tl;dv
tldv.io
Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.
- Data retention window not stated
See Before you sign, with what to ask for ↓
Scanned Oct 5, 2026 · Public evidence · Point-in-time
Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.
Before you sign
Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.
What to ask for: Get retention windows, in days, in writing.
“Video and audio recording, written transcriptions Site and application Provision of the main service, sharing and collaboration Free user: 3 months Paying user: until account deletion”
Buyer questionsanswered only from the public evidence scanned — click a row for the answer
✓Will they train on your data?Clear
The security page states that no customer data is used to train the AI.
“No customer data is used to train the AI.”
“Tldx Solutions GmbH does not use Customer Content, including meeting recordings, transcripts, notes, files, or other data processed through the Services, to train, fine-tune, or improve foundation models, large language models, or other generative AI models for the benefit of tldx Solutions GmbH or any third party. Where we use third-party AI service providers to deliver features of the Services, Customer Content is processed solely to provide the requested functionality and is not used by tldx Solutions GmbH or such providers to train or improve their general-purpose AI models.”
“Bei tl;dv sind Ihre Daten durch Ende-zu-Ende-Verschlüsselung, GDPR-Konformität und SOC 2-zertifizierte Sicherheit geschützt. Ihre Aufnahmen und Transkripte gehören Ihnen (nicht uns). Und wir werden sie niemals für das Training von KI verwenden. Niemals.”
!How long do they keep your data?Ask the vendor
Video/audio recordings and transcripts are retained for 3 months for free users and until account deletion for paying users; no post-deletion purge window is stated.
Requires written confirmation — see Before you sign ↓
“Video and audio recording, written transcriptions Site and application Provision of the main service, sharing and collaboration Free user: 3 months Paying user: until account deletion”
✓Who else can access your data?Clear
tl;dv names Anthropic as its generative AI partner and states that identifying metadata (email, company name, first and last name) is anonymised before being processed by Anthropic.
“We partner with Anthropic and have added mechanisms that keep your data safe and secure: We are anonymizing any metadata we share with Anthropic. Your e-mail address, company name, and first and last name will be anonymized before being processed.”
“All our services are hosted in Europe (within the European Economic Area) with the exception of part of our service involving artificial intelligence, depending on your choice of hosting location. tldx may use large language models provided by Anthropic via Google Cloud Vertex AI to generate written summaries or other derived content.”
“tl;dv hosts its software in Google Cloud Platform, Amazon Web Services (AWS) facilities and Hetzner . Google, AWS and Hetzner data centers are certified as ISO 27001, PCI DSS Service Provider Level 1, and/or SOC 1 and 2 compliant.”
“Category of subcontractor Name of the subcontractor(s) Hosting/infrastructure/storage providers Google Cloud, Hetzner, Wasabi Payment processors Stripe Analysis tool providers Mixpanel, Cloudflare, Sentry Customer support tool providers Intercom, Sentry Marketing and email tool providers CustomerIO, Gmail Internal communication tool providers Slack, Gmail”
“Artificial Intelligence provider Anthropic, Google Vertex Human Resources tool provider Deel Sales tool provider, customer tracking (CRM) Hubspot Platform-as-a-Service provider used to build, manage, and operate customer-authorized integrations with third-party applications Paragon Transcription provider AssemblyAI, ElevenLabs”
✓Where is your data processed?Clear
Customers can choose whether the AI processing is hosted in Europe or the US; the security page also advertises privately hosted AI on request.
“You have full sovereignty over the data that you record. To further enhance this control, you can now choose where your AI is hosted –Europe or the US– ensuring compliance with regional data protection standards.”
“For the purpose of providing the requested AI-powered features, in accordance with applicable data protection laws and the safeguards described in this Privacy Policy, limited portions of meeting transcripts may be processed either: within the European Union (e.g. Google Cloud regions located in the EU), or within the United States of America depending on the AI hosting location that you select in your account’s preferences .”
“Data is stored and protected by restricted security groups in S3 on Wasabi servers and processed in our private Google Cloud Platform (GCP) data centers and our own & dedicated servers on Hetzner. All our data centers are located in Europe.”
“We have ensured that appropriate guarantees are in place for these transfers, namely the use of standard data protection clauses adopted or approved by the European Commission.”
!What happens in a security incident?Ask the vendor
A published vulnerability disclosure contact exists and the security team commits to respond within 24 hours.
