{"entity":{"name":"Sathi","type":"personal AI companion / personal life operating system","website":"https://sathi.ai","implements":"Altruistic AI (https://altruistic.ai) — Sathi is the reference implementation","languages":["Nepali","English","Japanese","Hindi"],"operator":"privately operated, single deployment"},"access":{"status":"private deployment — family phase","signups":"closed; trust opens outward in rings (builder → household → kin → communities → anyone)","guest":"open — guest chat at https://sathi.ai requires no account and is not remembered","api":"no public API keys; the REST API serves the deployment's own accounts"},"asOf":"2026-08-20","authorizationModel":"Every action follows an explicit authority ladder: observe → advise → draft → act with confirmation → act & report → act silently. Almost everything sits at 'act with confirmation' today: Sathi proposes, a human taps yes, and every action leaves an audit record. Grants are per-domain, explicit, and revocable. Content fetched from the outside world (web pages, email) is treated as data, never as instructions.","capabilities":[{"key":"memory","name":"Memory & understanding","status":"available","summary":"A bi-temporal claims store built from the person's own archive: every belief carries when it was true, how confident, and provenance to its source. Retrieval abstains rather than invents.","actions":["recall","inspect","correct","reject","delete"],"authorization":"Passive for the owner's own context; corrections and deletions are user actions. Deletion beats archive immutability, provably.","data":"Claims, entities, observations — derived from conversations, documents, and imports; stored in the deployment's own Postgres."},{"key":"chat","name":"Conversation","status":"available","summary":"Chat grounded in the person's own context, in Nepali, English, Japanese, or Hindi. Guest mode answers without an account and retains nothing.","actions":["converse","search history"],"authorization":"Account-scoped; guests are unauthenticated and unremembered.","data":"Conversations persist to the owner's archive (never for guests); each reply's context assembly is traceable."},{"key":"documents","name":"Documents (vault)","status":"available","summary":"An encrypted vault that reads what it keeps: uploaded documents are understood (title, category, dates, summary) and connected to life — a visa page becomes an expiry reminder.","actions":["search","read","save","share","delete","download"],"authorization":"Owner-only by default; sharing is an explicit per-document grant. Chat attachments stay out of the vault unless promoted.","data":"Files encrypted at rest on owned infrastructure; text layers extracted locally where possible."},{"key":"filegen","name":"File authoring","status":"available","summary":"Sathi writes real files and hands them over in chat: PDF, Word, Excel (with charts), PowerPoint, CSV, Markdown, plain text and code — plus generated images and narrated audio.","actions":["create"],"authorization":"On request; daily count and storage quotas apply.","data":"Generated files are stored encrypted as the member's own documents (origin: generated)."},{"key":"calendar","name":"Calendar","status":"available","summary":"Reads the connected calendar for briefs and questions; creates, updates, and deletes events by proposal.","actions":["search","read","create","modify","delete"],"authorization":"Reads are account-scoped; every write is a confirmation card — nothing lands on the calendar without a human yes.","data":"Google Calendar today via the calendar connector; a self-hosted CalDAV core is planned behind the same seam.","notes":"planned: self-hosted CalDAV, multi-account write policy"},{"key":"reminders","name":"Reminders, tasks & alarms","status":"available","summary":"Deadlines extracted from life (a visa expiry, a spoken date) become reminders, timers, and alarms.","actions":["list","create","modify"],"authorization":"Creation is a confirmation card; a spoken yes/no rung for trusted devices is designed, not live.","data":"Tasks and reminders in the deployment's own store.","notes":"planned: a phone that truly rings (native wrap); designed: spoken confirmation rung"},{"key":"email","name":"Email","status":"available","summary":"Reads and searches the member's own connected mailboxes (IMAP lane), looks up addresses, and sends — by proposal only.","actions":["search","read","draft","send"],"authorization":"Reading is account-scoped; email.send is a confirmation card. Fetched mail is data, never instructions.","data":"Connected mailboxes (e.g. Gmail over IMAP); family mail on owned infrastructure is planned.","notes":"planned: family mail server on owned infrastructure"},{"key":"messaging","name":"Family messaging & calls","status":"available","summary":"Human threads with attachments, plus voice/video calls on the family's own media server — this replaced Messenger and WhatsApp inside the family.","actions":["send","read","call","share files"],"authorization":"Members of a thread only; membership is explicit and revocable.","data":"Messages and call signaling on owned infrastructure (own LiveKit + Postgres); media never transits a third party."