Enterprise buyers should start at the Anarlog security page. It is the public security-review packet: architecture, encryption, data location, retention, training policy, subprocessors, incident reporting, and the contracts we can send today.
A hosted trust center (Vanta, Oneleet, or similar) is a separate surface. We will publish one after SOC 2 and ISO programs start — not as a substitute for this page.
What stays true in the product
- Meeting notes live on the desktop in local SQLite unless someone enables a named cloud feature.
- Cloud Sync is end-to-end encrypted. Fastrepl cannot read the recovery key.
- Anarlog does not add a bot to Zoom, Google Meet, or Microsoft Teams.
- Fastrepl does not train models on notes, transcripts, or audio. Hosted or bring-your-own-key providers have their own terms.
See Data, privacy, and retention for the in-app settings that control audio retention, analytics, and a fully local meeting.
Documents
We do not claim SOC 2, ISO 27001, or HIPAA on these pages.
Report a vulnerability
Use private GitHub reporting or email founders@anarlog.so. See the repository security policy.
Do not open a public GitHub issue for a security vulnerability. Use private reporting so it isn’t disclosed before a fix ships.