tl;dv

tldv.io

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
48 / 100D
Procurement decision
Approve with conditions
1 condition outstanding
  • Data retention window not stated

See Before you sign, with what to ask for ↓

Evidence MediumFreshness CurrentVerification Partial

Scanned Oct 5, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Before you sign

Data retention window not statedCondition

Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.

What to ask for: Get retention windows, in days, in writing.

Evidence
Vendor publishedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“Video and audio recording, written transcriptions Site and application Provision of the main service, sharing and collaboration Free user: 3 months Paying user: until account deletion”

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

✓Will they train on your data?Clear

The security page states that no customer data is used to train the AI.

Evidence
Vendor publishedtl;dv Security Information ↗retrieved Oct 5, 2026
“No customer data is used to train the AI.”
Vendor publishedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“Tldx Solutions GmbH does not use Customer Content, including meeting recordings, transcripts, notes, files, or other data processed through the Services, to train, fine-tune, or improve foundation models, large language models, or other generative AI models for the benefit of tldx Solutions GmbH or any third party. Where we use third-party AI service providers to deliver features of the Services, Customer Content is processed solely to provide the requested functionality and is not used by tldx Solutions GmbH or such providers to train or improve their general-purpose AI models.”
Vendor publishedAI Notetaker-Vergleiche - tl;dv ↗retrieved Oct 5, 2026
“Bei tl;dv sind Ihre Daten durch Ende-zu-Ende-Verschlüsselung, GDPR-Konformität und SOC 2-zertifizierte Sicherheit geschützt. Ihre Aufnahmen und Transkripte gehören Ihnen (nicht uns). Und wir werden sie niemals für das Training von KI verwenden. Niemals.”
!How long do they keep your data?Ask the vendor

Video/audio recordings and transcripts are retained for 3 months for free users and until account deletion for paying users; no post-deletion purge window is stated.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“Video and audio recording, written transcriptions Site and application Provision of the main service, sharing and collaboration Free user: 3 months Paying user: until account deletion”
✓Who else can access your data?Clear

tl;dv names Anthropic as its generative AI partner and states that identifying metadata (email, company name, first and last name) is anonymised before being processed by Anthropic.

Evidence
Vendor publishedtl;dv Security Information ↗retrieved Oct 5, 2026
“We partner with Anthropic and have added mechanisms that keep your data safe and secure: We are anonymizing any metadata we share with Anthropic. Your e-mail address, company name, and first and last name will be anonymized before being processed.”
Externally corroboratedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“All our services are hosted in Europe (within the European Economic Area) with the exception of part of our service involving artificial intelligence, depending on your choice of hosting location. tldx may use large language models provided by Anthropic via Google Cloud Vertex AI to generate written summaries or other derived content.”
Externally corroboratedtl;dv Security Information ↗retrieved Oct 5, 2026
“tl;dv hosts its software in Google Cloud Platform, Amazon Web Services (AWS) facilities and Hetzner . Google, AWS and Hetzner data centers are certified as ISO 27001, PCI DSS Service Provider Level 1, and/or SOC 1 and 2 compliant.”
Externally corroboratedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“Category of subcontractor Name of the subcontractor(s) Hosting/infrastructure/storage providers Google Cloud, Hetzner, Wasabi Payment processors Stripe Analysis tool providers Mixpanel, Cloudflare, Sentry Customer support tool providers Intercom, Sentry Marketing and email tool providers CustomerIO, Gmail Internal communication tool providers Slack, Gmail”
Externally corroboratedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“Artificial Intelligence provider Anthropic, Google Vertex Human Resources tool provider Deel Sales tool provider, customer tracking (CRM) Hubspot Platform-as-a-Service provider used to build, manage, and operate customer-authorized integrations with third-party applications Paragon Transcription provider AssemblyAI, ElevenLabs”
✓Where is your data processed?Clear

Customers can choose whether the AI processing is hosted in Europe or the US; the security page also advertises privately hosted AI on request.

