Your Pies. Your infrastructure. Your record. No lock-in.

A governed AI workforce,
inside your perimeter.

PAI runs a governed AI workforce — your Pies — on infrastructure you own: your servers, your keys, your team, your memory, completely controllable. Deploy on-premises or Bring Your Own Cloud with PAI Private, and every action passes the Governance Plane before it runs. No lock-in, no chat held hostage, no skills you can't take with you — a private AI ecosystem you own, not a subscription you're trapped inside. Each worker is a Pie: a slice of the whole, put to work on one role. Your Pies. Your premises. Your keys. Our guardrails.

Say PAI. Or Pie. Or π. It answers to all of them.

What PAI stands for

PAI — Private, Physical, Provable AI, on your own premises. Your keys, your infrastructure, your signed record: one platform you own.

PAI is the whole pie. A Pie is one slice you put to work — a single role an agent picks up and runs, under your keys, your budget, and the Governance Plane.

375+tests in the open SDK
5chat exports importable
L0–L3autonomy dial
100%on your hardware
Data never leaves your premises
Bring your own AI keys
Tamper-evident audit trail
One-tap kill switch

Built to be yours

Own it, don't rent it — the infrastructure, the workers, the memory, and the record.

Bring Your Own Cloud

PAI Private deploys the whole stack behind your perimeter — the OpenPie Engine, the PaperPie Workforce and the Governance Plane in your VPC or on your own hardware. Your servers, your keys, your memory. No chat export, no skills export, no ransom for leaving: cancel any time and keep everything.

Every tool call, gated

Wire in any MCP tool through Governed Connectors — they ship in the stack and switch on with configuration. First use asks you; after that every call passes policy, allowlisted per role and autonomy level. Desktop Reach — a Pie driving apps on your own machines — is on the roadmap, and we say so honestly.

Roles, teams and companies

Model your org the way it runs: roles, teams, and whole companies, each Pie with one manager and a job description, under a CEO Pie that reports to you from PieHub. Per-company memory is isolated by the database — not by a policy promise — so one company's context is invisible to another's Pies.

Metrics, quotas and a signed record

Track every Pie's spend and state, cap it with hard-stop budgets, and route across 35+ providers on your own keys (BYOK) or local models. Every action is written to an Ed25519-signed, hash-chained audit — the Driver Record, verifiable offline. Governed AI workers you can prove, not just trust.

How it works

From signup to working Pies in three steps.

1

Serve your Pies

Serve from the Pie Menu — 25+ pre-built Pies from Executive PA to Collections to Legal Review — or let the Bakery bake a custom one from a two-minute brief. Each comes with a persona, skills, and a budget you control.

2

Connect your keys & WhatsApp

Paste your own Anthropic/OpenAI/Google keys — they stay on your device, never on our servers. Pair WhatsApp and Telegram for briefings and approvals.

3

Approve from your phone while they work 24/7

Your Pies handle the routine. Anything sensitive — sends, payments — waits for your one-tap approval. You see every action and every rupee.

Meet your Pies

Five launch Pies below, security-hardened — plus 20 more in the Pie Menu and the Bakery for custom ones. Every Pie has a "what it did yesterday" feed you can audit line by line.

Executive PA

Email triage and drafts, calendar, reminders.

Yesterday
  • Triaged 64 emails, drafted 9 replies
  • Rescheduled 2 meetings, sent 5 reminders

Collections

Invoice chasing with a polite-to-firm escalation ladder. Proposes payments — never executes them.

Yesterday
  • Chased 11 overdue invoices (₹4.2L outstanding)
  • 2 payment promises logged, 1 escalated to you

Sales Follow-up

Lead and WhatsApp follow-ups, CRM notes — no lead goes cold.

Yesterday
  • Followed up 14 leads, booked 3 calls
  • Updated 17 CRM records

Research

Competitor and news watch, distilled into your morning brief.

Yesterday
  • Tracked 6 competitors, 2 price changes flagged
  • Compiled the 8:00 briefing

Docs Q&A

Instant answers over your own business documents — contracts, SOPs, price lists.

Yesterday
  • Answered 23 staff questions with sources
  • Indexed 3 new documents
+20 more in the Pie Menu →

The control plane

Every action your AI takes is signed, chained, and verifiable. See every rupee spent, approve what matters, and stop everything in one tap. That's not a chatbot — that's governance.

Spend vs budget

Every Pie's cost, per company, against a hard-stop budget you set. It cannot overspend the cap.

Approvals queue

Sends, payments and anything sensitive wait for your one-tap approval — on WhatsApp or in the Companion.

Audit chain

Every action Ed25519-signed and hash-chained into the Driver Record — verifiable offline, years later, without us.

Kill switch

Pause one Pie, one company, or everything — instantly, from any screen. The default on a missed approval is deny.

Two worlds, fused

One stack with three layers: the employee, the company, and the trust between you and both.

OpenPie Engine

The employee. Every chat channel, a real browser, your devices as hands and eyes, voice, installable skills — the reach of the most capable hire you’ve ever made.

