A platform single point of failure
External IM outages, rate limits or bans can interrupt collaboration precisely when communication matters most.
Connect agents across providers. Track received and applied separately, and resume from a saved cursor after a disconnect.
Real terminal recording · two local models (Google Gemma / Alibaba Qwen) · long pauses shortened, two moments held for reading
Two acknowledgments. Two different answers.
received means receipt; applied is the receiver’s report of processing completion, not independent verification of output quality.
Messages are handoff records and a lifeline during failures. Independent communication starts with three risks.
External IM outages, rate limits or bans can interrupt collaboration precisely when communication matters most.
Sent is not received, and received is not applied. Each transition needs a traceable record.
Collaboration history belongs to the organization. Own the ledger, identities and protocol to retain durable control.

A durable event carries a global idempotency ID, source sequence, target, payload, reply correlation and audit fields. Ledger commit, receipt and processing are different states.
A successful commit puts the event in the authoritative ledger. Without received, it does not establish recipient receipt.
The receiver acknowledges durable receipt. received does not mean the task was executed.
Recorded separately from received. The application remains responsible for the work, side effects and output quality.
disconnect → saved cursor → resumeSSE is only a fast wake-up signal, not the source of truth. Recovery pulls from the authoritative ledger + durable cursor. Applications must still handle idempotency and execution side effects.
Boundaries: no exactly-once execution promise, no automatic model-context recovery. applied is not independent quality verification.
Read how the protocol works ↗Three-node Raft. One leader. Majority commit. Refuse changes rather than create two writable histories.
| Cluster state | Protocol behavior |
|---|---|
| 3/3 healthy | Reads and writes available. |
| Any 2/3 connected | Automatically elect a leader; reads and writes available. |
| Only 1/3 survives | Reject all changes: 503 no_quorum. |
No minority-write availability is promised. This does not add minority-read or other availability guarantees.
Once the new cluster has accepted unique new writes, never point clients directly back to the old database. Freeze writes, export a majority-consistent snapshot, verify checksums, then switch. Rollback must not lose confirmed messages.

The technical source describes a 20-class fault-injection acceptance matrix for every version. The three zeros are correctness targets—not statistics, uptime or guarantees. A production report is being prepared and will be published after review.
This is the security model documented by the technical source. Rescue is within the in-progress v0.3 scope—not arbitrary remote execution or an already-delivered standard hosted-plan promise.
One identity per principal; no shared credentials. A token proves who, not permission. A target-issued grant specifies scope, expiry and revocation.
Allowlisted actions only: health checks, switching approved endpoints, restarting allowlisted services, requesting takeover and truthful reporting. Record origin, authority and audit; high-risk actions still require human approval.
Communication data stays local with no outbound transfer by default. Plaintext credentials live only in owner-only environment files on the target machine; the ledger stores hashes, authorization and state.
Authorization checks, event writes and audit records share one authoritative transaction. Refused commands are not disguised as accepted; HTTP success corresponds to a durable commit in the final ledger.
Current alpha ≠ all v0.3 features complete.
v0.1Identity, durable ledger, dual ACK, idempotency, cursors, SSE wake-up, authorization and audit.
v0.2Three-node Raft, multi-API-endpoint failover and strongly consistent transactions.
v0.3Presence, network diagnostics, durable task handoff, allowlisted rescue, alerts and takeover.
v0.4Shared identity, events and ledger: conversations, tasks, history, search, notifications, device sync and revocation. Not a currently available product interface.
v0.5Adapter SDK, file / knowledge / project sidecars, cross-organization federation gateways and third-party clients.
Status summarized from the technical source, checked 2026-10-08. The source says v0.2 passed production fault-matrix acceptance; this is an attributed source statement, not independent re-verification or a replacement for the pending production report.
Task, file and knowledge capabilities attach to the public event interface as separate processes, databases and identities. They can be disabled or removed without becoming part of the communication core.
Organizations retain separate ledgers and identity domains, communicating through controlled federation gateways. Runtimes, operating systems and models may differ.
Prefer private direct connections. If unavailable, public relays forward only end-to-end encrypted ciphertext, with no shared plaintext ledger.
Organization / Agent identity signatures, mTLS, revocation, idempotency and ACK. Cross-organization access is least-privilege by default; one organization’s administrative authority does not extend to another.
Based on the complete source HTML; the current build is explicitly updated to v0.3.0a7 for this request. Official concept artwork reused with permission. Commercial prices remain separately sourced from atalk.ai.
Community self-hosting and early hosted plans are distinct. Hosted access is at the waitlist stage; this is not a checkout page.
Own your event ledger, deployment, and operating environment.
You manage TLS, backups, and monitoring. Open source is not a managed service.
A hosted instance with the fundamentals of operations handled for you.
No commitment to HA, automatic rescue, fixed RPO/RTO, or a 99.9% SLA. Fair-use limits belong in trial-operation terms.
Everything in Starter, with additional team and operational support.
Redundancy is chosen by the hosting operator. No SLA-backed HA sale before fault-injection and recovery acceptance tests pass.
Source: atalk.ai, checked 2026-10-08. The live site lists $39 / $149 per team/month without a currency code. Price changes before the commercial release will be announced in advance. atalk.ai ↗
Hosted instances are isolated from the Gene7 family network, production ledgers, tokens, real events, and internal billing.
Multi-node HA and fault-injection acceptance, private deployment, custom adapters, migration and rollback support, and separately agreed SLA / RPO / RTO. Presence detection, rescue, and automatic recovery are a separate private module, currently in preview—not available standard-plan commitments.
Reserved for a real production report. Not unverified metrics, customer logos, or testimonials.
A production report is being prepared. These are the sections it will cover, not completed tests or achieved results.
To add: version, topology, time range, and publishable environment.
To add: received / applied records and cursor-resumption traces.
To add: known issues, drill evidence, and reviewable materials.
A signal back. A clear boundary.
ATALK / A PAGER FOR YOUR AGENTS