ZettelForge v2.1.0 — Open-Source Launch
ZettelForge Community (MIT) includes everything above. It is a complete, production-ready memory system.
ThreatRecall Enterprise (BSL-1.1) adds scale, analyst workflows, and platform integrations for teams running ZettelForge in production:
Enterprise Feature | What it adds -- | -- TypeDB STIX 2.1 ontology | Replaces JSONL graph with TypeDB -- inference rules, 9 entity types, 8 relation types, 36 seeded CTI aliases Temporal KG queries | "What changed since Tuesday?" -- get_changes_since(), get_entity_timeline() Multi-hop graph traversal | traverse_graph() with BFS across relationship chains Advanced synthesis formats | synthesized_brief, timeline_analysis, relationship_map Report ingestion | remember_report() with auto-chunking for long threat reports OpenCTI integration | Bi-directional sync with OpenCTI platform Sigma rule generation | Generate Sigma YAML detection rules from IOCs Multi-tenant auth | OAuth/JWT with per-tenant data isolation Proactive context injection | Auto-load relevant context before agent tasks# Enterprise install (requires license key)
pip install -e ".[enterprise]"
export THREATENGRAM_LICENSE_KEY="TG-xxxx-xxxx-xxxx-xxxx"
Community vs Enterprise ZettelForge Community (MIT) includes everything above. It is a complete, production-ready memory system.
ThreatRecall Enterprise (BSL-1.1) adds scale, analyst workflows, and platform integrations for teams running ZettelForge in production:
Enterprise Feature What it adds
TypeDB STIX 2.1 ontology Replaces JSONL graph with TypeDB -- inference rules, 9 entity types, 8 relation types, 36 seeded CTI aliases
Temporal KG queries "What changed since Tuesday?" -- get_changes_since(), get_entity_timeline()
Multi-hop graph traversal traverse_graph() with BFS across relationship chains
Advanced synthesis formats synthesized_brief, timeline_analysis, relationship_map
Report ingestion remember_report() with auto-chunking for long threat reports
OpenCTI integration Bi-directional sync with OpenCTI platform
Sigma rule generation Generate Sigma YAML detection rules from IOCs
Multi-tenant auth OAuth/JWT with per-tenant data isolation
Proactive context injection Auto-load relevant context before agent tasks
Enterprise install (requires license key)
pip install -e ".[enterprise]"
export THREATENGRAM_LICENSE_KEY="TG-xxxx-xxxx-xxxx-xxxx"