PaperPie Workforce

The company. Org charts, goals, tasks, heartbeats, and salaries in tokens — your Pies get a boss, a title, and a job description.

Governance Plane

The trust layer. One-tap approvals, autonomy floors, hard-stop budgets, a signed audit chain, and the kill switch — the leash and the flight recorder.

Explore what they make possible →

Built on the open-source OpenClaw & Paperclip projects (MIT) — credited, not hidden.

Own it, don't rent it

The difference between hiring staff and subscribing to someone else's.

AspectPAICloud AI SaaS
Where your data livesOn your device or your private podTheir multi-tenant cloud
Whose AI keysYours — you pay providers directly, at costTheirs — usage marked up, limits theirs
What happens if you cancelYou keep the box, the agents, and all your data. Only our dashboards stop.Access ends. Export what you can, while you can.

Four ways to run it — one image

Not four products. The same container, the same governance, the same Pies. What changes is where it runs and who holds the keys.

Solo

You, personally

An individual, a founder, an operator with their own hardware.

Your Pie runs on your own Mac or a Box on your desk. No account with us is required and no cloud is involved — point it at local models and nothing leaves the room. You are the owner; there is no admin above you.

Your box. Your keys. Optionally your own models.

Run it on your own Mac →

Org

An owner-led business

Typically ₹2–200 Cr, often more than one company.

A pod for the organization, a Pie per person, budgets per driver. Invite your people, give a mentor read-only sight of decisions, and keep the kill switch on your phone. This is the mode the cloud sign-up creates.

Our cloud or yours. Provider keys stay in your pod.

Start in the cloud →

BYOC

A corporate with rules

Regulated, or simply not willing to move the data.

The pod runs inside your VPC. Your keys, your data, your network — we orchestrate, we never hold it. The pod calls out to enroll and heartbeat; the control plane never connects in. That invariant is the whole reason this can be honest rather than a checkbox.

Your VPC. Your keys. We never reach in.

Read the security design →

Partner

Resellers & cohorts

Miatz, ashr.work, and others packaging it as their own.

Sell it inside your package. A training cohort gets a Pie per learner, a mentor console, and an auditable record of what each learner decided — signed, and verifiable after they leave. Demystify also delivers it directly as a forward-deployed engagement.

Your customers. Your brand. Our governance.

See what it does →

Simple pricing

Pod from ₹12,000/mo DRAFT — or own the hardware outright with a Box. All plans include the Control Plane. Annual = 2 months free. Prices exclusive of GST.

See full pricing →
DPDP-alignedMetadata-only telemetry by defaultOpen-source agent stack you can inspectIndia-region pods

Questions owners actually ask

Three ways, your pick — the setup wizard asks once. Bring your own key and your data goes straight to the provider under your account, at cost, no markup; the key lives in your pod's vault, never in our code or logs. Run local models and nothing leaves the box at all. Or take metered access on an org pod, where each person gets their own key with their own budget and a hard stop. Whichever you choose, nobody using a Pie ever holds the provider key.

Your device keeps working locally and queues its audit telemetry for up to 72 hours. Agents that need cloud AI models pause gracefully; anything running on local models (Box Plus) keeps going. When the connection returns, everything syncs — with zero gaps in the audit chain.

Only with your approval. Payments are propose-only by design — a Pie can prepare a payment and send you the link, but a human always taps pay. That's a platform rule, not a setting you can accidentally switch off.

Owner-led businesses — typically ₹2–200 Cr revenue, often running more than one company — where the owner lives on WhatsApp and wants outcomes (chased invoices, answered leads, a daily brief) with control (what did it do, what did it cost, stop it now).

An open-source agent stack you can inspect — agent runtime, organization/governance layer, a model gateway for your keys, a local database for memory and documents — plus our governance daemon that signs every action into a tamper-evident audit trail. No public inbound ports; management traffic only over a private network.

They govern the agent. We govern the pair: one named human — the Driver — bound to their Pies, their budget, and their own chain of custody. That pair is the thing nobody else models, and it's why spend, approvals and the audit trail all line up per person instead of per bot. The runtime underneath is an implementation detail we could swap; the accountability layer is the product.

Yes, and without us. Every action is Ed25519-signed and hash-chained on your device, and any person's decisions can be exported as a portable credential that verifies offline with no access to your systems or ours. Not “trust our dashboard” — check it yourself, anywhere, years later.

Yes — same container, your VPC. It's one image with four modes: your laptop, our cloud, your cloud, or a demo. The pod always calls out to enroll and report; we never need inbound access to your network, and your keys, your data and your signing key never leave it. A firewall that allows only outbound HTTPS is enough.

Three routes. Direct from Demystify Systems — with a forward-deployed engineer to stand it up, or as the replacement for hiring one. Through a partner who resells it inside their own package (Miatz for training cohorts, ashr.work, and others). Or self-serve on your own hardware, where you get the full stack and no reseller at all.