AI answers you can actually trust.
Altretta is your private second brain: your notes and your code in one signed graph. Ask anything and every answer cites the exact source it came from — the decision, the note, or the function — without anything leaving your computer.
When was the migration approved?
The migration was approved on March 12, with a budget of €48.000.
Every answer, with its proof
In brief
Altretta is a private, local-first notes app: your notes and your code are your own Markdown files, and every AI answer cites the exact source it came from, with a signed history.
- Your files
- Markdown on your machine, no silo
- Your own AI
- Connect your model over MCP
- Everything leaves proof
- Signed, reversible history
- Available on
- macOS · Windows · Linux · free
Knowledge deserves something better.
Your notes are trapped in someone else's app
Proprietary databases, closed formats, and syncs that disappear one day. Your knowledge should be yours, forever.
AI answers without proof
Assistants hallucinate, mix sources, and you can't verify where each claim came from. Without evidence, there's no trust.
Team knowledge stays siloed
Fragmented wikis, permissions impossible to revoke, and sensitive data exposed to third parties. Sharing shouldn't mean losing control.
Don't trust it. Check it.
Trust is something you extend. Verification is something you do. Altretta is built so you never have to take its word — or your AI's — for anything that matters.
A checkmark that had to earn it
The badge appears only when two things hold at once: the signature actually checks out, and the note still matches what that signature covers. If either check fails there is no badge — it fails closed rather than giving itself the benefit of the doubt.
It tells you when something changed
If a note was signed and then edited, you are told exactly that — not quietly downgraded to "unsigned". A signature that no longer covers what you are reading is worth saying out loud.
An assistant that will say it does not know
Ask about something your notes do not cover and it tells you so — no answer is produced at all. Getting one anyway is a separate choice you have to make on purpose.
Answers point at the page, not the file
PDFs, Word files, presentations and spreadsheets are read in with their structure intact — page numbers, slide numbers, even the article numbers in a regulation — so a grounded answer cites the exact place it came from instead of just a filename.
Your notes stay yours
Every note is an ordinary file on your computer. No lock-in, no format you can't open. Move it, back it up, or leave Altretta anytime — your knowledge comes with you.
It connects the dots you'd miss
Altretta links related notes automatically, surfacing the idea from months ago you forgot you wrote — all on your machine, nothing uploaded.
See the shape of everything you know
One click turns your notes into a world you can walk through. Folders become floors, hidden connections rise to the surface, and the shape of your thinking finally comes into view.
Understand your whole project — what you write and what you code.
Altretta reads your repository and maps it as a signed map: every symbol, how they call each other, and the decision that governs each one. So your AI doesn't just know your notes — it understands your code and how to change it without breaking anything.
Connect your AI. On your terms.
Bring the AI you already use — ChatGPT, Claude, Cursor — to your notes with your own subscription. You decide what it sees, and everything it does is signed and can be undone.
An encrypted, verifiable, revocable team brain.
Share knowledge without giving up control. End-to-end encryption, access you revoke in an instant, and a provable history.
Fewer tokens, by design
Altretta plugs into your AI over MCP and, powered by AIngle (its semantic engine), gives the model only the notes that matter, grounded and cited. Your AI works from the relevant context instead of your whole vault, so it spends fewer tokens and you stop re-pasting to explain yourself.
| Query | Without Altretta | With Altretta | Savings |
|---|---|---|---|
| Average per query | 23,020 | 1,363 | 94.1% |
| 8-query conversation | 184,609 | 46,709 | 74.7% |
Measured on the standard Studio Ghibli demo vault (43 notes, 24 pre-registered questions): the full vault pasted as context vs the cited passages Altretta serves over MCP with its real engine. Input tokens; the ratio is stable across tokenizers. Reproduce it yourself with the Altretta skill and the Studio Ghibli demo vault.
The savings come from connecting your AI to the Altretta skill over MCP: it gets only the cited passages that matter, not your whole vault. Reproduce it yourself with the Studio Ghibli demo vault.
