คำตอบ AI ที่ ไว้ใจได้จริงๆ.
Altretta คือสมองที่สองส่วนตัวของคุณ: โน้ตและโค้ดของคุณอยู่ในกราฟที่ลงลายเซ็นเดียวกัน ถามอะไรก็ได้ และทุกคำตอบจะอ้างอิงแหล่งที่มาที่แน่นอน — การตัดสินใจ โน้ต หรือฟังก์ชัน — โดยไม่มีอะไรออกจากเครื่องของคุณ
การย้ายระบบได้รับการอนุมัติเมื่อไหร่?
การย้ายระบบได้รับการอนุมัติเมื่อ 12 มีนาคมพร้อมงบประมาณ €48.000.
ทุกคำตอบ พร้อมหลักฐาน
โดยย่อ
Altretta คือแอปโน้ตส่วนตัวแบบ local-first: โน้ตและโค้ดของคุณเป็นไฟล์ Markdown ของคุณเอง และทุกคำตอบของ AI จะอ้างอิงแหล่งที่มาที่แน่นอนที่มันมา พร้อมประวัติที่ลงลายเซ็น
- ไฟล์ของคุณ
- Markdown ในเครื่องของคุณ ไม่มีการล็อกไว้
- AI ของคุณเอง
- เชื่อมต่อโมเดลของคุณผ่าน MCP
- ทุกอย่างทิ้งหลักฐานไว้
- ประวัติที่ลงลายเซ็นและย้อนกลับได้
- ใช้ได้บน
- macOS · Windows · Linux · ฟรี
ความรู้สมควรได้รับสิ่งที่ดีกว่านี้
โน้ตของคุณติดอยู่ในแอปของคนอื่น
ฐานข้อมูลแบบเป็นเจ้าของ รูปแบบปิด และการซิงค์ที่อาจหายไปวันหนึ่ง ความรู้ของคุณควรเป็นของคุณตลอดไป
AI ตอบโดยไม่มีหลักฐาน
ผู้ช่วยประดิษฐ์คำตอบ ผสมแหล่งที่มา และคุณไม่สามารถตรวจสอบได้ว่าแต่ละคำกล่าวอ้างมาจากไหน ไม่มีหลักฐาน ไม่มีความไว้วางใจ
ความรู้ของทีมถูกแยกส่วน
วิกิที่กระจัดกระจาย การอนุญาตที่เพิกถอนไม่ได้ และข้อมูลสำคัญที่เปิดเผยต่อบุคคลที่สาม การแชร์ไม่ควรหมายถึงการสูญเสียการควบคุม
อย่าเชื่อ จงตรวจสอบ
ความเชื่อใจคือสิ่งที่คุณมอบให้ ส่วนการตรวจสอบคือสิ่งที่คุณลงมือทำเอง Altretta ถูกสร้างมาเพื่อให้คุณไม่ต้องเชื่อคำพูดของเรา หรือของ AI ในเรื่องที่สำคัญ
เครื่องหมายถูกที่ต้องพิสูจน์ตัวเองมาก่อน
ป้ายจะขึ้นก็ต่อเมื่อสองเงื่อนไขเป็นจริงพร้อมกัน คือ ลายเซ็นผ่านการตรวจสอบจริง และโน้ตยังตรงกับสิ่งที่ลายเซ็นนั้นครอบคลุมอยู่ ถ้าข้อใดข้อหนึ่งไม่ผ่าน ก็จะไม่มีป้าย ระบบเลือกที่จะไม่แสดงมากกว่าจะอนุมานให้เอง
ถ้ามีอะไรเปลี่ยน มันจะบอกคุณ
ถ้าโน้ตถูกเซ็นแล้วถูกแก้ไขภายหลัง คุณจะได้รับแจ้งตรงตามนั้น ไม่ใช่ถูกลดชั้นเงียบ ๆ ให้เป็น “ไม่ได้เซ็น” ลายเซ็นที่ไม่ครอบคลุมสิ่งที่คุณกำลังอ่านอยู่แล้ว เป็นเรื่องที่ควรพูดออกมาให้ชัด
ผู้ช่วยที่ยอมบอกว่าไม่รู้
ถามเรื่องที่โน้ตของคุณไม่ได้ครอบคลุม แล้วมันจะบอกคุณตรง ๆ โดยไม่สร้างคำตอบขึ้นมาเลย ถ้ายังอยากได้คำตอบอยู่ดี นั่นเป็นอีกทางเลือกหนึ่งที่คุณต้องตั้งใจเลือกเอง
คำตอบชี้ไปที่หน้า ไม่ใช่แค่ไฟล์
