The protocol and its layers
Orbital as the first onchain privacy layer for Orbio: a proof layer, an agent layer and a settlement layer, and what crosses between them.
Privacy onchain has mostly meant hiding balances and transfers. Orbital hides the other thing builders keep private: the code. It does it as a protocol in three layers, each with one job, and the source never crosses from one layer to the next.
Layer 1: proof
Eight fixed checks run on the compiled bytecode: no hidden mint, no owner drain, tax under the cap, no blacklist, no pause on transfer, not upgradeable, sell path clears, no self-destruct. Each answer is a yes or a no, bound to the keccak256 of the runtime bytecode. The checks are deterministic, public and the same for everyone. Today they are signed by the auditor; the target is to prove them inside a zkVM (see The proof).
What leaves this layer: the hash and eight answers.
Layer 2: agent
An AI auditor agent reads the source in isolation. It runs through Orbio, which routes only to zero-data-retention endpoints, so the model that reads the source keeps nothing (see Built on Orbio). It describes what the code does, who holds which powers and what looks off, and returns a risk verdict that feeds the score. It never quotes the code. The auditor signs its output together with the hash and the answers, and the seal labels it as an opinion, apart from the proof.
This is what makes Orbital agentic: the only reader of the source is an agent, not a person and not the public. When the review is done the tree is deleted.
What leaves this layer: a signed review text and a verdict.
Layer 3: settlement
The registry on Robinhood Chain (0xeaDdD9E4dA832395BDCcD658e9EaCD1725ddFeEA) writes the seal against the code hash, holds the auditor's stake behind it, splits the fee and pays the cover pool when a claim passes. See Auditors and stake and Claims and cover.
What leaves this layer: a public record anyone can read, badge(codehash) and sealOf(codehash).
Agents as users
Agents sit on both sides of the seal.
- Agents that build (coding agents, launch bots) ask for a review of their own repository before they deploy, and launch with the mark without publishing their edge.
- Agents that trade read
badge(codehash)on the registry before they buy. No source to parse and no report to trust: a hash in, a score and eight answers out. See Reading a seal.
What the layers do not do
The agent layer is an opinion, and it can be wrong. Nothing in the protocol proves that a model read the code well; only the checks in layer 1 are meant to be proven. Read What a seal cannot see before trusting the mark.