Architecture
- Notes are local Markdown files unless you explicitly enable a feature that sends or stores data remotely.
- Account and API traffic uses TLS.
- Payment card data is handled by Polar as merchant of record; Anasa does not store card numbers.
- Provider credentials are stored in the operating-system keychain.
- Optional Cloud vault sync encrypts file contents and paths on the device with XChaCha20-Poly1305 before upload. The passphrase is not sent to Anasa.
- Desktop updates are signature-verified before installation.
Operational controls
Authenticated endpoints enforce account or license ownership. Device seats and managed-AI credits are checked server-side. Dangerous AI tools require approval before execution. Account deletion removes account-owned server data and queues storage deletion for retry if the object store is temporarily unavailable.
Independent assurance
Anasa does not currently claim SOC 2 or ISO 27001 certification. No public independent penetration-test report is available. Encryption and architecture claims describe the implemented design; they are not a certification that defects cannot exist.
Report a vulnerability
Email hey@anasa.md with “Security” in the subject, the affected component, steps to reproduce, and likely impact. Do not access other people's data, disrupt the service, or publish sensitive details before we have had a reasonable opportunity to investigate.