Sathi

An intelligence that grows around your life.

This page explains how Sathi is built, what it promises, what data leaves our infrastructure, and what we deliberately refuse to do. It exists so that people outside our family can check our thinking and tell us where we are wrong.

Why Sathi exists

Sathi is the trusted, evolving interface through which a person interacts with an increasingly intelligent world.

We plan for a world where intelligence itself stops being scarce — where reasoning, planning, and generation are cheap and abundant. When that happens, the scarce things are the human ones: trust, continuity, agency, context, identity, good judgment, and alignment with what a person actually values. Sathi is built to preserve those, not to add one more clever tool.

So its objective is deliberately not the industry's. Sathi does not optimize engagement, obedience, profit, or productivity alone. Its aim is to help people flourish — a broader thing than comfort or efficiency: less unnecessary suffering, more autonomy, stronger relationships, better understanding, and room to pursue meaningful goals. We assume our grasp of "living well" is incomplete and will keep changing, so the architecture is built to change with it.

Reality has priority over ideology. Every belief Sathi holds stays open to revision by better evidence — from science, from lived experience, or from a simple user correction. Confidence should scale with evidence; where it is uncertain, it should say so rather than perform certainty. A good companion tells you what it honestly believes, flags its doubts, stays correctable, and respects your freedom to choose. The measure of Sathi is not how well it defends today's beliefs but how gracefully it finds tomorrow's better ones.

Participant, not spectator

Elon Musk has described a simple choice in the development of AI: be a spectator or be a participant. His argument — made when he launched xAI in 2023 and again in January 2026 — is that if AI is going to be built either way, taking part gives at least some ability to influence its direction. “I can either be a spectator or a participant, but I can't stop it,” as he put it on Moonshots; so at least as a participant he can try to steer it toward an AI that seeks truth, holds good values, and cares about humanity.

That idea is part of why we build Sathi.

We could simply be spectators: use whatever AI systems others build, accept their assumptions and incentives, and hope that the resulting technology develops in a direction that is good for people. Or we can participate.

Sathi is our attempt to participate constructively in the future of AI — not by claiming that we know exactly what that future should look like, but by putting our values into something real and testing them against reality.

We want to build AI that is truth-seeking, genuinely useful, human-centered, respectful of human agency, and oriented toward human flourishing. An intelligence that helps people understand reality rather than distort it; that strengthens people's ability to make decisions rather than quietly taking their agency away; that can develop deep context about a person while respecting their privacy, consent, and boundaries; and that ultimately treats human life and human flourishing as things worth protecting.

This is also why Sathi is not simply an AI assistant or another interface to a language model. It is an experiment in what a different relationship between people and AI could look like.

Participation also has to be ours to verify. Other AI systems will offer zero-retention policies and learn collectively from everyone's use; unless everything they run is open, those policies are their word. And even when the code is open, the values inside it are not ours to set. Sathi is how our values survive on our own terms — running on infrastructure we control, stated in public where they can be attacked, and corrected when an attack lands.

We don't expect Sathi to determine the future of AI by itself. Nor do we believe that good intentions are enough. The real test is whether these principles survive contact with actual technology, users, incentives, scale, and the messy complexity of human life. The point is to participate — to build, learn, question, correct, and influence the direction of AI while we still have the opportunity to do so.

Sathi is our attempt.

What it feels like — five small moments

Feature lists say little, so here is daily use as it actually looks. Every moment below works today — in Nepali, English, Japanese or Hindi — and each caption names the machinery behind it.

It remembers for you

Mom has a hospital appointment on the 17th next month — remind us.
September 17 — shall I set it, with a reminder the evening before and that morning?
Yes.
Done.Sep 17 · Hospital — reminders set
A date said once becomes a reminder for the right people — after your yes, never before it.

It writes real files

Which fertilizer for wheat, rice and maize? Make me notes.
Here's the full comparison — doses, when to split the nitrogen, and zinc for all three. I've also made a PDF for offline reading.Fertilizer-notes.pdf
Answers can become actual files — documents, spreadsheets, slides — stored in your vault and handed over in chat.

It reads what you keep

When does Mom's visa expire?
March 2, 2027 — from the visa page in your vault. Want a reminder two months before?
Documents you keep are read, understood, and connected to the dates that matter.

