EV Code-Signed · Enterprise-Grade · Zero Trust (EU residency · no telemetry · login-only data)

The PowerShell IDE
Built for Production

Describe what you need. Get a production-ready script. Execute locally in a persistent runspace. Script output, credentials, and runspace state stay on your machine — only what you actively send reaches the AI.

EV Code-Signed
ECDSA Mutual Auth
.NET 10 + PS7 SDK
Native C++ Security Core

A Practical AI Workbench for PowerShell Administration.

ShellPilot brings AI-assisted scripting into a workflow administrators can actually use: a real Windows UI, local execution, persistent PowerShell state, and clear control over what reaches the AI.

Many AI tools start from the command line. ShellPilot starts from the administrator's workflow. You can describe a task, review the generated PowerShell, execute it locally, inspect the output, paste screenshots or errors when needed, and continue working in the same session.

The goal is not to force every admin into an autonomous agent model. ShellPilot keeps the useful parts of AI assistance while preserving the parts administrators already rely on: visible output, explicit execution, copy-and-paste, documentation, local credentials, and a persistent runspace.

Cloud AI works immediately through the managed proxy. Local AI can be used where the customer already has or wants its own model infrastructure. Either way, the product stays UI-first and operationally simple: copy the executable, activate it, and work.

Built from real infrastructure delivery experience: mixed environments, change pressure, screenshots, logs, credentials, documentation, local execution, and administrators who need control before automation.

Three Ways to Script in 2026

Every tool generates PowerShell. The difference is what happens after.

Web AI

COPY-PASTE WORKFLOW
  • Generate script in browser, copy to clipboard
  • Paste into terminal, execute manually
  • Error? Copy, switch window, paste, wait
  • No local execution — everything is copy-paste
  • No persistent session — context resets
  • All input and output processed in cloud

VS Code + Copilot

HEAVY INSTALL · CLOUD-DEPENDENT
  • 300+ MB install with extensions and dependencies
  • Must be installed on every machine
  • Cloud subscription required
  • Every keystroke and output sent to cloud
  • Not portable — not designed for field use
  • No persistent runspace across scripts

* ShellPilot runs with the permissions of the current user. Elevated operations require admin rights as expected.
Application control policies (AppLocker, WDAC) are respected — ShellPilot does not bypass security controls.

Vendor-Independent by Design

ShellPilot was built to fill gaps that existing tools leave open — persistent sessions, local execution, data privacy by default. PowerShell is the language. How you use it is your decision, not your vendor's. The AI recommends the best approach for your environment, not the one that sells more cloud subscriptions.

What Makes ShellPilot Different

Not another AI chatbot with a terminal. A purpose-built execution environment engineered for IT infrastructure operations.

Persistent Runspace

Embedded PowerShell 7 SDK with full session persistence. Variables, connections, and module state survive across every script execution. Connect-AzAccount once, use it for your entire session.

EMBEDDED PS7 SDK

Native C++ Security Core

Security-critical operations run in a native C++ module. Cryptographic keys, device authentication, and credential handling are isolated from managed code.

ECDSA P-256 / DPAPI

Challenge-Response Auth

Client and proxy mutually verify each other using ECDSA signatures before any data exchange. Intercepted traffic cannot impersonate either endpoint.

MUTUAL AUTHENTICATION

Hardware-Bound Licensing

Device fingerprints generated from hardware characteristics. Licenses cannot be copied between machines or shared across unauthorized devices.

DEVICE FINGERPRINT

Vision Analysis

Paste screenshots directly into the chat. AI analyzes error messages, log outputs, and configuration dialogs to generate targeted solutions.

IMAGE RECOGNITION

Crash-Safe Execution

Multi-layer defense against runaway scripts. Interactive processes, infinite loops, and unexpected behaviors are caught and terminated without affecting your session.

DEFENSE IN DEPTH
90 MB · Single File · Self-Contained

Built-in PowerShell 7 SDK and .NET 10 runtime. No installation, no dependencies, no admin rights required.

Portable executable EV code-signed SIEM-compatible logging Runs anywhere

Three Steps. That's It.

01

Describe

Tell ShellPilot what you need in plain language. Paste errors, logs, screenshots, requirements. It understands context.

02

Review

AI generates production-ready PowerShell with error handling. Edit inline if needed. Multiple solutions presented when appropriate.

03

Execute

One click. Runs locally in your persistent runspace. Results stay on your machine. No data transmitted. Period.

Engineered for Environments
Where Security Is Non-Negotiable

Every layer verified. Every connection authenticated. Every output stays local. Designed for regulated industries.

Zero Data Persistence

No chat history stored. No scripts saved. No output cached. Close the application — everything is gone. Nothing is written to disk unless you explicitly export.

Local Execution Only

Scripts execute in an embedded PS7 runspace. Output, variables, credentials never leave your machine.

Mutual Authentication

Client verifies the proxy. Proxy verifies the client. ECDSA challenge-response prevents MITM attacks.

Authenticated Request Path

Every AI request runs through the authenticated proxy path with device-bound session credentials. Captured traffic alone cannot be replayed against another device or reused outside the active session.

