AI Governance Practices
Overview
Anam provides infrastructure for real-time AI avatar experiences. Anam’s proprietary CARA avatar models generate the visual output of a persona, including facial movement, lip-sync and expression. A session may also combine speech recognition, language-model, text-to-speech and integration components configured by Anam or by the customer. The selected configuration determines which systems process session data.
Features, providers and data flows vary by deployment. This page describes Anam’s current operating practices; the customer agreement, Data Processing Addendum and product configuration govern each customer’s use of the service.
Architecture and model ownership
CARA models: Anam develops and owns the avatar-generation models responsible for the visual face, lip-sync and expression produced from audio.
Conversation stack: customers may use Anam-managed services or connect Custom LLM, Custom TTS, speech-recognition and orchestration components. Anam does not train or own the third-party foundation models used in those components.
Provider choice: the providers and data flows used in a session depend on the persona, integration and enterprise configuration selected for that deployment.
Customer responsibilities and responsible use
Customers determine their use case, prompts, content, provider configuration and whether human review or approval is required. Customers are responsible for establishing a lawful basis for processing, providing required notices, obtaining consent—including permission to use a person’s likeness or voice for a custom avatar—and applying deployment-specific safeguards.
Anam’s Acceptable Use Policy prohibits harmful and unlawful uses. Anam also maintains security and access controls for the service. Customers should configure model guardrails and human oversight appropriate to their use case because available safety controls depend on the selected models and integration.
Training data and model development
Anam trains its proprietary CARA avatar models using data that has been legally obtained from a mixture of publicly available sources, permissibly licensed datasets and data commissioned from studios. Specific dataset composition and preparation details are proprietary and confidential.
Anam does not use customer session content to train CARA or third-party foundation models unless this is separately agreed in writing and carried out under the customer’s instructions.
Privacy, retention and deletion
Zero Data Retention (ZDR) is an optional, configuration-dependent Enterprise feature that can be enabled at persona or session level. When enabled, Anam does not persist customer session content, including transcripts, user audio, TTS text, LLM prompts and responses, or session recordings. Operational metadata needed for billing, service delivery and security may still be retained. See the ZDR documentation.
For non-ZDR sessions, recordings are retained for up to 30 days. Session reports—including transcripts, per-turn analytics, summaries and generated insights—remain available until the customer deletes them.
Customers can permanently delete the customer information captured for an ended session through DELETE /v1/sessions/{id}. This deletes the session report, generated insights, summary, recording and requester IP. The session record and usage data required for billing and aggregate reporting remain.
Regional processing
Customer-facing production inference and media are hosted on CoreWeave in Spain/EU and US East. Enterprise customers can choose an EU or US session-engine region. A strict region policy keeps engine processing in the selected region and returns an error rather than failing over; a preferred policy may fail over. See the session-region documentation.
Engine-region selection is not a blanket residency commitment for website, Lab, account, support, billing or customer-selected third-party provider processing. Contractual Data Residency is available only where expressly agreed, applies to customer session content rather than Lab assets or general account data, and requires ZDR to be enabled.
Security and compliance
Anam maintains a formal information security program with access controls, encryption, secure development practices, vulnerability management and incident-response procedures. Anam has a SOC 2 Type II report and HIPAA-aligned controls. Suitability for a regulated use case, including any Business Associate Agreement requirement, is confirmed contractually.
Security and compliance evidence is available through the Anam Trust Center.
Governance and contact
Anam assigns responsibility for AI model development, product security and compliance to appropriate internal owners. Product and policy practices are reviewed as the service, customer use cases and applicable requirements evolve.
For more information, see our Privacy Policy, Data Processing Addendum, Terms of Service and Acceptable Use Policy, or contact support@anam.ai.
© 2026 Anam Labs
SOC 2 Type II report · HIPAA-aligned controls.