You never start from zero

Should I take this job?
Against what you've told me: the pay beats your current role, but in June you said staying near your parents matters most this year. Want the trade-offs side by side?
Understanding is assembled from your own history, with sources — never invented.

The family, inside the boundary

Send to the family thread: I'll be late tonight.
Draft: “Coming home late tonight.” Send it?
Send.
Sent.Family thread · messages & calls
Family messaging and calls run on the family's own server — here, they replaced Messenger and WhatsApp.

One intelligence. Many contexts.

  • It remembers what matters. Not everything becomes a permanent memory: Sathi keeps the people, events, ideas and intentions that count — and what you delete is removed from live records and derived understanding.*
  • It understands. Conversations, documents, calendars and relationships connect into one picture, so it can see what matters to you — not just what you asked.
  • It acts — within what you allowed. It drafts the message, prepares the calendar change, lines up the follow-through. A clear, private, low-risk request can run directly; anything sensitive, or sent to someone else, waits for your yes.
  • It grows with you. Understanding is re-derived as your life changes and models improve; your corrections teach it.

And your life doesn't exist in isolation. Family, work, health, school — each carries its own context, its own authorities, its own boundaries. Sathi works across the contexts you choose to connect, without collapsing them into one: you decide what connects, what stays private, and what may be shared.

Where this is going (direction, August 2026 — stated as direction because it is not built): your Sathi comes with you. By default it stays you-first — one consolidated view of your life, where a workplace or a club appears as one relationship, not another dashboard to manage. Step into a company's context and you are not handing yourself over: the company holds only the slice of you it was given, and your personal Sathi stays present the way a trusted contact does. If work needs something personal, the company's side cannot reach in — it asks your Sathi, and your Sathi asks you. Switching context is never switching accounts; when you leave, that link — and what it allowed — is revoked. And the workplace need not run Sathi at all: it may run its own system entirely, and your Sathi still comes along, on the same explicit terms.

What Sathi is an instance of

Sathi is one private, opinionated instantiation of Altruistic — an emerging architecture for sovereign, adaptable, trustworthy information communities. Its public scratchpad deliberately embeds as few values as possible; Sathi adds its own, and owes the world a published copy. Sathi's are this page.

The architecture’s current thinking — its axioms, ontology, recursive composition, and how understanding travels while ownership stays home — is published in five languages at altruistic.ai. It is not restated here, on purpose: one surface per audience, and that one is written for people who came to understand the architecture rather than to use it.

What Sathi is

Sathi is a personal life operating system: one private deployment that holds a family's conversations, documents, calendars, and — with consent — an archive of their digital life, and turns it into an assistant that genuinely understands the people it serves. It speaks Nepali, English, Japanese, Hindi and Bengali. It runs on a single server we own and operate.

The organizing goal is sovereignty, for the sake of privacy: moving daily habits — messaging, calls, documents, assistant queries, and eventually voice at home — off rented corporate surfaces onto infrastructure the family controls. Renting encrypted storage is acceptable: a landlord who can delete but never read is survivable with backups. Routing the family's plaintext life through third parties is what we are retiring, one habit at a time.

Underneath, Sathi models the world the way the framework does: as a graph, not a container. Each person is a sovereign community of one — a node that belongs to itself — and belonging, to this family or to a future neighborhood, is a consented, revocable link, never a location. Since July 2026 that is schema, not metaphor: every relationship in the system is a link row carrying the consent that created it, and your export is a sealed, signed archive that can rebuild your Sathi on a fresh account — memories, history, and conversations restored after an integrity check. The exit is a tested code path, not a promise. (The full archive is one bundle — your document files ride inside it, each fingerprinted by the seal; your copy of shared conversations comes along as history, while the live thread itself belongs to everyone in it.) Leaving issues a signed receipt of what was destroyed and what remains, with the consent basis for each retention — and a verified return reactivates every connection the other side never revoked.

