Privacy for Tokenized Securities: Confidential, Auditable
On September 1, 2026, the SEC proposed the first substantive update to its transfer agent rules since they were adopted in the late 1970s and early 1980s, and the fact sheet names blockchain-based recordkeeping as one reason. The proposal treats a ledger as a legitimate place to keep an ownership record. It leaves a harder design question to the market: privacy for tokenized securities. A fund manager who rebalances a tokenized real estate or commodity position on a public ledger can publish their book to every competitor in the same block that settles the trade.
Why transparency became a cost at institutional size
Public ledgers earned their credibility by being readable. Anyone can check that a transfer happened, that a supply figure is correct, that a reserve wallet holds what its operator says. For real-world assets, that readability is a large part of the value: settlement that finishes in minutes, records that reconcile themselves, and data an investor can verify without asking the issuer.
The same property becomes expensive once the holders are institutions. Addresses on a public network are pseudonymous, not anonymous. Once a wallet is tied to a fund, by a disclosed transaction, a counterparty or simple pattern analysis, every past and future movement of that wallet is attributable. A manager building a position in a tokenized office portfolio shows the market their accumulation in real time. A manager selling shows their exit before it is finished.
Traditional markets solved this decades ago with layered visibility. The registrar knows who owns what. The regulator can ask. The market sees prices and aggregate volume, and in some venues not even that until after the trade. It is the normal condition under which large holders agree to trade at all.
The Bank for International Settlements framed the other side of the problem in its 2025 annual report: pseudonymity on public blockchains can preserve privacy, but it also facilitates illicit use. Institutional design has to resolve both halves at once. Too little confidentiality and serious holders stay away. Too much and the instrument stops being a supervised security.
Retail privacy hides everything. Securities need the reverse.
Most privacy technology on public networks was built for payments between individuals. The design goal is that no observer, including the operator, can link sender, receiver and amount. Shielded pools on Ethereum and its scaling networks work this way: a user moves funds into a pool, transacts inside it privately, and later withdraws.
Two things about that model do not fit regulated assets.
First, the privacy is partial in the wrong places. In typical shielded-pool designs, the deposit into the pool and the withdrawal out of it remain visible on the public ledger. An observer may not see what happens inside, but they can see that a known fund wallet moved a known amount in on Tuesday and a similar amount came out on Thursday. For a consumer payment, that leak is tolerable. For a manager rebalancing a nine-figure real-asset allocation, the entry and exit are the information. Timing and size are exactly what a counterparty would trade against.
Second, the privacy is total in the wrong places. A tokenized fund unit or property interest is a security with a legal owner of record. The SEC's proposing release describes the master securityholder file as the authoritative record of who owns an issuer's securities, and it would require that record to carry each holder's full name and a physical mailing address, with a digital wallet address as additional identifying information for a tokenized security. A system in which nobody can see who holds what cannot support that record, cannot pay a distribution to the right person, and cannot restore a holder who loses access.
So the requirement runs opposite to retail privacy. Positions and counterparties should be hidden from the market and fully visible to the parties with a duty to see them: the transfer agent, the auditor, the regulator, and the holder. Confidential to the public, auditable to the accountable.
Four requirements for an institutional-grade model
No single technology settles this, and performance claims for specific privacy systems deserve independent verification before anyone relies on them. The requirements, though, are stable enough to state.
Selective disclosure with defined roles. Each participant sees what their role entitles them to and nothing more. A holder sees their own position. A counterparty sees the trade they are party to. An auditor sees the full register for the period under review. A regulator can obtain what the law allows. Access should be scoped, logged and revocable, so that disclosure itself leaves a trail.
A holder registry kept apart from public ledger data. The legal ownership record, with names and addresses, should not live in public view. The SEC proposal points in this direction. It leaves the choice of technology for the master securityholder file to the transfer agent, on the condition that the agent "maintains at all times exclusive control" over it, and it asks commenters whether the rules adequately support systems that associate onchain records such as wallet address and quantity with offchain records such as name and address. The pattern that follows is a ledger that moves the asset and a controlled registry that knows who the holder is, linked so that one transfer updates both. We set out how those layers fit together in how asset tokenization works across the full stack.
Attestations that prove facts without exposing positions. An investor in tokenized bullion wants to know the bars exist. A lender wants to know collateral is unencumbered. A fund's investors want to know total units outstanding match the assets held. None of those questions requires publishing who owns how much. Reserve and supply attestations can confirm aggregate facts on a schedule, and cryptographic proofs can show that a hidden balance satisfies a condition, such as being sufficient for a trade, without revealing the number. The mechanics of the reserve side are covered in what proof of reserve means for real-world assets.
Transfer rules that still run when data is hidden. Eligibility checks, holding periods and jurisdiction limits have to execute at the moment of transfer. If amounts and parties are concealed from the network, the system needs a way to show that the rules were satisfied anyway. Otherwise confidentiality is bought at the price of the controls that make the asset a recognized security.
What partial privacy costs a real-asset manager
Consider a manager running a multi-asset real-asset sleeve: tokenized interests in a logistics portfolio, a gold position, and a block of carbon credits held for corporate clients. Quarter-end requires trimming property and adding bullion.
On a fully transparent ledger, each leg is visible as it settles. Property interests trade thinly, so a visible seller of size moves the price against themselves. With deposit-and-withdraw privacy, the internal transfers are hidden, but the movement of the manager's known wallet into and out of the shielded environment still signals that a rebalance is under way, and roughly how large. The manager has paid for privacy and still leaked the trade.
With role-based confidentiality, the outcome differs at each layer. The market sees that a transfer settled and that aggregate supply is unchanged. The counterparty sees their side. The transfer agent's registry updates and remains complete. At year-end, the auditor is granted a view of the whole period. The manager's clients receive verifiable statements of their own holdings.
This is also what makes on-chain liquidity for private assets plausible at size. Secondary markets in property, credit and commodity interests are thin by nature. Thin markets punish visible intent. A venue where large holders can trade without advertising it is a precondition for them to quote at all.
What allocators and issuers should ask now
The SEC proposal is open for comment for 60 days after publication in the Federal Register, and its final shape is not settled. The questions it raises are useful regardless of outcome, and they apply to any issuance happening this year.
For allocators: who can see my position, and under what authority? Is the holder registry separate from the public ledger, and who controls it? What does an observer learn from my entry and exit, not only from activity in between? Are reserve and supply attestations independent, scheduled and published? If I need to prove a holding to my own auditor, can I do so without exposing it to anyone else?
For issuers and sponsors: can distributions, restrictions and holder recovery all operate with confidentiality switched on? Is every disclosure to a third party logged?
Commertize's view as a digital capital markets platform is that confidentiality and verifiability are not a trade-off to be split down the middle. Investors browsing the marketplace should be able to verify the asset, the reserves and the rules in public while their own position stays their own business. The markets that attract institutional size will be the ones that deliver both at once.
Prefer email? Send the offering memo or a short asset summary to deals@commertize.com. We reply within one business day, with no obligation to engage us.