CAPPZ.AI : Trust, Fidelity & Provenance

CAPPZ keeps both sides of a business document on the same version — orders, claims, records and confirmations — without a required central message hub for peer sync.

LIVE PATTERN · CAPPZ REPLICATOR

The middleware hub just became optional. Parties synchronize directly. Contracts, applications, data, and shared multi-master state bilaterally replicated, peer to peer.

  • 1 WHISPER (UDP BEACON · PAIRING CODE)
  • 2 PUBLISH HEADERS
  • 3 DISCOVER MISSING STATE
  • 4 SYNCOFFERED ↔ SYNCREQUESTED
  • 5 ENCRYPTED A2A BLOCKS
  • 6 HASHES VERIFIED
  • 7 HEADS CONVERGED
  • 8 HIGH QOS CHECKSUM DELIVERY · HASH-PRINT RECEIPT

REAL-WORLD DEMO

Two wallet copies, two tabs. Create an ISO 20022 payment in one and watch it verify and converge in the other.

CAPPZ.AI : Trust, Fidelity & Provenance

Keep both sides of a business document on the same version.

CAPPZ helps your systems and partners exchange orders, claims, records and confirmations, keep their copies in sync, and trace what changed. Your documents can stay on your device or in your data center; a central message hub is not required for peer message sync.

  • Works with the documents you already send.
  • Keeps the payload where you run it.
  • Shows the history of changes.

Receive the document. Apply its map and process. Keep both sides current.

Existing message flows receive a document, transform it, route it, and track its lifecycle. CAPPZ keeps the document and its change history with the copies that need it; a central hub is optional for peer message sync.

For existing BizTalk estates, start with one real flow and assess its maps, partner exceptions and recovery requirements before moving traffic.

How the wallet, event bus and governance work →

The support clock is running. Your payments cannot miss a beat.

BizTalk Server 2020 mainstream support ends April 2028; extended support ends April 2030. For banks, treasuries, utilities and their systems integrators, the harder deadline is losing the people who know each map and partner exception. Start with one critical corridor while there is still time to prove the move.

A missing change? The other copy catches up.

Replicator finds missing records and reconciles copies directly. The payload stays with its owners; the message path does not require a central hub. Account sign-in and hosted functions remain separate services.

Explore Replicator →

Whisper to find. Connect to move.

Discovery whispers, transfer connects. Peers find each other by UDP beacon, relay rendezvous, pairing code or wallet breadcrumbs, then move the same signed, checksummed frames over TCP, QUIC, WebRTC, a WebSocket bridge or a USB bundle. No host in the middle, no browser required.

  • UDP beacon
  • Relay rendezvous
  • Pairing code
  • Wallet breadcrumbs
  • Transport
  • Runs on
  • NAT
  • Offline
  • TCP
  • Standalone node
  • Needs a reachable port
  • LAN
  • QUIC
  • Standalone node
  • NAT-friendly (UDP)
  • LAN
  • WebRTC
  • Browser
  • Hole-punching
  • LAN
  • WebSocket bridge
  • Browser → local node
  • Localhost only
  • Yes
  • USB bundle
  • Anywhere
  • n/a
  • Air-gap

A read-only XRPL connector watches validated ledger headers and checks anchoring proofs itself — no hosted verifier, and it never submits transactions.

Borrowed from Bitcoin: the peer pattern. Left behind: proof-of-work and global broadcast.

# standalone Replicator edge node (Deno) CAPPZ_POW=<your POW> \ CAPPZ_TLS_CERT=cert.pem CAPPZ_TLS_KEY=key.pem \ deno run --allow-net --allow-read --unstable-net \ packages/cappz-edge-node/main.ts --tcp 41441 --quic 41443 --ws 41442

EXPLAINER · THE CAPPZ REPLICATOR IN 40 SECONDS · TEMPORARY NARRATION

Same spine. Different schema.

Your underlyer settles. CAPPZ is the color.

If value moves, it moves in the underlyer you already use — internal settlement coin, custodian-network coin, or a stable of your choosing.

CAPPZ colors that movement: who, which document, which prior transaction, which constraint.

If no value moves, the color still binds identity and provenance to the document.

Device, data center, private network.

Banks, hospitals, and agencies that cannot put the document in the general cloud keep the payload on-prem.

Models can switch. The graph is the memory.

Build on the spine. Keep the proof.

The typed SDK exposes wallet-copy sync, on-chain skill discovery, and PrinciplesChainlet governance through live in-repository entry points.

Use the same functions the CAPPZ interface runs, with examples for bootstrap, reconciliation, and principle-hash verification.

Explore the CAPPZ SDK →

18 named models. One governed choice.

CAPPZ is model-independent. The title-bar picker writes the operator’s choice as a hash-sealed ModelSelected transaction; every app replays that same latest-wins record. Auto preserves both a cloud and local target, then routes from the selected primary slot.