Get the Altretta skillExtend it with skills & plugins from the Apilium Hub.
hub.apilium.com
From note to verifiable knowledge.
Write in Markdown
Take notes as always. Every idea is saved as a file you own on your disk.
Altretta links it all
It connects related notes and keeps a signed history of every change — all on your computer.
Connect your AI in a click
Plug in the AI you already pay for. It reads your notes; you choose what it can see.
Ask and verify
Get answers that quote your notes, with a confidence score you can check for yourself.
What actually happens when you open it.
No account, no setup wizard, no upload. You point it at a folder and it starts working.
- 01
Point it at a folder
Your existing notes folder works exactly as it is. Nothing is imported, converted or moved — Altretta reads the Markdown files already sitting on your disk.
- 02
Connect the AI you already pay for
It finds Claude, Cursor, VS Code, Windsurf, Zed and others already installed on your machine and sets them up for you. No keys to paste, no config files to edit.
- 03
Ask it something only your notes know
The first grounded answer is the moment it clicks: the reply quotes the note it came from, and you can open that note and see for yourself.
- 04
Then try to catch it out
Ask about something you never wrote down. It will tell you it has nothing to go on — and that, more than any answer, is the reason to keep it.
It costs you nothing to find out.
The app is free, it runs on your machine, and your files stay exactly where they already are. There is no trial clock and nothing to cancel.
No account needed
Download, open, work. Signing in is only for the paid features — everything local keeps working while you are signed out.
Works with the network off
Your notes are on your disk and so is the app. A flight, a dead connection, a company that disappears — none of it stops you reading or writing.
Files in a format that outlives us
Plain Markdown in an ordinary folder. Not a database, not a container. Open them in any editor, today or in ten years, with or without us.
Nothing is measured about you
No analytics, no usage reporting, no crash telemetry. A fresh install does not even work out which machine it is running on.
Start free. Pay only when you grow.
The app on your computer is free forever, and so is your first synced folder. Paid plans add as many synced folders as you like, publishing verifiable pages, and the encrypted team brain.
Why people upgrade
What changes when you pay.
The free app is genuinely the whole product for one person on one machine. Paying is about reach — more devices, more history, other people.
The same vault on every machine
Write on the laptop, pick it up on the desktop — through storage you already own and chose: your Dropbox, your OneDrive, a network share, a USB stick. What lands there is encrypted, with scrambled file names and no folder structure, and there is no copy on our servers because our servers are not in the path at all.
Turn chosen notes into a page others can open
Publish a selection of your vault as a site, with the provenance of each page attached to it.
Reach further back
Free keeps the last week within easy reach. Paying opens the older versions, so you can go back to how something read before you changed your mind.
A shared brain that is still yours
Share an encrypted vault with your team, hand out and take back access one person at a time, and always know who changed what.
- The full desktop app
- Notes, graph, Bases & Canvas
- Use the AI you already pay for
- Answers grounded in your notes
- Sync one folder via your own cloud
- Unlimited synced folders
- Publish pages others can verify
- Longer version history
- Import from Notion & Confluence
- Priority support
- Shared encrypted team vault
- Add or remove people in a click
- Encrypted sync across the team
- Roles & team dashboard
- See who wrote what
Every organisation arrives with its own security review, procurement process and compliance requirements. Tell us yours and we will work through them with you.
Talk to sales- ✓Free foreverThe local app and your notes are yours, offline, even if you never pay.
- ✓No lock-inEverything is standard Markdown files. Leave whenever you want, with your knowledge.
- ✓Cancel anytimeIndividual plans are month-to-month; team plans renew yearly. Managed from your portal.
Prices in EUR · VAT included · subscription managed at my.apilium.com
Where a valid VAT number means no VAT is due, the amount charged is the price before VAT.
We have no idea you are using this.
That is not a policy we could change, it is how the app is built. There is no analytics library inside it, no crash reporter, nothing fetched from a server to draw the interface, and a fresh install never works out which machine it is on.
