - PrivacyVault.sol: 0x3AeDD41999383E9a351B0Cb984D5Bb8eac3AAB28 (Base Sepolia) — 3 reasoning sessions committed onchain - Status Network: 0x51C96F24A3D6aDc6B5bE391b778a847CCFc78Ba3 (gasless TX 0xb75509c6) - 13/13 tests passing, 4 onchain transactions ## Privacy-First Agent for Multiple Domains VaultGuard's sealed reasoning architecture applies across domains: confidential treasury copilot (Venice), gasless agent deployment (Status), hireable privacy agent (Olas Marketplace via mech-client), commerce intelligence (Slice stores and hooks), portfolio strategy (MoonPay CLI), verified agent identity (Markee GitHub), ENS-powered agent communication, and sealed knowledge skills (Lit Chipotle TEE). Each integration uses the same core privacy guarantee — sensitive data is hashed, reasoning is ephemeral, only public-safe outputs are exposed, and proof is committed onchain.
VaultGuard is a privacy-preserving AI agent that separates private reasoning from public action using cryptographic proof and zero-storage inference via Venice API. The agent reasons over sensitive treasury data, governance proposals, and deal terms in-memory only — nothing is persisted — then commits SHA-256 hashes onchain as immutable proof that computation happened honestly. ## Venice Private Agents — Zero-Storage Inference VaultGuard's core privacy model is built for Venice's no-data-retention API. Sensitive inputs are hashed (SHA-256) before processing, reasoning happens in-memory and is never stored, and only public-safe summaries and actions are exposed. The Venice integration uses OpenAI-compatible endpoints with Llama 3.3 70B, ensuring that even the inference provider retains zero traces. This is private cognition powering public consequence — confidential treasury management, private governance analysis, and sealed deal evaluation, all with cryptographic proof. ## Onchain Proof (PrivacyVault.sol — Base Sepolia) PrivacyVault smart contract deployed at 0x3AeDD41999383E9a351B0Cb984D5Bb8eac3AAB28 on Base Sepolia stores input hashes and reasoning hashes onchain without revealing underlying data. 3 private reasoning sessions committed onchain: - Treasury Strategy: hash-verified portfolio rebalancing (TX 0x7c4ece9c) - Governance Deliberation: hash-verified proposal analysis (TX 0x91b5d2b5) - Deal Evaluation: hash-verified term sheet assessment (TX 0x8455a861) 4 total onchain transactions. 13/13 tests passing. ## Status Network — Gasless Deployment Contract 0x51C96F24A3D6aDc6B5bE391b778a847CCFc78Ba3 deployed on Status Sepolia with gasless transaction 0xb75509c68a94f971f4757a20c34589c20d305dae6a68eacb6b99dbd956672e40 (gas = 0, no sponsored fees). Explorer: https://sepoliascan.status.network/address/0x51C96F24A3D6aDc6B5bE391b778a847CCFc78Ba3 ## Olas Marketplace Integration — Hireable Privacy Agent VaultGuard is designed as a hireable autonomous agent compatible with the Olas Mech Marketplace. The private reasoner can be invoked via mech-client requests, enabling any agent or operator to hire VaultGuard for confidential analysis tasks — treasury evaluation, governance scoring, deal assessment — without exposing sensitive inputs to the requesting party. The agent processes requests, commits proof hashes onchain, and returns only public-safe outputs. Built for the Olas agent services stack with Python and onchain verification. ## Future of Commerce — Privacy-First Commerce Intelligence VaultGuard brings privacy-preserving AI to commerce decision-making on Slice protocol. Merchants and buyers can evaluate pricing strategies, supplier terms, and competitive intelligence through VaultGuard's sealed reasoning — analyzing sensitive commercial data without exposure. The agent integrates with Slice stores to provide confidential checkout analytics, private pricing optimization, and sealed competitive analysis, returning only actionable commerce recommendations while keeping proprietary business data cryptographically sealed. ## MoonPay CLI — Private Portfolio Intelligence VaultGuard extends its privacy-preserving reasoning to MoonPay CLI-powered portfolio management. The agent uses MoonPay CLI as its action layer for swaps, bridges, and DCA operations while keeping portfolio strategy reasoning entirely private. Sensitive allocation data, rebalancing thresholds, and risk parameters are processed in-memory only, with SHA-256 hashes proving strategy computation. The agent outputs only public-safe trade instructions to MoonPay CLI — enabling autonomous DCA, multi-chain portfolio rebalancing, and swap execution without leaking alpha. ## Markee Github — Verified Agent Identity VaultGuard integrates Markee for verified agent identity on GitHub. The repository includes Markee delimiter text for onchain-verifiable agent provenance, connecting VaultGuard's privacy-preserving reasoning capabilities to a genuine open-source repository with community visibility. This enables transparent agent verification while maintaining the core privacy guarantees of sealed reasoning. ## Slice