Cloud · Lovable AI Gateway

Nine verified Google and OpenAI choices. Auto can keep one as the cloud primary or fallback.

  • Gemini 3.7 Flash google/gemini-3.7-flash · Google · fast
  • Gemini 3.1 Flash Lite google/gemini-3.1-flash-lite · Google · fast
  • Gemini 3.1 Pro (Preview) google/gemini-3.1-pro-preview · Google · premium
  • GPT-5.6 Luna openai/gpt-5.6-luna · OpenAI · fast
  • GPT-5.6 Terra openai/gpt-5.6-terra · OpenAI · standard
  • GPT-5.6 Sol openai/gpt-5.6-sol · OpenAI · premium
  • GPT-5.5 openai/gpt-5.5 · OpenAI · premium
  • GPT-5.4 Mini openai/gpt-5.4-mini · OpenAI · standard
  • ChatGPT (Instant) openai/chat-latest · OpenAI · standard

On this machine · Ollama / LM Studio

These starters seed the model wallet. Runtime discovery also exposes any other model installed on the operator’s endpoint.

  • Kimi K2 (Moonshot, open weights) kimi-k2:latest · open weights · local
  • Qwen 3 qwen3:latest · open weights · local
  • DeepSeek R1 deepseek-r1:latest · open weights · local
  • Llama 3 llama3:latest · open weights · local
  • Mistral mistral:latest · open weights · local

In this browser · WebGPU

Wallet-published browser models show download and local weight-custody status before execution.

  • Llama 3.2 3B (WebGPU) Llama-3.2-3B-Instruct-q4f32_1-MLC · WebGPU · local
  • Llama 3.2 1B (WebGPU) Llama-3.2-1B-Instruct-q4f32_1-MLC · WebGPU · local
  • Qwen 2.5 1.5B (WebGPU) Qwen2.5-1.5B-Instruct-q4f16_1-MLC · WebGPU · local
  • Phi-3 mini (WebGPU) Phi-3-mini-4k-instruct-q4f16_1-MLC · WebGPU · local

Visible, not enabled

These rows are deliberately disabled. They are not sent to Lovable AI Gateway and are not selectable today.

“We applied CAPPZ to Lovable, ChatGPT and Claude” describes the development environments where the discipline was forged. It is not the runtime catalog: ChatGPT is selectable now; Claude remains a visible, disabled bring-your-own-key entry.

Questions, answered plainly.

Q1. What is CAPPZ?

Q2. Is this a banking product?

Q3. Is CAPPZ Agent-to-Agent chat?

Q4. What moves?

Q5. Don’t those messages need merge logic?

Q6. What is a chainlet?

Q7. What does this have to do with x402?

Q8. What is the color overlay?

Q9. How does this relate to BizTalk?

Q10. How does this relate to BitLocker?

Q11. Does CAPPZ replace IBM MQ or MuleSoft?

Q12. Must there be a hosted relay?

Q13. Can it run in a bank or hospital data center?

Q14. Can two devices sync with no host and no browser?

Q15. Where does the model run?

Q16. What is COTA?

Q17. How is it sold?

Q18. What should someone see first?

Example corpus: the Bible Codex

Five canons. Multiple languages. Every verse a notarized HD node — the same spine applied to a document collection.

Bible Codex

Apply to your domain

See the codex live

Browse canons, traverse equivalencies, inspect notarization TXs.

92 skills in inventory. The skill catalog is inventory; the spine is the product.

Every binding pays. No operator required.

Every skill binding emits a fee event to the Royalty Flywheel — 777 CAPPZ + TX fee, split on-chain. Distributions to skill authors, template owners, and treasury happen automatically. Transaction-sourced royalty configs are inherited by every cloned wallet.

Direct royalty to the wallet that authored each bound skill.

To the wallet that owns the cloned template lineage.

Funds the substrate — no operator needed.

Q&A

What is CAPPZ?

A wallet-native document spine. Each application is a wallet. The wallet holds the message, the map, and the lifecycle. Copies of that wallet reconcile with each other. Message sync is peer-path. Relay remains optional for discovery and offline pickup. Sign-in/admin may still be hosted. The document does not have to live on a vendor bus or in the public cloud.

Is this a banking product?

No. Banking is one corridor. Every vertical that already exchanges documents is in scope — the same way BizTalk and BitLocker were infrastructure, not industry apps.

Is CAPPZ Agent-to-Agent chat?

No. Open A2A is task messaging between agents. CAPPZ A2A state sync is replica reconciliation: wallet copies exchange append-only blocks so both sides hold the same object. Chat is only a control surface.

What moves?