Evidence
Vendor publishedtl;dv Security Information ↗retrieved Oct 5, 2026
“You have full sovereignty over the data that you record. To further enhance this control, you can now choose where your AI is hosted –Europe or the US– ensuring compliance with regional data protection standards.”
Vendor publishedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“For the purpose of providing the requested AI-powered features, in accordance with applicable data protection laws and the safeguards described in this Privacy Policy, limited portions of meeting transcripts may be processed either: within the European Union (e.g. Google Cloud regions located in the EU), or within the United States of America depending on the AI hosting location that you select in your account’s preferences .”
Externally corroboratedtl;dv Security Information ↗retrieved Oct 5, 2026
“Data is stored and protected by restricted security groups in S3 on Wasabi servers and processed in our private Google Cloud Platform (GCP) data centers and our own & dedicated servers on Hetzner. All our data centers are located in Europe.”
Vendor publishedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“We have ensured that appropriate guarantees are in place for these transfers, namely the use of standard data protection clauses adopted or approved by the European Commission.”
!What happens in a security incident?Ask the vendor

A published vulnerability disclosure contact exists and the security team commits to respond within 24 hours.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedtl;dv Security Information ↗retrieved Oct 5, 2026
“If you have discovered a privacy or security issue that we should address, please always let us know at [email protected] . Our security team will respond within 24 hours.”
Vendor publishedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“Finally, when a personal data breach likely to create a high risk for your rights and freedoms is detected, you will be informed of this breach as soon as possible.”

Email to send the vendor6 items to confirm in writing

Subject: Supplier assessment: written confirmation requested
Hello tl;dv team,

We are assessing tl;dv as part of our supplier review. Before we proceed, please confirm the following in writing:

1. How long do you retain our data, in days, for each type (inputs, outputs, logs and backups), and how is it deleted?
2. What is your commitment to notify customers of a security incident affecting our data, including the timeframe?
3. Please share the current SOC 2 Type II report (auditor, period, in-scope systems). Which EU-US transfer mechanism do you actually rely on, and why does the security page still display a Privacy Shield badge? What is the basis for the 'EU AI Act compliant' assertion (role classification, risk category, any conformity assessment)?
4. How do you evaluate transcription and summary accuracy and the sales coaching scores (metrics, test sets, languages)? Is there human review or a customer-facing accuracy disclosure, and how are AI outputs used in performance reviews constrained?
5. Is AWS currently a subprocessor, and if so in what role and region? Please confirm the authoritative subprocessor list and change-notification process. What exactly does 'end-to-end encryption' mean in your architecture given third-party AI and transcription processing?
6. What is the deletion window for recordings, transcripts and backups after account deletion? What processor breach-notification commitment do you give to business customers (timeframe, threshold)? How are changes to AI providers, models or hosting regions communicated to customers in advance?

A written reply to each point, or a link to where it is documented, is enough. Where a point is covered by a certification or independent report, please include the certificate number or the report and its date.

Thank you,
Audit evidence: a verified report maps its findings to ISO/IEC 27001 supplier controls, ISO/IEC 42001 third-party controls and APRA CPS 230. See verified reports →

Key findingsclick a row for the evidence

✓Clear, repeated no-training commitment with a named AI provider and data-minimisation safeguardsStrong

Three separate documents (security page, privacy policy section 9, marketing page) state that customer recordings and transcripts are not used to train or improve AI models, and the privacy policy extends the commitment to third-party providers. The generative AI provider (Anthropic, consumed via Google Cloud Vertex AI) and transcription providers (AssemblyAI, ElevenLabs) are named in a public subprocessor table, metadata is anonymised and meetings are chunked and shuffled before reaching the LLM provider, and customers can choose EU or US AI hosting.

This is the level of disclosure a buyer needs to answer the training, recipients and location questions without a questionnaire round-trip. The chunking approach is unusual and specific, which lends credibility beyond a boilerplate statement.