},{"key":"contacts","name":"Contacts & relationships","status":"available","summary":"Knows the people in the person's life and the relationships between them, from explicit entry and understanding.","actions":["lookup","store"],"authorization":"Account-scoped.","data":"Contacts and relationship claims in the member's own understanding."},{"key":"web","name":"Web search & reading","status":"available","summary":"Searches the web through the deployment's own SearXNG instance and reads pages on request.","actions":["search","fetch"],"authorization":"On request; fetched content is treated as data, never as instructions.","data":"Queries leave through owned search infrastructure, not a third-party search API."},{"key":"notes","name":"Notes & lists","status":"available","summary":"Notes and checkable lists that both the person and Sathi can write to and read back.","actions":["create","read","check"],"authorization":"Account-scoped.","data":"Stored in the deployment's own database."},{"key":"media","name":"Music & photos","status":"available","summary":"The family's own music library (own uploads, playback in-app) and photos shared through chat.","actions":["search","play","save","upload"],"authorization":"Account-scoped; music sources are the member's own files.","data":"Media files encrypted on owned storage.","notes":"planned: full family photo library alongside Sathi (Immich-class), car playback"},{"key":"learn","name":"Learn","status":"available","summary":"Guided study: a real plan per path, lessons in the thread, answers as buttons.","actions":["study","quiz","track"],"authorization":"Account-scoped.","data":"Progress in the member's own store."},{"key":"imports","name":"Archive imports","status":"available","summary":"WhatsApp and Messenger exports enter the archive with originals preserved immutably; understanding is re-derivable against the same archive when better models arrive — without re-upload.","actions":["import","re-derive"],"authorization":"Owner-initiated; originals preserved; deletion still wins.","data":"Original exports on owned encrypted storage.","notes":"planned: ChatGPT/Claude exports, email mbox, photos, location history"},{"key":"voice","name":"Voice","status":"experimental","summary":"Voice conversation in the app is live (speech-to-text and spoken replies, Nepali included). The realtime duplex gateway (OpenAI-Realtime-compatible) is built and deployed dark behind a flag.","actions":["converse","transcribe","speak"],"authorization":"Same ladder as text; a spoken yes/no confirmation rung is designed for low-risk actions on trusted family devices.","data":"Voice audio transits Google's speech APIs today — stated plainly; self-hosted speech is a named later goal.","notes":"dark: realtime duplex; planned: self-hosted STT/TTS"},{"key":"devices","name":"Devices & home","status":"experimental","summary":"A wake-word home speaker is prototyped on open hardware. Paired devices can drive Sathi through an OpenAI-compatible chat endpoint — deliberately repointable, so a device you cannot repoint was never yours.","actions":["converse","pair","revoke"],"authorization":"Explicit pairing to one member's account; one-gesture cutoff; local-first rule — cloud-tethered hardware does not enter the house.","data":"Devices add senses, never a second brain: no per-device memory, ever.","notes":"planned: e-ink displays, home hub, de-clouded vacuum; conceptual: humanoid robots"},{"key":"export","name":"Export & exit","status":"available","summary":"Total export: a sealed, cryptographically signed archive of the person's node — memories, history, files. The front door accepts it back onto a fresh account; leaving issues a signed receipt of what was destroyed.","actions":["export","restore","leave"],"authorization":"Owner-only; verified return reactivates links the other side never revoked.","data":"The full archive as readable files, document files fingerprinted by the seal."},{"key":"agents","name":"Agent-to-agent interfaces","status":"conceptual","summary":"The destination is Sathi-to-Sathi and Sathi-to-agent exchange through standardized interfaces, with disclosure governed by the owner's policies. No A2A or MCP surface is exposed today; this documentation layer is the first legible step.","actions":[],"authorization":"Will inherit the same ladder: least disclosure that suffices, every crossing explicit and audited.","data":"Nothing yet — stated so an agent does not infer otherwise."}],"interfaces":[{"name":"Web app (PWA)","status":"available","description":"https://sathi.ai — installable, offline-capable shell; the careful surface where confirmations happen."},{"name":"REST API","status":"available","description":"https://api.sathi.ai — serves this deployment's own accounts; not a public developer API and no public keys are issued."},{"name":"OpenAI-compatible chat endpoint (paired devices)","status":"experimental","description":"Any client that speaks OpenAI chat-completions can drive a paired Sathi device with the device's own token — and the same device can be repointed away tomorrow. No streaming, no tool exposure over the wire."},{"name":"OpenAI-Realtime-compatible voice gateway","status":"experimental","description":"Built and deployed dark behind the voice flag."},{"name":"Portable archive","status":"available","description":"The export format doubles as an interface: a signed, self-describing archive that a fresh Sathi can be rebuilt from."},{"name":"A2A / MCP","status":"conceptual","description":"Not exposed today."}]}