Your Pies. Your infrastructure. Your record. No lock-in.

A governed AI workforce,
inside your perimeter.

PAI runs a governed AI workforce — your Pies — on infrastructure you own: your servers, your keys, your team, your memory, completely controllable. Deploy on-premises or Bring Your Own Cloud with PAI Private, and every action passes the Governance Plane before it runs. No lock-in, no chat held hostage, no skills you can't take with you — a private AI ecosystem you own, not a subscription you're trapped inside. Each worker is a Pie: a slice of the whole, put to work on one role. Your Pies. Your premises. Your keys. Our guardrails.

Say PAI. Or Pie. Or π. It answers to all of them.

What PAI stands for

PAI — Private, Physical, Provable AI, on your own premises. Your keys, your infrastructure, your signed record: one platform you own.

PAI is the whole pie. A Pie is one slice you put to work — a single role an agent picks up and runs, under your keys, your budget, and the Governance Plane.

375+tests in the open SDK
5chat exports importable
L0–L3autonomy dial
100%on your hardware
Data never leaves your premises
Bring your own AI keys
Tamper-evident audit trail
One-tap kill switch

Built to be yours

Own it, don't rent it — the infrastructure, the workers, the memory, and the record.

Bring Your Own Cloud

PAI Private deploys the whole stack behind your perimeter — the OpenPie Engine, the PaperPie Workforce and the Governance Plane in your VPC or on your own hardware. Your servers, your keys, your memory. No chat export, no skills export, no ransom for leaving: cancel any time and keep everything.

Every tool call, gated

Wire in Slack, Gmail, GitHub, your databases — or any MCP tool server — through Governed Connectors. They ship in the stack and switch on with configuration; first use asks you, and after that every call passes policy, allowlisted per role and autonomy level. Desktop Reach turns your own machine into a governed tool the same way — the pod reaches out, nothing reaches in. Connect everything, governed →

Roles, teams and companies

Model your org the way it runs: roles, teams, and whole companies, each Pie with one manager and a job description, under a CEO Pie that reports to you from PieHub. Per-company memory is isolated by the database — not by a policy promise — so one company's context is invisible to another's Pies. Each venture gets a Founder OS — a private operating plane your leadership Pies keep current.

Metrics, quotas and a signed record

Track every Pie's spend and state, cap it with hard-stop budgets, and route across 35+ providers on your own keys (BYOK) or local models. Every action is written to an Ed25519-signed, hash-chained audit — the Driver Record, verifiable offline. Governed AI workers you can prove, not just trust.

Connectors · Model Context Protocol

Connect the tools you already run — every call governed

Paste a token for Slack, Gmail or GitHub; point the pod at any MCP tool server for your databases and SaaS; or turn your own desktop into a tool. Whatever it gains, every call passes the same gate — first use asks you, and it's signed on your own device.

Slack
Gmail
GitHub
Database
Desktop
Governor gatefirst use asks you · policy on every call · fails closed

signed on the chain — mcp:id.tool · params hashed

1

Connect

Own-token integrations (Slack, Gmail, GitHub, coding CLI) go in once and reach every Pie — tokens stay write-only in the pod's vault. Or point at any MCP server over streamable-HTTP / SSE.

2

Govern

Every tool becomes a governed action: first use asks you, risky classes park for approval, a server that changes a tool re-earns trust, and internal hosts are refused. It fails closed.

3

See

Every call lands on the Ed25519 audit chain as mcp:id.tool with its params hashed — what ran, what it cost, who approved it, verifiable offline.

What you can wire in

  • Slack, Gmail, GitHub & coding tokens Live
  • Any MCP tool server (databases, SaaS, community) Enableable
  • Your own desktop as a governed tool Enableable

Use cases

  • The ERP and the CRM under the same leash as email.
  • “File those downloads” — the pod drives your desktop, per-call approved.
  • One connector registry, per-company policy across the fleet.
Story · illustrative

“We pointed a Pie at our internal orders database over MCP. First time it tried to run a query, it asked. We approved. When the vendor pushed a tool update, the schema hash changed and it asked again — exactly what we'd want. Every query is on the chain, so finance can see who ran what, when, for how much.”

