Skip to content

Plans, seats & Enterprise SSO

Free covers one synced folder, Pro unlocks the paid single-user capabilities, Team unlocks the encrypted team brain, and Enterprise adds single sign-on for your whole organization.

What each tier unlocks

There are four tiers: Free, Pro, Team, and Enterprise.

FreeProTeamEnterprise
The full local editor, graph, search, bring-your-own-AIYesYesYesYes
Synced folders (through a folder you choose)OneUnlimitedUnlimitedUnlimited
Publishing (hosted and local folder export)YesYesYes
Notion & Confluence connectorsYesYesYes
Version history beyond the last 7 daysYesYesYes
Encrypted team brain, roles, revocationYesYes
Signed audit exportYes
Single sign-on (SSO / OIDC)Yes

Verifying a signed audit file is deliberately available on every tier, including Free — a recipient should never need a licence to check that what they were handed is intact. Only producing the export is Enterprise.

How seats work

A seat is consumed by every member on a team vault's roster, whatever their role — Owner, Admin, Writer and Reader alike.

Readers are not free. If you are sizing a plan, count everyone who will be on the roster, not just the people who will write.

Adding a member when the roster is already at the licensed seat count is refused, and the message tells you the current count and the limit. A roster that is already over the count — because it grew before the check existed, or after a plan change — is not invalidated: existing members keep working and only the next addition is refused.

Licences, devices and going offline

A licence is bound to the device it was activated on, and is checked against a signed grant from your Apilium account. If it can't be reached, Altretta keeps honouring a cached licence for a 14-day offline grace period; after that the app falls back to Free capabilities until it can check again. Nothing local is taken away — your notes, editor, graph and search never depend on a licence.

Individual sign-in vs. Enterprise SSO

Individuals sign in to their Apilium account with an email and password, or with social sign-in via Google, GitHub or Microsoft.

Enterprise SSO / OIDC

Enterprise unlocks single sign-on (SSO) using OIDC, configured per organization and keyed to your domain — when someone with your company's email domain signs in, they're routed through your identity provider. Consumer mailbox domains are refused, so an SSO configuration can't be claimed for gmail.com and its equivalents.

SSO is set up per organization on the Apilium side — the identity-provider configuration, including the client secret, lives there and is never stored by the desktop app. Altretta supports standard OIDC single sign-on; specific provider setup is arranged as part of onboarding your organization.