> ## Documentation Index
> Fetch the complete documentation index at: https://docs.anarlog.so/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and procurement

> Where security, legal, and IT teams can review Anarlog's data handling, processors, and evaluation path.

Enterprise buyers should start at the [Anarlog security page](https://anarlog.so/security). It is the public security-review packet: architecture, encryption, data location, retention, training policy, subprocessors, incident reporting, and the contracts we can send today.

A hosted trust center (Vanta, Oneleet, or similar) is a separate surface. We will publish one after SOC 2 and ISO programs start — not as a substitute for this page.

## What stays true in the product

* Meeting notes live on the desktop in local SQLite unless someone enables a named cloud feature.
* Cloud Sync is end-to-end encrypted. Fastrepl cannot read the recovery key.
* Anarlog does not add a bot to Zoom, Google Meet, or Microsoft Teams.
* Fastrepl does not train models on notes, transcripts, or audio. Hosted or bring-your-own-key providers have their own terms.

See [Data, privacy, and retention](/data-and-privacy) for the in-app settings that control audio retention, analytics, and a fully local meeting.

## Documents

* [Security](https://anarlog.so/security)
* [Privacy Policy](https://anarlog.so/privacy)
* [Terms of Service](https://anarlog.so/terms)
* Data Processing Addendum: email [founders@anarlog.so](mailto:founders@anarlog.so?subject=Anarlog%20DPA)

We do not claim SOC 2, ISO 27001, or HIPAA on these pages.

## Report a vulnerability

Use [private GitHub reporting](https://github.com/fastrepl/anarlog/security/advisories/new) or email [founders@fastrepl.com](mailto:founders@fastrepl.com). Do not open a public issue. See the repository [security policy](https://github.com/fastrepl/anarlog/blob/main/SECURITY.md).