A representative scenario, not a named customer. Behaviour matches the shipped governance tests (first-use approval, schema-drift re-approval, signed chain).

See the full Connectors story →

One governed action, end to end

How Pai turns a request into a signed, approved outcome

A request passes the Governor gate, waits for your approval, runs its tools, and is signed on the chain
  1. 1AskA task arrives — from chat, a routine, or a webhook.
  2. 2GovernThe gate classifies it; first use always asks you.
  3. 3ApproveAnything that sends, pays or publishes waits for your thumb.
  4. 4ActIt runs its tools — only after the yes.
  5. 5ProveSigned and hash-chained, verifiable offline, forever.

How it works

From signup to working Pies in three steps.

1

Serve your Pies

Serve from the Pie Menu — 33 ready-made Pies from Executive PA to Collections to Legal Review — or let the Bakery bake a custom one from a two-minute brief. Each comes with a persona, skills, and a budget you control.

2

Connect your keys & WhatsApp

Paste your own Anthropic/OpenAI/Google keys — they stay on your device, never on our servers. Pair WhatsApp and Telegram for briefings and approvals.

3

Approve from your phone while they work 24/7

Your Pies handle the routine. Anything sensitive — sends, payments — waits for your one-tap approval. You see every action and every rupee.

Meet your Pies

Five launch Pies below, security-hardened — plus 28 more in the Pie Menu and the Bakery for custom ones. Every Pie has a "what it did yesterday" feed you can audit line by line.

Executive PA

Email triage and drafts, calendar, reminders.

Yesterday
  • Triaged 64 emails, drafted 9 replies
  • Rescheduled 2 meetings, sent 5 reminders

Collections

Invoice chasing with a polite-to-firm escalation ladder. Proposes payments — never executes them.

Yesterday
  • Chased 11 overdue invoices (₹4.2L outstanding)
  • 2 payment promises logged, 1 escalated to you

Sales Follow-up

Lead and WhatsApp follow-ups, CRM notes — no lead goes cold.

Yesterday
  • Followed up 14 leads, booked 3 calls
  • Updated 17 CRM records

Research

Competitor and news watch, distilled into your morning brief.

Yesterday
  • Tracked 6 competitors, 2 price changes flagged
  • Compiled the 8:00 briefing

Docs Q&A

Instant answers over your own business documents — contracts, SOPs, price lists.

Yesterday
  • Answered 23 staff questions with sources
  • Indexed 3 new documents
+28 more in the Pie Menu →

The control plane

Every action your AI takes is signed, chained, and verifiable. See every rupee spent, approve what matters, and stop everything in one tap. That's not a chatbot — that's governance.

Spend vs budget

Every Pie's cost, per company, against a hard-stop budget you set. It cannot overspend the cap.

Approvals queue

Sends, payments and anything sensitive wait for your one-tap approval — on WhatsApp or in the Companion.

Audit chain

Every action Ed25519-signed and hash-chained into the Driver Record — verifiable offline, years later, without us.

Kill switch

Pause one Pie, one company, or everything — instantly, from any screen. The default on a missed approval is deny.

42 capabilities · one honest list

Everything PAI does — at a glance

24 live · 17 enableable (ships in the stack, switched on at setup) · 1 on the roadmap. Grouped so you can see the whole surface — every one carries its honest status on the explorer.

Govern & prove

The leash and the flight recorder.

  • One-tap approvals
  • Autonomy dial + payment floors
  • Hard-stop budgets
  • Signed audit chain
  • On-device PII shield

Connect any tool

Under one roof, every call gated.

  • Slack · Gmail · GitHub (live)
  • Any MCP tool server
  • Your desktop as a tool
  • Webhooks & event triggers

A workforce of Pies

Roles you serve, not staff you configure.