ไฟล์ PDF, ไฟล์ Word, งานนำเสนอ และสเปรดชีตถูกอ่านเข้ามาโดยคงโครงสร้างเดิมไว้ — เลขหน้า เลขสไลด์ ไปจนถึงเลขมาตราในกฎระเบียบ — คำตอบที่มีหลักฐานจึงอ้างอิงตำแหน่งที่มาได้อย่างแม่นยำ ไม่ใช่เพียงชื่อไฟล์
โน้ตของคุณเป็นของคุณเสมอ
ทุกโน้ตเป็นไฟล์ธรรมดาในคอมพิวเตอร์ ไม่ถูกล็อค ไม่มีรูปแบบที่เปิดไม่ได้ ย้าย สำรองข้อมูล หรือออกจาก Altretta เมื่อไหร่ก็ได้ — ความรู้ของคุณไปกับคุณ
เชื่อมโยงสิ่งที่คุณมองข้ามไปโดยอัตโนมัติ
Altretta เชื่อมโยงโน้ตที่เกี่ยวข้องโดยอัตโนมัติ ดึงความคิดที่คุณเขียนไว้หลายเดือนก่อนแล้วลืมไปกลับมาใหม่ — ทั้งหมดในเครื่องของคุณ ไม่มีอะไรถูกอัปโหลด
เห็นรูปทรงของทุกสิ่งที่คุณรู้
คลิกเดียวเปลี่ยนโน้ตของคุณให้เป็นโลกที่เดินเข้าไปได้ โฟลเดอร์กลายเป็นชั้น ๆ การเชื่อมโยงที่ซ่อนอยู่ผุดขึ้นสู่พื้นผิว และรูปทรงของความคิดคุณก็ปรากฏชัดในที่สุด
เข้าใจทั้งโปรเจกต์ของคุณ — ทั้งที่คุณเขียนและที่คุณเขียนโค้ด
Altretta อ่านที่เก็บโค้ดของคุณและวาดมันเป็นแผนที่ที่ลงลายเซ็น: ทุกสัญลักษณ์ วิธีที่พวกมันเรียกกัน และการตัดสินใจที่กำกับแต่ละอัน AI ของคุณจึงไม่ได้รู้แค่โน้ตของคุณ — แต่เข้าใจโค้ดของคุณและวิธีเปลี่ยนมันโดยไม่ทำให้อะไรพัง
เชื่อมต่อ AI ของคุณ ตามเงื่อนไขของคุณ
นำ AI ที่คุณใช้อยู่แล้ว — ChatGPT, Claude, Cursor — มาเชื่อมกับโน้ตด้วยการสมัครสมาชิกของตัวเอง คุณตัดสินใจว่ามันจะเห็นอะไร และทุกสิ่งที่มันทำถูกลงนามและย้อนกลับได้
สมองทีมที่เข้ารหัส ตรวจสอบได้ และเพิกถอนได้
แชร์ความรู้โดยไม่สละการควบคุม เข้ารหัส end-to-end การเข้าถึงที่เพิกถอนได้ทันที และประวัติที่พิสูจน์ได้
โทเคนน้อยลง ตั้งแต่การออกแบบ
Altretta เชื่อมกับ AI ของคุณผ่าน MCP และด้วย AIngle (เอนจินเชิงความหมายของมัน) จะส่งให้โมเดลเฉพาะโน้ตที่สำคัญ พร้อมแหล่งอ้างอิง AI ของคุณทำงานกับบริบทที่เกี่ยวข้องแทนคลังทั้งหมด จึงใช้โทเคนน้อยลงและคุณไม่ต้องวางซ้ำอีก
| คำถาม | ไม่ใช้ Altretta | ใช้ Altretta | ประหยัด |
|---|---|---|---|
| เฉลี่ยต่อคำถาม | 23,020 | 1,363 | 94.1% |
| บทสนทนา 8 คำถาม | 184,609 | 46,709 | 74.7% |
วัดจากคลังเดโมมาตรฐาน Studio Ghibli (43 โน้ต): วางคลังทั้งหมดเป็นบริบท เทียบกับข้อความอ้างอิงที่ Altretta ส่งผ่าน MCP ด้วยเอนจินจริง โทเคนอินพุต; อัตราส่วนคงที่ระหว่างโทเคไนเซอร์ ทำซ้ำได้ตามโปรโตคอลที่เผยแพร่
การประหยัดมาจากการเชื่อม AI ของคุณเข้ากับ skill ของ Altretta ผ่าน MCP: มันจะได้รับเฉพาะข้อความอ้างอิงที่สำคัญ ไม่ใช่ทั้งคลังของคุณ ลองทำซ้ำด้วยตัวเองกับคลังเดโม Studio Ghibli