Confirm in writing: Ask the vendor to state this in writing before signing.
“If you have discovered a privacy or security issue that we should address, please always let us know at [email protected] . Our security team will respond within 24 hours.”
“Finally, when a personal data breach likely to create a high risk for your rights and freedoms is detected, you will be informed of this breach as soon as possible.”
Email to send the vendor6 items to confirm in writing
Hello tl;dv team, We are assessing tl;dv as part of our supplier review. Before we proceed, please confirm the following in writing: 1. How long do you retain our data, in days, for each type (inputs, outputs, logs and backups), and how is it deleted? 2. What is your commitment to notify customers of a security incident affecting our data, including the timeframe? 3. Please share the current SOC 2 Type II report (auditor, period, in-scope systems). Which EU-US transfer mechanism do you actually rely on, and why does the security page still display a Privacy Shield badge? What is the basis for the 'EU AI Act compliant' assertion (role classification, risk category, any conformity assessment)? 4. How do you evaluate transcription and summary accuracy and the sales coaching scores (metrics, test sets, languages)? Is there human review or a customer-facing accuracy disclosure, and how are AI outputs used in performance reviews constrained? 5. Is AWS currently a subprocessor, and if so in what role and region? Please confirm the authoritative subprocessor list and change-notification process. What exactly does 'end-to-end encryption' mean in your architecture given third-party AI and transcription processing? 6. What is the deletion window for recordings, transcripts and backups after account deletion? What processor breach-notification commitment do you give to business customers (timeframe, threshold)? How are changes to AI providers, models or hosting regions communicated to customers in advance? A written reply to each point, or a link to where it is documented, is enough. Where a point is covered by a certification or independent report, please include the certificate number or the report and its date. Thank you,
Key findingsclick a row for the evidence
✓Clear, repeated no-training commitment with a named AI provider and data-minimisation safeguardsStrong
Three separate documents (security page, privacy policy section 9, marketing page) state that customer recordings and transcripts are not used to train or improve AI models, and the privacy policy extends the commitment to third-party providers. The generative AI provider (Anthropic, consumed via Google Cloud Vertex AI) and transcription providers (AssemblyAI, ElevenLabs) are named in a public subprocessor table, metadata is anonymised and meetings are chunked and shuffled before reaching the LLM provider, and customers can choose EU or US AI hosting.
This is the level of disclosure a buyer needs to answer the training, recipients and location questions without a questionnaire round-trip. The chunking approach is unusual and specific, which lends credibility beyond a boilerplate statement.
“We partner with Anthropic and have added mechanisms that keep your data safe and secure: We are anonymizing any metadata we share with Anthropic. Your e-mail address, company name, and first and last name will be anonymized before being processed.”
“All our services are hosted in Europe (within the European Economic Area) with the exception of part of our service involving artificial intelligence, depending on your choice of hosting location. tldx may use large language models provided by Anthropic via Google Cloud Vertex AI to generate written summaries or other derived content.”
“You have full sovereignty over the data that you record. To further enhance this control, you can now choose where your AI is hosted –Europe or the US– ensuring compliance with regional data protection standards.”
“We are chunking your meetings into small pieces and randomizing the sequence order with Anthropic . Anthropic will never be able to access more than a short sequence of your meeting at once and also not be able to know which segments belong to the same meeting.”
“No customer data is used to train the AI.”
“Tldx Solutions GmbH does not use Customer Content, including meeting recordings, transcripts, notes, files, or other data processed through the Services, to train, fine-tune, or improve foundation models, large language models, or other generative AI models for the benefit of tldx Solutions GmbH or any third party. Where we use third-party AI service providers to deliver features of the Services, Customer Content is processed solely to provide the requested functionality and is not used by tldx Solutions GmbH or such providers to train or improve their general-purpose AI models.”
“Bei tl;dv sind Ihre Daten durch Ende-zu-Ende-Verschlüsselung, GDPR-Konformität und SOC 2-zertifizierte Sicherheit geschützt. Ihre Aufnahmen und Transkripte gehören Ihnen (nicht uns). Und wir werden sie niemals für das Training von KI verwenden. Niemals.”
