KEPTA

Local-first memory for AI assistants

Your AI forgets.
KEPTA keeps the record.

One encrypted memory on your own machine, shared by every assistant you use. No cloud, no account.

macOS — Apple silicon and Intel  ·  No account, no card, no key  ·  The engine is BUSL-1.1, free forever

    Hybrid retrievalBM25 + vectors + graph
    One fileEncrypted at rest
    AES-256SQLCipher 4
    MCPEvery AI client
    BUSL-1.1Open core

    The mechanism

    One engine between every app and your disk.

    Your assistants speak MCP. KEPTA answers, and keeps a single encrypted file. The same code path serves the apps, the HTTP API and the browser, so every client gets the same answers.

    YOUR AI APPS Claude Desktop Cursor Windsurf / VS Code Gemini CLI / Cline Zed / Codex / Continue scripts over HTTP kepta-mcp stdio from npm · HTTP from source one code path One encrypted file SQLCipher 4, AES-256 ~/.kepta/kepta.db stays on your machine
    # finds Claude Desktop, Cursor, VS Code, Gemini CLI and more
    $ npx -y kepta-mcp setup
    # the same encrypted file, in your browser, live
    $ npx -y kepta-mcp ui

    Sealed

    One file. Yours.

    The knowledge base is a single encrypted database. The key is created and held by your operating system, so no assistant ever sees it.

    At rest
    SQLCipher 4: AES-256 with an HMAC-SHA512 over every page, the write-ahead log included.
    The key
    256 random bits, created and kept in the macOS Keychain, Windows DPAPI or the Linux Secret Service.
    Exposure
    Loopback only, 127.0.0.1. There is no server that could receive your notes, because there is no server.
    Telemetry
    None. No account, no analytics, no call home. This page runs no tracking either.
    Licensing
    Nothing to activate. The engine is source-available under BUSL-1.1 and free forever; the enterprise side is a contract, not a key.
    KEPTA privacy shield turning personal data into neutral placeholders before a cloud AI would see it.
    Plate IThe shield inside the app.

    Privacy shield

    live example, edit the text
    Names, phone numbers, addresses and email addresses become placeholders before a cloud model would ever see them.

    It remembers in time

    Ask what you knew on any day.

    Facts carry validity windows. When one is replaced, the old one is marked and kept, never quietly deleted. Drag the date and watch the file tell you the truth as it stood.

    Validity
    Every note can carry valid_from and valid_to, and answers a query for a past moment.
    Supersede
    A new fact displaces the old one and points to it, so the reasoning stays traceable.
    Weighting
    Expired and replaced notes lose relevance in ranking, but never disappear from the file.

    As known on

    2026-09-20

      Three ways to remember

      Three ways in, one ranked answer.

      Full text, meaning and connection are searched at once, fused into one ranking, and re-ranked on your machine. Nothing is sent away.

      Full text

      Exact words

      BM25 finds the phrase you actually used: the name, the number, the reference.

      Meaning

      Close enough

      Vector similarity finds the note that says it differently, in another language if needed.

      Connection

      Linked in

      The knowledge graph follows the links between notes, so a hit brings its neighbours.

      Fusion

      One ranking

      The three are fused with Reciprocal Rank Fusion, then re-ranked locally by term coverage, phrases, title and tags.

      The evidence

      The memory, made visible.

      KEPTA is the desktop app on the same engine: what your notes contain, how they connect, and which assistant touched them.

      • 01

        The interface

        Browse by kind and tag, search ranked by relevance, write and edit.

      • 02

        The knowledge graph

        Every note a node, every link an edge, with a time slider for any day.

      • 03

        Activity

        Which assistant read or wrote what, live, while you talk to it.

      The KEPTA interface: notes listed by kind and tag, with search and a live activity feed.
      KEPTA knowledge graph with notes as nodes and links as edges.
      KEPTA activity feed listing which AI app saved, updated or looked up a note.

      Screenshots show the app on a demo corpus, worked on by Claude and Cursor through the MCP server of the open core.

      The terms

      Free on your own machine, or under contract.

      Everything that makes the memory smart lives in the free engine. There is no tier inside it, and nothing that locks you out later.

      CoreStart here

      Everyone — download and use

      €0forever — no account, no contract, no remote

      The whole desktop app: knowledge graph, chat with your memory, Today, privacy shield, dossiers. For agents and scripts the same engine ships headless — the MCP server, the HTTP API, the Python client. Source available under BUSL-1.1.

      Download for macOS (Apple silicon and Intel)

      Enterprise

      Organizations

      By agreementShaped to your size

      The same engine as an organization infrastructure: tenant memory behind one wall, a tamper-evident audit chain with one-click verification, human review for agent writes, point-in-time recovery, scope per key and per-tenant encryption keys. Self-hosted, firewall or air-gapped.

      damian2212todi@gmail.com
      Talk to Damian on LinkedIn
      Trust Center — the open architecture answer

      Four lines on the enterprise side are still open: a tool filter per key, read parity for memory_list and memory_graph at the MCP door, the asOf parameter there, and the private shield. If one of them is load-bearing for you, ask before you sign.

      Open core

      Inspect it before you trust it.

      The memory engine is BUSL-1.1 and free forever (converts to AGPL-3.0 four years after each release). The Python client is MIT, standard library only. Read the code, fork it, ship your own product from it.

      1,500+ automated tests in the desktop app, 474 in this open core.

      # connect every assistant on this machine
      $ npx -y kepta-mcp setup
      
      # or embed it from Python, standard library only
      $ pip install kepta

      Questions

      The short answers.

      Every answer below is taken word for word from the sections above.

      Where does my data live?

      The knowledge base is a single encrypted database. SQLCipher 4: AES-256 with an HMAC-SHA512 over every page, the write-ahead log included.

      Does KEPTA send anything anywhere?

      None. No account, no analytics, no call home. Loopback only, 127.0.0.1. There is no server that could receive your notes, because there is no server.

      Is it really free?

      Yes. The engine is source-available under BUSL-1.1 and free forever — running it in your own organization is always allowed. There are no tiers inside the memory: everything that makes it smart is in the free engine.

      Which AI clients are supported?

      Claude Desktop, Claude Code, Cursor, Windsurf, VS Code, Gemini CLI, Cline, Roo Code, Zed, Codex, Continue, any MCP client.

      Where do the benchmark numbers come from?

      From LongMemEval-S: 500 questions, a fixed dataset with a pinned checksum, graded by a local judge. 61.5 % — and every question record of every run is committed to the public repository: its id, type and skill, the judge's verdict, how many notes retrieval returned and which of them settled the answer. The question and answer texts are not in the repo; they come from the pinned upstream dataset. Read the number as what it measures: context sufficiency rather than end-to-end answer accuracy, a partial verdict counting as half a point, and every setting (top-k, temporal split, HyDE, judge size) chosen on these same 500 questions — an in-sample figure. You can rerun the whole benchmark yourself.

      What is KEPTA Enterprise?

      The same engine as an organization infrastructure: tenant memory behind one wall, a tamper-evident audit chain with one-click verification, human review for agent writes, point-in-time recovery, scope per key and per-tenant keys. Self-hosted, firewall or air-gapped. Licensed by agreement.