รับ skill ของ Altrettaต่อยอดด้วยสกิลและปลั๊กอินจาก Apilium Hub
hub.apilium.com
จากโน้ตสู่ความรู้ที่ตรวจสอบได้
เขียนใน Markdown
จดโน้ตตามปกติ ทุกความคิดถูกบันทึกเป็นไฟล์ที่คุณเป็นเจ้าของบนดิสก์ของคุณ
Altretta เชื่อมโยงทุกอย่าง
มันเชื่อมโน้ตที่เกี่ยวข้องและเก็บประวัติที่ลงนามของทุกการเปลี่ยนแปลง — ทั้งหมดในคอมพิวเตอร์ของคุณ
เชื่อมต่อ AI ด้วยคลิกเดียว
เสียบ AI ที่คุณสมัครอยู่แล้ว มันอ่านโน้ตของคุณ คุณเลือกสิ่งที่มันมองเห็น
ถามและตรวจสอบ
รับคำตอบที่อ้างอิงโน้ตของคุณ พร้อมคะแนนความน่าเชื่อถือที่คุณตรวจสอบเองได้
สิ่งที่เกิดขึ้นจริงเมื่อคุณเปิดมัน
ไม่ต้องสมัครบัญชี ไม่มีตัวช่วยตั้งค่า ไม่ต้องอัปโหลด แค่ชี้ไปที่โฟลเดอร์ แล้วมันก็เริ่มทำงาน
- 01
ชี้ไปที่โฟลเดอร์
โฟลเดอร์โน้ตที่คุณมีอยู่ใช้งานได้ทันทีอย่างที่มันเป็น ไม่มีการนำเข้า แปลง หรือย้ายไฟล์ Altretta อ่านไฟล์ Markdown ที่อยู่บนดิสก์ของคุณอยู่แล้ว
- 02
เชื่อมต่อ AI ที่คุณจ่ายค่าบริการอยู่แล้ว
มันจะหา Claude, Cursor, VS Code, Windsurf, Zed และตัวอื่น ๆ ที่ติดตั้งอยู่ในเครื่องของคุณ แล้วตั้งค่าให้เสร็จ ไม่ต้องวางคีย์ ไม่ต้องแก้ไฟล์คอนฟิก
- 03
ถามสิ่งที่มีแต่โน้ตของคุณเท่านั้นที่รู้
คำตอบที่มีหลักฐานครั้งแรกคือจังหวะที่ทุกอย่างเข้าที่ คำตอบจะยกข้อความจากโน้ตต้นทางมาให้ และคุณเปิดโน้ตนั้นดูเองได้
- 04
จากนั้นลองจับผิดมันดู
ถามเรื่องที่คุณไม่เคยจดไว้เลย มันจะบอกว่าไม่มีข้อมูลอะไรให้ยึด และนั่นแหละคือเหตุผลที่ควรเก็บมันไว้ ยิ่งกว่าคำตอบใด ๆ
ลองพิสูจน์ดู ไม่มีค่าใช้จ่าย
แอปนี้ฟรี ทำงานบนเครื่องของคุณ และไฟล์ของคุณยังอยู่ที่เดิม ไม่มีนาฬิกานับถอยหลังช่วงทดลองใช้ และไม่มีอะไรให้ยกเลิก
ไม่ต้องมีบัญชี
ดาวน์โหลด เปิด แล้วทำงานได้เลย การลงชื่อเข้าใช้มีไว้สำหรับฟีเจอร์แบบเสียเงินเท่านั้น ทุกอย่างที่ทำงานในเครื่องยังใช้ได้ต่อแม้ไม่ได้ลงชื่อเข้าใช้
ปิดเน็ตก็ยังใช้ได้
โน้ตอยู่บนดิสก์ของคุณ และแอปก็เช่นกัน อยู่บนเครื่องบิน เน็ตล่ม หรือบริษัทหายไป ก็ไม่มีอะไรหยุดคุณจากการอ่านและเขียน
ไฟล์ในรูปแบบที่อยู่ได้นานกว่าเรา
Markdown ล้วน ๆ ในโฟลเดอร์ธรรมดา ไม่ใช่ฐานข้อมูล ไม่ใช่คอนเทนเนอร์ เปิดด้วยเอดิเตอร์ตัวไหนก็ได้ ทั้งวันนี้และในอีกสิบปี จะมีเราอยู่หรือไม่ก็ตาม
ไม่มีการวัดอะไรเกี่ยวกับคุณ
ไม่มีการวิเคราะห์การใช้งาน ไม่มีการรายงานการใช้ ไม่มีเทเลเมทรีตอนแอปพัง แอปที่เพิ่งติดตั้งใหม่ไม่แม้แต่จะหาว่าตัวเองกำลังทำงานอยู่บนเครื่องไหน
เริ่มต้นฟรี จ่ายเมื่อ เติบโต.
