本文档仅以英文发布。它说明哪些内容会离开您的设备,以及我们在合同上作出的承诺;在这些问题上,您能够核对的原文比无法核对的译文更有价值。
Security and data processing
Written for the reviewer who has to approve it. Tables, not prose, and four checks you can run yourself.
- Document
- Security fact sheet
- Version
- 1.0
- Updated
- 2026-08-03
- Controller
- Apilium Technologies OÜ, Tallinn, Estonia
- Scope
- Altretta desktop application
Vendor-questionnaire summary
The rows a reviewer usually has to ask for, in the order they are usually asked.
| Question | Answer |
|---|---|
| Is an account required to use the product? | No |
| Telemetry or analytics in the desktop application? | None |
| Where is customer data stored? | On the customer device, as Markdown files |
| Where does indexing and search run? | On the device. No network call |
| Proprietary format or lock-in? | No. Markdown in a folder the customer chooses |
| Encryption in transit and at rest for sync? | Yes. Encrypted on the client before it leaves |
| Can the vendor read synced content? | No. The server stores ciphertext |
| Immutable audit trail? | Yes. A signed action chain the customer can verify |
| AI model included by default? | No. The customer supplies endpoint and key |
| Data processing agreement available? | Yes, for plans where we process anything |
| Controller jurisdiction? | Estonia — EU / EEA |
| Transfers outside the EEA by default? | None |
What leaves the device
Exhaustive. There is no fourth row.
| What leaves | When | Destination | Encrypted | Optional |
|---|---|---|---|---|
| Retrieved passages and your question | When you ask the AI for an answer | The endpoint you configure | Provider TLS | Yes — with a local model, nothing leaves |
| Vault files | Only with sync enabled (paid plans) | A destination you choose | Yes, on the client, before it leaves | Yes |
| A clipped page | Only when you use the web clipper | Your local vault | Not applicable — it does not leave | Yes |
Never leaves: The vault as a whole, the semantic index, the signed chain, file names, folder structure, and any usage data.
The AI boundary
Altretta ships with no model and no key. The endpoint is the customer choice, and it decides this table on its own.
| Configuration | What leaves the machine |
|---|---|
| A local model (localhost, or another machine on your network) | Nothing |
| A hosted provider | The passages relevant to the question, and the question |
With a local model, retrieval, the graph, the citations and the signed history behave identically.
Legal and contractual
| Point | Status |
|---|---|
| Controller established in the EU | Yes — Estonia |
| GDPR applicable | Yes |
| Data processing agreement | Available for plans where we process |
| International transfers by default | None |
| Terms and privacy policy published | Yes — on the legal page |
Your vendor questionnaire. Send it to us and we will complete it against your plan and your deployment. Questions not answered above are answered there, where we can give you the context a public table cannot.
Verify it yourself
Four checks. None of them requires talking to us.
| Check | How | Time |
|---|---|---|
| Data does not leave | Configure a local model, disconnect the network, use the product | 5 min |
| No lock-in | Open the vault folder in any other Markdown editor | 10 s |
| Answers are supported | Every claim cites file and lines. Open the file | 1 min |
| The history is intact | The byte layout is published and the verifier runs in your browser | 15 min |
Audit trail
Every change is recorded as a signed action in a hash-linked chain. Renames, merges and bulk edits included.
| Property | Status |
|---|---|
| Immutable once written | Yes — hash-linked |
| Verifiable by the customer without the vendor | Yes |
| Format specification published | Yes |
| Proves a note was not altered afterwards | Yes |
Grounded answers
| Property | Status |
|---|---|
| Every claim cites file and lines | Yes |
| Insufficient evidence is reported as such | Yes — marked weak evidence, passages still shown |
| The model can answer without supporting passages | No |
Plugins
| Property | Status |
|---|---|
| Signed | Yes |
| Sandboxed | Yes |
| Permissions declared before execution | Yes |
| Network or disk access without a declaration you accepted | No |
Contact
| Subject | Route |
|---|---|
| Vendor questionnaires and DPAs | [email protected] |
| Security enquiries | [email protected] |
| Responsible disclosure | See the security policy |
| Data protection | [email protected] |
Maintained by Apilium Technologies OÜ. The version and date in the header identify the current revision.