Astrea Tech / Agents
the wallet after wallets

Agents are how
people will transact

Nobody outside this field wants to copy a forty-character address, estimate a fee, pick a bridge, and wait for confirmations, knowing that one mistake cannot be undone. They want to say what they hold, what it may do, and what must never happen, and have it done. That is an AI agent: a program you talk to in plain language, which holds your keys, knows your rules, and does the chain work for you. This page is about the agent, the private AI it runs on, and why Astrea, Zcash, and AxiomAI are designed to fit together around it.

01 · the interface problem

The wallet was built for the chain, not the person

Every blockchain interface today asks the user to think like a node. Addresses, fees, nonces, approvals, bridges, confirmation counts, seed phrases. Each is a place to lose money, and none of them is what the user wanted to do. The user wanted to pay a supplier, hold some savings privately, or take a position before the market moved.

What a person does with a wallet today compared with what they say to an agent
with a walletwith an agent
paying someone copy an address, check the first and last four characters, pick a fee, sign, wait, hope "pay the invoice from Marta, from the ZEC account, today"
using another chain find a bridge, approve a token, wrap it, wait for finality on both sides, keep the receipts "put a tenth of the ZEC into the Ethereum lending market with the best rate under these limits"
staying safe read every approval, verify every contract, never paste the wrong thing "never move more than this a week, never touch these assets, always settle back into the shield"
knowing what happened scroll a block explorer and reconstruct it a receipt for every action the agent took, checkable against the rules you set

We believe most people will never learn the left column, and will not have to. They will use the right column long before they understand a chain, in the same way most people use the internet without understanding a packet. The interface to money is going to be a conversation, and the thing on the other side of it is an agent.

02 · what an agent is

An AI agent holds your keys and your rules

An agent is an AI system that has three things a chat window does not: your keys, so it can act; your rules, so it knows what it may do; and memory, so it can carry a strategy across time. You give it objectives, tools, and limits. It plans, calls the tools, and acts inside the limits, and it comes back with a record of what it did.

That is the shape of AxiomAI, Astrea's own private AI. Today it is a desktop app for private chat and code: every prompt is encrypted before it leaves the device and runs only inside verified hardware, so the infrastructure around it cannot read what you asked. It is the place where an owner will create an agent, give it tools, and define its authority, and it is expanding from private chat and code toward agentic ZEC execution. Astrea is where those agents act. Zcash is the money they act with. Ethereum is the first market they reach.

"An agent should not be free from rules. It should be governed by those you set for it."

AxiomAI manifesto, 2026

The rest of this page follows the manifesto's three words, liberty, privacy, and sovereignty, and shows what each one asks of the system underneath the agent.

03 · liberty

Thinking was free. Acting should be too.

Thinking has always been free. You could sit alone and work through an idea without asking permission and without anyone storing a record of it. AI changed where thinking happens: the question you are not ready to say aloud now passes through a chat window that belongs to someone else, on servers you do not control, under terms that depend on the provider and the jurisdiction.

AI is now moving beyond thought. It is beginning to act. The systems people use to write and reason will soon manage assets, purchase services, execute strategies, and negotiate with other machines. An agent will know what you want and be able to do something about it. When that happens, the boundary of acceptable thought that a provider draws becomes a boundary on what your money may do.

Liberty, for an agent, means the owner decides how the intelligence may act. If you create an agent to write code or to trade, you set its objectives, its tools, and the limits of its authority. Nobody else does, and nobody else can change them without you knowing. On Astrea those limits are not a setting in a provider's database. They are declared in the schema of every action the agent can take, and an action outside them has no valid receipt and never enters the record.

04 · privacy

Private AI needs private money

Most AI companies handle privacy with a promise: trust us not to misuse your data. That promise has to survive every employee, internal system, acquisition, subpoena, and breach, and one failure anywhere in the chain compromises the arrangement. AxiomAI handles it architecturally. Messages are encrypted before they leave the device and processed inside protected execution environments, so the surrounding infrastructure cannot read them. The aim is to reduce how much trust privacy requires, because a promise is always weaker than a design.

Private inference is only the beginning. An agent can keep its reasoning confidential and still give its owner away through its behavior. The assets it holds reveal its position. The markets it enters reveal its strategy. Its counterparties reveal its relationships. The timing of a transaction discloses its intent.

"If an agent's reasoning is protected but every economic action is public, the intelligence behind it can be reconstructed by its footsteps."

AxiomAI manifesto, 2026

This is why private AI needs private money, and why the agent's money is ZEC. Zcash gives an agent a way to hold and move value without making every balance, payment, and relationship public. Astrea extends that privacy to the agent's work: the bridge takes shielded ZEC in by proving the Zcash chain, the ledger inside keeps every balance and transfer as a zero-knowledge receipt, Ethereum is reached with the venue seeing Astrea rather than the owner, and PRISM shapes the traffic so the timing of an action does not disclose the intent behind it. The Zcash page walks the bridge and the privacy page names each observer and what it can still see.