แอปในคอมพิวเตอร์ฟรีตลอดไป รวมถึงการซิงค์หนึ่งโฟลเดอร์ แผนชำระเงินเพิ่มโฟลเดอร์ซิงค์ไม่จำกัด การเผยแพร่หน้าที่ตรวจสอบได้ และสมองทีมเข้ารหัส
ทำไมคนถึงอัปเกรด
จ่ายแล้วเปลี่ยนอะไรบ้าง
สำหรับคนหนึ่งคนบนเครื่องหนึ่งเครื่อง แอปฟรีคือตัวผลิตภัณฑ์ทั้งหมดจริง ๆ การจ่ายเงินคือเรื่องของขอบเขต — อุปกรณ์มากขึ้น ประวัติยาวขึ้น และมีคนอื่นร่วมด้วย
คลังโน้ตเดียวกันบนทุกเครื่อง
เขียนบนแล็ปท็อป แล้วไปเขียนต่อบนเดสก์ท็อป ผ่านพื้นที่จัดเก็บที่คุณเป็นเจ้าของและเลือกเอง ไม่ว่าจะเป็น Dropbox, OneDrive, ไดรฟ์ที่แชร์ในเครือข่าย หรือ USB สิ่งที่ไปอยู่ที่นั่นถูกเข้ารหัส ชื่อไฟล์ถูกสลับ และไม่มีโครงสร้างโฟลเดอร์ และไม่มีสำเนาใดอยู่บนเซิร์ฟเวอร์ของเรา เพราะเซิร์ฟเวอร์ของเราไม่ได้อยู่ในเส้นทางนั้นเลย
เปลี่ยนโน้ตที่เลือกไว้ให้เป็นหน้าเว็บที่คนอื่นเปิดได้
เผยแพร่โน้ตที่เลือกจากคลังของคุณเป็นเว็บไซต์ พร้อมแนบที่มาของแต่ละหน้าไปด้วย
ย้อนกลับไปได้ไกลกว่าเดิม
แบบฟรีเก็บสัปดาห์ล่าสุดไว้ให้หยิบใช้ได้ง่าย เมื่อจ่ายเงินก็จะเปิดเวอร์ชันที่เก่ากว่านั้น คุณจึงย้อนกลับไปดูได้ว่าข้อความเคยเป็นอย่างไรก่อนคุณจะเปลี่ยนใจ
สมองส่วนกลางที่ยังเป็นของคุณ
แชร์คลังโน้ตที่เข้ารหัสกับทีมของคุณ ให้และเรียกคืนสิทธิ์เข้าถึงได้ทีละคน และรู้เสมอว่าใครแก้อะไร
- แอปเดสก์ท็อปเต็มรูปแบบ
- โน้ต กราฟ Bases & Canvas
- ใช้ AI ที่คุณสมัครอยู่แล้ว
- คำตอบที่มีรากฐานจากโน้ตของคุณ
- ซิงค์หนึ่งโฟลเดอร์ผ่านคลาวด์ของคุณ
- โฟลเดอร์ซิงค์ไม่จำกัด
- เผยแพร่หน้าที่คนอื่นตรวจสอบได้
- ประวัติเวอร์ชันยาวขึ้น
- นำเข้าจาก Notion & Confluence
- การสนับสนุนแบบพิเศษ
- vault ทีมเข้ารหัสที่ใช้ร่วมกัน
- เพิ่มหรือลบสมาชิกด้วยคลิกเดียว
- ซิงค์เข้ารหัสทั่วทั้งทีม
- บทบาทและแดชบอร์ดทีม
- ดูว่าใครเขียนอะไร
ทุกองค์กรมีการตรวจสอบด้านความปลอดภัย กระบวนการจัดซื้อ และข้อกำหนดการปฏิบัติตามกฎระเบียบเป็นของตนเอง บอกเราว่าของคุณคืออะไร แล้วเราจะดำเนินการไปด้วยกัน
พูดคุยกับฝ่ายขาย- ✓ฟรีตลอดไปแอปท้องถิ่นและโน้ตของคุณเป็นของคุณ ออฟไลน์ได้ แม้ไม่ชำระเงิน
- ✓ไม่ถูกล็อคทุกอย่างเป็นไฟล์ Markdown มาตรฐาน ออกไปเมื่อไหร่ก็ได้ พร้อมความรู้ของคุณ
- ✓ยกเลิกได้เมื่อต้องการแผนบุคคลต่ออายุรายเดือน แผนทีมต่ออายุรายปี จัดการจากพอร์ทัลของคุณ
ราคาในสกุล EUR · รวม VAT แล้ว · จัดการการสมัครสมาชิกที่ my.apilium.com
หากหมายเลขผู้เสียภาษีที่ถูกต้องทำให้ไม่ต้องเสียภาษี จะเรียกเก็บเป็นจำนวนก่อนภาษี
เราไม่รู้เลยว่าคุณกำลังใช้สิ่งนี้อยู่
