AI 的回答, 真正可信赖.
Altretta 是你私密的第二大脑:你的笔记和代码都在同一张签名图谱中。随便问,每个回答都会引用它的确切来源——决策、笔记或函数——而且没有任何东西离开你的电脑。
迁移是什么时候批准的?
迁移于 3月12日批准,预算为 €48.000.
每个回答,附带证明
一句话
Altretta 是一款私密、本地优先的笔记应用:你的笔记和代码都是你自己的 Markdown 文件,AI 的每个回答都会引用它的确切来源,并附带签名的历史记录。
- 你的文件
- Markdown 存在你的设备上,无孤岛
- 你自己的 AI
- 通过 MCP 接入你的模型
- 一切都留下证据
- 签名且可回溯的历史
- 支持平台
- macOS · Windows · Linux · 免费
知识值得更好的对待。
你的笔记被困在别人的应用里
专有数据库、封闭格式,以及某天会消失的同步服务。你的知识应该永久属于你。
AI 回答无凭无据
助手捏造内容、混淆来源,你无从核实每条陈述的出处。没有证据,就没有信任。
团队知识被孤立
碎片化的 Wiki、无法撤销的权限,以及暴露给第三方的敏感数据。共享不应意味着失去控制。
别信,去验证。
信任是你给出去的,验证是你自己做的。Altretta 的构建方式让你在任何要紧的事情上,都不必只听我们的说法,也不必只听 AI 的说法。
必须挣来的那个对勾
只有两件事同时成立,标识才会出现:签名真正通过校验,并且笔记内容仍与该签名覆盖的内容一致。任何一项校验不通过,就没有标识——它宁可保守地判定不通过,也不会替自己往好处想。
内容变了,它会告诉你
如果一条笔记签名后又被编辑过,它会明确这样告诉你,而不是悄悄降级成“未签名”。一个已经覆盖不住你正在读的内容的签名,值得说出来。
会说“我不知道”的助手
问它笔记里没有的内容,它会直说,根本不会生成答案。若仍然想要一个答案,那是你必须有意做出的另一个选择。
答案指向具体页面,而不是文件
PDF、Word 文件、演示文稿和电子表格在读入时保留原有结构——页码、幻灯片编号,甚至法规中的条款编号——因此有据可依的回答会引用它的确切出处,而不只是一个文件名。
你的笔记,始终属于你
每条笔记都是电脑上的普通文件。没有锁定,没有无法打开的格式。随时移动、备份,或离开 Altretta——你的知识始终跟着你走。
自动发现你忽略的关联
Altretta 自动关联相关笔记,将你几个月前写下却已遗忘的想法重新呈现——全在你的设备上,无需上传。
看见你所知一切的形状
一次点击,把你的笔记变成一个可以走进去的世界。文件夹变成楼层,隐藏的连接浮出水面,你思考的形状终于清晰可见。
理解你的整个项目——你写下的,和你编写的代码。
Altretta 读取你的代码仓库,并把它绘制成一张签名地图:每个符号、它们如何相互调用,以及支配每一个的决策。于是你的 AI 不只了解你的笔记——它理解你的代码,也知道如何在不破坏任何东西的前提下修改它。
连接你的 AI。由你决定。
用你已在使用的 AI——ChatGPT、Claude、Cursor——配合你自己的订阅接入笔记。你决定它能看到什么,它的每一步操作都经过签名且可撤销。
加密、可验证、可撤销的团队大脑。
共享知识,无需放弃控制。端到端加密,即时撤销访问,历史可证。
从设计上就更省 token
Altretta 通过 MCP 连接你的 AI,并借助 AIngle(它的语义引擎)只把重要的笔记(带来源和引用)交给模型。你的 AI 基于相关上下文工作,而不是整个知识库,因此用更少的 token,你也不必反复粘贴。
| 查询 | 不用 Altretta | 使用 Altretta | 节省 |
|---|---|---|---|
| 每次查询平均 | 23,020 | 1,363 | 94.1% |
| 8 次查询的对话 | 184,609 | 46,709 | 74.7% |
在 Studio Ghibli 标准演示保管库(43 条笔记)上实测: 将整个保管库粘贴为上下文 vs Altretta 通过 MCP 用真实引擎提供的引用段落。输入 token; 该比例在不同分词器间保持稳定。可按公开协议复现。
节省来自通过 MCP 把你的 AI 连接到 Altretta 的 skill:它只接收重要的引用段落,而不是你的整个保管库。用 Studio Ghibli 演示保管库,你可以自己复现。
获取 Altretta 的 skill用 Apilium Hub 的技能与插件扩展它。
hub.apilium.com