“Artificial Intelligence provider Anthropic, Google Vertex Human Resources tool provider Deel Sales tool provider, customer tracking (CRM) Hubspot Platform-as-a-Service provider used to build, manage, and operate customer-authorized integrations with third-party applications Paragon Transcription provider AssemblyAI, ElevenLabs”
!SOC 2 Type II is NDA-gated; trust badges include a defunct framework and an unverifiable EU AI Act claimGap
tl;dv claims a SOC 2 Type II report (security, privacy, availability, confidentiality) via a Vanta trust report and NDA link, but auditor, period and system boundary are not public, so it is vendor-claimed only. The badge row also shows 'EU US PRIVACY SHIELD', a framework invalidated in 2020 that the privacy policy itself does not rely on (it cites SCCs), and 'EU AI ACT COMPLIANT' with no explanation. The ISO 27001 and PCI DSS references belong to the hosting providers' data centres, not to tl;dv.
A stale or inaccurate badge on the security page undermines confidence in the other badges. Buyers should rely on the SOC 2 report itself, not the page, and should not read ISO 27001 as a tl;dv certification.
Question for vendor: Please share the current SOC 2 Type II report (auditor, period, in-scope systems). Which EU-US transfer mechanism do you actually rely on, and why does the security page still display a Privacy Shield badge? What is the basis for the 'EU AI Act compliant' assertion (role classification, risk category, any conformity assessment)?
“tl;dv is SOC2 compliant. Our SOC 2 (Type II) shows our commitment towards a continuous effective build and improvement of our system and organization controls regarding security, privacy, availability, and confidentiality. This report explains the extreme care we take to earn and maintain our users’ trust in tl;dv, its systems, and product. Request your report here.”
“Access our Vanta Trust Report NDA link for our SOC 2 SOC2 COMPLIANT GDPR COMPLIANT HOSTED AND STORED IN THE EU PRIVATELY HOSTED AI ON REQUEST EU US PRIVACY SHIELD EU AI ACT COMPLIANT”
“tl;dv hosts its software in Google Cloud Platform, Amazon Web Services (AWS) facilities and Hetzner . Google, AWS and Hetzner data centers are certified as ISO 27001, PCI DSS Service Provider Level 1, and/or SOC 1 and 2 compliant.”
“We have ensured that appropriate guarantees are in place for these transfers, namely the use of standard data protection clauses adopted or approved by the European Commission.”
!No AI testing, evaluation or accuracy disclosure, despite performance-scoring featuresGap
testing_and_evaluation is marked not_evidenced, not not_applicable: this is a hosted AI product that summarises meetings and, in the sales offering, scores how representatives handle objections, so evaluation evidence is owed and could be supplied. The only relevant statement is a marketing assertion that structured workflows avoid hallucinations; no accuracy metrics, transcription or summary quality benchmarks, bias testing or human-review process are published. None of the ten domains were marked not_applicable, because all of them arise for a hosted meeting-recorder SaaS.
Summaries and scores feed CRMs and manager decisions about staff. Without published evaluation, buyers cannot judge error rates or fairness of AI-derived performance insights, and employee-monitoring uses may attract works council or regulator scrutiny in the EU.
Question for vendor: How do you evaluate transcription and summary accuracy and the sales coaching scores (metrics, test sets, languages)? Is there human review or a customer-facing accuracy disclosure, and how are AI outputs used in performance reviews constrained?
“Arbeit und Halluzinationen passen nicht gut zusammen. tl;dv schafft ein Gleichgewicht zwischen Flexibilität und strukturierten Arbeitsabläufen und gewährleistet so verwertbare Ergebnisse ohne unnötige Komplexität.”
“Unsere KI beobachtet, wie Ihre Leitfäden umgesetzt werden und bewertet den Umgang mit Einwänden. Sie bietet Managern Einblicke, die helfen die Leistung im Vertrieb zu steigern.”
“Die KI-Meeting-Agenten von tl;dvautomatisieren die Aufzeichnung, Transkription, Zusammenfassung und Integration in Tools wie CRMs und Produktivitätsplattformen.”
!Hosting and encryption statements do not line up across pagesGap
The security page names AWS as a hosting facility, but the privacy policy's subprocessor table lists only Google Cloud, Hetzner and Wasabi for hosting/storage. Marketing pages claim 'end-to-end encryption', while the security page describes TLS in transit and AES-256 at rest and the privacy policy confirms transcript portions are processed by Anthropic and transcription providers, which is incompatible with end-to-end encryption in the usual sense.