Full documents. ISO 20022, FpML, FIX, AL3, HL7, EDI, plus contracts, claims, work orders, titles, filings, telemetry batches. Not chat transcripts. Not field patches.

Don’t those messages need merge logic?

No. The standards specified supersession. Cancel-replace is a new full message correlated to the original. The amendment has full fidelity and deprecates the previous message. Ack, confirm, execution report, amend, terminate are known flows. Resident BPMN runs them. XSLT or an equivalent map transforms the XML.

What is a chainlet?

A local micro-ledger per session or topic. Blocks stay on the wallet. Heads can move peer-to-peer. Public-chain anchors are optional and carry lifecycle or dispute hashes, not the payload.

What does this have to do with x402?

x402 pays for a request. It does not keep both parties on the same object after payment. CAPPZ binds settlement to a message hash in the chain. Pay on the underlyer; prove the document on the color.

What is the color overlay?

The underlyer is whatever the estate already settles in — or nothing, if the corridor is documents only. CAPPZ does not replace that coin. It colors the event: wallet, document, prior transaction, constraint, fee split if any.

How does this relate to BizTalk?

BizTalk was maps, orchestrations, pub/sub, and adapters. Azure Logic Apps rehosted those parts and kept the hub. CAPPZ keeps schema, map, correlation, and orchestration-as-BPMN next to the document in the wallet. The hub becomes optional.

How does this relate to BitLocker?

BitLocker protects a volume on the device. CAPPZ protects and proves the artifact in a local container: identity, integrity, and policy at the object, not only encryption of the disk. Same class of primitive. Different layer.

Does CAPPZ replace IBM MQ or MuleSoft?

Not as the first move. MQ can still carry bytes. MuleSoft can still expose APIs. CAPPZ replaces the hub as system of record for the document. First estates are corridors leaving BizTalk, EDI VANs, and point-to-point confirmation matching.

Must there be a hosted relay?

Message sync is peer-path. Relay remains optional for discovery and offline pickup. Sign-in/admin may still be hosted. Two copies can pull missing blocks on a channel derived from both wallet keys. Only hashes need a public trail; the document spine does not require a relay.

Where does the serverless part live?

Hosted functions remain wherever a secret, a third-party webhook, a privacy boundary, or a timer requires a server — the rest is facade-intercepted and runs in your wallet. The live hosted set is small and named: sign-in, the public agent door, Inquiry & Feedback, payments and XRPL anchoring, and calendar or notification timers. Legacy hosted functions are archived as internal ops.

Can it run in a bank or hospital data center?

Yes. That is a deploy mode, not the product definition. Regulated estates keep the payload on-prem. Other estates may use a private network or a device. GDPR and outsourcing rules are why the general cloud is optional, not mandatory.

Can two devices sync with no host and no browser?

Yes. A standalone edge node finds peers by UDP beacon or pairing code, then moves the same signed, checksummed frames over TCP or QUIC. Browsers use WebRTC or ride a local node over a WebSocket bridge; air-gapped sites carry a signed USB bundle. A read-only XRPL connector checks anchoring proofs without a hosted verifier.

Where does the model run?

The graph is the memory. Models are interchangeable — local, cloud, or auto. Hand-off is addresses and a scoped fact sheet, not the document.

What is COTA?

The constitution on invocation: identity, provenance, zero-trust execution, no-harm. It governs the flow. It is not the settlement asset.

How is it sold?

Infrastructure license and maintenance for the spine, maps, and on-prem runtime. Application charges, if any, settle in the estate’s underlyer. The CAPPZ token is not the bank’s money and is not the hero offer.

What should someone see first?

/replicator: copies reconcile from replication records. A copy that lacks blocks posts to its in-queue; the source answers on the key-derived channel. That page is the product. The skill catalog is inventory.

Keep both sides on the same document version

CAPPZ.AI : Trust, Fidelity & Provenance. CAPPZ helps systems and partners exchange orders, claims, records and confirmations, keep their copies in sync, and trace what changed. The document payload can stay on the device or in a data center; a central hub is not required for peer message sync.

The CAPPZ SDK exposes typed wallet-copy sync, on-chain skill discovery, and PrinciplesChainlet governance through live in-repository entry points. Its examples cover bootstrap, reconciliation, and principle-hash verification.

CAPPZ A2A state sync is replica reconciliation rather than agent chat: wallet copies exchange append-only blocks so both sides hold the same object. The same spine carries ISO 20022, FpML, FIX, AL3, HL7 and EDI documents while the payload can remain on the device, in a data center or on a private network.

BizTalk Server 2020 mainstream support ends in April 2028 and extended support ends in April 2030. Banks, corporate treasuries, utilities and systems integrators can begin with one corridor assessment at /gtm/biztalk-migration. A local wallet proof can unlock sign-in without a hosted account, while hosted function lookup and admin routes remain distinct dependencies.