นี่ไม่ใช่นโยบายที่เราจะเปลี่ยนเมื่อไรก็ได้ แต่เป็นวิธีที่แอปถูกสร้างขึ้น ข้างในไม่มีไลบรารีวิเคราะห์การใช้งาน ไม่มีตัวรายงานข้อขัดข้อง ไม่มีการดึงอะไรจากเซิร์ฟเวอร์มาวาดหน้าจอ และแอปที่เพิ่งติดตั้งใหม่ไม่เคยหาว่าตัวเองอยู่บนเครื่องไหน
ไม่มีการวิเคราะห์การใช้งานใด ๆ ทั้งสิ้น
ไม่มีไลบรารีวิเคราะห์การใช้งานหรือการใช้ผลิตภัณฑ์รวมมาในตัวแอป ไม่ใช่ปิดไว้เป็นค่าเริ่มต้น แต่คือไม่มีอยู่เลย
ไม่มีการรายงานข้อขัดข้องหรือข้อผิดพลาด
เมื่อมีอะไรผิดพลาด มันผิดพลาดอยู่บนเครื่องของคุณ และอยู่บนเครื่องของคุณต่อไป
ไม่มีการโหลดอะไรจากที่อื่น
ฟอนต์และไฟล์ประกอบมาพร้อมอยู่ในตัวแอป หน้าจอไม่เคยเรียกเซิร์ฟเวอร์เพื่อวาดตัวเอง
แอปที่เพิ่งติดตั้งยังคงไม่ระบุตัวตน
ไม่มีอะไรที่บอกลักษณะอุปกรณ์ของคุณ เว้นแต่คุณจะเริ่มทดลองใช้หรือเปิดใช้งานไลเซนส์ ซึ่งเป็นช่วงเวลาเดียวที่เครื่องของคุณถูกระบุตัวตน
อย่าเพิ่งเชื่อคำพูดของเรา
แอปติดต่อเครือข่ายอยู่ไม่กี่จุด และเป็นจุดที่น่าเบื่อมาก คุณเฝ้าดูได้ทุกจุด: การตรวจสอบอัปเดตกับไฟล์แบบสแตติก และ — เฉพาะเมื่อคุณใช้งานจริงเท่านั้น — ผู้ให้บริการ AI ของคุณเอง บัญชี Notion หรือ Confluence ของคุณ และเซิร์ฟเวอร์ไลเซนส์ของเรา ลองเอาเครื่องมือมอนิเตอร์เครือข่ายมาจับดูได้เลย
For the reader who does not believe marketing copy.
Everything above, restated as mechanism — names, curves, sizes, thresholds, and the places where a limit exists, including the ones that are not flattering. If you find something here the code does not do, we would rather hear about it than not.
The signed history
Every change is an action in a directed acyclic graph. An action carries its parent hashes, the author node, a per-author sequence number, a UTC timestamp and the payload. Its identity is BLAKE3-256 over those fields concatenated in a fixed order — parents, author, sequence, timestamp, payload — with the signature deliberately excluded, so signing never changes the hash. The signature is Ed25519 over the 32 raw digest bytes, not over the preimage and not over its hex rendering. The byte layout is published as a spec, aingle-dag-action-v1, so you can rebuild the preimage yourself; a test pins the published spec against the code that actually hashes, so the two cannot drift apart in silence.