A subprocessor list that omits a named host cannot be relied on as complete, and an inaccurate encryption claim can mislead a buyer's data-flow assessment.
Question for vendor: Is AWS currently a subprocessor, and if so in what role and region? Please confirm the authoritative subprocessor list and change-notification process. What exactly does 'end-to-end encryption' mean in your architecture given third-party AI and transcription processing?
“tl;dv hosts its software in Google Cloud Platform, Amazon Web Services (AWS) facilities and Hetzner . Google, AWS and Hetzner data centers are certified as ISO 27001, PCI DSS Service Provider Level 1, and/or SOC 1 and 2 compliant.”
“Category of subcontractor Name of the subcontractor(s) Hosting/infrastructure/storage providers Google Cloud, Hetzner, Wasabi Payment processors Stripe Analysis tool providers Mixpanel, Cloudflare, Sentry Customer support tool providers Intercom, Sentry Marketing and email tool providers CustomerIO, Gmail Internal communication tool providers Slack, Gmail”
“Artificial Intelligence provider Anthropic, Google Vertex Human Resources tool provider Deel Sales tool provider, customer tracking (CRM) Hubspot Platform-as-a-Service provider used to build, manage, and operate customer-authorized integrations with third-party applications Paragon Transcription provider AssemblyAI, ElevenLabs”
“Bei tl;dv sind Ihre Daten durch Ende-zu-Ende-Verschlüsselung, GDPR-Konformität und SOC 2-zertifizierte Sicherheit geschützt. Ihre Aufnahmen und Transkripte gehören Ihnen (nicht uns). Und wir werden sie niemals für das Training von KI verwenden. Niemals.”
“Data is stored and protected by restricted security groups in S3 on Wasabi servers and processed in our private Google Cloud Platform (GCP) data centers and our own & dedicated servers on Hetzner. All our data centers are located in Europe.”
!Retention tied to account lifetime, high-risk-only breach notice, and weak change-notice commitmentsGap
Paying users' recordings and transcripts are kept until account deletion with no stated purge window afterwards; free users' content is kept 3 months. Breach notification to data subjects is promised only for high-risk breaches and 'as soon as possible', with no customer-as-controller commitment or timeframe. The Terms commit only to 'try' to give notice of material changes, and nothing addresses notice of AI model or provider changes.
Enterprise buyers typically need a defined deletion window, 72-hour-style processor breach notification, and advance notice when the AI provider or model changes. These are DPA-level commitments that the public documents do not make.
Question for vendor: What is the deletion window for recordings, transcripts and backups after account deletion? What processor breach-notification commitment do you give to business customers (timeframe, threshold)? How are changes to AI providers, models or hosting regions communicated to customers in advance?
“Video and audio recording, written transcriptions Site and application Provision of the main service, sharing and collaboration Free user: 3 months Paying user: until account deletion”
“Finally, when a personal data breach likely to create a high risk for your rights and freedoms is detected, you will be informed of this breach as soon as possible.”
“We may suspend or discontinue any part of the Services, or we may introduce new features or impose limits on certain features or restrict access to parts or all of the Services. We’ll try to give you notice when we make a material change to the Services that would adversely affect you, but this isn’t always practical.”
“Code development follows a standardized process. All code changes are reviewed for security and extensively tested prior to deployment into production. tl;dv development and testing environments are separate from the production environment.”
Assurance dimensionsweighted components of one score — not eight separate ratings
Organisation & AI governance15% of the score40
Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.
Assessed against ISO 42001 · NIST AI RMF · AIUC-1
“The Data Controller is Tldx Solutions GmbH, headquartered at Tldx Solutions GmbH, Kaiser-Friedrich-Allee 51, 52074 – AACHEN, GERMANY registered under number HRB 23730 of the commercial register of the following jurisdiction: Amtsgericht Aachen, represented by its President Mr. Raphaël ALLSTADT.”
“For any information or exercise of your Information Technology and Civil Liberties rights on personal data processing, you can contact our data protection officer (DPO):”
“To further guarantee our GDPR compliance, our team maintains an internal record of data processing activities to document how we process personal data for each of our products.”
“Furthermore, we apply the need-to-know principle regarding access given to employees, agents, subcontractors, and other third parties who may process your data . These parties will only process your personal data on our instructions and are subject to a duty of confidentiality .”
AI system15% of the score33
What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.