How understanding works (and what we rejected)

Sathi's architecture separates what happened from what we currently believe:

conversationsdocumentsvoiceimportsThe archiveoriginals, unchanged — live deletion takes precedenceUnderstandingclaims: when true · how sure · where fromchathome briefsearchremindersbetter modelsre-read the same lifeyour correctionsteach it
  • Archive first. Originals — messages, documents, exports — are preserved unchanged. Understanding is always re-derivable from them, so when better models arrive, the same life gets understood better without re-uploading anything. Exception, permanent: deletion beats immutability — live deletion removes the affected archive records and derived understanding. Backup and downstream retention are separate.*
  • Beliefs are bi-temporal claims. Every extracted fact carries when it was true and when we learned it, a confidence score, and provenance back to its source. New facts supersede old ones instead of overwriting them, so "what did I believe last year?" stays answerable. Contradictions are surfaced to the user, not silently resolved.
  • The assistant may say "I don't know." If retrieval finds nothing relevant, Sathi says so. Inventing memories is treated as a defect of the highest severity.
  • Hypotheses are labeled. Patterns Sathi notices about a person are shown as guesses with evidence, and the user can confirm, correct, or reject each one; rejections teach it.
  • Context assembly is the product. Each reply is grounded in a budgeted selection of relevant memories, documents, and knowledge — scored by relevance, recency, importance, and confidence — and every assembly is traceable.
the old beliefThe family lives in Kathmandu.believed true since Nov 2025 · from: a conversation · confidence: high
the new evidenceWe've moved — home is Osaka now.today · from: you, in chat
That changes something I believed — that home was Kathmandu, since last November. Did the move happen? I'll keep the history either way.
Yes — we moved last month.
superseded — keptThe family lives in Kathmandu.closed, not erased: "where did we live last year?" stays answerable
currentWe've moved — home is Osaka now.valid from last month · provenance: your confirmation
New facts supersede old beliefs instead of overwriting them, conflicts are surfaced instead of silently resolved, and one correction reaches every surface at once — chat, brief, search, reminders. This is the shipped mechanic, not a mock.

Choices we evaluated and rejected, with reasons — after studying the memory-system literature and practice (mem0, Zep/Graphiti, Letta/MemGPT, MemOS, LongMemEval, and practitioner post-mortems):

  • No graph database. Relationships live as structured rows; a graph engine added operational weight without adding answers at our scale.
  • No per-capability memory. Every surface — chat, voice, documents, future devices — reads one shared understanding. A user never repeats themselves to a different "mode."
  • No fine-tuning as memory. Understanding lives in data we can inspect, correct, and delete — not in opaque weights.
  • No memory SaaS. The understanding layer is the moat and the responsibility; outsourcing it would outsource both.

Your memory belongs to you

"Sovereign" is our word; these are the buttons. Three verbs, all real today:

See itAsk what Sathi believes about you and why: the memory panel lists every claim with its sources and confidence, and replies are grounded in selections you can trace.
Change itCorrect a claim and the correction teaches it; reject a hypothesis and it stays rejected. Deletion is the one law above the archive: live deletion removes the record and derived understanding; backup and downstream retention are separate.
Take itExport covers your supported records and files, not yet every app: a sealed, signed archive of your memories, history and files. The front door accepts it back, and leaving issues a signed receipt of what was destroyed.

What Sathi is allowed to do (trust before authority)

observeadvisedraftact with confirmation — when neededact & reportact silently
  • Sathi proposes; server policy decides. Permissions belong to the person or organization and are scoped and revocable. A more capable model does not gain broader authority by itself.
  • Clear, private, low-risk requests can run directly. An ambiguous private action receives a separate tool-free sentinel review: allow, deny, or ask once for the concrete action. The sentinel cannot weaken ownership, risk, budget or capability checks.
  • Sensitive actions and sending to others retain their required approval. A scoped approval can cover the authorized follow-up without another consent loop; it does not authorize a different recipient or wider task. Completion is reported from the operation’s receipt.
  • Web pages, mail, documents and other people’s words supply evidence, never permission. The same server checks apply through chat, voice and explicit controls.

What leaves our infrastructure — honestly

Sathi keeps its archive and derived understanding on its operated node. That storage boundary does not mean the contents are never processed elsewhere: relevant messages, documents, images, audio and reply text can be sent to the configured provider for a task.

