For defense software teams
Defense comes first.
An AI API your developers connect to the tools they already use. It is not a chat app, and it is for unclassified work only.
You’ll need someone who can set a base URL in a tool: a developer, or your IT contractor. The leader brief says what it takes.
On a Department of Defense (DoD) network? Read the status ledgerFour kinds of team.
-
01
Software factories
Many editors let you set a custom endpoint in the OpenAI chat completions format. Line Three is that endpoint, for code review, test generation, refactoring and documentation. What is supported, and what isn’t.
Each developer gets a key with its own cap, so one busy sprint can’t spend the whole month’s budget.
Coding agents: compatibility not yet verified. Which editors are tested, and when.
generate table tests for parse_window()
-
02
Squadron and program-office developers
A few developers, a real backlog and no enterprise AI contract. Set a cap, issue keys and start. At the cap, requests stop, so there is no overage bill to explain.
explain this legacy module before I refactor it
-
03
Staff work
Turn an instruction into steps, tighten a point paper, or pull what you need from a long reference. The answer is a draft: you check it and you sign it.
Line Three has no chat window of its own at launch: staff use it through a chat tool your IT contractor or developer sets up.
summarize this unclassified instruction into a checklist
-
04
Defense contractors and subcontractors
Defense contractors and subcontractors may use Line Three: prepaid credit on a company card, or monthly after use, by company card or on a company purchase order payable net-30 (within 30 days of the invoice).
Line Three is not CMMC assessed; don’t send anything in your CMMC scope.
Who approves, in a company. Inside a company, your facility security officer (FSO) or information system security manager (ISSM) and your export-control officer decide whether Line Three may be used, and for what. Check your prime contract’s flow-down clauses too. This is guidance, not legal advice.
write table tests for this unclassified parser
Where Line Three fits.
The fit: a small team’s own tools, a hard cap, and a card or purchase order.
Why pay for Line Three instead of a chat portal, or Amazon Bedrock in your own account? Line Three’s rates include the gateway, caps, key controls, usage reports and support. The government has no agreement with AWS through Line Three.
Choose Line Three when…
- Your developers need an API, not a chat window.
- You want to pay by card once it opens and your approvals are in hand.
- You want open-weight models, hosted in the United States.
- You want a hard limit on spend: prepaid credit, or a monthly cap billed in arrears.
| What you need | Line Three | A chat portal | An enterprise AI platform | Amazon Bedrock in your own AWS account |
|---|---|---|---|---|
| Use from your own tools | Yes, OpenAI-compatible, a key per person or tool. | Typically none: a chat window for people. | Typically, if the contract includes it. | Yes, OpenAI-compatible, with Bedrock API keys; you set it up. |
| What you run | Only your tools; Line Three runs the rest. | Typically nothing: its operator runs it. | Typically nothing: the provider runs it. | Your own AWS account and its security controls. |
| Pay for what you use | Yes, per request, up to your hard cap, per key too. | Typically per user, used or not. | Typically per seat, used or not. | Yes, per request; per-key hard caps are yours to build. |
| What’s kept of your prompts and answers | None: each is discarded once delivered. | Typically set by its operator; ask for its terms. | Typically set in the contract. | None by default; logging is yours to switch on. |
| Price | Published: $0.25–$0.90 per 1M tokens in, $0.90–$3.00 out, with the gateway, keys, caps, reports and support. | Usually provided by your organization at no direct cost to your team. | Typically a negotiated contract price. | AWS’s published rates, on your AWS bill. |
| Authorization status | None held. Your AO decides. | Typically set by its operator; ask for its authorization. | Typically set by the provider for its environment; ask which. | Your account, region and your AO’s decision. |
| CUI | Not accepted. | Typically set by its operator; ask for its terms. | Typically only where the contract and its authorization cover it. | Possible in AWS GovCloud (US), under your own ATO. |
-
A chat portal your organization already provides
Use it when your people need a chat window for everyday writing, and it is already approved for your work.
Line Three has no chat window at launch.
-
An enterprise AI contract
Look for one when you need an authorized environment for CUI or above, or AI at the scale of a program.
Line Three holds no authorization and does not accept CUI at launch.
-
Line Three
Fits when a small team of developers wants an API their own tools can call, for unclassified work, with a small monthly cap.