Assessed against ISO 42001 · NIST AI RMF
“Die KI-Meeting-Agenten von tl;dvautomatisieren die Aufzeichnung, Transkription, Zusammenfassung und Integration in Tools wie CRMs und Produktivitätsplattformen.”
“tl;dv bietet KI-Agenten-Workflows , die auf modularen KI-Bausteinen aufgebaut sind und Aufgaben wie Aufzeichnung, Transkription, Zusammenfassung und Integrationen übernehmen.”
“Arbeit und Halluzinationen passen nicht gut zusammen. tl;dv schafft ein Gleichgewicht zwischen Flexibilität und strukturierten Arbeitsabläufen und gewährleistet so verwertbare Ergebnisse ohne unnötige Komplexität.”
“Unsere KI beobachtet, wie Ihre Leitfäden umgesetzt werden und bewertet den Umgang mit Einwänden. Sie bietet Managern Einblicke, die helfen die Leistung im Vertrieb zu steigern.”
How AI features are evaluated before and after release — evals, red-teaming, monitoring.
Assessed against NIST GenAI · NIST AI RMF · ISO 42001
“Arbeit und Halluzinationen passen nicht gut zusammen. tl;dv schafft ein Gleichgewicht zwischen Flexibilität und strukturierten Arbeitsabläufen und gewährleistet so verwertbare Ergebnisse ohne unnötige Komplexität.”
How changes to models and AI features are controlled and communicated — versioning, notice, rollback.
Assessed against ISO 27001 · ISO 42001
“Code development follows a standardized process. All code changes are reviewed for security and extensively tested prior to deployment into production. tl;dv development and testing environments are separate from the production environment.”
“We may suspend or discontinue any part of the Services, or we may introduce new features or impose limits on certain features or restrict access to parts or all of the Services. We’ll try to give you notice when we make a material change to the Services that would adversely affect you, but this isn’t always practical.”
AI system description: vendor-evidenced, not yet independently corroborated.
Testing & evaluation: not publicly evidenced.
Model10% of the score60
Which model providers and versions process customer data, and how changes to them are disclosed.
Assessed against NIST GenAI · ISO 42001
“We partner with Anthropic and have added mechanisms that keep your data safe and secure: We are anonymizing any metadata we share with Anthropic. Your e-mail address, company name, and first and last name will be anonymized before being processed.”
“All our services are hosted in Europe (within the European Economic Area) with the exception of part of our service involving artificial intelligence, depending on your choice of hosting location. tldx may use large language models provided by Anthropic via Google Cloud Vertex AI to generate written summaries or other derived content.”
“You have full sovereignty over the data that you record. To further enhance this control, you can now choose where your AI is hosted –Europe or the US– ensuring compliance with regional data protection standards.”
Model provider transparency: vendor-evidenced, not yet independently corroborated.
Customer data15% of the score60
Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.
Assessed against ISO 27018 · OAIC APPs · EU AI Act
“We are chunking your meetings into small pieces and randomizing the sequence order with Anthropic . Anthropic will never be able to access more than a short sequence of your meeting at once and also not be able to know which segments belong to the same meeting.”
“No customer data is used to train the AI.”
“Tldx Solutions GmbH does not use Customer Content, including meeting recordings, transcripts, notes, files, or other data processed through the Services, to train, fine-tune, or improve foundation models, large language models, or other generative AI models for the benefit of tldx Solutions GmbH or any third party. Where we use third-party AI service providers to deliver features of the Services, Customer Content is processed solely to provide the requested functionality and is not used by tldx Solutions GmbH or such providers to train or improve their general-purpose AI models.”
“Video and audio recording, written transcriptions Site and application Provision of the main service, sharing and collaboration Free user: 3 months Paying user: until account deletion”
“Tldx Solutions GmbH does not access your recordings and transcriptions at any time, unless you personally share access with individual employees for technical assistance . Even in this case, only the recordings and transcriptions for which access rights have been granted to the support team member will be accessible.”
“For the purpose of providing the requested AI-powered features, in accordance with applicable data protection laws and the safeguards described in this Privacy Policy, limited portions of meeting transcripts may be processed either: within the European Union (e.g. Google Cloud regions located in the EU), or within the United States of America depending on the AI hosting location that you select in your account’s preferences .”
“Data is stored and protected by restricted security groups in S3 on Wasabi servers and processed in our private Google Cloud Platform (GCP) data centers and our own & dedicated servers on Hetzner. All our data centers are located in Europe.”