Removal is a retraction, not a delete
Deleting a note does not erase anything. It appends a signed deletion action naming what it retracts, so the earlier state stays reachable and provable and time-travel survives. One exception, stated because you would find it: a prune operation does physically remove old actions under an explicit retention policy. It never prunes the tips, and it writes a checkpoint recording what it removed — but it is a real delete, and where it is exposed to AI tooling it is marked destructive rather than hidden among the read-only calls.
What the lock proves — and what it does not
A verified lock means two things at once: the Ed25519 signature on the anchoring action verified, and the note on disk still hashes to exactly what that signature attests. Either one failing yields no lock, and every error path fails closed — no key, no graph, a malformed hash or a missing action all produce "unverified" rather than the benefit of the doubt. "Signed, then edited" is reported as its own state instead of collapsing to unsigned. What it does not prove: the key is your vault's own, generated locally, so this is a self-attestation, not an identity — there is no certificate authority and no binding to a person. The timestamp is your machine's clock, sealed inside the signed bytes; there is no timestamping authority, so anyone holding the seed could back-date. And the signing seed is stored unencrypted next to the database. It proves these bytes were ingested and signed here and have not changed since. That is a smaller claim than "authentic", and it is the one we make.
Encryption at the sync target
One random 32-byte master key per target, generated on the device. Three subkeys derived from it with BLAKE3 derive_key under distinct context strings: one for content, one for blob names, one for a public target id. Content is XChaCha20-Poly1305 with a fresh random 24-byte nonce per write and a 16-byte tag. The master key is reachable two ways, both held only by you: a passphrase wrapped with Argon2id — the argon2 crate defaults, 19 MiB, 2 iterations, 1 lane, with a 16-byte random per-target salt — stored in a keybox on the target itself so any machine that can see the folder can unlock it; or a one-time recovery key, which is the master key rendered as 56 Crockford base32 characters with a checksum. Nothing is escrowed. We hold no copy and there is no reset, which is the same thing as saying we could not read your files even if we wanted to.
What actually lands in the folder
A blob's name is a keyed BLAKE3 hash of its vault path, Crockford base32 encoded — always 52 characters, so the length of a path leaks nothing either. The real path travels inside the sealed payload, so decrypting one blob is enough to place it: there is no manifest and no name table that could be lost or corrupted. The authentication tag covers the path, so a blob renamed or moved by anything other than the app is detected rather than silently accepted. Padding is applied to the plaintext before sealing: the padded length is the next multiple of 4 KiB up to 64 KiB, and the next multiple of 64 KiB above that. On disk a blob is that padded length plus exactly 40 bytes — a 24-byte nonce and a 16-byte authentication tag.
What an observer of that folder can still see
Stated here because you would find it anyway, and because a limitation you discover for yourself is worth far more doubt than one we hand you. Someone who can read the synced folder learns: that it is an Altretta target, because the header file is plaintext on purpose so a second machine can find the salt; the number of notes, since there is one blob each; and each file's size to within its padding bucket. Because a blob's name is a deterministic function of its path, every note keeps the same name for its whole life — a stable pseudonym. That determinism is what lets two machines agree where a note lives without a shared index, and it is also what lets an observer watch how often you edit any single note, note by note, from timestamps alone — without ever learning which note it is. Deletions are the sharpest of these, and they are exact rather than approximate: a removed blob is moved into a trash directory rather than unlinked, keeping its name and gaining the millisecond it was removed. So the precise number of notes you have deleted, the exact moment of each deletion, and which pseudonym each deleted note had while it existed are all plainly readable. The public target id is a stable fingerprint linking two folders to the same key. None of it discloses a title, a path, or a word of content.
What makes the assistant refuse
Retrieval embeds your question, over-fetches from the memory index, keeps only chunk entries and re-ranks them by pure cosine similarity — deliberately discarding the composite recency-and-importance score the memory layer would otherwise apply, because relevance to the question is the only thing that should decide a citation. A verdict of "grounded" requires the best match to clear the high threshold and at least 2 chunks to clear it: corroboration, not one lucky passage. With the neural embedder the product ships, those thresholds are 0.80 and 0.77, calibrated against a measurement that unrelated pairs top out near 0.76. Between the two is "weak"; below both is "ungrounded". The answerability gate is then: at least one visible source after your folder exclusions have been applied, and — if you asked for grounded answers only — a verdict of exactly "grounded". When that gate fails, no model call is made at all. Answering anyway is a separate flag that is never inferred on your behalf, and when you set it the weak passages are withheld from the model so it cannot cite what did not qualify.
