The on-device security layer for the AI you already use

Your AI. Your keys.
Your data stays yours.

Lili is a desktop AI assistant that runs on your own OpenAI, Anthropic or Gemini key. She redacts secrets — keys, card numbers, IDs — on your device before any model sees them. Speak or type; she reads files, sends messages, opens apps.

  • Free — your own key, no subscription
  • Secrets redacted before any model call
  • Local audit of every redaction

See her work

Watch Lili redact a secret before it's sent.

A real prompt full of keys, card numbers and IDs — scrubbed on-device before it reaches any model.

Play, scrub, and adjust volume right in the player 🔊

What she does

An assistant that acts — and protects you while it does.

She listens

On-device wake word. Say "Hey Lili" — she hears you across the room.

She thinks — with your key

Your OpenAI, Anthropic or Gemini key. Requests go device-to-provider, never through us.

She protects

Every prompt clears an on-device redaction gate first. Secrets are masked before they leave, restored only in your view.

She does

Files, apps, mail, calendar, Slack, GitHub, search, reminders — real actions from one command.

Private by design

She redacts secrets before they're sent.

To answer, Lili sends your prompt to the model you choose — but scans it on-device first and strips anything sensitive: keys, passwords, card numbers, IBANs, SSNs, emails. The real values never reach the model; Lili restores them locally in the reply you see.

  • Redaction runs on your device — an inspectable engine, not a black box.
  • Wake word and speech-to-text stay on-device.
  • Your model keys live in your OS keychain — never on our servers.
  • Your content never trains the providers' models.
  • Privacy Activity log records every redaction — types and counts only, never your text.
See your Privacy Activity →

Built in

Everything you need from day one.

Your key, any model

Switch between Claude, GPT and Gemini anytime. Model-agnostic by design.

Allow-list only

She opens only the apps you've approved. Nothing else.

Lili from Slack, anywhere

DM or @mention her from any device to run tasks on your PC while you're out. Coworkers can ask too — their actions wait for your one-tap approval.

Memory that survives restarts

Tell her once — she remembers until you say "forget that." Reminders fire a Windows toast on time, running or not.

Speaks MCP, the open standard for AI tools — flip on a connector and the new skill is there next time you call her: Filesystem · GitHub · Slack · Gmail · Calendar · Microsoft 365 · Brave Search · custom servers.

Pricing

Two products. One security spine.

Free for individuals, and an enterprise deployment that runs inside your own infrastructure. Sensitive content is always processed where it lives.

  1. Lili Free
    $0forever
    Bring your own model key
    Works with your key from
    Anthropic Claude OpenAI GPT Google Gemini

    Requests go straight from your device to your provider

    • On-device redaction before any model call
    • Local audit of every redaction
    • Voice + text, real actions, every built-in tool
    • No subscription · nothing routed through our servers
  2. For institutions
    Lili Enterprise
    Custom
    Deployed to your environment
    Model endpoint
    Regional Azure OpenAI / Bedrock Sovereign self-hosted

    Only redacted, minimized text — only to the endpoint you approve

    • Runs inside your VPC or data center
    • Central policy & admin console (RBAC) · SSO
    • Org-wide aggregated audit + SIEM export
    • Fleet deployment · support SLA · security-review support

Windows 10 & 11 · bring your own key · free forever for individuals. Enterprise is sold per institution — no self-serve payment.