Security
What a first security review needs: how Anarlog stores meeting data, who can see it, how long it is kept, and which documents we can send today. Fastrepl does not claim SOC 2, ISO 27001, or HIPAA here.
Last updated August 29, 2026
Architecture
Local-first by default. Cloud features are optional and named. Nothing in the default product joins a meeting as a participant.
01
Employee devices
Canonical notes, transcripts, recordings, and most settings live in local SQLite. The MIT-licensed desktop client is auditable.
02
Optional Cloud Sync
End-to-end encrypted replicas so other signed-in devices stay current. Fastrepl cannot read the recovery key or the note content.
03
Optional AI and transcription
On-device models, bring-your-own keys, or Anarlog Cloud. Content goes only to the provider the user selected for that request.
04
Optional sharing and Cloud API
A server-readable copy exists only when someone shares a note or turns on Cloud API & Connectors. Turning the API off deletes those copies.
Security review answers
- How is meeting content encrypted?
- The desktop app stores notes, transcripts, and meeting metadata in a local SQLite database. Optional Cloud Sync encrypts that content on the device with keys derived from a recovery key that stays in the operating-system keychain and never reaches Fastrepl. Sync servers see encrypted records plus account and workspace identifiers, timestamps, sizes, and device names — not titles or note content. Data in transit uses HTTPS/TLS. Shared notes and Cloud API & Connectors are separate, opt-in paths that store a server-readable copy so a recipient or agent can open the note.
- Where does data live, and which jurisdiction applies?
- Local notes never leave the device unless a user enables a cloud feature. Fastrepl-operated cloud — accounts, optional Cloud Sync ciphertext, shared notes, and hosted AI/transcription gateways — currently runs in the United States. Customer-hosted capture and a customer-controlled data plane are the way to keep meeting infrastructure in a region you choose. We do not offer a certified-cloud EU SKU today.
- How long do you keep data?
- Local notes, transcripts, and recordings stay on the device until the user removes them. Audio retention on the desktop is a user setting (don't save, 1 day, 3 days, 1 week, 1 month, or forever). Cloud Sync records, transcription results, shared notes, and Cloud API copies are deleted within 30 days of account deletion unless the law requires a longer hold. Audio uploaded for cloud transcription is deleted from our storage once the job completes. Cloud API copies are deleted when the feature is turned off. Shared notes remain available until sharing stops or the account is deleted.
- Do you train models on our meetings?
- Fastrepl does not use notes, transcripts, audio, or connected calendar data to train AI models, and we do not sell that data. If a team uses on-device transcription and a local language model, meeting content never leaves the device for AI. If they use Anarlog Cloud or a bring-your-own-key provider, the audio or text needed for that request goes to the selected provider under that provider's terms — review that provider's retention and training policy before sending sensitive meetings.
- Who are your subprocessors?
- The current processor list lives in the table below and in the privacy policy. Providers receive only what the enabled feature needs. Cloud Sync storage holds ciphertext. Speech-to-text and model providers receive content only when a user selects a hosted or bring-your-own-key route. Analytics and error tools are designed not to include meeting audio, transcripts, notes, or summaries.
- Does a bot join our calls?
- Anarlog does not send a meeting bot into Zoom, Google Meet, Microsoft Teams, or other calls. Capture happens on the desktop from microphone and system audio. That is the product, not a setting. Customer-hosted Meet or Zoom workers, when used by an enterprise pilot, are a separate capture path and are disclosed as such — they are not the default desktop product.
Subprocessors
Grounded in the privacy policy. A processor receives data only when the matching feature is enabled.
| Processor | Purpose | What they can receive |
|---|---|---|
| Fly.io, Netlify, Supabase, Render, Amazon Web Services, Cloudflare | Hosting, authentication, storage, and downloads | Account data, operational metadata, and any server-side records created by an enabled cloud feature |
| SQLite Cloud | Cloud Sync storage | End-to-end encrypted sync records plus operational metadata |
| Nango | Calendar and connected-account integrations | Encrypted OAuth tokens and the calendar or issue-tracker data needed for a connected feature |
| Stripe | Payments | Billing details; Fastrepl never stores card numbers |
| PostHog, Google Analytics, Microsoft Clarity | Product and website analytics | Pseudonymous usage events, page views, and optional website session replay — not meeting audio, transcripts, notes, or summaries |
| Sentry, Honeycomb | Error monitoring and observability | Sanitized diagnostics and crash reports with meeting content stripped |
| Deepgram, Soniox, AssemblyAI, Gladia, ElevenLabs, Fireworks AI, OpenAI, Mistral, Alibaba Cloud | Optional cloud transcription | Audio for a transcription job when a user selects a hosted speech-to-text route |
| OpenRouter, routing to providers such as Anthropic, Google, and Mistral | Optional cloud AI | The text and instructions needed for a summary or chat request the user starts |
| Exa, Jina | Optional web search from AI chat | Search queries when a user enables web search in chat |
| Loops | Email address and the content of transactional or marketing messages |
Retention
| Data | Kept until |
|---|---|
| Local notes, transcripts, and recordings | On the device until the user deletes them |
| Desktop audio files | User-selected: don't save, 1 day, 3 days, 1 week, 1 month, or forever |
| Cloud Sync, transcription results, shared notes, Cloud API copies | Deleted within 30 days of account deletion, unless the law requires a hold |
| Audio uploaded for cloud transcription | Deleted from Fastrepl storage when the job completes |
| Cloud API & Connectors copies | Deleted when the feature is turned off |
Certifications and contracts
SOC 2, ISO 27001, AIUC-1, and HIPAA/BAA programs are planned after we have operational evidence. This page does not claim any of them. A hosted trust center — the Vanta or Oneleet surface buyers expect — comes after those programs start. It will be a separate site, not this page.
- Privacy PolicyWhat we collect, local-first defaults, and processor list
- Terms of ServiceContract for using Anarlog
- Data Processing AddendumAvailable on request for enterprise evaluations
Incident response
Report a vulnerability privately — do not open a public GitHub issue. We acknowledge reports within 3 business days, keep you updated while we investigate, and credit you in the release notes if the report is accepted unless you prefer to stay anonymous.
What ships, and how a pilot works
Ships today
- Desktop app on macOS, with Windows and Linux in beta
- Bot-free local capture from microphone and system audio
- Local SQLite as the source of truth, plus Markdown and other exports
- On-device transcription and local models, or bring-your-own API keys
- Optional end-to-end encrypted Cloud Sync
- Optional sharing and Cloud API & Connectors, each with a distinct data path
With early partners
- Team workspaces, domain SSO, and SCIM provisioning
- Org-wide sharing, retention, and consent policies
- Customer-hosted capture and a customer-controlled data plane
We work directly with early enterprise partners. We will only publish a named or properly anonymized outcome after that partner approves the company context, constraint, deployment mode, and result. This page does not invent metrics or logos.
- 1
Security review
Forward this site to IT, security, and legal. The security page, privacy policy, and source-visible client are the packet. We answer questionnaires from the same facts — we will not invent certifications.
- 2
Scoped pilot
A founder-led trial with a named team, a defined data boundary (local-only, encrypted sync, or customer-hosted capture), and a success check you choose. No SDR queue.
- 3
Rollout
Expand seats and policies after the pilot. Workspace admin, SSO/SCIM, or a customer-hosted data plane land with the teams that need them — not as a surprise bot in every meeting.
Request the packet
Book a founder call, or email founders@anarlog.so for a DPA and questionnaire responses grounded in this page.