You know where your data goes. The AI comes to you.
An AI engine wired into your business, with the providers named in writing. LinearPilot masks sensitive fields before the call and restores them in the answer.
Private AI that actually understands your business.
Three layers of intelligence — each designed to keep your data safe while giving you powerful AI capabilities.
Private AI Engine
An AI engine that reads your documents, CRM and data, and answers questions in seconds — with the providers it uses named on our Sub-processors page.
Learn moreUse any AI model — without the risk.
LinearPilot holds the provider accounts, so there are no keys for you to obtain or rotate. Whichever model answers, sensitive fields — emails, phone numbers, card and ID numbers, addresses — are swapped for placeholders before your question leaves, then restored in the answer you see.
See how it worksEnterprise-grade security
Sensitive fields are encrypted at rest with AES-256-GCM and masked before any request leaves. Data in transit is encrypted with TLS, and every AI interaction is written to an audit trail.
See the security controlsThe AI Engine is opinionated on purpose
Named providers under no-training terms, sensitive fields masked before they leave, a strict tool registry, and explicit budgets per agent. Here is what ships in every deployment.
All three LinearPilot tiers — Spark, Core and Max — are open on every plan, so moving up is a setting, not a rewrite. Every tier runs under provider terms that exclude your data from training, and the provider behind each tier is named on our Sub-processors page.
Frontier models from named providers when a task needs more horsepower. LinearPilot holds the accounts, and you pick which tier answers. Every outbound call has sensitive fields masked and is written to the audit trail.
Extendable per plan. Search finds records by meaning rather than by keyword, and every answer can be traced back through the connections it was built from.
Sales, HR, support, docs, research and more — each seeded per tenant with its own tools and budget. Add custom agents on higher plans.
READ tools run on their own. CREATE tools add new records and notify you. MODIFY tools — anything that changes or sends existing data — wait for your explicit approval before they run.
80% warning, 100% auto-pause. Visible to admins. Resets on the 1st of each month.
Agents run proactively on a schedule you set. Example: “Sales · weekdays 9am · surface stale deals.”
Every tool run and every outbound model call is recorded — what was asked, what came back, how long it took, and whether sensitive fields were masked.
One engine, a whole stack of AI
Chat is just the front door. The same engine runs code, works with images, audio, documents and data, listens and speaks, and works in the background — lightweight, security-sensitive steps run on LinearPilot's own models, and heavier AI goes to named providers with sensitive fields masked.
Vision, audio, documents, and data
The engine does far more than chat. Lightweight and security-sensitive work runs on LinearPilot's own models; heavier generation and extraction goes to an external provider — with sensitive fields masked, your consent, and the provider named in writing.
Sandboxed code execution
For real analysis, the engine writes and runs code in a network-isolated sandbox — and only after you approve the run. A Pro add-on; included on Max.
Voice in and out
Talk to the engine and hear it answer. Spoken replies are generated on your device and never leave it; dictation now uses external transcription, with sensitive fields masked and only when your workspace has enabled it.
AI Inbox + nightly learning
A background digest lands every six hours with its sources cited. Overnight, a learning loop reviews the day's work and shows you what improved in What's New.
AI that respects your data.
Get the power of AI without the privacy trade-off. Start free today.