Technology
How CloakMe and FlashElves work together.
CloakMe runs the phone line and the voice AI on it. FlashElves runs your elf, the one that gets real-world work done. Here is exactly how the two talk to each other, what each side is allowed to do, and the safeguards in between.
The big picture
A phone line, a voice AI, and tools it can reach mid-call
Every call on your CloakMe number arrives over the regular phone network. CloakMe streams the audio to a real-time voice AI that follows your instructions for that number. During the call the AI can use tools: check your calendar or hand a task to your elf through FlashElves, search the web, or ask you a question.
Sequence diagrams
Four flows, step by step
1. Connecting FlashElves to CloakMe
You choose which numbers FlashElves can use. FlashElves never sees your password, and access ends the moment you disconnect.
2. Your AI answers a call and books a meeting
While the caller is still on the line, your AI asks FlashElves for your real free time, then sends the full call report when the call ends.
3. You call your AI and hand a task to your elf
Calling your CloakMe number from that same line in the CloakMe app puts your AI in task mode. It takes the request and passes it to FlashElves; when you say goodbye it hangs up. Your elf texts you from your CloakMe number when it's done.
4. A scheduled call on your behalf
FlashElves keeps the task until the time you chose, then asks CloakMe to place the call with your goal and your limits. If something comes up that your limits don't cover, the AI asks before agreeing.
Safeguards
Built so neither side can overstep
Scoped, revocable access
FlashElves holds a token for your account and only the numbers you picked. Disconnect from CloakMe or FlashElves and it stops working at once.
Every request signed
Each request CloakMe sends to FlashElves carries a timestamp and a signature over the exact method, path and body, made with a key unique to your link and stored encrypted. Questions and results for a call use a key unique to that call.
Delivered with retries
Call reports wait in a queue and are retried after 10 seconds, 1 minute and 5 minutes if FlashElves doesn't confirm them. Texts and calls requested by FlashElves carry an idempotency key, so a retry never sends or dials twice.
Texting with limits
Connected apps can send up to 100 texts a day per account, and never to premium-rate, satellite or emergency numbers.
Calls that end cleanly
Your AI says goodbye and hangs up when the conversation is done. Long silences and stuck calls end on their own; no call runs past 30 minutes.
Your limits on every call
What it may agree to and must never do are given to the AI on every call. Anything outside them becomes a question to you, at most five per call.
For developers
What a signed request looks like
Requests from CloakMe to FlashElves are plain HTTPS POSTs with a JSON body. The receiver recomputes the signature with the link's key and rejects anything that doesn't match. Redirects are never followed, so a signature can't be forwarded to another host.
POST /api/cloakme-links/{link_id}/received-calls Content-Type: application/json X-FlashElves-Timestamp: 1791751200 X-FlashElves-Signature-V2: sha256=9f2c…e41a # signature = HMAC-SHA256(link key, # timestamp + "." + METHOD + "." + path + "." + raw body) { "id": "…", "number": "+1725…", "caller": { "number": "+1702…" }, "outcome": "…", "summary": "…", "meeting": { … } }
Give your elf a phone line.
Get a CloakMe number, then connect FlashElves from Connected apps.
CloakMe