> For the complete documentation index, see [llms.txt](https://docs.nullmask.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.nullmask.io/compliance/revocation-keys.md).

# Revocation Keys

Revocation keys enable retrospective taint recovery — a mechanism unique to Nullmask that addresses the problem of funds being tainted after they've entered the privacy pool.

## The Problem

In existing privacy protocols (e.g., Railgun), once tainted funds enter the pool, there is no way for users to disassociate from them. The entire pool remains tainted indefinitely.

## Nullmask's Solution

The guard publishes a **revocation key pair** with each approved deposit:

* The **public key** (`revocationPublicKeyX`, `revocationPublicKeyY`) is published in the `Deposit` event
* The **public key hash** is used as the `value_trapdoor` in the deposit note commitment

Each Nullmask note includes encrypted information about the deposits that funded it.

## Retrospective Taint Recovery

If a deposit is flagged as tainted after approval:

1. The guard publishes the **secret key** corresponding to the revocation public key
2. Each protocol participant can use this key to:
   * Determine if their notes were funded by the tainted deposit
   * If not tainted: generate a proof of disassociation
   * If tainted: verifiably clean the rest of their untainted balance

## Comparison

| Protocol      | Retrospective Taint Handling                                                     |
| ------------- | -------------------------------------------------------------------------------- |
| Railgun       | No mechanism — pool remains tainted indefinitely                                 |
| Privacy Pools | Exclusion proofs + retrospective compliance, but no shielded transfers available |
| **Nullmask**  | Revocation keys enable targeted taint recovery                                   |

This mechanism ensures that even if some tainted funds enter the pool, individual users can prove their funds are clean, and the pool can recover from tainted deposits.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.nullmask.io/compliance/revocation-keys.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