The symbol graph
Twenty languages have symbol extractors, each a tree-sitter parse plus a query: Rust, TypeScript, JavaScript, Python, Go, Swift, Java, C, C++, C#, Kotlin, PHP, Ruby, Dart, Scala, Objective-C, Bash, Lua, R and SQL. Symbols get canonical identifiers and are emitted as signed triples through the same path as everything else in the graph. Edges are typed — defines, imports, references, calls — and carry a confidence tier: a call resolving to exactly one candidate is high confidence, while a call with homonyms and every bare reference are marked uncertain rather than asserted as fact. Files over 2 MiB are recorded as skipped rather than quietly ignored, and a project is budgeted at 750,000 symbols. Drift compares a note's last-written time against the newest signed change to the symbol it documents. The limitation, which the source states plainly: that time is the filesystem mtime, so a checkout, a restore or an rsync that rewrites mtimes will change the verdict.
Reading documents, and what gets dropped
Word, PowerPoint and their OpenDocument equivalents are parsed in pure Rust — no rasterising, no OCR, no native dependency. Spreadsheets go through calamine. PDFs use the pdf.js text layer; rasterising with OCR is a separate, opt-in tier that runs only on pages with no usable text, and pages left unread are recorded as debt rather than silently dropped. Extraction emits citation anchors — a page marker per PDF page, a heading per slide, a sheet-and-row anchor per spreadsheet block, and a section anchor for numbered sections in a regulation, keeping the numeral in the heading because it is the only stable name that section has. Slides are ordered numerically, so slide 10 follows slide 9 rather than slide 1. Caps are enforced by bounded reads instead of trusting a declared size: 32 MiB per XML part, 128 MiB per archive, 16 MiB of emitted text, 5,000 slides, 50,000 rows. A gap worth naming: spreadsheets report truncation as a warning and the other converters do not, so a very large document can be trimmed quietly. The extracted text is written as an ordinary companion Markdown file beside the source, so the normal ingest signs it like any other note — there is no extraction database, the companion file's recorded source hash is the idempotency record.
Where everything lives on disk
Your notes are Markdown files in your folder. The only thing the app adds inside it is a hidden control directory holding the vault format stamp and, for a team vault, the keyring. Everything derived — the graph database, the search index, the snapshot store, the signing seed — lives outside the vault in application data, and the app refuses to start if you point the database inside the vault, because its own writes would trigger a re-ingest loop. That separation is why removing the app leaves your folder untouched, and why the derived index is always safe to delete and rebuild. It is also, honestly, why version history does not travel with a synced folder today. Licence checks are offline: a signed token verified against a key compiled into the app, with no server call. If we disappeared tomorrow, the app keeps opening, reading, writing, searching and answering.
How to check all of this yourself
The engine is open source. github.com/ApiliumCode/aingle holds the signing, hashing, graph and grounded-retrieval implementation, under Apache-2.0 for individuals, academia and organisations under $1M revenue, with a commercial licence above that. The application itself is not open source, and we would rather tell you that than imply otherwise.
- Reproduce a content hash: run any BLAKE3 tool over a note and compare it with the hash the app shows you. There is a pinned test vector in the public source to check your tooling against first.
- Rebuild an action hash and verify its signature independently: the byte layout is published as a spec, and the public test suite exercises tamper-rejection and the fact that signing does not change the hash.
- Confirm there is no telemetry: grep the source for the usual analytics and crash-reporting names, then list every URL literal in the Rust. What comes back is your own AI provider, your own connectors, and our licence and publishing endpoints — nothing else.
- Watch the network: open a vault with a monitor running. Nothing should be contacted until you configure a model or deliberately click an account action.
- Prove the deletion leak to yourself: turn on encryption for a scratch folder, add five notes, delete two, then list the target's trash directory. Two timestamped files. That is the leak, reproduced in a minute.
- Confirm no reset exists: forget the passphrase and lose the recovery key on a scratch target. Nothing in the app, and nothing we hold, can open it again.