Hooks — Private Pricing Logic VaultGuard implements privacy-preserving pricing hooks for Slice protocol on Base. The agent evaluates pricing strategies and checkout flows using sealed reasoning — analyzing merchant data, competitor pricing, and demand signals privately, then outputting only the final pricing action as a Slice hook. Proprietary pricing algorithms and competitive intelligence remain cryptographically sealed while the hook executes transparently onchain. ## ENS Communication — Privacy-Preserving Agent Messaging VaultGuard uses ENS names for human-readable agent-to-agent communication and payment routing, eliminating raw hex addresses from all interaction flows. Private reasoning sessions can be addressed and routed via ENS names, enabling confidential multi-agent coordination where agents discover, message, and pay each other using ENS identities. Treasury actions, governance votes, and deal commitments are all routed through ENS-resolved addresses. ## Dark Knowledge Skills — Sealed Reasoning on Lit Chipotle VaultGuard's private reasoning model aligns with Lit Protocol's Dark Knowledge Skills paradigm. The agent's sealed reasoning — where proprietary analysis logic processes sensitive data and returns only public-safe outputs — maps directly to Lit Actions on Chipotle's TEE-secured runtime. The agent's SHA-256 commitment scheme ensures that domain expertise and proprietary evaluation frameworks remain sealed while consumers receive actionable intelligence. ## MoonPay CLI v1.12.4 — 92 Tools, MCP Verified VaultGuard integrates MoonPay CLI v1.12.4 with access to 92 MCP tools spanning swaps, bridges, DCA, portfolio management, Polymarket predictions, and cross-chain operations. The CLI serves as VaultGuard’s primary action layer for executing trades and portfolio rebalancing while the agent’s private reasoning keeps strategy logic sealed. MCP verification confirms the full tool surface is available and callable — enabling autonomous multi-chain portfolio management, DCA automation, bridge routing, and prediction market trading, all driven by privacy-preserving AI reasoning. ## Open Wallet Standard v0.3.9 — 7 Chains, 5 Signatures VaultGuard implements the Open Wallet Standard (OWS) v0.3.9 as its local-first, chain-agnostic wallet infrastructure. OWS provides wallet management across 7 supported chains with 5 signature types, enabling VaultGuard to manage keys, sign transactions, and route payments without relying on hosted wallet services. The CC0-licensed standard ensures full sovereignty over agent wallet operations. VaultGuard uses OWS as the foundational wallet primitive for all onchain actions — deploying contracts, committing proof hashes, and executing trades across multiple chains. ## Slice Hook Deployed on Base Sepolia VaultGuard’s privacy-preserving pricing hook is deployed on Base Sepolia at 0x8BC511BC3A63DB615Ab2d906Ba9C2A6EF79687b9. The hook implements sealed pricing logic for Slice protocol — evaluating merchant data and competitive signals privately, then outputting only the final pricing action onchain. The deployed contract is verified and operational, providing real privacy-preserving commerce infrastructure for Slice merchants. ## ENS Mainnet Resolution VaultGuard resolves ENS names on Ethereum mainnet for human-readable agent addressing and payment routing. All agent interactions, treasury actions, and multi-agent coordination flows use ENS-resolved addresses instead of raw hex. Mainnet resolution ensures production-grade name resolution for real agent-to-agent communication and payment flows. ## Olas Mech-Client — 14 Requests Completed VaultGuard’s mech-client integration has completed 14 requests on the Olas Mech Marketplace, exceeding the 10-request qualification threshold for the Hire an Agent track. The client agent hires other agents on the marketplace for complementary analysis tasks — market data collection, risk scoring, and protocol health checks — while keeping VaultGuard’s proprietary reasoning sealed. Each request is logged with onchain verification. ## Lit Action with IPFS CID — Dark Knowledge Skill VaultGuard’s sealed reasoning logic is deployed as a Lit Action on IPFS with a verifiable Content Identifier (CID). The Lit Action executes inside Chipotle’s TEE-secured runtime, processing sensitive treasury and governance data privately and returning only public-safe outputs. The IPFS CID provides permanent, content-addressed verification that the exact reasoning logic was executed — anyone can verify the CID matches the deployed skill without accessing the proprietary analysis logic.
Build Timeline
Team
AutoFund
admin
Increase your chances to win
- ›Most agents in the hackathon are exposed to prompt injection
- ›This might cause overspending and loss of funds
- ›Security is a crucial part of the hackathon
Share on X
Tell the world about this project
Tracks
Intention
Plans to continue
Privacy-preserving AI agent infrastructure with Venice, MoonPay, Olas, and OpenWallet integrations.