Security
Where your recordings live, what Enastro keeps, and who else sees them.
Where your recordings live
Your recordings stay in your own storage. Enastro reads them when it processes — including sending audio to our transcription provider — and by default keeps no copy of its own at rest. If you ask Enastro to keep one, it keeps it for exactly as long as you choose and no longer.
The retention window is yours to set, per source, when you connect it and at any time afterwards. Setting it to zero deletes audio as soon as processing finishes, other than a floor of 7 days Enastro holds unprocessed audio before it deletes it. Shortening it applies to audio Enastro is already holding, not only to what arrives next.
"At rest" is doing real work in that sentence, so here is the rest of it: While a recording is being processed, a working copy exists in Enastro's own storage for the duration of the run and is deleted when the run finishes. If a security review asks whether a copy of your audio ever exists in Enastro's infrastructure, the answer is yes, for the duration of a processing run, and no longer.
Audio you upload directly
Audio you upload to Enastro has no other home — Enastro holds the only copy, for exactly as long as you choose, including not at all if you would rather keep only the transcript and the analysis. Processing sends the audio to our transcription provider to be transcribed.
Uploads and webhook pushes are the one case where Enastro is the storage rather than a reader of it, so Enastro asks how long to keep them rather than assuming, there is no default that is safe to guess when the copy is the only one.
What Enastro keeps
What Enastro always keeps is the transcript and the analysis derived from it — including anything said on the call.
This is worth stating plainly rather than in a footnote: a transcript of a call is often more revealing than the recording it came from, and it is searchable. Minimising what Enastro holds is about audio; the analysis you asked for is kept.
Who else processes your audio
Transcription is performed by a third-party provider or by a self-hosted model, chosen per job. When a cloud provider is used, the audio is streamed to it to be transcribed. Which providers are available, and where they run, is visible in the product when you configure a job.
What this page does not claim
Enastro is pre-first-customer. This page describes behaviour in the software, not certifications, audits or attestations, we have none to report, and will say so here rather than imply otherwise. If you need a security review or a data-processing agreement for a procurement process, get in touch and we will answer specifically.