JefferyAkorful.sol

Work / NoxEscrow

NoxEscrow

Confidential milestone escrow; an AI arbiter inside an Intel TDX enclave settles disputes.

  • Sepolia testnet
  • Privacy
  • AI agents
  • Solidity
  • iExec Nox
  • ERC-7984

ETH Sepolia.

// how it works
// proof

Tests

$ npx hardhat test
test cases
18

Refuse paths (custom-error boundaries) and scripted multi-milestone scenarios. No stateful fuzzing or invariant suite.

Deployed

Sepolia testnet No mainnet deployment.

Counted from NoxEscrow@651a042 on 2026-10-05. Addresses from dApp/src/contracts/addresses.json, each checked onchain; explorer verification checked 2026-10-05.

# NoxEscrow// the record

Milestone escrow where the money and the work stay private. Budgets are held as an ERC‑7984 confidential token, requirements and deliverables are encrypted, and disputes go to an AI arbiter running inside an Intel TDX enclave.

  1. 01

    One escrow key per contract protects requirements, deliverables, chat and reviews.

  2. 02

    The arbiter gets transient read access through the onchain ACL and returns PAY_FREELANCER or REFUND_CLIENT.

  3. 03

    Prompt-injection defence: the parties' statements are sandboxed as untrusted evidence.

  4. 04

    Reviews are double-blind, revealed only when both sides submit or after 14 days.

// beat by beat
  1. DraftClient

    The client drafts an escrow from the app's Smart Contract Audit template: two milestones, 3,500 cUSDC.

  2. LockClient

    Terms are encrypted in the browser, an escrow clone is deployed and the budget is locked. Explorers only see encrypted handles.

    • callinitializeEscrow(payouts, proofs, reqs, proofs)L102
    • eventContractInitialized(client, freelancer, 2)L141
  3. DeliverFreelancer

    The freelancer submits the deliverable. It is encrypted client-side before it leaves the browser.

    • callsubmitDeliverable(deliverableHash, proof)L144
    • eventDeliverableSubmitted(0, ⟨encrypted⟩)L166
  4. Break itFreelancer

    The freelancer tries to release their own payout while the client's review window is still open. The contract refuses.

    • callreleaseMilestone(…) from freelancerL169
    • revertReviewWindowNotExpired()L179
  5. ReleaseClient

    The client reviews, rates five stars and releases milestone 1. Payout and reputation update onchain.

    • callreleaseMilestone(5)L169
    • eventMilestoneApproved(0)L197
  6. DisputeClient

    Milestone 2 is contested. Raising a dispute grants the TEE arbiter read access to the encrypted terms and work.

    • callraiseDispute()L230
    • eventDisputeOpened(1, ⟨reqs⟩, ⟨deliverable⟩)L261
  7. VerdictTEE arbiter

    Inside an Intel TDX enclave the AI arbiter decrypts both sides, scores compliance and the contract settles.

    • callresolveDispute(true) from TEE arbiterL264
    • eventDisputeResolved(1, true)L285