generated: '2026-08-11' method: searched source: https://tadeus.net/trust derived_from: - openapi/tadeus-api-integration-openapi.json - conventions/tadeus-api-conventions.yml summary: >- Tadeus' conformance posture is almost entirely REGULATORY rather than technical. It publishes an unusually deep, versioned, dated EU AI Act compliance library — including its own self-classification and an Article 13 Instructions for Use — and makes that its lead differentiator. On the API-standards side it conforms to very little: no RFC 9457, no OAuth 2.0, no OIDC, no RFC 9116 security.txt, no RFC 8594 deprecation signalling, and the spec is Swagger 2.0 rather than OpenAPI 3.x. standards: - id: openapi conforms: partial version: swagger-2.0 evidence: >- https://app.tadeus.net/api/integration/v1/swagger/?format=openapi returns a valid Swagger 2.0 document with 31 paths and 47 operations, served as application/openapi+json. It is auto-generated by drf-yasg: every operation has a unique operationId and a tag, but NO operation has a summary or description, and no operation declares any 4xx/5xx response or any example. gap: >- Swagger 2.0 has been superseded since 2017. Upgrading to OpenAPI 3.1 and adding summaries, descriptions, error responses and examples is the single highest-value contract improvement available. - id: rfc9457 name: Problem Details for HTTP APIs conforms: false evidence: >- Errors return the Django REST Framework {"detail": "..."} envelope as application/json. No application/problem+json anywhere. - id: oauth2 conforms: false evidence: >- No oauth2 securityScheme in the spec; two apiKey header schemes only. /.well-known/oauth-authorization-server returns 403. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 403 on every host. - id: sso-saml conforms: partial evidence: >- "SSO, SAML & EU data residency" is listed as an Enterprise-tier entitlement at https://tadeus.net/#pricing. No SAML metadata or configuration documentation is public, and it does not apply to the API surface. - id: rfc9116 name: security.txt conforms: false evidence: /.well-known/security.txt returns 403 on all three hosts. - id: rfc8594 name: Sunset header conforms: false evidence: No Sunset or Deprecation header observed; no deprecation policy published. - id: pagination conforms: true style: page-number evidence: >- DRF page-number pagination with a count/next/previous/results envelope; a `page` query parameter is declared on every list operation in the spec. - id: idempotency conforms: false evidence: >- No Idempotency-Key header or equivalent anywhere in the spec or documentation, on an API whose POSTs send invitations to real people and start billed jobs. - id: json-api conforms: false - id: rest conforms: true evidence: >- Resource-oriented paths, correct verb usage across GET/POST/PUT/PATCH/DELETE, 201 on create and 204 on delete. - id: mcp name: Model Context Protocol conforms: partial evidence: >- A hosted MCP server is live at https://app.tadeus.net/mcp and Tadeus describes itself as "MCP-native" (https://tadeus.net/blog/tadeus-out-of-beta-mcp-launch, 2026-07-14). It answers JSON-RPC POSTs with a 401 auth challenge. gap: >- Authenticates with the proprietary api_key_id/api_secret pair rather than the MCP OAuth flow, and publishes no /.well-known/oauth-protected-resource, so an MCP client cannot discover the auth requirement programmatically. - id: a2a name: Agent2Agent conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json both return 403 on all three hosts. No agent card is published. - id: llmstxt conforms: true evidence: >- https://tadeus.net/llms.txt and https://app.tadeus.net/llms.txt both return 200 with real, well-formed llms.txt documents. The root one is a curated index that explicitly states its own purpose and points at the compliance library; it also advertises that every compliance document is served as plain markdown at its URL + ".md" (verified: https://tadeus.net/trust/instructions-for-use.md returns 200). regulatory: - id: eu-ai-act name: EU AI Act (Regulation 2024/1689) conforms: claimed posture: published-self-classification evidence: https://tadeus.net/trust documents: - title: How Tadeus Classifies Itself Under the EU AI Act type: Self-classification version: '1.2' reviewed: '2026-07-15' url: https://tadeus.net/trust/how-tadeus-classifies-itself markdown: https://tadeus.net/trust/how-tadeus-classifies-itself.md - title: Tadeus Instructions for Use (Article 13) type: Instructions for use version: '1.1' reviewed: '2026-07-15' url: https://tadeus.net/trust/instructions-for-use markdown: https://tadeus.net/trust/instructions-for-use.md - title: The EU AI Act Classification Framework for Workforce AI type: Framework version: '1.1' reviewed: '2026-07-11' url: https://tadeus.net/trust/classification-framework - title: EU AI Act Classification Memo Template type: Template version: '1.1' reviewed: '2026-07-11' url: https://tadeus.net/trust/classification-framework#memo-template key_claims: - >- Article 5(1)(f) — the workplace emotion-inference prohibition, in force since 2025-02-02 — is addressed by design: Tadeus states it works from the transcript, not the voice; retains no audio; runs no emotion inference; and reports comprehension and engagement signals about RESPONSES rather than profiles of people. - >- Article 50 transparency (applies 2026-08-02) is treated as a per-person timestamped disclosure record rather than a configuration setting. - >- Annex III point 4 high-risk status (applies 2027-12-02) is argued to be avoided by aggregate-only output, with named "drift triggers" that would change the classification. note: >- These are the provider's published positions, recorded as claims. API Evangelist has not audited them. - id: gdpr conforms: claimed evidence: >- "GDPR-aligned · We do not train models on your data · Data encrypted in transit and at rest" (https://tadeus.net/). EU data residency is an Enterprise entitlement. Analytics is PostHog EU with consent gating. - id: dpa conforms: partial evidence: A DPA is named as an Enterprise-tier entitlement; no DPA template is published. certifications: audited: [] note: >- NO third-party security certification is claimed anywhere on the site — no SOC 2, no ISO 27001, no ISO 42001, no HIPAA, no FedRAMP, no PCI. The Enterprise tier offers a "security review", which is a buyer-run process, not an attestation. For a vendor whose entire pitch is regulated-workplace deployment, the compliance depth is real but is 100% self-published and 0% independently audited. provider_gaps: - Migrate the contract from Swagger 2.0 to OpenAPI 3.1. - Adopt RFC 9457 problem details and declare error responses. - Publish an RFC 9116 security.txt (currently 403 at the edge). - >- Pair the self-published EU AI Act library with a third-party attestation (ISO 27001 and/or ISO 42001) — the compliance story is the product's differentiator and is currently unaudited.