Tadeus API · Trust Center

Tadeus Api Trust Center

Trust center

Tadeus runs a public, ungated trust surface built entirely around the EU AI Act rather than around security certifications. It publishes versioned, dated documents with a review date on each, describes itself as "data-room style", and serves every document as plain markdown at its URL plus ".md" so machines can read it. It also ships a free, no-sign-up interactive classifier that walks a buyer through Article 5, Article 6(1), all eight Annex III categories and the Article 50 duties, and pre-fills a memo.

Tadeus API maintains a public trust center documenting count, audited, claimed, and note compliance.

Voice AIResearchInterviewsWorkforceHR TechConversational AIEmployee ExperienceAI AgentsMCPEU AI ActComplianceEmployee Engagement
Trust center: https://tadeus.net/trust

Certifications & Compliance

countauditedclaimednote

Source

Trust Center

Raw ↑
generated: '2026-08-11'
method: searched
source: https://tadeus.net/trust
present: true
name: Tadeus Trust — Compliance tools and documents
url: https://tadeus.net/trust
type: self-published-document-library
gated: false
sign_in_required: false
description: >-
  Tadeus runs a public, ungated trust surface built entirely around the EU AI Act rather
  than around security certifications. It publishes versioned, dated documents with a
  review date on each, describes itself as "data-room style", and serves every document as
  plain markdown at its URL plus ".md" so machines can read it. It also ships a free,
  no-sign-up interactive classifier that walks a buyer through Article 5, Article 6(1),
  all eight Annex III categories and the Article 50 duties, and pre-fills a memo.
documents:
  - title: How Tadeus Classifies Itself Under the EU AI Act
    kind: self-classification
    version: '1.2'
    reviewed: '2026-07-15'
    formats: [html, md]
    url: https://tadeus.net/trust/how-tadeus-classifies-itself
    markdown_url: https://tadeus.net/trust/how-tadeus-classifies-itself.md
    markdown_status: 200
  - title: Tadeus Instructions for Use (Article 13)
    kind: instructions-for-use
    version: '1.1'
    reviewed: '2026-07-15'
    formats: [html, md]
    url: https://tadeus.net/trust/instructions-for-use
    markdown_url: https://tadeus.net/trust/instructions-for-use.md
    markdown_status: 200
    note: Published ahead of the December 2027 obligation.
  - title: The EU AI Act Classification Framework for Workforce AI
    kind: framework
    version: '1.1'
    reviewed: '2026-07-11'
    url: https://tadeus.net/trust/classification-framework
  - title: EU AI Act Classification Memo Template
    kind: template
    version: '1.1'
    reviewed: '2026-07-11'
    formats: [md, docx]
    url: https://tadeus.net/trust/classification-framework#memo-template
tools:
  - name: EU AI Act Classifier for Workforce AI
    version: '3.0'
    reviewed: '2026-07-15'
    url: https://tadeus.net/trust/ai-act-classifier
    free: true
    sign_up_required: false
certifications:
  count: 0
  audited: []
  claimed: []
  note: >-
    No third-party attestation of any kind is claimed — no SOC 2, ISO 27001, ISO 42001,
    HIPAA, PCI DSS or FedRAMP. This is the defining characteristic of the Tadeus trust
    surface: deep regulatory documentation, zero independent audit.
security_practices_claimed:
  source: https://tadeus.net/
  claims:
    - No audio retained — the system works from the transcript; raw audio is never stored.
    - No video or facial biometrics.
    - Comprehension and engagement signals, not emotion inference.
    - Region-gated configuration so EU deployments stay clear of the AI Act line.
    - Data encrypted in transit and at rest.
    - Models are not trained on customer data.
    - Privacy-friendly EU-hosted analytics (PostHog), consent-gated.
  enterprise_tier_only:
    - SSO and SAML
    - EU data residency
    - DPA
    - SLA
    - security review
observed_transport_posture:
  source: live probe 2026-08-11
  https_only: true
  tls: TLSv1.3
  hsts: false
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: none
  note: >-
    See security/tadeus-api-domain-security.yml. Worth reading against the trust claims:
    there is no HSTS, no DNSSEC, no CAA record, and DMARC is at p=none (monitor only, no
    enforcement) on the domain of a vendor selling into regulated workplaces.
vulnerability_disclosure:
  present: false
  see: security/tadeus-api-vulnerability-disclosure.yml
provider_gaps:
  - Obtain and publish a third-party attestation (ISO 27001 and/or ISO 42001).
  - Publish a vulnerability disclosure policy and a security.txt.
  - Move DMARC from p=none to p=quarantine or p=reject; add HSTS, CAA and DNSSEC.
  - Publish the DPA and SLA rather than gating them behind an Enterprise conversation.
x-evidence:
  fetched: '2026-08-11'
  evidence:
    - url: https://tadeus.net/trust
      http_status: 200
    - url: https://tadeus.net/trust/instructions-for-use
      http_status: 200
    - url: https://tadeus.net/trust/instructions-for-use.md
      http_status: 200
    - url: https://tadeus.net/trust/how-tadeus-classifies-itself.md
      http_status: 200