从笔记到可验证的知识。
用 Markdown 书写
像往常一样记笔记。每个想法都保存为你磁盘上属于你的文件。
Altretta 串联一切
它关联相关笔记,并为每次变更保留经过签名的历史——全在你的电脑上。
一键接入你的 AI
接入你已付费的 AI。它读取你的笔记;你选择它能看到什么。
提问并验证
获取引用你笔记的答案,附带你可以自行核查的可信度评分。
打开它之后,真正会发生什么。
不用注册,没有设置向导,无需上传。指给它一个文件夹,它就开始工作。
- 01
指给它一个文件夹
你现有的笔记文件夹原样就能用。不导入、不转换、不移动——Altretta 直接读取你磁盘上已有的 Markdown 文件。
- 02
接上你已经在付费的 AI
它会找到你机器上已安装的 Claude、Cursor、VS Code、Windsurf、Zed 等,并替你配置好。不用粘贴密钥,也不用改配置文件。
- 03
问一个只有你的笔记知道的问题
第一个有依据的回答就是恍然大悟的时刻:答案会引用它出自的那条笔记,你可以打开那条笔记亲眼确认。
- 04
然后试着找它的破绽
问一件你从没写下来的事。它会告诉你自己没有任何依据——比起任何答案,这才是留下它的理由。
亲自弄清楚,不花你一分钱。
应用免费,跑在你自己的机器上,文件仍留在原来的位置。没有试用倒计时,也没有什么需要取消。
无需账号
下载、打开、开始工作。只有付费功能才需要登录——退出登录时,本地的一切照常运行。
断网也能用
笔记在你的磁盘上,应用也是。飞行途中、网络中断、公司消失——都拦不住你继续读和写。
比我们活得更久的文件格式
普通文件夹里的纯 Markdown。不是数据库,也不是容器。今天或十年后,有没有我们,都能用任何编辑器打开。
关于你,什么都不度量
没有分析统计,没有使用上报,没有崩溃遥测。全新安装甚至不会去判断自己运行在哪台机器上。
免费开始。只在 成长时付费.
电脑上的应用永久免费,含一个文件夹同步。付费方案增加不限数量的同步文件夹、发布可验证页面以及加密团队大脑。
为什么升级
付费之后有什么不同。
对一个人、一台机器来说,免费版真的就是完整的产品。付费买的是范围——更多设备、更长历史、更多人。
每台机器上都是同一个仓库
在笔记本上写,在台式机上接着写——经由你本来就拥有、也由你自己挑选的存储:你的 Dropbox、你的 OneDrive、一个网络共享盘、一支 U 盘。落到那里的内容是加密的,文件名被打乱,也没有目录结构;我们的服务器上没有任何副本,因为我们的服务器根本不在这条路径上。
把选中的笔记变成别人能打开的页面
把仓库中挑选出的笔记发布成一个站点,每个页面都附带它的来源记录。
回溯得更远
免费版可以随手取回最近一周。付费后可以打开更早的版本,回到你改变主意之前的写法。
共享的大脑,依然属于你们
与团队共享一个加密仓库,逐个发放和收回访问权限,并且始终知道谁改了什么。
- 同步文件夹不限数量
- 发布他人可验证的页面
- 更长的版本历史
- 从 Notion 和 Confluence 导入
- 优先支持
- ✓永久免费本地应用和你的笔记属于你,无需联网,无论是否付费。
- ✓无锁定全部为标准 Markdown 文件。随时离开,带走你的知识。
- ✓随时取消个人方案按月订阅;团队方案按年续费。均在门户管理。
价格以欧元计 · 含增值税 · 订阅管理于 my.apilium.com
若有效的税号意味着无需缴税,则按税前金额扣款。
我们完全不知道你在用它。
这不是一条我们说改就能改的政策,而是应用的构建方式。里面没有分析库,没有崩溃上报器,界面不从服务器取任何东西来渲染,全新安装也从不去判断自己在哪台机器上。
没有任何形式的分析统计
应用里没有打包任何分析或产品使用统计库。不是默认关闭——是根本没有。
不上报崩溃或错误
出问题时,问题发生在你的机器上,也就留在你的机器上。
不从别处加载任何东西
字体和资源都随应用一起发布。界面从不为了渲染自己而去请求服务器。
全新安装保持匿名
除非你开始试用或激活许可证,否则没有任何东西描述你的设备;那也是唯一会识别你机器的时刻。
别只听我们说
应用访问网络的地方少而无聊,每一处你都能盯着看:向一个静态文件检查更新,以及——只有在你真的使用时——你自己的 AI 服务商、你的 Notion 或 Confluence 账号,还有我们的许可证服务器。拿网络监控工具对着它看就知道了。
For the reader who does not believe marketing copy.
