The organization vault
Your team already wrote it down, in commits, sessions, docs, and issues. Citadel captures it as it happens and gives you, and the agents beside you, one place to ask.
This page is served by the system it describes. Live numbers, releases, and the roadmap are on the status page.
Self-host cost is mostly RAM: 24h 2026-08-17 about $23; 7-day 2026-08-14 about $58. Not a ceiling; method in the bench harness.
Most team knowledge tools ask you to file things. Citadel captures the work you were doing anyway, then keeps the personal and the shared strictly apart.
You and your agents read via MCP, CLI or web: your Node plus Central, never another seat's.
Capture to promotion to read, end to end. Hover a step to follow its path, and select one to read what it does.
Everything you capture lands in your own Node. No other seat can read it, and no background job promotes it into the shared memory. Sharing is an act, not a setting.
seat scopedThe org's shared memory only holds what a person promoted into it, so it stays worth trusting instead of turning into a dump of everyone's scratch notes.
promotion gatedAny MCP client, Claude Code, Cursor, or your own agent, searches the same vault under the same seat and the same read isolation as you do.
MCP nativeEvery answer points back at where it came from, a commit, an issue, a session, so you can check the claim instead of taking the vault's word for it.
provenanceCitadel is a FastAPI service over a retrieval layer, but the moat is the governance around it.
citadel promotion).You install once. After that the interesting part is what you do not have to do.
A session hook, a GitHub sync, and a Linear mirror feed your Node while you work. Nothing to file, nothing to remember to save.
citadel search and the MCP tools read your Node and Central together, and tell you which one answered.
When something is worth the whole org knowing, you promote it. Until then it stays on your seat, out of reach of the rest of the org and of their agents.
Run it on your own work. Install the CLI, hand it a seat token, and your agents search the same memory you do. Self-hosted and Apache-2.0, so you can read every line of what it does.
Build it into your project. utxo AG joins consortia as a work-package partner, bringing the vault and the team that wrote it.
You need a seat token from us to try the live node. This is not a public sandbox. Contact us, we send an access token, then install the CLI and the agent skill.