ANKIR
Try the demo

Analyst Notes, Knowledge & Incidents Repository

Every fact in the case, anchored.

The OUTLINER you think in, the CASE MANAGEMENT you report from, the KNOWLEDGE BASE nobody updates and the GLUE SCRIPTS between them, as one local-first platform. Every note, artifact and edit is hashed, attributed and timestamped, from the first messy line to the report that leaves the building.

01 · NOTES

Every line you type is an anchor.

A note in the Vault is hashed and attributed the moment it is written. The messy first draft is already evidence-grade.

02 · ARTIFACTS & INDICATORS

So is every hash, IP and timestamp.

Indicators are recognised where you typed them. Uploaded artifacts are hashed on arrival. Nothing is entered twice, and nothing is unaccounted for.

03 · PROMOTIONS

Moving a note to the team is an anchor too.

Nothing leaves the Vault on its own. A promotion to the Workspace records who, when and what hash.

04 · THE REPORT

The report is the sweep, in order.

Export the case and the whole chain of anchors goes with it. Every hash it collected and every hand it passed through are already in the file.

The report knows who is reading it.

One case leaves the building as several documents. Export applies an audience overlay and a redaction profile over the same anchors, so the board, the responders and counsel each get the register they need without anyone maintaining three versions by hand.

The case itself is untouched. Only the view that leaves it changes.

EXPORT · INC-2026-014 4 anchors selected
AUDIENCE
Executive Technical Legal
REDACTION
none moderate strict

INC-2026-014 · technical · moderate

Architecture

Deploys inside your environment.

ANKIR runs on infrastructure you control. Private work stays in a local Vault inside the browser. Shared work lives in a Workspace on your own servers, and there is no vendor cloud in the path between your analysts and their data.

  • Workspace membership decides who can open which case, down to the individual realm
  • Runs fully disconnected, including on air-gapped networks
  • Updates are applied on your schedule, never pushed at you mid-incident

Local

The browser is the whole client

  • The Vault is real SQLite running in your browser on OPFS, not a server round-trip
  • Pull the network cable mid-triage and the editor behaves exactly the same
  • Close the tab mid-thought and the block outliner reopens where you left it

Interop

Speaks the formats your tooling already speaks

  • STIX 2.1 in and STIX 2.1 out, so a bundle from your TIP loads without a conversion script
  • ATT&CK technique IDs are typed fields on an asset, not free text in a notes box
  • Evidence and indicators are queryable records rather than documents someone has to read

Where it runs

Every surface is the same client build. Evaluate it in the browser, then bring it fully in-house when you are ready.

Evaluation demo
A client build that runs entirely in your browser, seeded with sample DFIR cases you can open and pull apart.
Workspace deployment
The full platform inside your own environment, with case data and evidence never leaving infrastructure you control.
Desktop application
A native desktop client. Run it Vault-only, or connect it to your organization’s Workspace.
Built on

SQLite · PostgreSQL · S3-compatible object storage

Inside your environment. Hashed. No telemetry.

The demo opens a seeded DFIR case in your browser. There's no account to create, and the vault data stays in the tab.