Use cases · teams and consortia

What people run Citadel for, and where we partner.

utxo AG · Zug, SwitzerlandLooking for: one work package

The short version

For a team. Citadel gathers the records you already produce, code, tickets, documents, coding sessions, and keeps them in one place where each item is traceable to its source, only visible to the people allowed to see it, and logged every time it is read or changed. You and your agents ask it questions instead of asking each other the same ones again.

For a consortium. That same system is what utxo AG brings to an EU project, as a partner running one work package. We are a Swiss company, and Switzerland is part of the Digital Europe Programme, so we count toward your minimum number of countries rather than sitting outside it. We apply for Swiss national co-funding toward our own share, and we scope the work package with you rather than off a price list.

Use cases

Four things teams run it for

None of these need anyone to file anything. The capture already happened while people were working.

The first two weeks of a new engineer

Why is it built this way, what was tried before, who decided. A new joiner asks the vault and gets an answer with the commit, issue, or decision record behind it, instead of interrupting the three people who remember.

onboarding without a tax on the team

Agents that know your codebase

Claude Code, Cursor, or your own agent connects over MCP and answers from your team's memory under your seat and your read scope. The agent stops guessing at context it was never given.

MCP · same seat, same isolation

One question across every tool

The answer to "what happened with X" is usually split across a commit, a ticket, a document, and a coding session nobody wrote down. One search reads all of them and tells you which memory answered.

code · tickets · docs · sessions

Evidence you can hand to someone else

Every retrieved item carries a content fingerprint and points back at where it came from, and every read and write is logged. When a report or a review needs proof, it is already assembled.

source linked · audited

The rest of this page is the same system offered to EU consortia as a work-package partner. If you are here as a team rather than a coordinator, the home page and the live status are the shorter read.

Partnering · where we fit

Two jobs consortia give us

The software is the same in both. Only what we connect it to changes.

Proving compliance without the paper chase

The evidence a report needs is scattered across a dozen systems, and by the time it is collected it is out of date. We keep it gathered continuously, each item traceable back to where it came from, so a report can be produced, and defended, from records rather than recollection.

gather → check → report

Shared knowledge across partner organisations

Five organisations over 24 months usually run their knowledge on shared drives and email. We give each partner a private space and the consortium a shared one, with clear rules for what moves between them and a log of who saw what.

private per partner · shared per project
What we can and can't do

Three honest categories

Rather than one long capability list, here is the only distinction that matters to you when you are assembling a consortium: what already works, what we would build with project funding, and what you need somebody else for.

Works now

Running in production today: you can check it before committing

Records flow in automatically from code repositories, issue trackers and documents. Every item carries a digital fingerprint so you can prove it hasn't been altered. Access is controlled per person and per organisation, and every read and write is logged. People use a command-line tool or a web page; AI assistants connect through a standard interface.

The technical versionGo deeper
  • Apache-2.0, public repository, CI on every push.
  • Live hosted node with a public state report and a no-secrets status endpoint.
  • Seat-bound tokens, role-scoped tool access, per-call audit.
  • Read isolation between each seat's private Node and shared Central, with a multi-gate promotion engine controlling what moves between them.
  • SHA-256 content digest returned on every retrieved item; secret scanning on every write path.
  • Production connectors for a GitHub organisation, repository content and an issue tracker.
  • Three access surfaces: hosted MCP, a zero-dependency CLI, and an HTTP API.
  • Basic conflict detection across ingested documents.
We'd build

Specified in our roadmap, funded by the project

Making every single item traceable back to the exact document and moment it came from. Spotting when two records disagree and keeping both rather than quietly overwriting one. Spotting when a record has gone stale. Writing the rules a regulation implies in a form software can check automatically, then reporting what evidence is still missing. Connectors for whatever systems your pilot actually uses.

