Notarized everything. Zero-trust. Zero deep fakes.
Download the CAPPZ pitch materials.
CAPPZ.AI — A TRUSTWORTHY AUTONOMOUS AGENT PLATFORM FOR DATA, CONTENT, AND APPLICATIONS.
Be COOL and COPE.
Rapidly assemble apps from 88 skills. Run anywhere — autonomously and redundantly. From the silicon enclave to the agent, one notarized graph.
Eleven stack components — Decentralized Identity For All (DIFA), notarization, wallet-as-container, lifecycle administration, embedded AI agent, on-chain ontology, BPMN, RepoZ, CPM, Claude/MCP, silicon primitives — one substrate. All legacy cloud apps must be rebuilt decentralized with zero-trust protections. All digital code and content must be notarized and operated on blockchain rails for payments, permissions, and operations. Pick the lane that maps to your hardware, your corpus, or your tool plane — the recipe stays the same.
Every app is a wallet.
One container holds the app's HD root, embedded admin agent, included skills, notarized TX graph, and cappz-store cache. Every partnership lane below plugs into this one shape.
Every app on CAPPZ is this container. Every included skill is itself another container. Recursion terminates at substrate primitives.
A wallet container holds the app's HD root, embedded admin agent, included skills, notarized TX graph, and cappz-store cache. That's the whole app.
Eleven steps. One substrate.
From identity to silicon — every layer of the platform composed as notarized transactions on wallet-addressed rails.
People, places, things. Credentials, code, models, data, and existing contracts in any format — each given a blockchain address as identity and residence in a wallet at that address.
Hashprint everything, placed on transactions sent to the target address for anyone to verify content fidelity. The blockchain is the anonymous registry.
HD root, embedded admin agent, included skills, notarized TX graph, cappz-storage cache, and chainlets. The container is the app.
Every app on CAPPZ is this container. Every included skill is itself another container. Recursion terminates at substrate primitives.
Created, Amended, Included, Deprecated — all lifecycle and business events flow as a graph of metadata-enriched transactions.
Prompt interface. The agent administers content versioning, access control, cloning/copying, TX-defined royalty collection and distribution, process execution, analytics, and Agent-to-Agent state synchronization (A2A).
Application and content ontology graph defined on-chain, serving as reference data and application scope anchor. No AI drift. No hallucinations. All history preserved in the learning tree of knowledge.
Capabilities executed by the resident agent running the BPMN engine as a skill. BPMNs define the exposed edge functions of each skill.
Runs parallel to GitHub/GitLab or replaces them entirely. HD-addressed, multi-master, notarized.
On-chain TX manifest of constituents. Hash-verified bundles. No rogue supply chain.
Every skill is exposed as a governed MCP tool. Manifest at /.well-known/mcp.json. Royalty events fire on tool invocation.
ARM instructions will eventually secure devices regardless of operating system or apps — anchoring wallet key operations in the silicon enclave.
Ship an app in an afternoon by binding skills.
No servers to stand up. No supply chain to vet. Clone a template, bind skills from the 88-skill library, and the embedded agent wires the rest — governed by BPMN, notarized on deploy.
Clone from an on-chain registered template (ontology + BPMN + edge functions included).
Compose from 88 governed skills. Each carries its own ontology, BPMN, and scope.
Embedded admin agent boots, resolves dependencies from chain, and enters COPE-crystallized state.
Build artifacts, prompts, and datasets anchored via Twin-TX. Provenance from the first boot.
Every binding pays. No operator required.
Every skill binding emits a fee event to the Royalty Flywheel — 777 CAPPZ + TX fee, split on-chain. Distributions to skill authors, template owners, and treasury happen automatically. Transaction-sourced royalty configs are inherited by every cloned wallet.
Direct royalty to the wallet that authored each bound skill.
To the wallet that owns the cloned template lineage.
Funds the substrate — no operator needed.
Generative AI is brilliant — and unreliable.
Without a pinned external ontology, every model session re-derives the world. Vocabulary drifts. Schemas amnesia in. APIs hallucinate. The fix is structural, not statistical.
From drift to discipline.
We applied CAPPZ to Lovable, chatGPT and Claude to prevent hallucinations and drift. Let me speak plainly. AI outright lied about what it accomplished by implementing fake output from non-functional code and operations. Houston - we have a problem! Hallucinating APIs. Forgetting schemas. Renaming our own vocabulary mid-session. Then we anchored everything to an on-chain ontology — and the drift stopped.