Evidence
Vendor publishedtl;dv Security Information ↗retrieved Oct 5, 2026
“We partner with Anthropic and have added mechanisms that keep your data safe and secure: We are anonymizing any metadata we share with Anthropic. Your e-mail address, company name, and first and last name will be anonymized before being processed.”
Externally corroboratedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“All our services are hosted in Europe (within the European Economic Area) with the exception of part of our service involving artificial intelligence, depending on your choice of hosting location. tldx may use large language models provided by Anthropic via Google Cloud Vertex AI to generate written summaries or other derived content.”
Vendor publishedtl;dv Security Information ↗retrieved Oct 5, 2026
“You have full sovereignty over the data that you record. To further enhance this control, you can now choose where your AI is hosted –Europe or the US– ensuring compliance with regional data protection standards.”
Vendor publishedtl;dv Security Information ↗retrieved Oct 5, 2026
“We are chunking your meetings into small pieces and randomizing the sequence order with Anthropic . Anthropic will never be able to access more than a short sequence of your meeting at once and also not be able to know which segments belong to the same meeting.”
Vendor publishedtl;dv Security Information ↗retrieved Oct 5, 2026
“No customer data is used to train the AI.”
Vendor publishedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“Tldx Solutions GmbH does not use Customer Content, including meeting recordings, transcripts, notes, files, or other data processed through the Services, to train, fine-tune, or improve foundation models, large language models, or other generative AI models for the benefit of tldx Solutions GmbH or any third party. Where we use third-party AI service providers to deliver features of the Services, Customer Content is processed solely to provide the requested functionality and is not used by tldx Solutions GmbH or such providers to train or improve their general-purpose AI models.”
Vendor publishedAI Notetaker-Vergleiche - tl;dv ↗retrieved Oct 5, 2026
“Bei tl;dv sind Ihre Daten durch Ende-zu-Ende-Verschlüsselung, GDPR-Konformität und SOC 2-zertifizierte Sicherheit geschützt. Ihre Aufnahmen und Transkripte gehören Ihnen (nicht uns). Und wir werden sie niemals für das Training von KI verwenden. Niemals.”
Externally corroboratedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“Artificial Intelligence provider Anthropic, Google Vertex Human Resources tool provider Deel Sales tool provider, customer tracking (CRM) Hubspot Platform-as-a-Service provider used to build, manage, and operate customer-authorized integrations with third-party applications Paragon Transcription provider AssemblyAI, ElevenLabs”
!SOC 2 Type II is NDA-gated; trust badges include a defunct framework and an unverifiable EU AI Act claimGap

tl;dv claims a SOC 2 Type II report (security, privacy, availability, confidentiality) via a Vanta trust report and NDA link, but auditor, period and system boundary are not public, so it is vendor-claimed only. The badge row also shows 'EU US PRIVACY SHIELD', a framework invalidated in 2020 that the privacy policy itself does not rely on (it cites SCCs), and 'EU AI ACT COMPLIANT' with no explanation. The ISO 27001 and PCI DSS references belong to the hosting providers' data centres, not to tl;dv.

A stale or inaccurate badge on the security page undermines confidence in the other badges. Buyers should rely on the SOC 2 report itself, not the page, and should not read ISO 27001 as a tl;dv certification.

Question for vendor: Please share the current SOC 2 Type II report (auditor, period, in-scope systems). Which EU-US transfer mechanism do you actually rely on, and why does the security page still display a Privacy Shield badge? What is the basis for the 'EU AI Act compliant' assertion (role classification, risk category, any conformity assessment)?

Evidence
Vendor publishedtl;dv Security Information ↗retrieved Oct 5, 2026
“tl;dv is SOC2 compliant. Our SOC 2 (Type II) shows our commitment towards a continuous effective build and improvement of our system and organization controls regarding security, privacy, availability, and confidentiality. This report explains the extreme care we take to earn and maintain our users’ trust in tl;dv, its systems, and product. Request your report here.”
Apparent contradictiontl;dv Security Information ↗retrieved Oct 5, 2026
“Access our Vanta Trust Report NDA link for our SOC 2 SOC2 COMPLIANT GDPR COMPLIANT HOSTED AND STORED IN THE EU PRIVATELY HOSTED AI ON REQUEST EU US PRIVACY SHIELD EU AI ACT COMPLIANT”
Externally corroboratedtl;dv Security Information ↗retrieved Oct 5, 2026
“tl;dv hosts its software in Google Cloud Platform, Amazon Web Services (AWS) facilities and Hetzner . Google, AWS and Hetzner data centers are certified as ISO 27001, PCI DSS Service Provider Level 1, and/or SOC 1 and 2 compliant.”
Vendor publishedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“We have ensured that appropriate guarantees are in place for these transfers, namely the use of standard data protection clauses adopted or approved by the European Commission.”
!No AI testing, evaluation or accuracy disclosure, despite performance-scoring featuresGap

testing_and_evaluation is marked not_evidenced, not not_applicable: this is a hosted AI product that summarises meetings and, in the sales offering, scores how representatives handle objections, so evaluation evidence is owed and could be supplied. The only relevant statement is a marketing assertion that structured workflows avoid hallucinations; no accuracy metrics, transcription or summary quality benchmarks, bias testing or human-review process are published. None of the ten domains were marked not_applicable, because all of them arise for a hosted meeting-recorder SaaS.

