PAI runs a governed AI workforce — your Pies — on infrastructure you own: your servers, your keys, your team, your memory, completely controllable. Deploy on-premises or Bring Your Own Cloud with PAI Private, and every action passes the Governance Plane before it runs. No lock-in, no chat held hostage, no skills you can't take with you — a private AI ecosystem you own, not a subscription you're trapped inside. Each worker is a Pie: a slice of the whole, put to work on one role. Your Pies. Your premises. Your keys. Our guardrails.
Sales follow-up drafted for the Meridian deal. Expires 41:12.
audit chain #4,812 · signed · verified ✓
Spend today₹312 / ₹2,000
Pies working5 across 2 companies
Kill switchArmed — one tap
What PAI stands for
PAI — Private, Physical, Provable AI, on your own premises. Your keys, your infrastructure, your signed record: one platform you own.
PAI is the whole pie. A Pie is one slice you put to work — a single role an agent picks up and runs, under your keys, your budget, and the Governance Plane.
Answers every text at 2amChases every unpaid invoiceMorning brief at 7:00Logs into the supplier portal for youRemembers every client preferenceApprove payments from the beachOne kill switch for everythingAnswers every text at 2amChases every unpaid invoiceMorning brief at 7:00Logs into the supplier portal for youRemembers every client preferenceApprove payments from the beachOne kill switch for everything
375+tests in the open SDK
5chat exports importable
L0–L3autonomy dial
100%on your hardware
Data never leaves your premises
Bring your own AI keys
Tamper-evident audit trail
One-tap kill switch
Built to be yours
Own it, don't rent it — the infrastructure, the workers, the memory, and the record.
Bring Your Own Cloud
PAI Private deploys the whole stack behind your perimeter — the OpenPie Engine, the PaperPie Workforce and the Governance Plane in your VPC or on your own hardware. Your servers, your keys, your memory. No chat export, no skills export, no ransom for leaving: cancel any time and keep everything.
Every tool call, gated
Wire in any MCP tool through Governed Connectors — they ship in the stack and switch on with configuration. First use asks you; after that every call passes policy, allowlisted per role and autonomy level. Desktop Reach — a Pie driving apps on your own machines — is on the roadmap, and we say so honestly.
Roles, teams and companies
Model your org the way it runs: roles, teams, and whole companies, each Pie with one manager and a job description, under a CEO Pie that reports to you from PieHub. Per-company memory is isolated by the database — not by a policy promise — so one company's context is invisible to another's Pies.
Metrics, quotas and a signed record
Track every Pie's spend and state, cap it with hard-stop budgets, and route across 35+ providers on your own keys (BYOK) or local models. Every action is written to an Ed25519-signed, hash-chained audit — the Driver Record, verifiable offline. Governed AI workers you can prove, not just trust.
How it works
From signup to working Pies in three steps.
1
Serve your Pies
Serve from the Pie Menu — 25+ pre-built Pies from Executive PA to Collections to Legal Review — or let the Bakery bake a custom one from a two-minute brief. Each comes with a persona, skills, and a budget you control.
2
Connect your keys & WhatsApp
Paste your own Anthropic/OpenAI/Google keys — they stay on your device, never on our servers. Pair WhatsApp and Telegram for briefings and approvals.
3
Approve from your phone while they work 24/7
Your Pies handle the routine. Anything sensitive — sends, payments — waits for your one-tap approval. You see every action and every rupee.
Meet your Pies
Five launch Pies below, security-hardened — plus 20 more in the Pie Menu and the Bakery for custom ones. Every Pie has a "what it did yesterday" feed you can audit line by line.
Executive PA
Email triage and drafts, calendar, reminders.
Yesterday
Triaged 64 emails, drafted 9 replies
Rescheduled 2 meetings, sent 5 reminders
Collections
Invoice chasing with a polite-to-firm escalation ladder. Proposes payments — never executes them.
Yesterday
Chased 11 overdue invoices (₹4.2L outstanding)
2 payment promises logged, 1 escalated to you
Sales Follow-up
Lead and WhatsApp follow-ups, CRM notes — no lead goes cold.
Yesterday
Followed up 14 leads, booked 3 calls
Updated 17 CRM records
Research
Competitor and news watch, distilled into your morning brief.
Yesterday
Tracked 6 competitors, 2 price changes flagged
Compiled the 8:00 briefing
Docs Q&A
Instant answers over your own business documents — contracts, SOPs, price lists.
25 pre-built Pies, each with a persona, a reviewed skill set, conservative autonomy defaults, and a budget you set — plus The Bakery when you need one that doesn’t exist yet.
Executive Pie
Your day, triaged, prepped, and closed out
operations
Inbox Pie
Email triage and replies in your voice
operations
Calendar Pie
Scheduling without double-bookings or lost focus time
operations
Meeting Pie
Minutes, actions, and follow-ups from every meeting
describe a role · AI bakes the Pie · you set its leash
The control plane
Every action your AI takes is signed, chained, and verifiable. See every rupee spent, approve what matters, and stop everything in one tap. That's not a chatbot — that's governance.
Spend vs budget
Every Pie's cost, per company, against a hard-stop budget you set. It cannot overspend the cap.