Credential Safety

Get-Credential and Read-Host -AsSecureString handled natively. Passwords encrypted in memory. Never logged, never sent to AI.

SIEM-Ready

Full ScriptBlock Logging compatibility. Windows Event Log integration. Audit every script execution.

Device-Bound

Hardware-based device fingerprints. Activation tied to physical machines. Sessions cannot be cloned or transferred.

Server-Enforced Limits

Budget, rate limits, device count all enforced server-side. Client-side tampering cannot bypass restrictions.

EV Code-Signed

Extended Validation certificate. Immediate SmartScreen trust on all Windows systems. No download warnings.

Complete Separation of Script Generation and Execution

Only your text prompt leaves your machine. Scripts, output, credentials, and session data never do.

YOUR MACHINE — 100% LOCAL Chat Display Full conversation, every script output PS7 Runspace Persistent session, embedded execution Native C++ Core Mutual verification, client anti-tampering MANAGED AI CONTEXT Separate from the chat. Usually shorter. Trimmed automatically. DATA BOUNDARY Prompt Output (opt-in) Reply SHELLPILOT CLOUD — AZURE EU (api.shellpilot.app) Secure Proxy Strips your identity before the request reaches Google Vertex AI — Gemini europe-west4 region Generates scripts from prompts

The visible chat is not the AI context

What you see in the chat is the full conversation, including every script output. What the AI receives is a separate, automatically managed context — usually shorter, trimmed to fit the model's window. Only your prompts and the outputs you actively send via Send to AI enter it.

What crosses the boundary

Solid arrow: your prompt — crosses automatically.
Dashed arrow: a specific script output — crosses only when you click Send to AI on that result.
Reply: the generated script, returned to the chat.

Mutual verification on every request

The client verifies the proxy. The proxy verifies the device. Both directions, every call — not just at login. The verification logic lives in the Native C++ Core and protects only the integrity of the connection.

Transparent to SSL inspection

Enterprise SSL inspection sees your prompt, the generated script, and a short-lived session token bound to this specific device. None of those lets an attacker impersonate the proxy or reproduce the backend. A captured token without the matching device is inert.

Google does not know who you are

The Secure Proxy strips your identity before forwarding the request. Your email, subscription, and company are not part of what Google sees — only an anonymous device hash and your prompt.

Nothing is stored server-side

Prompts, scripts, chat history, and script outputs are not persisted on the proxy or anywhere else. The proxy holds only what it needs to operate: your email, subscription state, and the device hash.

Everything Your Infrastructure Throws at You

If PowerShell can do it, ShellPilot does it faster. Describe, execute, document — in one tool.

ACTIVE DIRECTORY

User & Group Management

Bulk changes, permission audits, group nesting analysis, stale accounts, tiering assessments.

AZURE / M365

Cloud Administration

Azure resources, Entra ID, license management, compliance policies. Connect once, run everything.

REPORTING

Instant Documentation

HTML reports, Excel exports, audit trails, compliance docs — generated from live data in seconds.

HYPER-V

VM Management

Clone VMs, manage snapshots, move storage, check replication. No more Hyper-V Manager clicking.

EXCHANGE

Mailbox Operations

Permissions, quotas, forwarding rules, message tracking, archive policies.

NETWORK

DNS / DHCP / Firewall

DNS records, DHCP scopes, firewall rules, connectivity tests. Network admin as code.

GPO

Policy Management

Compare GPOs, find conflicts, analyze inheritance, export settings.

AUTOMATION

Build Your Own Tools

Monitoring agents, scheduled tasks, job orchestration. Build an entire toolbox over time.

ANY TECH

If PowerShell Can Do It...

SQL queries, REST APIs, file operations, registry, services — ShellPilot does it faster.

Local AI Mode

Run your own LLM on-premises. AI inference stays on your network. The application still contacts the ShellPilot Azure proxy for subscription verification on launch and refreshes its licence token hourly when online.

Compliance

100% Data Sovereignty

Local LLM means inference stays inside your infrastructure. Designed for strict data-sovereignty requirements in banking, government, and healthcare environments.

BCM

Business Continuity

Cloud outage? Your infrastructure management keeps running. ShellPilot operates independently when AI connectivity is interrupted.

24h

Resilient Licence Path

The client refreshes its licence token hourly when online. If the proxy is briefly unreachable, an already-running Local AI session continues for up to 24 hours since the last successful refresh. AI inference itself runs on your hardware throughout.

Local models have inherent limitations (smaller context window). Optimized for standard scripting and automation tasks.

Ready to Work Smarter?

All plans include the full application with embedded PowerShell 7 + .NET 10. Cancel anytime.

Starter

$34
per month
  • AI Script Generation
  • Local Execution
  • Persistent Runspace
  • 3 Devices
  • Community Support
Subscribe

Pro Plus

$79
per month
  • Everything in Pro
  • Premium AI Capacity
  • Local AI Integration *
  • Priority Support
Subscribe

All prices in USD, net (excluding applicable taxes). Billed monthly. Cancel anytime.
Annual billing on invoice available for business customers — see checkout.
* Local AI Integration available on Pro and Pro Plus

Want to test ShellPilot in your environment? Request a Demo →