The code supports direct model APIs and routed providers such as OpenRouter, including Google speech and image processing. Model developer, intermediary and serving host are different roles. The route depends on deployment settings and the task; source support is not proof that a particular route is currently serving.

Connected mail and calendars contact their providers. SearXNG sends searches to external engines. Human calls use our LiveKit transport; a call involving Sathi can also use external speech or reasoning, and a telephone call uses its carrier. Account verification and reset mail can use Resend.

Encrypted backups are separate copies, with 14 daily, 8 weekly and 12 monthly snapshots. Live deletion and a signed operation receipt do not prove that backups, recipient copies or downstream records have already expired. Self-hosting suitable models is a direction, not a promise of zero external processing.

Current processing and retention details →

Honest limitations

  • Today, a private family deployment. One operator, one server, a signup window open for testing, no billing, no SLA. But the goal grew (August 2026): Sathi is built so that any person or family — in Nepal, Japan, anywhere — can eventually join or run one. The interface stays the same for everyone; what differs is only the links and their capabilities. Each ring of trust is earned before the next opens; today's signup window is for testing and feedback, and this page exists so you can evaluate the thinking before anyone is asked to trust the deployment.
  • Operator access is granted, never assumed — the design, with a disclosed beta exception. The administrator can open a member's threads, claims, and documents only after that member grants support access in their own account — a revocable consent recorded on the relationship graph. During the beta, support access is on by default for every account so problems can be found and fixed — stated in the agreements, shown as a beta default rather than a grant, one tap to switch off — until Sathi runs reliably without us looking. Every admin request lands in a tamper-evident audit log. Running the deployment (suspending accounts, quotas, deleting an account on request) never requires it. Honest limit: enforcement is application-level and audited, not yet cryptographic — the operator still runs the database; cryptographic separation is planned for the first community the operator does not run.
  • Some processing is still rented. See “What leaves our infrastructure” above — we publish what transits third parties rather than pretending it doesn't.
  • Sharing is the destination — behind a gate. The rings open outward: the builder, the household, then kin — a nephew, a sister-in-law — then communities in Nepal and Japan, then anyone. Each ring opens only when Sathi is genuinely more trustworthy than the incumbents for the people in it. The gate is unchanged; what changed is that opening is the goal, not a maybe — and this page is how outsiders help us test the gate honestly.

Where this goes — ring by ring

Openness is the declared destination, not a maybe — but each ring opens only when the people in the previous one genuinely prefer Sathi to the incumbents. In honest tenses:

the builderliving on it since day onethe householdnow — the family phasekinnext — invites work; disclosure policies firstcommunitiesNepal & Japan first — polish and billinganyonemany operators, federation, forks welcome

The long view: Sathi when ASI is ubiquitous *

We plan on the assumption that very capable AI becomes cheap and abundant. In that world, the rented superintelligences will be owned by large corporations, and their loyalty will be contractually elsewhere. The scarce thing will not be intelligence; it will be an intelligence whose objective is purely you — one that holds your ground truth, briefs outside intelligences on a need-to-know basis, verifies their answers against your life, and keeps an audit trail of exactly what was disclosed to whom. Whatever shape it takes — one model or many, software or devices — Sathi is built to become that intelligence, yours. If that day truly arrives, ownership stops mattering to us: the intent is to open the ecosystem and let communities — human or otherwise — maintain it.

Until then, seven commitments bind every near-term decision:

  1. Archive first; understanding is regenerable.
  2. One understanding, many surfaces — never per-device memory.
  3. Provider independence — no vendor owns the moat layer.
  4. User sovereignty — deletion wins; export is meant to be total (today: the supported records and files).
  5. Trust before authority — grants and audits, never defaults.
  6. Family context is permission-structured from day one.
  7. Sensitivity is classified the moment data arrives.

If a near-term decision would break one of these, the decision is wrong regardless of how much time it saves.

Tell us where we're wrong

This page fails at its purpose if it only collects agreement. Architecture criticism, privacy holes, better prior art — all welcome. Messages go straight to the operator.

  1. What breaks?
  2. Who is affected?
  3. What is the smallest adequate correction?
  4. What might it break in turn?

Sathi is the living product through which the Altruistic architecture is being learned. The framework and reusable code are not released yet.