Approvals queue
Sends, payments and anything sensitive wait for your one-tap approval — on WhatsApp or in the Companion.
Audit chain
Every action Ed25519-signed and hash-chained into the Driver Record — verifiable offline, years later, without us.
Kill switch
Pause one Pie, one company, or everything — instantly, from any screen. The default on a missed approval is deny.
Two worlds, fused
One stack with three layers: the employee, the company, and the trust between you and both.
OpenPie Engine
The employee. Every chat channel, a real browser, your devices as hands and eyes, voice, installable skills — the reach of the most capable hire you’ve ever made.
PaperPie Workforce
The company. Org charts, goals, tasks, heartbeats, and salaries in tokens — your Pies get a boss, a title, and a job description.
Governance Plane
The trust layer. One-tap approvals, autonomy floors, hard-stop budgets, a signed audit chain, and the kill switch — the leash and the flight recorder.
Built on the open-source OpenClaw & Paperclip projects (MIT) — credited, not hidden.
Own it, don't rent it
The difference between hiring staff and subscribing to someone else's.
Aspect
PAI
Cloud AI SaaS
Where your data lives
On your device or your private pod
Their multi-tenant cloud
Whose AI keys
Yours — you pay providers directly, at cost
Theirs — usage marked up, limits theirs
What happens if you cancel
You keep the box, the agents, and all your data. Only our dashboards stop.
Access ends. Export what you can, while you can.
Four ways to run it — one image
Not four products. The same container, the same governance, the same Pies. What changes is where it runs and who holds the keys.
Solo
You, personally
An individual, a founder, an operator with their own hardware.
Your Pie runs on your own Mac or a Box on your desk. No account with us is required and no cloud is involved — point it at local models and nothing leaves the room. You are the owner; there is no admin above you.
A pod for the organization, a Pie per person, budgets per driver. Invite your people, give a mentor read-only sight of decisions, and keep the kill switch on your phone. This is the mode the cloud sign-up creates.
Our cloud or yours. Provider keys stay in your pod.
Regulated, or simply not willing to move the data.
The pod runs inside your VPC. Your keys, your data, your network — we orchestrate, we never hold it. The pod calls out to enroll and heartbeat; the control plane never connects in. That invariant is the whole reason this can be honest rather than a checkbox.
Miatz, ashr.work, and others packaging it as their own.
Sell it inside your package. A training cohort gets a Pie per learner, a mentor console, and an auditable record of what each learner decided — signed, and verifiable after they leave. Demystify also delivers it directly as a forward-deployed engagement.
Pod from ₹12,000/mo DRAFT — or own the hardware outright with a Box. All plans include the Control Plane. Annual = 2 months free. Prices exclusive of GST.
DPDP-alignedMetadata-only telemetry by defaultOpen-source agent stack you can inspectIndia-region pods
Questions owners actually ask
Three ways, your pick — the setup wizard asks once. Bring your own key and your data goes straight to the provider under your account, at cost, no markup; the key lives in your pod's vault, never in our code or logs. Run local models and nothing leaves the box at all. Or take metered access on an org pod, where each person gets their own key with their own budget and a hard stop. Whichever you choose, nobody using a Pie ever holds the provider key.
Your device keeps working locally and queues its audit telemetry for up to 72 hours. Agents that need cloud AI models pause gracefully; anything running on local models (Box Plus) keeps going. When the connection returns, everything syncs — with zero gaps in the audit chain.
Only with your approval. Payments are propose-only by design — a Pie can prepare a payment and send you the link, but a human always taps pay. That's a platform rule, not a setting you can accidentally switch off.
Owner-led businesses — typically ₹2–200 Cr revenue, often running more than one company — where the owner lives on WhatsApp and wants outcomes (chased invoices, answered leads, a daily brief) with control (what did it do, what did it cost, stop it now).
An open-source agent stack you can inspect — agent runtime, organization/governance layer, a model gateway for your keys, a local database for memory and documents — plus our governance daemon that signs every action into a tamper-evident audit trail. No public inbound ports; management traffic only over a private network.
They govern the agent. We govern the pair: one named human — the Driver — bound to their Pies, their budget, and their own chain of custody. That pair is the thing nobody else models, and it's why spend, approvals and the audit trail all line up per person instead of per bot. The runtime underneath is an implementation detail we could swap; the accountability layer is the product.
Yes, and without us. Every action is Ed25519-signed and hash-chained on your device, and any person's decisions can be exported as a portable credential that verifies offline with no access to your systems or ours. Not “trust our dashboard” — check it yourself, anywhere, years later.
Yes — same container, your VPC. It's one image with four modes: your laptop, our cloud, your cloud, or a demo. The pod always calls out to enroll and report; we never need inbound access to your network, and your keys, your data and your signing key never leave it. A firewall that allows only outbound HTTPS is enough.
Three routes. Direct from Demystify Systems — with a forward-deployed engineer to stand it up, or as the replacement for hiring one. Through a partner who resells it inside their own package (Miatz for training cohorts, ashr.work, and others). Or self-serve on your own hardware, where you get the full stack and no reseller at all.