generated: '2026-08-11' method: searched source: https://tadeus.net/trust present: true name: Tadeus Trust — Compliance tools and documents url: https://tadeus.net/trust type: self-published-document-library gated: false sign_in_required: false description: >- Tadeus runs a public, ungated trust surface built entirely around the EU AI Act rather than around security certifications. It publishes versioned, dated documents with a review date on each, describes itself as "data-room style", and serves every document as plain markdown at its URL plus ".md" so machines can read it. It also ships a free, no-sign-up interactive classifier that walks a buyer through Article 5, Article 6(1), all eight Annex III categories and the Article 50 duties, and pre-fills a memo. documents: - title: How Tadeus Classifies Itself Under the EU AI Act kind: self-classification version: '1.2' reviewed: '2026-07-15' formats: [html, md] url: https://tadeus.net/trust/how-tadeus-classifies-itself markdown_url: https://tadeus.net/trust/how-tadeus-classifies-itself.md markdown_status: 200 - title: Tadeus Instructions for Use (Article 13) kind: instructions-for-use version: '1.1' reviewed: '2026-07-15' formats: [html, md] url: https://tadeus.net/trust/instructions-for-use markdown_url: https://tadeus.net/trust/instructions-for-use.md markdown_status: 200 note: Published ahead of the December 2027 obligation. - title: The EU AI Act Classification Framework for Workforce AI kind: framework version: '1.1' reviewed: '2026-07-11' url: https://tadeus.net/trust/classification-framework - title: EU AI Act Classification Memo Template kind: template version: '1.1' reviewed: '2026-07-11' formats: [md, docx] url: https://tadeus.net/trust/classification-framework#memo-template tools: - name: EU AI Act Classifier for Workforce AI version: '3.0' reviewed: '2026-07-15' url: https://tadeus.net/trust/ai-act-classifier free: true sign_up_required: false certifications: count: 0 audited: [] claimed: [] note: >- No third-party attestation of any kind is claimed — no SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS or FedRAMP. This is the defining characteristic of the Tadeus trust surface: deep regulatory documentation, zero independent audit. security_practices_claimed: source: https://tadeus.net/ claims: - No audio retained — the system works from the transcript; raw audio is never stored. - No video or facial biometrics. - Comprehension and engagement signals, not emotion inference. - Region-gated configuration so EU deployments stay clear of the AI Act line. - Data encrypted in transit and at rest. - Models are not trained on customer data. - Privacy-friendly EU-hosted analytics (PostHog), consent-gated. enterprise_tier_only: - SSO and SAML - EU data residency - DPA - SLA - security review observed_transport_posture: source: live probe 2026-08-11 https_only: true tls: TLSv1.3 hsts: false dnssec: false caa: [] spf: true dmarc: true dmarc_policy: none note: >- See security/tadeus-api-domain-security.yml. Worth reading against the trust claims: there is no HSTS, no DNSSEC, no CAA record, and DMARC is at p=none (monitor only, no enforcement) on the domain of a vendor selling into regulated workplaces. vulnerability_disclosure: present: false see: security/tadeus-api-vulnerability-disclosure.yml provider_gaps: - Obtain and publish a third-party attestation (ISO 27001 and/or ISO 42001). - Publish a vulnerability disclosure policy and a security.txt. - Move DMARC from p=none to p=quarantine or p=reject; add HSTS, CAA and DNSSEC. - Publish the DPA and SLA rather than gating them behind an Enterprise conversation. x-evidence: fetched: '2026-08-11' evidence: - url: https://tadeus.net/trust http_status: 200 - url: https://tadeus.net/trust/instructions-for-use http_status: 200 - url: https://tadeus.net/trust/instructions-for-use.md http_status: 200 - url: https://tadeus.net/trust/how-tadeus-classifies-itself.md http_status: 200