GuaGua AI Labs LLC

Agent-Governed AI Systems for Safe Enterprise Workflows.

We help enterprises turn goals into bounded tasks, verifiable checkpoints, and traceable decision briefs — without sacrificing safety, compliance, or auditability.

Texas, United States · Founded August 17, 2026

Updates

Company notes and launch updates

In progress Company setup Company setup in progress.

Company setup in progress.

Coming online Website & domain Website and domain coming online.

Website and domain coming online.

In progress Partner materials Partner and accelerator materials being prepared.

Partner and accelerator materials being prepared.

After review More product info Shared after review.

More product information will be shared after review.

Updated as basics land. Not a live dashboard. Not a status commitment.

The platform

Three pillars. One direction.

Agent-governed AI systems for the enterprise.

Agent governance

Every action is bounded. Each task runs against a governed agent operating under explicit rules. Every state change is locked at a checkpoint. Human approval is required for live connector enablement.

Read-only-first data

Connectors start in sandbox mode with canned sample data. Live network activation requires explicit Boss authorization. No write / send / trade / action methods reachable in sandbox mode.

Release scanning

Every release bundle is scanned for forbidden content — API keys, private keys, internal prompts, debug dashboards, and unreviewed specs — before any signing step.

What we do not do

  • We do not connect to live APIs without explicit authorization.
  • We do not process PHI, patient data, or EHR data in any current product.
  • We do not claim medical regulatory readiness.
  • We do not claim financial advisory status.
  • We do not enable write, send, trade, or action connectors in sandbox mode.

Use cases

Three concrete workflows.

Where agent-governed AI fits today.

Back-office operations

Receipts, invoices, and multilingual intake. No real PII. No real bank accounts.

Compliance research

Read-only access to public regulatory datasets. Sandbox read-only mode. No live FDA API. No live SEC API. No real patient data.

Internal development operations

Release auditing, codebase governance, and mock shell for testing. Internal tooling. Not customer-facing.

Governance & Safety

Safety is a feature, not an afterthought.

Built into the foundation, not bolted on at the end.

Connector lifecycle

Every connector starts in MockConnector mode (canned sample data, no live fetch). With explicit approval, it graduates to SandboxReadOnlyConnector (canned data plus fail-closed guards). With further approval, it graduates to ApprovedLiveConnector (read-only live fetch, Boss-gated).

Pre-launch: all current products are in MockConnector or SandboxReadOnlyConnector mode. No ApprovedLiveConnector is currently enabled.

Audit log

Every connector call is logged (URL, timestamp, response hash). Every state change is logged (checkpoint ID, reviewer, timestamp). Every release scan is logged (scanner version, target, findings). Audit logs are append-only and server-side.

Release scanner

Before any signing step, every release bundle is scanned for: API keys, OAuth tokens, bearer tokens, private keys, internal prompts, orchestration rules, test harnesses, debug dashboards, backup files, internal SOPs, and unreviewed markdown specs. The scanner is pure-Python, no-network, and no-credentials.

Human approval gates

AI may not self-approve. Boss approval is required for live connector enablement. Human reviewer approval is required for sensitive record classes. External release reviewer approval is required for every public release.

Compliance posture — what we are not

  • We are not a medical device.
  • We are not HIPAA-compliant (no PHI handling).
  • We are not a financial advisor (no buy / sell / hold advice).
  • We are not a trading platform.

All products carry persistent disclaimers. The human decision owner is always the final authority.

The GuaGua Crew

A small cast of studio characters that represent how we work together.

Dot portrait

Dot

Research

Pip portrait

Pip

Review

Koda portrait

Koda

Patterns

Patch portrait

Patch

Connection

Luma portrait

Luma

Clarity

Leadership

Two people. Many decisions.

Boss-gated governance requires real humans at the top.

Malone Hsieh

Founder / CEO

Leads the vision, the architecture, and the Boss-authorization gates. Writes the governance rules and reads the denylist scanner reports. Speaks for GuaGua AI Labs on partner and accelerator conversations.

Cindy Wang

CFO

Leads the finance, the runway, and the incorporation / compliance paperwork. Keeps the team focused on the next milestone. Owns the public-facing numbers — even when the answer is "pre-revenue, bootstrapped."

Leadership names are public-safe. No invites, no projections, no promises. Public decisions and public claims are made by the people named above.

About GuaGua AI Labs

Texas, USA. Founded August 17, 2026.

Company

Legal name
GuaGua AI Labs LLC
State / Country
Texas, United States
Founded
August 17, 2026
Stage
Founder-led
Funding
Bootstrapped / self-funded
Founder
Malone Hsieh — Founder / CEO
CFO
Cindy Wang

Contact

Email: contact@guaguaailabs.com

Backup: guaguaaistudio@gmail.com (temporary backup)

Website: guaguaailabs.com

For partner or accelerator review, please contact us via the email above.

Team

Founder-led. Small team of engineers focused on safety infrastructure for enterprise AI.