No analytics, of any kind
There is no analytics or product-usage library bundled in the app. Not switched off by default — not there at all.
No crash or error reporting
When something goes wrong it goes wrong on your machine, and it stays on your machine.
Nothing loaded from anywhere else
Fonts and assets ship inside the app. The interface never calls out to a server in order to draw itself.
A fresh install stays anonymous
Nothing describes your device unless you start a trial or activate a licence, which is the only moment your machine is identified at all.
Do not take our word for it
The app reaches the network in a small, boring set of places, and you can watch every one: a check for updates against a static file, and — only if you actually use them — your own AI provider, your Notion or Confluence account, and our licence server. Point a network monitor at it and see.
For the reader who does not believe marketing copy.
Everything above, restated as mechanism — names, curves, sizes, thresholds, and the places where a limit exists, including the ones that are not flattering. If you find something here the code does not do, we would rather hear about it than not.
The signed history
Every change is an action in a directed acyclic graph. An action carries its parent hashes, the author node, a per-author sequence number, a UTC timestamp and the payload. Its identity is BLAKE3-256 over those fields concatenated in a fixed order — parents, author, sequence, timestamp, payload — with the signature deliberately excluded, so signing never changes the hash. The signature is Ed25519 over the 32 raw digest bytes, not over the preimage and not over its hex rendering. The byte layout is published as a spec, aingle-dag-action-v1, so you can rebuild the preimage yourself; a test pins the published spec against the code that actually hashes, so the two cannot drift apart in silence.
Removal is a retraction, not a delete
Deleting a note does not erase anything. It appends a signed deletion action naming what it retracts, so the earlier state stays reachable and provable and time-travel survives. One exception, stated because you would find it: a prune operation does physically remove old actions under an explicit retention policy. It never prunes the tips, and it writes a checkpoint recording what it removed — but it is a real delete, and where it is exposed to AI tooling it is marked destructive rather than hidden among the read-only calls.
What the lock proves — and what it does not
A verified lock means two things at once: the Ed25519 signature on the anchoring action verified, and the note on disk still hashes to exactly what that signature attests. Either one failing yields no lock, and every error path fails closed — no key, no graph, a malformed hash or a missing action all produce "unverified" rather than the benefit of the doubt. "Signed, then edited" is reported as its own state instead of collapsing to unsigned. What it does not prove: the key is your vault's own, generated locally, so this is a self-attestation, not an identity — there is no certificate authority and no binding to a person. The timestamp is your machine's clock, sealed inside the signed bytes; there is no timestamping authority, so anyone holding the seed could back-date. And the signing seed is stored unencrypted next to the database. It proves these bytes were ingested and signed here and have not changed since. That is a smaller claim than "authentic", and it is the one we make.
Encryption at the sync target
One random 32-byte master key per target, generated on the device. Three subkeys derived from it with BLAKE3 derive_key under distinct context strings: one for content, one for blob names, one for a public target id. Content is XChaCha20-Poly1305 with a fresh random 24-byte nonce per write and a 16-byte tag. The master key is reachable two ways, both held only by you: a passphrase wrapped with Argon2id — the argon2 crate defaults, 19 MiB, 2 iterations, 1 lane, with a 16-byte random per-target salt — stored in a keybox on the target itself so any machine that can see the folder can unlock it; or a one-time recovery key, which is the master key rendered as 56 Crockford base32 characters with a checksum. Nothing is escrowed. We hold no copy and there is no reset, which is the same thing as saying we could not read your files even if we wanted to.
What actually lands in the folder
A blob's name is a keyed BLAKE3 hash of its vault path, Crockford base32 encoded — always 52 characters, so the length of a path leaks nothing either. The real path travels inside the sealed payload, so decrypting one blob is enough to place it: there is no manifest and no name table that could be lost or corrupted. The authentication tag covers the path, so a blob renamed or moved by anything other than the app is detected rather than silently accepted. Padding is applied to the plaintext before sealing: the padded length is the next multiple of 4 KiB up to 64 KiB, and the next multiple of 64 KiB above that. On disk a blob is that padded length plus exactly 40 bytes — a 24-byte nonce and a 16-byte authentication tag.
