Where does my data live?
The knowledge base is a single encrypted database. SQLCipher 4: AES-256 with an HMAC-SHA512 over every page, the write-ahead log included.
Local-first memory for AI assistants
One encrypted memory on your own machine, shared by every assistant you use. No cloud, no account.
The mechanism
Your assistants speak MCP. KEPTA answers, and keeps a single encrypted file. The same code path serves the apps, the HTTP API and the browser, so every client gets the same answers.
# finds Claude Desktop, Cursor, VS Code, Gemini CLI and more $ npx -y kepta-mcp setup
# the same encrypted file, in your browser, live $ npx -y kepta-mcp ui
Sealed
The knowledge base is a single encrypted database. The key is created and held by your operating system, so no assistant ever sees it.
127.0.0.1. There is no server that could receive your notes, because there is no server.It remembers in time
Facts carry validity windows. When one is replaced, the old one is marked and kept, never quietly deleted. Drag the date and watch the file tell you the truth as it stood.
valid_from and valid_to, and answers a query for a past moment.Three ways to remember
Full text, meaning and connection are searched at once, fused into one ranking, and re-ranked on your machine. Nothing is sent away.
BM25 finds the phrase you actually used: the name, the number, the reference.
Vector similarity finds the note that says it differently, in another language if needed.
The knowledge graph follows the links between notes, so a hit brings its neighbours.
The three are fused with Reciprocal Rank Fusion, then re-ranked locally by term coverage, phrases, title and tags.
The evidence
KEPTA is the desktop app on the same engine: what your notes contain, how they connect, and which assistant touched them.
Browse by kind and tag, search ranked by relevance, write and edit.
Every note a node, every link an edge, with a time slider for any day.
Which assistant read or wrote what, live, while you talk to it.
Screenshots show the app on a demo corpus, worked on by Claude and Cursor through the MCP server of the open core.
The terms
Everything that makes the memory smart lives in the free engine. There is no tier inside it, and nothing that locks you out later.
Everyone — download and use
€0forever — no account, no contract, no remote
The whole desktop app: knowledge graph, chat with your memory, Today, privacy shield, dossiers. For agents and scripts the same engine ships headless — the MCP server, the HTTP API, the Python client. Source available under BUSL-1.1.
Organizations
By agreementShaped to your size
The same engine as an organization infrastructure: tenant memory behind one wall, a tamper-evident audit chain with one-click verification, human review for agent writes, point-in-time recovery, scope per key and per-tenant encryption keys. Self-hosted, firewall or air-gapped.
damian2212todi@gmail.com
Talk to Damian on LinkedIn
Trust Center — the open architecture answer
Four lines on the enterprise side are still open: a tool filter per key, read parity for memory_list and memory_graph at the MCP door, the asOf parameter there, and the private shield. If one of them is load-bearing for you, ask before you sign.
Open core
The memory engine is BUSL-1.1 and free forever (converts to AGPL-3.0 four years after each release). The Python client is MIT, standard library only. Read the code, fork it, ship your own product from it.
1,500+ automated tests in the desktop app, 474 in this open core.
# connect every assistant on this machine $ npx -y kepta-mcp setup # or embed it from Python, standard library only $ pip install kepta
Questions
Every answer below is taken word for word from the sections above.
The knowledge base is a single encrypted database. SQLCipher 4: AES-256 with an HMAC-SHA512 over every page, the write-ahead log included.
None. No account, no analytics, no call home. Loopback only, 127.0.0.1. There is no server that could receive your notes, because there is no server.
Yes. The engine is source-available under BUSL-1.1 and free forever — running it in your own organization is always allowed. There are no tiers inside the memory: everything that makes it smart is in the free engine.
Claude Desktop, Claude Code, Cursor, Windsurf, VS Code, Gemini CLI, Cline, Roo Code, Zed, Codex, Continue, any MCP client.
From LongMemEval-S: 500 questions, a fixed dataset with a pinned checksum, graded by a local judge. 61.5 % — and every question record of every run is committed to the public repository: its id, type and skill, the judge's verdict, how many notes retrieval returned and which of them settled the answer. The question and answer texts are not in the repo; they come from the pinned upstream dataset. Read the number as what it measures: context sufficiency rather than end-to-end answer accuracy, a partial verdict counting as half a point, and every setting (top-k, temporal split, HyDE, judge size) chosen on these same 500 questions — an in-sample figure. You can rerun the whole benchmark yourself.
The same engine as an organization infrastructure: tenant memory behind one wall, a tamper-evident audit chain with one-click verification, human review for agent writes, point-in-time recovery, scope per key and per-tenant keys. Self-hosted, firewall or air-gapped. Licensed by agreement.
Legal
KEPTA is operated by Damian Todorovic, Germany. Nothing here is sold through a checkout: the engine is free, the enterprise side is a contract.
KEPTA is operated by Damian Todorovic, Germany. Contact: damian2212todi@gmail.com. Not affiliated with Anthropic, Google or Cursor.
The engine is source-available under BUSL-1.1: every line public, production use inside your own organization always allowed, offering it as a hosted service is reserved. Each version converts to AGPL-3.0-or-later four years after its release. The Python client is MIT, standard library only.
KEPTA runs locally. Your memory stays in one encrypted file on your machine — no telemetry, no cloud, no account, nothing to opt out of.
This page is a static file served by GitHub Pages. It sets no cookies, runs no analytics, and loads no third-party scripts: its fonts and images are embedded in the page itself.
The database is SQLCipher 4 with AES-256 and an HMAC-SHA512 over every page. Every read and write is entered in an append-only journal whose entries point at their predecessor, so an edit after the fact breaks the chain and the break is reported rather than hidden.
No certificates, no seals, no customer references. Where a number is shown, it was measured on the commit named beside it and can be run again.