Summaries and scores feed CRMs and manager decisions about staff. Without published evaluation, buyers cannot judge error rates or fairness of AI-derived performance insights, and employee-monitoring uses may attract works council or regulator scrutiny in the EU.

Question for vendor: How do you evaluate transcription and summary accuracy and the sales coaching scores (metrics, test sets, languages)? Is there human review or a customer-facing accuracy disclosure, and how are AI outputs used in performance reviews constrained?

Evidence
“Arbeit und Halluzinationen passen nicht gut zusammen. tl;dv schafft ein Gleichgewicht zwischen Flexibilität und strukturierten Arbeitsabläufen und gewährleistet so verwertbare Ergebnisse ohne unnötige Komplexität.”
“Unsere KI beobachtet, wie Ihre Leitfäden umgesetzt werden und bewertet den Umgang mit Einwänden. Sie bietet Managern Einblicke, die helfen die Leistung im Vertrieb zu steigern.”
“Die KI-Meeting-Agenten von tl;dvautomatisieren die Aufzeichnung, Transkription, Zusammenfassung und Integration in Tools wie CRMs und Produktivitätsplattformen.”
!Hosting and encryption statements do not line up across pagesGap

The security page names AWS as a hosting facility, but the privacy policy's subprocessor table lists only Google Cloud, Hetzner and Wasabi for hosting/storage. Marketing pages claim 'end-to-end encryption', while the security page describes TLS in transit and AES-256 at rest and the privacy policy confirms transcript portions are processed by Anthropic and transcription providers, which is incompatible with end-to-end encryption in the usual sense.

A subprocessor list that omits a named host cannot be relied on as complete, and an inaccurate encryption claim can mislead a buyer's data-flow assessment.

Question for vendor: Is AWS currently a subprocessor, and if so in what role and region? Please confirm the authoritative subprocessor list and change-notification process. What exactly does 'end-to-end encryption' mean in your architecture given third-party AI and transcription processing?

Evidence
Externally corroboratedtl;dv Security Information ↗retrieved Oct 5, 2026
“tl;dv hosts its software in Google Cloud Platform, Amazon Web Services (AWS) facilities and Hetzner . Google, AWS and Hetzner data centers are certified as ISO 27001, PCI DSS Service Provider Level 1, and/or SOC 1 and 2 compliant.”
Externally corroboratedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“Category of subcontractor Name of the subcontractor(s) Hosting/infrastructure/storage providers Google Cloud, Hetzner, Wasabi Payment processors Stripe Analysis tool providers Mixpanel, Cloudflare, Sentry Customer support tool providers Intercom, Sentry Marketing and email tool providers CustomerIO, Gmail Internal communication tool providers Slack, Gmail”
Externally corroboratedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“Artificial Intelligence provider Anthropic, Google Vertex Human Resources tool provider Deel Sales tool provider, customer tracking (CRM) Hubspot Platform-as-a-Service provider used to build, manage, and operate customer-authorized integrations with third-party applications Paragon Transcription provider AssemblyAI, ElevenLabs”
Vendor publishedAI Notetaker-Vergleiche - tl;dv ↗retrieved Oct 5, 2026
“Bei tl;dv sind Ihre Daten durch Ende-zu-Ende-Verschlüsselung, GDPR-Konformität und SOC 2-zertifizierte Sicherheit geschützt. Ihre Aufnahmen und Transkripte gehören Ihnen (nicht uns). Und wir werden sie niemals für das Training von KI verwenden. Niemals.”
Externally corroboratedtl;dv Security Information ↗retrieved Oct 5, 2026
“Data is stored and protected by restricted security groups in S3 on Wasabi servers and processed in our private Google Cloud Platform (GCP) data centers and our own & dedicated servers on Hetzner. All our data centers are located in Europe.”
!Retention tied to account lifetime, high-risk-only breach notice, and weak change-notice commitmentsGap

Paying users' recordings and transcripts are kept until account deletion with no stated purge window afterwards; free users' content is kept 3 months. Breach notification to data subjects is promised only for high-risk breaches and 'as soon as possible', with no customer-as-controller commitment or timeframe. The Terms commit only to 'try' to give notice of material changes, and nothing addresses notice of AI model or provider changes.