What an observer of that folder can still see
Stated here because you would find it anyway, and because a limitation you discover for yourself is worth far more doubt than one we hand you. Someone who can read the synced folder learns: that it is an Altretta target, because the header file is plaintext on purpose so a second machine can find the salt; the number of notes, since there is one blob each; and each file's size to within its padding bucket. Because a blob's name is a deterministic function of its path, every note keeps the same name for its whole life — a stable pseudonym. That determinism is what lets two machines agree where a note lives without a shared index, and it is also what lets an observer watch how often you edit any single note, note by note, from timestamps alone — without ever learning which note it is. Deletions are the sharpest of these, and they are exact rather than approximate: a removed blob is moved into a trash directory rather than unlinked, keeping its name and gaining the millisecond it was removed. So the precise number of notes you have deleted, the exact moment of each deletion, and which pseudonym each deleted note had while it existed are all plainly readable. The public target id is a stable fingerprint linking two folders to the same key. None of it discloses a title, a path, or a word of content.
What makes the assistant refuse
Retrieval embeds your question, over-fetches from the memory index, keeps only chunk entries and re-ranks them by pure cosine similarity — deliberately discarding the composite recency-and-importance score the memory layer would otherwise apply, because relevance to the question is the only thing that should decide a citation. A verdict of "grounded" requires the best match to clear the high threshold and at least 2 chunks to clear it: corroboration, not one lucky passage. With the neural embedder the product ships, those thresholds are 0.80 and 0.77, calibrated against a measurement that unrelated pairs top out near 0.76. Between the two is "weak"; below both is "ungrounded". The answerability gate is then: at least one visible source after your folder exclusions have been applied, and — if you asked for grounded answers only — a verdict of exactly "grounded". When that gate fails, no model call is made at all. Answering anyway is a separate flag that is never inferred on your behalf, and when you set it the weak passages are withheld from the model so it cannot cite what did not qualify.
The symbol graph
Twenty languages have symbol extractors, each a tree-sitter parse plus a query: Rust, TypeScript, JavaScript, Python, Go, Swift, Java, C, C++, C#, Kotlin, PHP, Ruby, Dart, Scala, Objective-C, Bash, Lua, R and SQL. Symbols get canonical identifiers and are emitted as signed triples through the same path as everything else in the graph. Edges are typed — defines, imports, references, calls — and carry a confidence tier: a call resolving to exactly one candidate is high confidence, while a call with homonyms and every bare reference are marked uncertain rather than asserted as fact. Files over 2 MiB are recorded as skipped rather than quietly ignored, and a project is budgeted at 750,000 symbols. Drift compares a note's last-written time against the newest signed change to the symbol it documents. The limitation, which the source states plainly: that time is the filesystem mtime, so a checkout, a restore or an rsync that rewrites mtimes will change the verdict.
Reading documents, and what gets dropped
Word, PowerPoint and their OpenDocument equivalents are parsed in pure Rust — no rasterising, no OCR, no native dependency. Spreadsheets go through calamine. PDFs use the pdf.js text layer; rasterising with OCR is a separate, opt-in tier that runs only on pages with no usable text, and pages left unread are recorded as debt rather than silently dropped. Extraction emits citation anchors — a page marker per PDF page, a heading per slide, a sheet-and-row anchor per spreadsheet block, and a section anchor for numbered sections in a regulation, keeping the numeral in the heading because it is the only stable name that section has. Slides are ordered numerically, so slide 10 follows slide 9 rather than slide 1. Caps are enforced by bounded reads instead of trusting a declared size: 32 MiB per XML part, 128 MiB per archive, 16 MiB of emitted text, 5,000 slides, 50,000 rows. A gap worth naming: spreadsheets report truncation as a warning and the other converters do not, so a very large document can be trimmed quietly. The extracted text is written as an ordinary companion Markdown file beside the source, so the normal ingest signs it like any other note — there is no extraction database, the companion file's recorded source hash is the idempotency record.
