Six things that are true of every session.
The front page shows three jobs as they happened. This page says what made them go, one mechanism at a time — and under each one, the frame where you already saw it.
It finishes the job.
Give it a job and it comes back done. It does not stop to ask which column you meant by revenue; it opens the file and works that out, and when a step breaks mid-run it reads the error and tries again. The only interruptions are the ones with consequences: a memo across four countries is one approval, then four workers.
“Done” is checked, not claimed. When the agent says it wrote a file, Safata looks for it on your disk, with content in it, before the turn can end. That is a check that the file is there, not that every number in it is right — which is why the workbooks keep their formulas live and the research rows carry their source, so you can check the file where it lands.
Seen on the front page: case 1 (the steps), case 3 (the workers)


Your model. Your memory.
US — OpenAI · Anthropic · Google · xAI Europe — Mistral China — Moonshot · DeepSeek · Z.ai Hundreds more — via OpenRouter
Pick the model you like, and change your mind at lunch. A second opinion is a second session — a different model reading the same folder — and you keep whichever file you trust. Case 1 is exactly that on one vendor's two models; case 2 ran again four days later on another vendor's, and the receipt prints what each found.
A new model is a key, not an update. Paste the vendor's key in Settings and its models appear in the catalog, priced; tick one and it is on the session chip. With one OpenRouter key the catalog is the long tail — each maker's current flagship on a shelf, a search for the rest, and a column that says whose cloud it runs on. A model Safata has never heard of is one line in a file on your disk, because the catalog is data and yours to edit.
Every model shares one memory, and it lives on your machine. Your sessions become a local record every model can search, and none of that searching leaves your computer. Switching costs you nothing, because your thinking was never stored inside any one of them.
Seen on the front page: case 1, both rows of the receipt · case 2, again, the switch


You keep the file, not the chat.
Safata makes the things knowledge work ships: analyses, documents, spreadsheets, decks. Each one lands in the folder you were working in, in the format your colleagues already open. Nobody is sent a link to your conversation.
You read it beside the conversation while it is still being made. A workbook with every formula computed, a deck slide by slide with its speaker notes, a memo with its sources — on the canvas, the moment it lands. A CSV is shown as the bytes on disk and never evaluated: Excel strips the leading zero off a phone number on sight; Safata shows you the file.
Seen on the front page: the file beat of every case



Everything stays here, except the turn you send.
Your files, your transcripts and your memory stay where they are. What leaves is the turn you send to the model you chose, and the ledger shows it, host by host, with the price beside it. In the three cases: one host, and nothing else. The bank export and the CRM export never left the disk; the model was sent what it read from them. Connect Google Drive, Dropbox or Box and its reads appear on the same ledger; the grants are read-only.
The keys are your own, so the bill and the off switch are yours too. If I stopped building this tomorrow, nothing you made would change: every session and every deliverable is an ordinary file on your own disk, in a format the apps your colleagues use already open, and no server of mine is in the path.
Seen on the front page: the “what left the machine” line under every receipt

| What went out, 19 Sep 2026 | to | requests | anywhere else |
|---|---|---|---|
| Case 1 · the forecast, Luna then Sol | api.openai.com | 38 + 26 | nothing |
| Case 2 · the board deck | api.openai.com | 22 | nothing |
| Case 3 · the memo and its four workers | api.openai.com (the searches ride inside) | 47 | nothing |
See the plan before it runs.
- iReads happen freely.
- iiWrites get gated.
- iiiAnything leaving the machine hits the floor.
- ivDestruction always asks.
Four sentences cover everything the agent is allowed to do, so you never have to work it out from watching it. Before a job runs, one card names the files it will read and write and the spend it may reach; approve once and it works alone. Grant standing permission where you want speed, and keep the gate where you would rather have a look first.
The floor is the part no grant reaches: anything that would leave the machine asks, whatever else you have allowed. In case 3 the plan had not named the web, so the first search stopped for a card and the memo waited seven minutes on the desk. That is the floor doing its job — and a plan that should have named the web.
Seen on the front page: the first frame of every case


On your machine, it's free.
Safata as you see it here, local and on your own keys, is free for local use, at home and at work, employed or freelance. A session costs whatever your model vendor charges your own key: the three jobs on the front page cost $4.11 together, $2.83 of it the big model's ten minutes, and the rerun on Kimi K3 $1.61. I add no markup and resell nothing.
And here is the business plan, written down before there is anything to sell.
What costs money is what somebody has to run for you. One is a cloud plan: Safata hosted, for a plan fee. Model access rides on the same bill at provider prices with no markup, so the fee pays for the hosting and never for a margin on your tokens. The other is the management layer an organization needs to deploy Safata across a team, which is paid by default. The rule under both: charge for a capability somebody operates for you, never for permission to run the product you already have.
Builder
One person, a knowledge worker before this, building the agent he wanted at his own desk. The bet: a person working with an agent beats either alone.
Victor Zhang · Barcelona
victorzhang.io · LinkedIn · The Knowledge Worker
Early build
Safata is a native desktop app: small, fast, built on Tauri. It opens on a keystroke and works against your disk at disk speed; open three windows and three agents run at once, on three different models if you like.
Status An early build, signed and notarized by Apple, so it opens like any other app. If something breaks, tell me; I read every one.
Version 0.1.3, for Macs with Apple silicon on macOS 13 or later. Windows comes later, and there is no Intel Mac build. It never checks for updates, because nothing in it phones home: watch the releases page and download the next one the same way. You'll need at least one API key from a provider above; getting one takes about two minutes.