The technical versionGo deeper
  • Attested per-item provenance: source-snapshot pointers, confidence and match type on every retrieved item, with unresolvable claims stripped rather than shown.
  • Claim-level contradiction ledger: records both sides of a disagreement instead of silently overwriting.
  • Durable structured knowledge owned by Citadel, with the search index rebuildable underneath it.
  • Machine-readable requirement models, and mapping from evidence to the obligation it satisfies.
  • Retrieval benchmark and vault lint running in CI: the project's measurable quality indicators.
  • Export packages carrying source links, timestamps and content digests.
Not us

You need another partner for these

Techniques for analysing data without exposing it. Digital identity wallets, electronic seals and other trust services. Connectors into the European data spaces, and the shared vocabularies a particular industry uses. We work with all of these. We don't build them, and we would rather say so now than at the technical review.

What we don't claim

Where we would fail a technical review

Read this before you believe the rest

Partner profiles list capabilities and stop. These are the gaps, checked against the live system rather than copied from our own documentation.

  • Items are fingerprinted, but not yet traceable. We can prove a record hasn't changed; we cannot yet show you, on every record, exactly which document it came from. That is the single biggest thing a project would fund, and we would rather fund it than claim it.
  • Disagreement detection is shallow. Today it compares document titles. Comparing the actual claims is designed and specified, but not built.
  • We are proven at team scale, not national scale. The system runs daily for a working team. Handling a country's reporting volume is real project work, and we scope it as such.
Draft work package

Written so you can lift it and edit

A coordinator assembling a proposal under time pressure needs text, not a brochure. Six tasks across 24 months, all negotiable against the structure you already have.

M1–M4

Work out what has to be proved

Turn the obligations you are targeting into rules software can check, and agree the interfaces with the partners supplying data and the partner building the reporting front-end.

M3–M10

Connect the pilot's systems

Build the connectors that pull records out of whatever the pilot actually runs on, with access rules and secret scanning applied as they arrive.

M5–M14

Make every record traceable

Each item points back to the document and moment it came from, with a confidence level. Anything that can't be traced is dropped rather than presented as evidence.

M8–M16

Check the evidence holds up

Flag records that disagree, records that have gone stale, and obligations with no evidence behind them at all.

M10–M20

Control access and produce the package

Per-organisation access rules, a log of every read and write, and an export carrying source links, timestamps and fingerprints for onward transmission.

M6–M24

Measure it, continuously

Automated quality checks running throughout the project, producing the numbers your reporting needs rather than a one-off assessment at the end.

We depend on other partners for data capture from the pilot's systems, privacy techniques, identity and trust services, and the industry vocabulary. We provide the store everything lands in, the way to query it, and the export that leaves it.

The ask

One work package, scoped to your call

Effort and cost depend on the call, the pilot systems, and which partners cover what around us. We work those out with you rather than publishing a figure that would be wrong for your project. Send us the call and the gap, and we come back with a costed work package written against your structure.

Role

A partner running one work package

We run the work package and hand over everything under Apache-2.0, plus support on the open-source release and dissemination. If your consortium is already full, we are just as happy as an associated partner or a subcontractor, and what we build does not change.

Eligibility

Switzerland is inside the Digital Europe Programme

Since 2025, Swiss organisations take part as full partners and can even lead, across Specific Objectives 1, 2, 4 and 5, though not 3 or 6. So we add a country to your count instead of complicating it.

Co-funding

We apply for Swiss money toward our own share

Swiss participants can ask SERI to co-fund the part the EU grant doesn't cover, which lowers what the consortium carries on our line. It is granted on request, so we treat it as likely rather than certain.

Check us

Verify before you commit to anything

The page you are reading is served by the system it describes. Nothing here needs to be taken on trust.

The source code

github.com/masumi-network/Citadel is Apache-2.0, with the full commit and test history, and the written record of every significant design decision.

read every line

The running system

Its own live status report: current numbers, what shipped when, and what is planned, generated by the system rather than written about it.

served by the node
Talk to us

Tell us the call and the gap

Send the call identifier, the topic, and the piece you need covered. We reply with a work package written against your structure rather than ours, usually within two working days.