Statistical, not anchored
- × Hallucinated API surfaces, week over week
- × Vocabulary drift — same concept, three names
- × Schema amnesia between sessions
- × Tool-call inconsistency across runs
- × Provenance loss — who said what, when?
LLMs re-derive the world from scratch
Without an external pinned ontology, every session reinvents vocabulary, schemas, and shape. The model is statistical. The world is not. The fix is to give the model a graph it cannot move.
Cognitive Ontological Oriented Learning (COOL) + COPE
- ✓ Anchored — every entity at a deterministic HD address
- ✓ Identified — every artifact in a wallet with COPE lifecycle
- ✓ Named — modal-free identifiers (AX-92)
- ✓ Verified — 92 axioms · 22 anti-patterns · 80+ event types
“If Cognitive Ontological Oriented Learning (COOL) and Cognitive Object Permanence Experiences (COPE) could discipline the two best AI tools on the planet, they will discipline yours.”
Yes, on-chain is fast.
Notarized on chain. Resolved at L1-cache speed.
Every COOL node is a wallet at a deterministic HD address. The hot working set lives in an in-memory graphology cache, hydrated from chainlet partitions, invalidated by event TXs, rebuilt offline-first from durable wallet blocks. Verifiable, traversable, and embarrassingly fast.
O(1) node lookup
O(degree) traversal
Reactive invalidation
Wallet-first hydration
Single-writer safety
Durable recovery
Verifiable
Offline-first
Notarized graph cache — every read verifiable, every hit at L1-cache speed AX-63 · AX-68 · AX-69 · AX-70 · AX-71 · AX-73 · AX-74 · AX-87
Before / After — internal measurements
The substrate, at a glance.
COOL — Cognitive Ontological Oriented Learning. Every node a wallet, every edge a notarized TX. AX-87 · AX-92
Five wallets, one substrate — each die has its own HD root and on-chain lifecycle admin AX-74 · COPE
The repeatable recipe — Notarize → HD-Address → Govern → Royalty AX-63 · AX-68 · AX-92 · AX-67
Agents are simple. The harness is the wallet.
The agent writes, BPMN executes, COPE decides — and every decision is a signed event held in the wallet it came from.
The CAPPZ Harness — the wallet holds explicit state, COPE answers the per-turn questions, BPMN runs the work, and every decision ends as a notarized event. AX-57 · AX-74 · AX-97 · COPE
Every routing, visibility and permission decision is a replayable transaction — ready for regulated buyers.
Sensitive work runs on local models inside the user wallet; only addresses ever cross to the cloud.
The same harness runs contracts and payouts, canon corpora, supply chain and code.
The receiving model reloads the whole conversation, and so does the model it hands back to.
The receiving model gets HD addresses and a scoped fact sheet, then resolves only what it needs from the graph cache.
Residency-aware routing — work goes where the context lives. Hand-offs pass addresses, never whole transcripts, so switching models does not mean re-reading everything. Wallet-host residency · PTW → POW → UPW
- DIMENSION
- JEV (PER PUBLIC BLUEPRINT)
- CAPPZ HARNESS
- Decisions
- Typed answers with probabilities, used within the session
- Typed answers notarized as signed event transactions — replayable and auditable later
- State after restart
- Explicit typed chunk store inside the harness
- State lives in the user's own wallet — portable across devices, works offline, outlives the app
- Trust routing
- File-sensitivity score picks first-party vs cheaper models
- Routing by data ownership and residency, including fully local models (Ollama / in-browser) with no cloud hop
- Policy
- Programmable allow / ask / deny command policies
- Allow / ask / deny plus hash-verified governing principles (COPE) on every action
Jev's column is limited to what its public blueprint describes. The CAPPZ column lists shipped platform capabilities. The advantages are our interpretation. No speed or cost multipliers are claimed for either side. CAPPZ is not affiliated with TypeSafe. Source: Jev Engineering for Coding Agents (Sept 2026) — Independent synthesis of design notes by Diogo Almeida (TypeSafe); not affiliated with or endorsed by TypeSafe.
From the silicon enclave to the agent.
Seven tiers, one notarized graph. ARM instructions resident in Qualcomm TrustZone anchor wallet key ops at L1 — every layer above inherits that root of trust.
