theangels.ai
Not a team, not a tenant, not an account: in this document, one Angel means one named beneficiary.
The people we want to build for are the ones whose requirements are strict. That is a statement of intent, not of who is served today.
A doctor can now complete one bounded task without us: the medical-data preflight below. It admits only a private local trial with synthetic material and refuses patient data or uncertainty. It does not operate a full Angel.
Answer the category questions. Do not enter names, patient details, or clinical text.
The same operator key is classified as authorized on one family's box and as a cross-network violation on a doctor's — and a box that handles patient data is floored to the stricter network, so a label can raise its isolation but never lower it.
Control model at this build: Phase1-shared-hetzner.angel-guardian/access.json
That is a shared-host phase, not dedicated hardware per person, and the sentence above describes how keys are classified — not what metal they sit on.
Each registered claim above had its declared proof re-run during this build.
A sentence whose proof stops passing does not get softened here — it stops rendering.
Admin writes are gated: every mutating path requires an explicit confirm and a passing local delegation preflight before it is allowed to run.
Two mandatory paths refuse to contact a stranger. Alerts to the owner ride a fail-closed recipient allowlist. The configured Gmail MCP now runs through a protocol proxy before the vendor server: explicit send and forward recipients must all be allowlisted, while sends whose full recipient set is implicit are refused rather than guessed. An unset allowlist refuses every outbound message.
A box that would hold patient data is refused at provisioning time unless its posture is declared and proven, and a plan to become compliant is treated as not compliant.
Clinical data is not admitted today: every medical Angel is declared on a synthetic, no-PHI footing, and provisioning refuses a medical box unless it is either no-PHI or backed by recorded US residency and a BAA. This is an enforced pre-production posture, not a claim of HIPAA compliance.
The legal filing gate has no success value. Its best possible answer is “attorney review required” — there is no input that makes it say a draft is ready to file. Three probe drafts, including one built on a case we invented, all came back BLOCKED.
Every pinned MCP server is described from source bytes tied to its configured command, installed package, hosted package, or exact fleet tool — or from explicit capability fields in its configured URL. No description is inferred from a server name; every observation retains its host and source digest.
A pin is a supply-chain record, not a capability count. These numbers describe different things and are printed separately on purpose.
Send us another agent's published record of what it cannot do.
works-e2e is mintable only by running a real proof and observing exit 0. It is not declarable.
Our legal corpus now contains sourced, full-text judicial opinions, and the filing gate can check a draft against that local caselaw as well as resolve missing citations externally. It still cannot tell a lawyer whether a real case remains good law: no treatment citator runs here, so a clean result still means “not obviously fabricated”, never “checked”.
2 of these 6 are still not proven end-to-end.