Where everything lives on disk
Your notes are Markdown files in your folder. The only thing the app adds inside it is a hidden control directory holding the vault format stamp and, for a team vault, the keyring. Everything derived — the graph database, the search index, the snapshot store, the signing seed — lives outside the vault in application data, and the app refuses to start if you point the database inside the vault, because its own writes would trigger a re-ingest loop. That separation is why removing the app leaves your folder untouched, and why the derived index is always safe to delete and rebuild. It is also, honestly, why version history does not travel with a synced folder today. Licence checks are offline: a signed token verified against a key compiled into the app, with no server call. If we disappeared tomorrow, the app keeps opening, reading, writing, searching and answering.
How to check all of this yourself
The engine is open source. github.com/ApiliumCode/aingle holds the signing, hashing, graph and grounded-retrieval implementation, under Apache-2.0 for individuals, academia and organisations under $1M revenue, with a commercial licence above that. The application itself is not open source, and we would rather tell you that than imply otherwise.
- Reproduce a content hash: run any BLAKE3 tool over a note and compare it with the hash the app shows you. There is a pinned test vector in the public source to check your tooling against first.
- Rebuild an action hash and verify its signature independently: the byte layout is published as a spec, and the public test suite exercises tamper-rejection and the fact that signing does not change the hash.
- Confirm there is no telemetry: grep the source for the usual analytics and crash-reporting names, then list every URL literal in the Rust. What comes back is your own AI provider, your own connectors, and our licence and publishing endpoints — nothing else.
- Watch the network: open a vault with a monitor running. Nothing should be contacted until you configure a model or deliberately click an account action.
- Prove the deletion leak to yourself: turn on encryption for a scratch folder, add five notes, delete two, then list the target's trash directory. Two timestamped files. That is the leak, reproduced in a minute.
- Confirm no reset exists: forget the passphrase and lose the recovery key on a scratch target. Nothing in the app, and nothing we hold, can open it again.
Available today for your platform.
macOS universal (Intel + Apple Silicon) · Windows x64 · Linux AppImage/deb
Common questions.
Do I truly own my notes?
Yes. Every note is a standard Markdown file on your disk. Open it with any editor, back it up, or leave Altretta whenever you want: your knowledge stays with you.
Why pay if the app is free?
The desktop app, answers grounded in your notes, and one synced folder are free forever. Paid plans add unlimited synced folders, publishing pages others can verify, and the encrypted team brain. If a single synced folder covers how you work, Free is genuinely all you need.
How can I trust the AI's answers?
Every answer quotes the exact notes it came from, with citations and a confidence score. If a claim isn't backed by your notes, Altretta tells you instead of making things up.
Do I need to be technical to connect my AI?
No. Altretta detects the AI apps you already have — like Claude, Cursor or VS Code — and connects them in one click. No config files, no keys to paste, and you choose which folders the AI can see.
Do I need to pay for AI separately?
Altretta is a pure memory layer: it doesn't include its own LLM. You connect your preferred model via MCP with your own subscription, so you use the AI you already pay for and keep control of your keys.
Can I bring my existing notes?
Yes. Altretta reads ordinary Markdown, so your current notes folder works as-is. Pro adds one-click import from Notion and Confluence.
How does the encrypted team brain work?
You share a vault whose note contents are encrypted on your device, so nobody outside the team can read what a note says — not us, not whoever hosts the folder. Access is per person and revocable: remove someone and the key is rotated, so they can no longer read anything. One limit we would rather state than have you discover: filenames and folder structure are not encrypted, so the host still sees the shape of the vault and every note's name.
Which platforms does it support?
Altretta is available today for macOS (Apple Silicon and Intel), Windows, and Linux. Downloads always point to the latest published version.
Take control of your knowledge.
Private, offline, and verifiable. Your notes, your AI, your rules.