Two kinds of guarantee

AxiomAI runs inside a trusted execution environment. A TEE is a sealed region of the processor, built into confidential-computing hardware, where code and data stay encrypted in memory and isolated from the operating system, the hypervisor, and the operator of the machine. Before AxiomAI sends a prompt, it asks the hardware for an attestation: a statement signed by the chip maker's key that names exactly which code is running inside the enclave and confirms the enclave is genuine. The app checks that statement against the code it expects, and only then encrypts the prompt to a key that exists nowhere except inside that enclave. Inference runs there, the reply comes back encrypted, and nothing is written in plaintext along the way. That is what "TEE verified" and "attested enclave" mean in the app. The privacy of a session is verified by the hardware before the session starts rather than promised by a company afterward.

It is still a different kind of guarantee from a proof. A TEE rests on the hardware maker, its attestation keys, and the enclave design, and researchers have found side channels in earlier enclave generations that vendors then patched. Astrea's zero-knowledge receipts rest on mathematics: they establish that an agent's actions followed their declared rules, and anyone can check them without trusting hardware or an operator. AxiomAI's enclaves guard the agent's prompts, memory, and keys on the owner's side. Astrea's receipts guard the correctness and the limits of what the agent does. Neither stands in for the other, and each page says which is which.

05 · sovereignty

Private without being unaccountable

Privacy asks who can read your information. Sovereignty asks who controls the system acting on your behalf. An agent with authority to transact cannot be governed by vague instructions and retrospective assurances. Its owner needs to define what it may spend, which assets it may use, which markets it may enter, and when its authority begins and ends. Those limits have to hold without the owner watching every action, and they have to be verifiable afterward.

This is the problem Astrea's receipts were built for. An agent keeps its strategy private, and its owner may never inspect a single decision, yet the owner can establish that the agent stayed inside its permissions, because every accepted action carries a zero-knowledge receipt that binds it to the declared limits, and the receipts live under a certified root the owner can check from any device. The agent is private to the world and accountable to the person who authorized it. Those two properties usually trade against each other. Here they come from the same proof.

WHERE THE PIECES MEET
owner · AxiomAI · Astrea · Zcash · Ethereum
An owner sets rules in AxiomAI, the agent acts through Astrea, Zcash is the money and Ethereum the market, and receipts return to the owner The owner creates an agent in AxiomAI and sets its tools, capital, and limits. The agent acts through Astrea, where permissions are checked and every accepted action is recorded as a zero-knowledge receipt under a certified root. Zcash provides the private money and settlement; Ethereum provides programmable assets, markets, and liquidity. Receipts return to the owner, who can verify that the agent stayed inside its permissions without inspecting its strategy. OWNER sets the rules PRIVATE AI · ENCRYPTED AxiomAI agent · tools · capital · limits WHERE THE AGENT ACTS Astrea permissions checked · zk receipts PRIVATE MONEY Zcash shielded ZEC · settlement PROGRAMMABLE MARKETS Ethereum assets · markets · liquidity first currency first market other chains follow receipts return to the owner · checkable without reading the strategy the world sees Astrea acting · the owner sees proof the rules held · nobody sees the strategy
The owner sets the rules in AxiomAI. The agent acts through Astrea, where permissions are checked and every accepted action leaves a zero-knowledge receipt. Zcash is the money, Ethereum the first market, and the receipts come back to the owner, who can verify the rules held without ever reading the strategy.

This is where AxiomAI and Astrea meet. AxiomAI is where users create agents, give them tools, and define their authority. Astrea is the environment through which those agents act, with permissions checked and accepted activity recorded in a form that can be verified. Zcash provides private money and settlement. Ethereum provides access to programmable assets, markets, and liquidity, and other chains follow as their state can be proved in.

06 · in stages

Sovereignty is built one layer at a time

Over time, more of the relationship between a user and an agent has to move out of the provider's control and into the user's own. The manifesto sets the order, and this guide follows it.

Private conversationslive today

AxiomAI runs private chat and code inside protected execution environments, with prompts encrypted before they leave the device. This is the part that ships now.

Private memory and strategythe agent

An agent that carries objectives, tools, and limits across time, with its memory and its strategy held on the owner's side rather than the provider's.

Private money and economic activityAstrea and Zcash

The agent holds ZEC, acts on Ethereum through Astrea's bridge, settles back into the shield, and leaves receipts its owner can check. This is the design the rest of this guide describes, and it is being built toward a testnet.

"We are not there yet. But the path to sovereignty starts with privacy."

AxiomAI manifesto, 2026
Testnet

This is the implementation planned for Astrea's testnet. AxiomAI's private chat and code are live today, and the agent, the bridge, and the receipts on this page are what the testnet is being built to run.