At Anara, safeguarding your data is our highest priority. We’ve designed our platform with security and privacy at its core. Below, you’ll find information on how we protect your data, our compliance efforts, and answers to common security questions.
We encourage responsible disclosure of any security vulnerabilities. Please send reports to security@anara.com, and our team will acknowledge and investigate promptly.
We are actively working with an audit partner to achieve full SOC 2 Type 2 compliance. This ensures that Anara’s controls around security, availability, processing integrity, confidentiality, and privacy meet rigorous, industry-recognized standards.
CCPA (California Consumer Privacy Act): California residents have rights to access, delete, and opt out of the sale of their personal information. Refer to our Privacy Policy for details on exercising these rights.
Anara employs advanced language models to surface insights from your research materials.
Our data security measures include multiple layers of encryption: our primary database uses AES-256 (or equivalent) encryption for all user and application data, which is hosted in US-based data centers. Uploaded files and media are protected in encrypted object storage buckets with server-side encryption, also located in US regions. Additionally, we employ managed in-memory data stores for caching and session data, all of which remains encrypted at rest using industry-standard algorithms.
All data transmitted to and from Anara is protected using industry-standard encryption protocols. We enforce TLS 1.2 or higher across our entire infrastructure, including web app access, API calls, database connections, object storage, CDN delivery, and internal service communications. This ensures that all data remains private and secure while in transit, with automatic rejection of any non-encrypted connection attempts.
We implement strict role-based access controls (RBAC) at both the application and infrastructure levels. Only authorized personnel have the minimum permissions required to perform their jobs. Database credentials, API keys, and production secrets are stored in encrypted secret-management services with fine-grained access policies.
All Anara employees with access to production systems are required to use MFA (with hardware tokens or authenticator apps). For organizations using Anara’s Enterprise tier, we offer Single Sign-On (SSO) via SAML 2.0 or OAuth2, integrating seamlessly with popular identity providers. MFA is enforced at the identity provider level.
Can I export my project data and attachments?
Yes. You can request a data export by emailing support@anara.com. We’ll prepare a downloadable ZIP file containing all your files, folders and library data.
How do you protect my data if I share a project with teammates?
What happens if Anara experiences a data breach?
In the unlikely event of a breach, our Incident Response Team will follow our documented IR playbook—identifying and containing the threat, notifying affected parties within 72 hours (or as legally required), and providing remediation guidance. We’ll also conduct a post-mortem to improve future defenses.
Are my transcripts or summaries used to train AI models?
No third-party AI vendor is permitted to use your data for model training. We only send temporary, encrypted text snippets to transcription providers, and they delete that data within 30 days.
Do you support Single Sign-On (SSO)?
Yes. Enterprise customers can configure SSO via SAML 2.0 or OAuth2. We integrate with popular identity providers. Audit logging and MFA enforcement are available through your identity provider.
How long do you retain backups?
We keep daily-encrypted database backups for 30 days. Old backups are securely deleted via automated retention policies. For files stored in object storage, older versions remain for 30 days before permanent deletion.
Can I delete my account and all associated data?
Yes. You can delete your account at any time by going to Settings → Account → Delete Account. After confirming deletion, your data will be queued for permanent deletion and removed from all active storage immediately.
How can I report a security vulnerability?
Please email any suspected vulnerabilities to security@anara.com. Include as much detail as possible (e.g., steps to reproduce, screenshots). Our team will respond within 48 hours to acknowledge receipt and keep you informed of remediation progress.
If you have further questions or need clarification about our security practices, please reach out to our Security team at security@anara.com. We’re here to ensure that your research environment is not only powerful, but also secure and trustworthy.