- L7 TIER 07 / 07 AI · Agents · LLMs COOL + COPE — anchored inference, no re-derivation. Models cite the graph; the graph cites back. CITES AX-92
- L6 TIER 06 / 07 Codices · Ontologies Bible · ISO 20022 · HL7 · FpML · FIX · domain corpora. Canonical knowledge precedes code. CITES PROV-014
- L5 TIER 05 / 07 Contracts · Finance Royalty Flywheel · DARC splits · 70 / 20 / 10. XRPL settlement, on-chain cite-and-earn. CITES AX-67
- L4 TIER 04 / 07 Skills · BPMN Governance 87 wallet-resident skills. BPMN is void main(). Every action a governed, verifiable step. CITES AX-57
- L3 TIER 03 / 07 Notarization Substrate Twin-TX. ContentIngested + ConstituentsAggregated under one correlationId. CITES AX-63
- L2 TIER 02 / 07 HD-Addressed Wallets m / 44' / 144' / … Every entity — event, skill, dataset, model — a deterministic address. CITES AX-68
- L1 TIER 01 / 07 Device Root of Trust ARM · Qualcomm TrustZone — wallet key ops resident in-enclave. Anti-deepfake at capture. CITES US 11,645,632 B2
Stratigraphic stack — from the silicon enclave (L1) to the agent (L7). One notarized graph. AX-63 · AX-68 · AX-92 · US 11,645,632 B2
Place your stack on the board.
Each partner lands on a different region of the substrate four lanes, one board
One wallet container. Any skill. Zero rogue supply chain.
Five substitutions collapse the modern stack into a sovereign, wallet-first substrate. Wallets talk to each other directly — off-chain, private — anchoring only what needs anchoring.
Hash-verified on-chain manifest. No rogue postinstall spreading across the globe.
HD-addressed multi-master repos. Parallel-use with GitHub — no central host to compromise.
Wallet-first hydration (AX-74). TX graph is canonical; caches are disposable.
Every app is a wallet with an embedded admin agent and its included skills.
cappz-sessions + chainlets + A2A sync. Wallets talk directly — off-chain, private, no broker. Lifecycle + signaling TXs flushed to chain opportunistically.
Apps are skills. Skills are apps.
App (wallet container) ├─ Embedded Admin Agent ← AI + BPMN + edge functions └─ Included Skills ├─ Skill A (wallet container) │ ├─ Admin Agent │ └─ Included Skills │ └─ Skill A.1 (wallet container) … └─ Skill B (wallet container) └─ … Every node clones from an on-chain template anchored to a registered ontology / codex. Recursion terminates at substrate primitives (RBAC #88, Build #87, Notarization, CPM, …).
Off-chain data plane. On-chain anchor plane.
cappz-sessions + chainlets + A2A sync. No broker in between.
HD-addressed channel between wallets. SessionOpenedTx / SessionClosedTx anchor lifecycle boundaries — optional and opportunistic.
Purpose-built micro-blockchain per session or topic. Local-first blocks; heads exchanged peer-to-peer.
Edge-to-edge block exchange between participating wallets. No broker. No shared server. Governed by a2a-sync.bpmn.
Payload never touches the chain. Only lifecycle (open/close), signaling (linkage-auth request/grant), and dispute anchors are flushed to disk opportunistically. Truly decentralized: private data stays off-chain, provenance anchors on-chain when it matters.
Same graph. Same answer. Every model, every agent, every time.
The recipe generalizes. Pick the lane that matches your hardware, your corpus, or your tool plane.
Cite-and-earn corpora with reproducible discovery.
- BibTeX-ready whitepaper
- Wallet-anchored datasets
- Royalty TXs per citation
Model lineage and dataset royalties, on-chain.
- Twin-TX provenance per checkpoint
- COOL-traceable training graphs
- Royalty Flywheel for contributors
Notarize everything at the device. TrustZone-resident wallet key ops eliminate deepfake at the root.
- TrustZone-resident key ops
- Anti-deepfake attestation at capture
- Wallet-first hydration · AX-74
- Offline-first notarization bus
Zero-server AI infrastructure for power-constrained devices.
- Reference design · Mbed-friendly
- LZ4 packaging via CPM
- Notarized OTA via HD-Address
87 governed skills, MCP-native, wallet-owned.
- Copy-as-Claude-Skill from catalog
- MCP manifest at /.well-known/mcp.json
- Royalty events on tool invocation
Pick a lane. Pilot a corpus.
We will scope a 6-week pilot against your domain, anchored to your wallets, with a notarized acceptance trail.