  • 33 ready-made + the Bakery
  • CEO autopilot
  • Heartbeat workforce
  • One-click decision cards

Talk to it anywhere

The boss's chair is your chat app.

  • One command channel
  • The 8:00 briefing
  • 26+ inboxes (omnichannel)
  • Voice & field-aware dictation

Memory you own

Isolated by the database, not a promise.

  • Per-company memory
  • Import 5 years of chat history
  • Grounded recall with citations
  • Document Q&A + extraction

Run it your way

One image, no lite edition.

  • Solo · Org · BYOC · Demo
  • BYOK — 35+ providers, at cost
  • Local models for private work
  • Sync to your own database

Accountable by person

Govern the pair, not just the agent.

  • The Driver Record
  • The Itz'at portable proof
  • Multi-company isolation
  • Fleet telemetry + anomaly watch

Founder OS

A private operating plane per venture.

  • Decisions, plans, budget, risks
  • Authored by your CXO Pies
  • Configurable modules
  • Mirrored secret-free to the cloud

Explore all 42 with their exact status →

Two worlds, fused

One stack with three layers: the reach, the company, and the trust between you and both.

OpenPie Engine

The reach. Every chat channel, a real browser, your devices as hands and eyes, voice, installable skills — the reach of the most capable worker you’ve ever had.

PaperPie Workforce

The company. Org charts, goals, tasks, heartbeats, and salaries in tokens — your Pies get a boss, a title, and a job description.

Governance Plane

The trust layer. One-tap approvals, autonomy floors, hard-stop budgets, a signed audit chain, and the kill switch — the leash and the flight recorder.

Explore what they make possible →

Built on the open-source OpenClaw & Paperclip projects (MIT) — credited, not hidden.

The Pocket Companion · your pod, in your hand

One app for the whole workforce — paired and encrypted

The Companion is an installable app that talks only to your pod. You pair it once with a bearer token over loopback or your private network — never a public port — and approve, watch and steer the workforce from your pocket.

A pod and a phone joined by a single encrypted link — the pod calls out, nothing reaches in

Paired, not exposed

The app holds a single bearer token on your device and reaches the pod over loopback or your Tailscale network. No inbound port is ever opened; nothing on the public internet can reach your pod.

Keys stay in the vault

Your model keys and connector tokens live in the pod's AES-256-GCM encrypted vault, write-only — the Companion never holds them, and they never reach our cloud.

The pod calls out

When you enrol with our cloud, the pod initiates every heartbeat and reports a secret-free rollup. The control plane never reaches in — even in your own VPC.

Works offline

Installable and offline-capable: approvals, budgets, the kill switch and the audit status stay in reach even without a connection, and sync catches up later.

Solo

The full pod on your own laptop or a box in the cupboard — nothing leaves it.

Org cloud

A hosted pod with the Fleet console — seats, org policy, one pane over every pod.

Your VPC (BYOC)

The same image inside your own cloud; your keys, your data, outbound-only.

Your database

Opt-in: keep a copy of your data in your own Postgres, MySQL or MongoDB.

How the encryption and audit chain work →

The voice of PAI

Meet Mysty

Mysty is the voice on every page — it narrates what the Governance Plane decided and the chain recorded, and answers from what actually ships, with an honest Live, Enableable or Roadmap status. It never decides, approves or acts; that is the Pies’ job, under your leash.

Own it, don't rent it

The difference between hiring staff and subscribing to someone else's.

AspectPAICloud AI SaaS
Where your data livesOn your device or your private podTheir multi-tenant cloud
Whose AI keysYours — you pay providers directly, at costTheirs — usage marked up, limits theirs
What happens if you cancelYou keep the box, the agents, and all your data. Only our dashboards stop.Access ends. Export what you can, while you can.

Four ways to run it — one image

Not four products. The same container, the same governance, the same Pies. What changes is where it runs and who holds the keys.

Solo

You, personally

An individual, a founder, an operator with their own hardware.