Everything above, restated as mechanism — names, curves, sizes, thresholds, and the places where a limit exists, including the ones that are not flattering. If you find something here the code does not do, we would rather hear about it than not.
The signed history
Every change is an action in a directed acyclic graph. An action carries its parent hashes, the author node, a per-author sequence number, a UTC timestamp and the payload. Its identity is BLAKE3-256 over those fields concatenated in a fixed order — parents, author, sequence, timestamp, payload — with the signature deliberately excluded, so signing never changes the hash. The signature is Ed25519 over the 32 raw digest bytes, not over the preimage and not over its hex rendering. The byte layout is published as a spec, aingle-dag-action-v1, so you can rebuild the preimage yourself; a test pins the published spec against the code that actually hashes, so the two cannot drift apart in silence.
Removal is a retraction, not a delete
Deleting a note does not erase anything. It appends a signed deletion action naming what it retracts, so the earlier state stays reachable and provable and time-travel survives. One exception, stated because you would find it: a prune operation does physically remove old actions under an explicit retention policy. It never prunes the tips, and it writes a checkpoint recording what it removed — but it is a real delete, and where it is exposed to AI tooling it is marked destructive rather than hidden among the read-only calls.
What the lock proves — and what it does not
A verified lock means two things at once: the Ed25519 signature on the anchoring action verified, and the note on disk still hashes to exactly what that signature attests. Either one failing yields no lock, and every error path fails closed — no key, no graph, a malformed hash or a missing action all produce "unverified" rather than the benefit of the doubt. "Signed, then edited" is reported as its own state instead of collapsing to unsigned. What it does not prove: the key is your vault's own, generated locally, so this is a self-attestation, not an identity — there is no certificate authority and no binding to a person. The timestamp is your machine's clock, sealed inside the signed bytes; there is no timestamping authority, so anyone holding the seed could back-date. And the signing seed is stored unencrypted next to the database. It proves these bytes were ingested and signed here and have not changed since. That is a smaller claim than "authentic", and it is the one we make.
Encryption at the sync target
One random 32-byte master key per target, generated on the device. Three subkeys derived from it with BLAKE3 derive_key under distinct context strings: one for content, one for blob names, one for a public target id. Content is XChaCha20-Poly1305 with a fresh random 24-byte nonce per write and a 16-byte tag. The master key is reachable two ways, both held only by you: a passphrase wrapped with Argon2id — the argon2 crate defaults, 19 MiB, 2 iterations, 1 lane, with a 16-byte random per-target salt — stored in a keybox on the target itself so any machine that can see the folder can unlock it; or a one-time recovery key, which is the master key rendered as 56 Crockford base32 characters with a checksum. Nothing is escrowed. We hold no copy and there is no reset, which is the same thing as saying we could not read your files even if we wanted to.
What actually lands in the folder
A blob's name is a keyed BLAKE3 hash of its vault path, Crockford base32 encoded — always 52 characters, so the length of a path leaks nothing either. The real path travels inside the sealed payload, so decrypting one blob is enough to place it: there is no manifest and no name table that could be lost or corrupted. The authentication tag covers the path, so a blob renamed or moved by anything other than the app is detected rather than silently accepted. Padding is applied to the plaintext before sealing: the padded length is the next multiple of 4 KiB up to 64 KiB, and the next multiple of 64 KiB above that. On disk a blob is that padded length plus exactly 40 bytes — a 24-byte nonce and a 16-byte authentication tag.
