🤫husshhussh
🤫husshhusshOnePuppy
hussh Research · Papers

The papers, indexed for the world.

A nicely organized directory of the research and documents behind 🤫 One - written and published for the world to read, implement, and build on. We own our name; we open our standards.

New: Private Agent One on Heterogeneous SupercomputeRead: Working Backwards from the HumanThe PCHP RFC
The problem these papers answer

Today, your identity is a reverse-lookup key.

Your phone number, your name, and your email are used to look you up inside other people's databases - to find you and learn everything about you, your finances, your health, your wants and needs, and what's on your mind 24/7. Companies hold it, their partners share it, and if a hacker gets in, it's theirs too - with you, the end user, left holding the bag. PCHP flips that: identity proves who you are without exposing what makes you you, and nothing is shared without your consent and a receipt.

Featured - read this first

Private Agent One on Heterogeneous Supercompute.

Our newest paper, by Manish Sainani: one private agent running across four tiers of silicon - iPhone Neural Engine, Apple-silicon Mac, NVIDIA DGX Spark, and a GB200 NVL72 rack - with a PCHP consent handshake on every hop between them. A research dossier and a technical essay in the author's own voice.

Paper · July 2026 · Manish Sainani

New

Private Agent One on Heterogeneous Supercompute - a research dossier and technical essay →

The compute ladder as a design problem: what runs on the phone because it must be instant and must never leave, what runs on the Mac because unified memory makes it free, what earns an escalation to the desk-sized NVIDIA box, and what is enormous enough to justify a rack you do not own. Every rung change is a consent gate. Includes the honest ledger of what is shipped versus what is cooking, and a provenance note on every performance figure - all of which are other people's published measurements, not ours.

Paper · 2026 · openly published

Featured

Working Backwards from the Human - a first-principles ontology →

A person-centered ontology for personal information and human-first agentic AI, grounded in the literature (Dunbar's circles, personal information management, privacy by design, calm technology, mixed-initiative interaction). Read the paper, the full verified research corpus, and the citations.

Paper · July 2026 · open problem

Open problem

Counting Without Watching - measuring agent usage under consent →

We state a problem we have not solved: how to know whether eight billion personal agents are genuinely useful each day, without the behavioral telemetry our own architecture forbids. Formal statement, a threat model in which the operator is the adversary, a construction over receipt-anchored edge sketches with calibrated noise and secure aggregation - and an honest account of what remains unsolved.

Paper · July 2026 · experience report

Experience report

Cold Start Is a First-Class Constraint - a production outage, analyzed →

We took our own site dark. A read-only index outgrew the memory available at process start, and because it was built at module load and transitively imported by unrelated routes, a directory change killed the home page too. Why warm tests, a green build, and a staging deploy all failed to see it; four design principles for large read-mostly indices on autoscaled runtimes; and the deploy gate whose absence was the real defect.

Paper · July 2026 · formal model

Formal model

Consent as an Operational Semantics - a formal model for scoped, revocable, auditable access →

Consent expressed as a small-step transition system over grants, requests, and receipts, so that access and its receipt are one transition rather than two things an implementation is trusted to do together. Five properties, and an unusually long section on what the model provably does not prevent - inference, aggregation across grants, re-sharing past the boundary, and the fact that revocation cannot un-know.

Paper · July 2026 · data engineering

Data engineering

Entity Resolution Under a Right to Removal →

248,568 organizations and 616,145 named professionals, where every subject can demand deletion. Why removability is a constraint on the resolution architecture rather than a compliance feature: deliberate under-merging because over-merging makes false statements about named people, claim-time verification against the authoritative regulator, 737 taxonomy codes collapsed into 27 human terms, and proximity as the primary key.

Founding papers & philosophy

The thinking, in writing.

The founding arguments for why your information is your business - and the architecture to finally build the personal One the internet was supposed to give us.

(opens PDF in a new tab)Paper · April 2026

Founding

The hussh One ↗

The founding paper. The personal One the internet was supposed to give us, and the architecture required to finally build it.

(opens PDF in a new tab)Reference · v1.0

Canon

The Foundation ↗

The canonical reference: philosophy, control & ownership, the experience system, and the brand. Six parts, twenty-four chapters, one spine.

Protocols & standards - open RFCs

PCHP - the open consent protocol.

RFC-001 - the Personal Consent Handshake Protocol (PCHP, “hu_ssh”), SSH for humans - published openly for policymakers, professors, and scientists to consider as a new consent layer on top of the communication protocols the world already uses. Open, not owned.

Open RFC · consent protocol

RFC-001

RFC-001 - The Handoff (PCHP) →

How two Ones meet on behalf of their humans: by consent, scoped, with a receipt. Four phases - identity, consent, scoped exchange, audit receipt. Published under an open license; any agent may implement it.

Open RFC · developer documentation

RFC-002

RFC-002 - the Preference Subscription Fabric →

The vocabulary a handshake exchanges: 252 scopes across seven roots, five tiers deciding what may ever happen to a field, and purpose bundles that make an ask legible to a person rather than a list of dot-paths. Written for an agent integrating against it.

MCP · A2A · AP2 · UCP

Standard

Composable over the open rails →

PCHP is a consent layer that sits on top of the rails the world already builds on - adding identity, scope, and a receipt to each, rather than replacing them.

github.com/hushh-labs

Code

Open-source research →

Reference implementations and applied research for the consent protocol. Own the name; open the pattern.

Personal knowledge & world model

A private brain about you.

The research behind the 🤫 One Personal Knowledge Model and how it becomes your portable, consent-shared Personal World Model.

Research · 🤫 One PKM

PKM

The Personal Knowledge & World Model →

How the 🤫 One Personal Knowledge Model - a private information-and-knowledge brain about you, owned by you - is trained and tuned from your usage to become a living Personal World Model, portable by consent to everyone you trust.

Business & financing

How One is paid for, in the open.

Transparent about the financing that lets the product never have to monetize you.

Paper · hushhtech.com

Whitepaper

Fund A - strategy whitepaper →

An AI-powered Berkshire Hathaway: free cash flow, quality ownership, and disciplined risk, told CEO-to-CEO. The returns that finance One.

Why we publish

Primitives outlive products.

A category spreads when others can build to its standard. So we publish the thinking, open the protocol, and keep only the name. PCHP - RFC-001 - is offered openly for policymakers, professors, and scientists to consider and adopt: a consent layer on top of the communication protocols the world already runs, so a person's identity can be resolved without their private life being handed over by default.

Read it once, carefully.

Then share it with one person whose judgment you trust more than your own - and, if you build, build to the open standard.

The Personal World ModelBuild on the railsAll research

🤫 One is made by Hushh Technologies Corporation, an independent company. We name the hardware and clouds One runs on to say where it runs. None of them endorse us, and we call a company a partner only once the agreement is signed.