พร้อมใช้งานสำหรับแพลตฟอร์มของคุณวันนี้
macOS universal (Intel + Apple Silicon) · Windows x64 · Linux AppImage/deb
สิ่งที่คุณอาจสงสัย
ฉันเป็นเจ้าของโน้ตของฉันจริงๆ ไหม?
ใช่ ทุกโน้ตเป็นไฟล์ Markdown มาตรฐานบนดิสก์ของคุณ คุณสามารถเปิดด้วยโปรแกรมแก้ไขใดก็ได้ สำรองข้อมูล หรือออกจาก Altretta เมื่อไหร่ก็ได้: ความรู้ของคุณยังคงอยู่กับคุณ
แอปฟรีอยู่แล้ว แล้วจะจ่ายเงินทำไม?
แอปเดสก์ท็อป คำตอบที่มีรากฐานจากโน้ต และการซิงค์หนึ่งโฟลเดอร์ ฟรีตลอดไป แผนชำระเงินเพิ่มโฟลเดอร์ซิงค์ไม่จำกัด การเผยแพร่หน้าที่คนอื่นตรวจสอบได้ และสมองทีมเข้ารหัส ถ้าโฟลเดอร์ซิงค์เดียวพอกับวิธีทำงานของคุณ Free เพียงพอแน่นอน
ฉันจะไว้ใจคำตอบของ AI ได้อย่างไร?
ทุกคำตอบอ้างอิงโน้ตต้นฉบับที่ชัดเจน พร้อมการอ้างอิงและคะแนนความน่าเชื่อถือ ถ้าข้อกล่าวอ้างไม่มีโน้ตรองรับ Altretta จะบอกตรงๆ แทนที่จะแต่งขึ้นมา
ต้องมีความรู้ด้านเทคนิคเพื่อเชื่อมต่อ AI ไหม?
ไม่ต้อง Altretta ตรวจจับแอป AI ที่คุณมีอยู่แล้ว — อย่าง Claude, Cursor หรือ VS Code — และเชื่อมต่อด้วยคลิกเดียว ไม่ต้องใช้ไฟล์คอนฟิก ไม่ต้องวาง key และคุณเลือกได้ว่าโฟลเดอร์ไหน AI จะมองเห็น
ต้องจ่ายค่า AI แยกต่างหากไหม?
Altretta เป็นชั้นหน่วยความจำล้วนๆ: ไม่มี LLM ของตัวเอง คุณเชื่อมต่อโมเดลที่ต้องการผ่าน MCP ด้วยการสมัครสมาชิกของคุณเอง ดังนั้นคุณใช้ AI ที่คุณจ่ายอยู่แล้วและรักษาการควบคุมคีย์ของคุณ
ฉันสามารถนำโน้ตที่มีอยู่มาใช้ได้ไหม?
ได้เลย Altretta อ่าน Markdown ธรรมดา ดังนั้นโฟลเดอร์โน้ตที่มีอยู่ใช้ได้ทันที Pro เพิ่มฟีเจอร์นำเข้าจาก Notion และ Confluence ด้วยคลิกเดียว
สมองทีมที่เข้ารหัสทำงานอย่างไร?
คุณแบ่งปันคลังความรู้ที่เนื้อหาโน้ตถูกเข้ารหัสบนเครื่องของคุณ คนนอกทีมจึงอ่านไม่ได้ว่าโน้ตเขียนอะไรไว้ ทั้งเราและผู้ที่โฮสต์โฟลเดอร์ก็อ่านไม่ได้ สิทธิ์เข้าถึงให้เป็นรายบุคคลและเพิกถอนได้ เมื่อคุณนำใครออก กุญแจจะถูกเปลี่ยน และเขาจะอ่านอะไรไม่ได้อีกเลย มีข้อจำกัดหนึ่งที่เราขอบอกก่อนที่คุณจะไปพบเอง ชื่อไฟล์และโครงสร้างโฟลเดอร์ไม่ได้ถูกเข้ารหัส ผู้โฮสต์จึงยังเห็นรูปร่างของคลังและชื่อของทุกโน้ต
ใช้งานได้บนแพลตฟอร์มใดบ้าง?
Altretta พร้อมใช้งานวันนี้สำหรับ macOS (Apple Silicon และ Intel), Windows และ Linux การดาวน์โหลดชี้ไปยังเวอร์ชันล่าสุดที่เผยแพร่เสมอ
ควบคุมความรู้ของคุณ
ส่วนตัว ออฟไลน์ และตรวจสอบได้ โน้ตของคุณ AI ของคุณ กฎของคุณ