What an observer of that folder can still see
Stated here because you would find it anyway, and because a limitation you discover for yourself is worth far more doubt than one we hand you. Someone who can read the synced folder learns: that it is an Altretta target, because the header file is plaintext on purpose so a second machine can find the salt; the number of notes, since there is one blob each; and each file's size to within its padding bucket. Because a blob's name is a deterministic function of its path, every note keeps the same name for its whole life — a stable pseudonym. That determinism is what lets two machines agree where a note lives without a shared index, and it is also what lets an observer watch how often you edit any single note, note by note, from timestamps alone — without ever learning which note it is. Deletions are the sharpest of these, and they are exact rather than approximate: a removed blob is moved into a trash directory rather than unlinked, keeping its name and gaining the millisecond it was removed. So the precise number of notes you have deleted, the exact moment of each deletion, and which pseudonym each deleted note had while it existed are all plainly readable. The public target id is a stable fingerprint linking two folders to the same key. None of it discloses a title, a path, or a word of content.
What makes the assistant refuse
Retrieval embeds your question, over-fetches from the memory index, keeps only chunk entries and re-ranks them by pure cosine similarity — deliberately discarding the composite recency-and-importance score the memory layer would otherwise apply, because relevance to the question is the only thing that should decide a citation. A verdict of "grounded" requires the best match to clear the high threshold and at least 2 chunks to clear it: corroboration, not one lucky passage. With the neural embedder the product ships, those thresholds are 0.80 and 0.77, calibrated against a measurement that unrelated pairs top out near 0.76. Between the two is "weak"; below both is "ungrounded". The answerability gate is then: at least one visible source after your folder exclusions have been applied, and — if you asked for grounded answers only — a verdict of exactly "grounded". When that gate fails, no model call is made at all. Answering anyway is a separate flag that is never inferred on your behalf, and when you set it the weak passages are withheld from the model so it cannot cite what did not qualify.
The symbol graph
Twenty languages have symbol extractors, each a tree-sitter parse plus a query: Rust, TypeScript, JavaScript, Python, Go, Swift, Java, C, C++, C#, Kotlin, PHP, Ruby, Dart, Scala, Objective-C, Bash, Lua, R and SQL. Symbols get canonical identifiers and are emitted as signed triples through the same path as everything else in the graph. Edges are typed — defines, imports, references, calls — and carry a confidence tier: a call resolving to exactly one candidate is high confidence, while a call with homonyms and every bare reference are marked uncertain rather than asserted as fact. Files over 2 MiB are recorded as skipped rather than quietly ignored, and a project is budgeted at 750,000 symbols. Drift compares a note's last-written time against the newest signed change to the symbol it documents. The limitation, which the source states plainly: that time is the filesystem mtime, so a checkout, a restore or an rsync that rewrites mtimes will change the verdict.
Reading documents, and what gets dropped
Word, PowerPoint and their OpenDocument equivalents are parsed in pure Rust — no rasterising, no OCR, no native dependency. Spreadsheets go through calamine. PDFs use the pdf.js text layer; rasterising with OCR is a separate, opt-in tier that runs only on pages with no usable text, and pages left unread are recorded as debt rather than silently dropped. Extraction emits citation anchors — a page marker per PDF page, a heading per slide, a sheet-and-row anchor per spreadsheet block, and a section anchor for numbered sections in a regulation, keeping the numeral in the heading because it is the only stable name that section has. Slides are ordered numerically, so slide 10 follows slide 9 rather than slide 1. Caps are enforced by bounded reads instead of trusting a declared size: 32 MiB per XML part, 128 MiB per archive, 16 MiB of emitted text, 5,000 slides, 50,000 rows. A gap worth naming: spreadsheets report truncation as a warning and the other converters do not, so a very large document can be trimmed quietly. The extracted text is written as an ordinary companion Markdown file beside the source, so the normal ingest signs it like any other note — there is no extraction database, the companion file's recorded source hash is the idempotency record.
