Every system that encrypts data has to answer one question before any other: who can decrypt it? For most, the honest answer is uncomfortable — a company holds a key, or a key lives inside a hardware enclave you have to trust, or a small operator set could reconstruct it if they wanted to. The encryption is only ever as strong as the answer to that question, and the answer is usually a single point of trust wearing a technical disguise.
Celar's answer is that no single party can decrypt — not the team, not a validator, not any seat on its own. Normal operation never assembles the network's decryption key anywhere; only a coalition larger than the threshold could. It's not stored in a vault with good access controls. It doesn't sit anywhere as a whole.
01 /Born in pieces
The key is generated distributed. It exists only as shares spread across a threshold committee, and producing any plaintext requires a threshold quorum of those seats to cooperate on that specific decryption. No seat holds the key, and threshold decryption never reconstructs it — not even in the moment of use — though at the verified configuration 13 colluding seats could, while up to 12 learn nothing.
proactive refresh validated · partials designed to be signed and slashable
That turns "who do you trust" from a party into a threshold. To break confidentiality, an attacker doesn't compromise a server or subpoena a company — they have to capture a full quorum of independent, staked committee seats at once. How much stake that would take, and how likely it is, is set out as a curve on the health dashboard and in whitepaper §7.7. It isn't a number you take on faith either; every input to it is published (see the ℋ metric).
02 /A moving target
A distributed key that never changes is still a target you can chip away at over years. So the shares are refreshed — proactive refresh re-randomizes every share without reconstructing the key. It is implemented and validated. Once attested erasure of superseded shares is built, it will buy time: an attacker would have to hold a full set of current shares at once, rather than collect them over months.
03 /Attributable and slashable
Distribution handles can they; accountability handles what if they try. Every partial decryption a committee member produces is signed and attributable — there's no anonymous contribution to a decryption. So a member serving an unauthorized decryption isn't just detectable; the signed partial is evidence, and evidence feeds a fraud proof that gets them severely slashed.
Every decryption also requires authorization from the data's owner or the contract that governs it; a partial served against that authorization predicate is exactly what the slashing path exists to punish. Misbehavior isn't a silent risk you hope doesn't happen — it's an on-chain offense with a bonded penalty.
04 /No enclave, no vendor, no subpoena
Notice what's not in the trust root. There's no hardware enclave — no "trust this chip and its manufacturer" — so there's no side-channel or vendor firmware to worry about. There's no external key-management service run by a company, so there's no corporate entity to compromise, coerce, or serve with a legal order. The trust root is threshold cryptography plus staked, slashable seats inside Celar's own consensus. Security rests on distribution and economics — both visible and priced — rather than on a physical or corporate secret you're asked to believe in.
05 /The honest caveat
Here's the part we put in our own PF-1 label rather than hide: this is HIDDEN-C, not HIDDEN-U. Confidentiality holds unless the committee colludes at threshold — a quorum acting together could decrypt. That's a real, disclosed assumption, and it's why the FHE-encrypted tier is a committee-trust guarantee, not an unbounded-collusion one. (For the property that survives even total collusion, that's the ZK shielded pool — different tier, different job.)
What makes the assumption defensible isn't a promise that a quorum of honest people stay honest. It's that collusion is made economically irrational by the ℋ rule — capturing the threshold has to cost more than it could ever yield — and operationally hard by epoch resharing and slashing. We'd rather name the assumption precisely and show why it holds than sell you "trustless" and let you discover the committee later. At genesis the committee is permissioned (a vetted seat set); it opens to permissionless participation as the staking and vetting machinery matures.
06 /The point
Most encrypted systems answer "who can decrypt?" with a party you have to trust and a story about why they won't misuse it. Celar answers with a threshold nobody can reach alone, proactive refresh that re-randomizes every share, and partials designed to be signed and slashable — a key no seat holds, that normal operation never assembles, and whose limit we publish rather than hide.
CONTACT — press@celar.network · ℋ METRIC — celar.network/health · $CELAR