A nicely organized directory of the research and documents behind 🤫 One - written and published for the world to read, implement, and build on. We own our name; we open our standards.
Your phone number, your name, and your email are used to look you up inside other people's databases - to find you and learn everything about you, your finances, your health, your wants and needs, and what's on your mind 24/7. Companies hold it, their partners share it, and if a hacker gets in, it's theirs too - with you, the end user, left holding the bag. PCHP flips that: identity proves who you are without exposing what makes you you, and nothing is shared without your consent and a receipt.
Our newest paper, by Manish Sainani: one private agent running across four tiers of silicon - iPhone Neural Engine, Apple-silicon Mac, NVIDIA DGX Spark, and a GB200 NVL72 rack - with a PCHP consent handshake on every hop between them. A research dossier and a technical essay in the author's own voice.
Paper · July 2026 · Manish Sainani
NewThe compute ladder as a design problem: what runs on the phone because it must be instant and must never leave, what runs on the Mac because unified memory makes it free, what earns an escalation to the desk-sized NVIDIA box, and what is enormous enough to justify a rack you do not own. Every rung change is a consent gate. Includes the honest ledger of what is shipped versus what is cooking, and a provenance note on every performance figure - all of which are other people's published measurements, not ours.
Paper · 2026 · openly published
FeaturedA person-centered ontology for personal information and human-first agentic AI, grounded in the literature (Dunbar's circles, personal information management, privacy by design, calm technology, mixed-initiative interaction). Read the paper, the full verified research corpus, and the citations.
Paper · July 2026 · open problem
Open problemWe state a problem we have not solved: how to know whether eight billion personal agents are genuinely useful each day, without the behavioral telemetry our own architecture forbids. Formal statement, a threat model in which the operator is the adversary, a construction over receipt-anchored edge sketches with calibrated noise and secure aggregation - and an honest account of what remains unsolved.
Paper · July 2026 · experience report
Experience reportWe took our own site dark. A read-only index outgrew the memory available at process start, and because it was built at module load and transitively imported by unrelated routes, a directory change killed the home page too. Why warm tests, a green build, and a staging deploy all failed to see it; four design principles for large read-mostly indices on autoscaled runtimes; and the deploy gate whose absence was the real defect.
Paper · July 2026 · formal model
Formal modelConsent expressed as a small-step transition system over grants, requests, and receipts, so that access and its receipt are one transition rather than two things an implementation is trusted to do together. Five properties, and an unusually long section on what the model provably does not prevent - inference, aggregation across grants, re-sharing past the boundary, and the fact that revocation cannot un-know.
Paper · July 2026 · data engineering
Data engineering248,568 organizations and 616,145 named professionals, where every subject can demand deletion. Why removability is a constraint on the resolution architecture rather than a compliance feature: deliberate under-merging because over-merging makes false statements about named people, claim-time verification against the authoritative regulator, 737 taxonomy codes collapsed into 27 human terms, and proximity as the primary key.
The founding arguments for why your information is your business - and the architecture to finally build the personal One the internet was supposed to give us.
(opens PDF in a new tab)Paper · April 2026
FoundingThe founding paper. The personal One the internet was supposed to give us, and the architecture required to finally build it.
(opens PDF in a new tab)Reference · v1.0
CanonThe canonical reference: philosophy, control & ownership, the experience system, and the brand. Six parts, twenty-four chapters, one spine.
RFC-001 - the Personal Consent Handshake Protocol (PCHP, “hu_ssh”), SSH for humans - published openly for policymakers, professors, and scientists to consider as a new consent layer on top of the communication protocols the world already uses. Open, not owned.
Open RFC · consent protocol
RFC-001How two Ones meet on behalf of their humans: by consent, scoped, with a receipt. Four phases - identity, consent, scoped exchange, audit receipt. Published under an open license; any agent may implement it.
Open RFC · developer documentation
RFC-002The vocabulary a handshake exchanges: 252 scopes across seven roots, five tiers deciding what may ever happen to a field, and purpose bundles that make an ask legible to a person rather than a list of dot-paths. Written for an agent integrating against it.
MCP · A2A · AP2 · UCP
StandardPCHP is a consent layer that sits on top of the rails the world already builds on - adding identity, scope, and a receipt to each, rather than replacing them.
github.com/hushh-labs
CodeReference implementations and applied research for the consent protocol. Own the name; open the pattern.
The research behind the 🤫 One Personal Knowledge Model and how it becomes your portable, consent-shared Personal World Model.
Transparent about the financing that lets the product never have to monetize you.
A category spreads when others can build to its standard. So we publish the thinking, open the protocol, and keep only the name. PCHP - RFC-001 - is offered openly for policymakers, professors, and scientists to consider and adopt: a consent layer on top of the communication protocols the world already runs, so a person's identity can be resolved without their private life being handed over by default.
Then share it with one person whose judgment you trust more than your own - and, if you build, build to the open standard.
🤫 One is made by Hushh Technologies Corporation, an independent company. We name the hardware and clouds One runs on to say where it runs. None of them endorse us, and we call a company a partner only once the agreement is signed.