The complete, dated history of what 🤫 One has shipped - 687 changes and counting, newest first, for users, our team, and the community. We build in the open: this is the record.
It is a small convention that means a lot to us: every 🤫 release is named after a human we celebrate, so the story of what we ship carries the memory of the people who inspire it. We celebrate humans as we build.

With almost no formal training he saw truths the establishment could barely verify. Raw human ingenuity, given the chance to reach the world, is what we exist to serve.
See all the humans we celebrateWe promise, on every listing and on all 51 university pages, that anyone can ask to be taken off. Preparing a letter to a university meant checking that promise against the code, and the code could not keep it. The way to honour a removal without waiting for an engineer had never worked, for anybody, since the day it shipped. This release is that fix, the pages that now offer the removal plainly instead of burying it in a sentence, the first count of removals honoured so the promise can be checked rather than only read, and the rest of a night spent holding our own claims to the standard we ask of everyone else.
There are two ways a removal is honoured here. One is a change to our source code, which needs an engineer and a deploy. The other is a configuration change, which is what makes the published 72 hours possible on a Friday night. The second one did not work, for any of the millions of people in the directory, from the day it shipped. Three faults in a row: the part that reads the setting changed the spelling of the name, so the two halves could never agree; the example in our own documentation used a kind of identifier no part of the system asks with; and for the largest set of listings the identifier contained commas, which is the character used to separate one removal from the next, so those requests were torn into fragments on the way in. All three are fixed, and the tests now start from what a person actually types rather than from what the parser happened to produce.
The sentence offering removal has always been there. The only button under it said Nominate a professor and opened a contact page that named no removal channel, so anybody who wanted off had to guess. There is now a direct address next to it, and a line saying what happens when you use it: no account, no form, nobody asking you to reconsider, and we will not put you back. Underneath, the pages run the same removal list as the directory, keyed per university so two people who happen to share a name cannot remove each other.
Each university page showed a count of people celebrated and left the reader to guess what it was a count of. At Stanford it is 61, which is about 2.6 percent of the faculty. The page now says it is a selection and not a roster. It still does not print a percentage, and the reason is the honest one: we hold no verified faculty count for any of the 51 universities, and a page whose whole argument is that every number on it is cited cannot start publishing a denominator it cannot source.
A draft letter asking Stanford for lawful access to faculty data, and an eleven-question memo to counsel, are both in the open repository, marked not sent. Writing them found four things wrong on our own side, which are in the memo rather than buried: a claim that our source code is public, which is not true of the repository that matters; a claim that no member of the public is ever charged, which is broader than what we can defend; the removal gap above; and the missing denominator. The letter names no recipient, because working out who owns this decision at a university is a task and not a guess.
The new local page opens with what we actually have and what we do not, rather than presenting a partial index as a complete one. California contractors also gained a verification door: the state licenses every one of them through a public register, so a builder on that page can be checked in one click. Most states still show no button, because we hold no verified lookup for them and a plausible wrong door is worse than none.
The weekly meeting pack prints a line reading not measured yet against removal requests honoured, and that line is what sent somebody to look at whether the mechanism behind the promise worked at all. It did not. Now that it does, the count can exist, and it is derived from the removal list the running site actually acts on, so anyone holding the build can check it rather than trusting a dashboard. It reads zero today, which is the honest state and is meant to be uncomfortable. It is deliberately not a completion rate: nothing yet counts the requests we receive, and zero means zero recorded rather than zero that ever happened. Four tests hold those sentences in place, because a caveat is the thing that gets dropped when a number is copied into a slide.
We did not design our all-hands. We read how Gokul Rajaram runs one and took most of it unchanged, and the post naming what we took, what we changed, and why the changes are ours rather than his advice is published with the receipts in it. The pack builds itself from systems that are already telling the truth, so nobody writes a status report. A number with no system behind it prints as not measured yet, and the loudest of those, every single week, is how many removal requests we have received and honoured. That line is why the top item in this release exists.
Apple keeps release notes per product; so do we. The timeline below is the full record - these are the curated, newest-first highlights for each 🤫 build, so a user, a partner, or a builder can follow just the one they care about.
Your private life-general-contractor - owned and controlled by you, every read a consented handshake.
Now built openly on PCHP / hu_ssh - the consent protocol every read completes.
Personal supercomputing you own, at home.
Full bill of materials and an Apple-grade first-time guide, published in the open.
The smallest 🤫 host - your consent, in your pocket.
Lineup finalized (flagship + SE, Ultra, Pup) with a published BOM.
The open protocol, the research, and the public portal every build ships to.
PCHP specification + four launch posts, donated to the community.
We are a Silicon Valley garage at heart - a small, hardcore team shipping in public. These notes update as we ship, most days, so users, partners, and the community can watch the company get built in real time. Garage-first is not nostalgia; it is a first principle and a core value of how we operate.
Kushal Trivedi, our co-founder and forward-deployed core engineer, works alongside Manish Sainani to build the best possible company to work at and with. The team pairs with Claude, Codex, Grok, and Gemini as everyday tools - shipping faster without ever losing the human at the center, which is the whole point of everything here.
Every change merged to main, documented here.
Shipped through a pull request and review.
The first change in this public record.
Each entry is a change shipped to production. Reviewed releases link to their pull request.
This is the whole record. Follow along, hold us to it, and tell us what to build next.
🤫 One is made by Hushh Technologies Corporation, an independent company. We name the hardware and clouds One runs on to say where it runs. None of them endorse us, and we call a company a partner only once the agreement is signed.