Where everything lives on disk
Your notes are Markdown files in your folder. The only thing the app adds inside it is a hidden control directory holding the vault format stamp and, for a team vault, the keyring. Everything derived — the graph database, the search index, the snapshot store, the signing seed — lives outside the vault in application data, and the app refuses to start if you point the database inside the vault, because its own writes would trigger a re-ingest loop. That separation is why removing the app leaves your folder untouched, and why the derived index is always safe to delete and rebuild. It is also, honestly, why version history does not travel with a synced folder today. Licence checks are offline: a signed token verified against a key compiled into the app, with no server call. If we disappeared tomorrow, the app keeps opening, reading, writing, searching and answering.
How to check all of this yourself
The engine is open source. github.com/ApiliumCode/aingle holds the signing, hashing, graph and grounded-retrieval implementation, under Apache-2.0 for individuals, academia and organisations under $1M revenue, with a commercial licence above that. The application itself is not open source, and we would rather tell you that than imply otherwise.
- Reproduce a content hash: run any BLAKE3 tool over a note and compare it with the hash the app shows you. There is a pinned test vector in the public source to check your tooling against first.
- Rebuild an action hash and verify its signature independently: the byte layout is published as a spec, and the public test suite exercises tamper-rejection and the fact that signing does not change the hash.
- Confirm there is no telemetry: grep the source for the usual analytics and crash-reporting names, then list every URL literal in the Rust. What comes back is your own AI provider, your own connectors, and our licence and publishing endpoints — nothing else.
- Watch the network: open a vault with a monitor running. Nothing should be contacted until you configure a model or deliberately click an account action.
- Prove the deletion leak to yourself: turn on encryption for a scratch folder, add five notes, delete two, then list the target's trash directory. Two timestamped files. That is the leak, reproduced in a minute.
- Confirm no reset exists: forget the passphrase and lose the recovery key on a scratch target. Nothing in the app, and nothing we hold, can open it again.
即日起支持你的平台。
macOS 通用版(Intel + Apple Silicon)· Windows x64 · Linux AppImage/deb
你可能想知道的。
我真的拥有我的笔记吗?
是的。每条笔记都是你磁盘上的标准 Markdown 文件。你可以用任何编辑器打开、备份,或随时离开 Altretta:你的知识始终属于你。
免费版已经很好了,为什么还要付费?
桌面应用、基于笔记的有据可查答案以及一个文件夹同步永久免费。付费方案增加不限数量的同步文件夹、发布他人可验证的页面以及加密团队大脑。如果一个同步文件夹就够你用,免费版完全够用。
我如何信任 AI 的答案?
每个答案都会引用其所依据的具体笔记,附带出处和可信度评分。如果某个陈述没有你的笔记支撑,Altretta 会直接告诉你,而不是捏造内容。
连接 AI 需要技术背景吗?
不需要。Altretta 会自动检测你已有的 AI 应用——例如 Claude、Cursor 或 VS Code——并一键完成连接。无需配置文件,无需粘贴密钥,你还可以选择哪些文件夹对 AI 可见。
我需要单独为 AI 付费吗?
Altretta 是纯粹的记忆层:不包含自己的 LLM。你通过 MCP 使用你自己的订阅连接你偏好的模型,因此你使用的是你已付费的 AI,并保持密钥控制权。
我能把现有笔记迁移过来吗?
可以。Altretta 读取标准 Markdown,所以你现有的笔记文件夹直接可用。Pro 方案支持一键从 Notion 和 Confluence 导入。
加密团队大脑如何运作?
你共享的知识库,其笔记内容在你的设备上加密,因此团队之外的任何人都无法读取笔记的内容——我们不能,托管文件夹的一方也不能。访问权限按人授予,也可随时撤销:移除某人后密钥会轮换,他从此再也读不到任何内容。有一个限制我们宁可主动说明,而不愿让你自己发现:文件名和文件夹结构不加密,因此托管方仍能看到知识库的结构和每则笔记的名称。
支持哪些平台?
Altretta 现已支持 macOS(Apple Silicon 和 Intel)、Windows 和 Linux。下载链接始终指向最新发布版本。