Built for editors and scripts; coding agents: compatibility not yet verified. Opening to early-access teams first.
What people send.
Unclassified, generic examples.
Control statements, SBOMs and Dockerfiles can carry CUI or export-controlled detail. Check the marking before you send them.
| Task | Who | Example request |
|---|---|---|
| Review a pull request for input-validation gaps | Software factory | review this handler for unchecked input; suggest fixes |
| Write the missing unit tests | Software factory | generate table tests for parse_window() |
| Explain a legacy module before a refactor | Program office | walk me through this module and list its side effects |
| Draft a design note from a whiteboard summary | Program office | turn these bullet points into a one-page design note |
| Turn an instruction into a checklist | Squadron staff | summarize this unclassified instruction into a checklist |
| Tighten a point paper | Squadron staff | cut this point paper to one page; keep every figure |
| Explain a failing CI pipeline | Software factory | read this pipeline log and tell me which step failed and why |
| Draft a fix for a static-analysis finding | Software factory | propose a fix for this finding and a test that proves it |
| Close a Security Technical Implementation Guide (STIG) finding | Software factory | explain this STIG finding and draft the configuration change that closes it |
| Draft a Risk Management Framework (RMF) control statement | Program office | draft the implementation statement for this control from our design notes |
| Compare two software bills of materials (SBOMs) | Software factory | list the components added, removed or upgraded between these two SBOMs |
| Harden a container image | Software factory | review this Dockerfile against our hardening checklist and propose fixes |
On a DoD network? Read this first.
- Approved for DoD use
- No. Line Three holds no authorization.
- No
- Network access
-
Line Three is a commercial internet service. Whether a government network can reach it is decided by that network’s owners.
Hand them this: hostname
api.linethree.ai, HTTPS on port 443, TLS 1.2 or later. - Your network owners decide
- Impact Level
- Not held. Line Three is for unclassified, non-CUI work and makes no Impact Level (IL) claim.
- Not held
- ATO
- Not held. No authority to operate (ATO) has been issued for Line Three.
- Not held
- FedRAMP
- Not held. Line Three holds no FedRAMP (federal cloud) authorization.
- Not held
- Models
- gpt-oss-120b, NVIDIA Nemotron 3 Super 120B, NVIDIA Nemotron Nano 3 30B. AWS lists each launch model as FedRAMP Class C in US West (Oregon) (us-west-2), the region Line Three uses. Line Three does not inherit any provider authorization. What the marks mean, and where they apply.
- Marks are AWS’s
- Classification
- Encrypted in transit. For unclassified work. Not an accredited secure communications line. Never send classified information.
- Unclassified
- CUI
- CUI is not accepted at launch. Do not send it. A CUI tier on AWS GovCloud (US) is planned.
- Not accepted
- Contractor data
- Do not send classified information, CUI, covered defense information under DFARS 252.204-7012, or export-controlled technical data (ITAR or EAR). If you’re unsure, don’t send it.
- Not accepted
- Your data
- Line Three stores no prompt or answer content. Amazon Bedrock follows AWS’s own terms. Read the data policy.
- No content kept
- Where it’s processed
- Requests are answered by the model provider, Amazon Bedrock, in US West (Oregon), so they are processed in the United States.
- United States
Who needs to say yes
- Your Authorizing Official (AO) or cyber office, for use on government systems.
- The office that runs your network, for network access.
- Your card approving official, and your IT purchase rules, for the buy.
- Your contracting office, for a purchase order.
- Your resource advisor or funds certifier, for the funds, and which fiscal year’s money applies.
Don’t know who your AO is? Ask your unit’s cybersecurity lead; they will know.
For your cyber office: every fact they will ask for, on one printable sheet.
Before your first request from a government machine
Ask the people who say yes.
Your Authorizing Official (AO) or cyber office, for use on government systems, and the office that runs your network, for network access. Hand them the assessor sheet.
Read your organization’s AI policy.
It may limit what you can send or which tools you can use. It takes precedence over anything on this site.
Send unclassified, non-CUI work only.
Check the marking on anything before you send it.
Give each person their own key.
Set a cap on every key, so the budget holds and usage is reported by key.
Start with one key.
A team starts with a prepayment or a monthly cap, and one key.