Your Pie runs on your own Mac or a Box on your desk. No account with us is required and no cloud is involved — point it at local models and nothing leaves the room. You are the owner; there is no admin above you.

Your box. Your keys. Optionally your own models.

Run it on your own Mac →

Org

An owner-led business

Typically ₹2–200 Cr, often more than one company.

A pod for the organization, a Pie per person, budgets per driver. Invite your people, give a mentor read-only sight of decisions, and keep the kill switch on your phone. This is the mode the cloud sign-up creates.

Our cloud or yours. Provider keys stay in your pod.

Start in the cloud →

BYOC

A corporate with rules

Regulated, or simply not willing to move the data.

The pod runs inside your VPC. Your keys, your data, your network — we orchestrate, we never hold it. The pod calls out to enroll and heartbeat; the control plane never connects in. That invariant is the whole reason this can be honest rather than a checkbox.

Your VPC. Your keys. We never reach in.

Read the security design →

Partner

Resellers & cohorts

Miatz, ashr.work, and others packaging it as their own.

Sell it inside your package. A training cohort gets a Pie per learner, a mentor console, and an auditable record of what each learner decided — signed, and verifiable after they leave. Demystify also delivers it directly as a forward-deployed engagement.

Your customers. Your brand. Our governance.

See what it does →

Simple pricing

Pod from ₹12,000/mo DRAFT — or own the hardware outright with a Box. All plans include the Control Plane. Annual = 2 months free. Prices exclusive of GST.

See full pricing →
DPDP-alignedMetadata-only telemetry by defaultOpen-source agent stack you can inspectIndia-region pods

Questions owners actually ask

Three ways, your pick — the setup wizard asks once. Bring your own key and your data goes straight to the provider under your account, at cost, no markup; the key lives in your pod's vault, never in our code or logs. Run local models and nothing leaves the box at all. Or take metered access on an org pod, where each person gets their own key with their own budget and a hard stop. Whichever you choose, nobody using a Pie ever holds the provider key.

Your device keeps working locally and queues its audit telemetry for up to 72 hours. Agents that need cloud AI models pause gracefully; anything running on local models (Box Plus) keeps going. When the connection returns, everything syncs — with zero gaps in the audit chain.

Only with your approval. Payments are propose-only by design — a Pie can prepare a payment and send you the link, but a human always taps pay. That's a platform rule, not a setting you can accidentally switch off.

Owner-led businesses — typically ₹2–200 Cr revenue, often running more than one company — where the owner lives on WhatsApp and wants outcomes (chased invoices, answered leads, a daily brief) with control (what did it do, what did it cost, stop it now).

An open-source agent stack you can inspect — agent runtime, organization/governance layer, a model gateway for your keys, a local database for memory and documents — plus our governance daemon that signs every action into a tamper-evident audit trail. No public inbound ports; management traffic only over a private network.

They govern the agent. We govern the pair: one named human — the Driver — bound to their Pies, their budget, and their own chain of custody. That pair is the thing nobody else models, and it's why spend, approvals and the audit trail all line up per person instead of per bot. The runtime underneath is an implementation detail we could swap; the accountability layer is the product.

Yes, and without us. Every action is Ed25519-signed and hash-chained on your device, and any person's decisions can be exported as a portable credential that verifies offline with no access to your systems or ours. Not “trust our dashboard” — check it yourself, anywhere, years later.

Yes — same container, your VPC. It's one image with four modes: your laptop, our cloud, your cloud, or a demo. The pod always calls out to enroll and report; we never need inbound access to your network, and your keys, your data and your signing key never leave it. A firewall that allows only outbound HTTPS is enough.

Three routes. Direct from Demystify Systems — with a forward-deployed engineer to stand it up, or as the replacement for hiring one. Through a partner who resells it inside their own package (Miatz for training cohorts, ashr.work, and others). Or self-serve on your own hardware, where you get the full stack and no reseller at all.

PAI