“Bei tl;dv sind Ihre Daten durch Ende-zu-Ende-Verschlüsselung, GDPR-Konformität und SOC 2-zertifizierte Sicherheit geschützt. Ihre Aufnahmen und Transkripte gehören Ihnen (nicht uns). Und wir werden sie niemals für das Training von KI verwenden. Niemals.”
Customer data treatment: vendor-evidenced, not yet independently corroborated.
AI supply chain10% of the score60
The named chain of AI and infrastructure providers behind the product, and how it is disclosed.
Assessed against ISO 27001 · ISO 27017
“tl;dv hosts its software in Google Cloud Platform, Amazon Web Services (AWS) facilities and Hetzner . Google, AWS and Hetzner data centers are certified as ISO 27001, PCI DSS Service Provider Level 1, and/or SOC 1 and 2 compliant.”
“Category of subcontractor Name of the subcontractor(s) Hosting/infrastructure/storage providers Google Cloud, Hetzner, Wasabi Payment processors Stripe Analysis tool providers Mixpanel, Cloudflare, Sentry Customer support tool providers Intercom, Sentry Marketing and email tool providers CustomerIO, Gmail Internal communication tool providers Slack, Gmail”
“Artificial Intelligence provider Anthropic, Google Vertex Human Resources tool provider Deel Sales tool provider, customer tracking (CRM) Hubspot Platform-as-a-Service provider used to build, manage, and operate customer-authorized integrations with third-party applications Paragon Transcription provider AssemblyAI, ElevenLabs”
Subprocessors & supply chain: vendor-evidenced, not yet independently corroborated.
Security foundation15% of the score45
How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.
Assessed against ISO 27001 · NIST AI RMF
“If you have discovered a privacy or security issue that we should address, please always let us know at [email protected] . Our security team will respond within 24 hours.”
“tl;dv regularly scans production infrastructure, applications, and networks for vulnerabilities using off-the-shelf tools to identify potential vulnerabilities.”
“Finally, when a personal data breach likely to create a high risk for your rights and freedoms is detected, you will be informed of this breach as soon as possible.”
Independent assurance evidence10% of the score35
Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.
Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008
“tl;dv is SOC2 compliant. Our SOC 2 (Type II) shows our commitment towards a continuous effective build and improvement of our system and organization controls regarding security, privacy, availability, and confidentiality. This report explains the extreme care we take to earn and maintain our users’ trust in tl;dv, its systems, and product. Request your report here.”
“Access our Vanta Trust Report NDA link for our SOC 2 SOC2 COMPLIANT GDPR COMPLIANT HOSTED AND STORED IN THE EU PRIVATELY HOSTED AI ON REQUEST EU US PRIVACY SHIELD EU AI ACT COMPLIANT”
None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.
Legal & contractual10% of the score60
The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.
Assessed against EU AI Act · OAIC APPs
“As you are using tldx to record meetings, you are responsible for collecting consents from all participants in the meeting prior to starting the recording. Participants have the option to leave the meeting. The transcript, which may also contain personal data, is treated the same way as the video recording. Video recordings and transcripts will not be accessed by tldx, unless upon specific request by the user who created such recordings with tldx.”
“In any event, tldx’s total liability shall not exceed the amount paid by you for the Service during the last 12 months prior to the incident that causes the liability.”
“We have ensured that appropriate guarantees are in place for these transfers, namely the use of standard data protection clauses adopted or approved by the European Commission.”
Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.
Not graded: Agent — not applicable to this scan.
What would strengthen assuranceeach figure is from today's score — resolving one changes the others
Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 48 → up to 71 with every identified gap resolved.
AI supply chainclick a node to focus it · drag to pan · zoom with the controls
View as list
What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0
This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.
Map your inherited responsibilitiesAssurance evidence: certifications 2 — registry checks and verification ladders, click to view
Vendor states the report covers security, privacy, availability and confidentiality; auditor, report period and system boundary are not published. Report available on request under NDA via a Vanta trust report.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.
Sources 12 — click to view
Appendix: standards landscape 8 — click to view
Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.
Want to go further?
This scan assesses tl;dv at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.
Scan a specific product →This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.
Monitor for changes
Get an email if its TRUSTYCYBER Score, grade or certifications change. One credit per refresh; reading the report always stays free.