Enterprise buyers typically need a defined deletion window, 72-hour-style processor breach notification, and advance notice when the AI provider or model changes. These are DPA-level commitments that the public documents do not make.

Question for vendor: What is the deletion window for recordings, transcripts and backups after account deletion? What processor breach-notification commitment do you give to business customers (timeframe, threshold)? How are changes to AI providers, models or hosting regions communicated to customers in advance?

Evidence
Vendor publishedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“Video and audio recording, written transcriptions Site and application Provision of the main service, sharing and collaboration Free user: 3 months Paying user: until account deletion”
Vendor publishedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“Finally, when a personal data breach likely to create a high risk for your rights and freedoms is detected, you will be informed of this breach as soon as possible.”
Vendor publishedTerms - tl;dv ↗retrieved Oct 5, 2026
“We may suspend or discontinue any part of the Services, or we may introduce new features or impose limits on certain features or restrict access to parts or all of the Services. We’ll try to give you notice when we make a material change to the Services that would adversely affect you, but this isn’t always practical.”
Vendor publishedtl;dv Security Information ↗retrieved Oct 5, 2026
“Code development follows a standardized process. All code changes are reviewed for security and extensively tested prior to deployment into production. tl;dv development and testing environments are separate from the production environment.”

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score40
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
Vendor publishedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“The Data Controller is Tldx Solutions GmbH, headquartered at Tldx Solutions GmbH, Kaiser-Friedrich-Allee 51, 52074 – AACHEN, GERMANY registered under number HRB 23730 of the commercial register of the following jurisdiction: Amtsgericht Aachen, represented by its President Mr. Raphaël ALLSTADT.”
Vendor publishedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“For any information or exercise of your Information Technology and Civil Liberties rights on personal data processing, you can contact our data protection officer (DPO):”
Vendor publishedtl;dv Security Information ↗retrieved Oct 5, 2026
“To further guarantee our GDPR compliance, our team maintains an internal record of data processing activities to document how we process personal data for each of our products.”
Vendor publishedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“Furthermore, we apply the need-to-know principle regarding access given to employees, agents, subcontractors, and other third parties who may process your data . These parties will only process your personal data on our instructions and are subject to a duty of confidentiality .”
AI system15% of the score33
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Evidence — AI system description
“Die KI-Meeting-Agenten von tl;dvautomatisieren die Aufzeichnung, Transkription, Zusammenfassung und Integration in Tools wie CRMs und Produktivitätsplattformen.”
“tl;dv bietet KI-Agenten-Workflows , die auf modularen KI-Bausteinen aufgebaut sind und Aufgaben wie Aufzeichnung, Transkription, Zusammenfassung und Integrationen übernehmen.”
“Arbeit und Halluzinationen passen nicht gut zusammen. tl;dv schafft ein Gleichgewicht zwischen Flexibilität und strukturierten Arbeitsabläufen und gewährleistet so verwertbare Ergebnisse ohne unnötige Komplexität.”
“Unsere KI beobachtet, wie Ihre Leitfäden umgesetzt werden und bewertet den Umgang mit Einwänden. Sie bietet Managern Einblicke, die helfen die Leistung im Vertrieb zu steigern.”
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Not Evidenced
Evidence — Testing & evaluation
“Arbeit und Halluzinationen passen nicht gut zusammen. tl;dv schafft ein Gleichgewicht zwischen Flexibilität und strukturierten Arbeitsabläufen und gewährleistet so verwertbare Ergebnisse ohne unnötige Komplexität.”
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Partial
Evidence — Change management
Vendor publishedtl;dv Security Information ↗retrieved Oct 5, 2026
“Code development follows a standardized process. All code changes are reviewed for security and extensively tested prior to deployment into production. tl;dv development and testing environments are separate from the production environment.”
Vendor publishedTerms - tl;dv ↗retrieved Oct 5, 2026
“We may suspend or discontinue any part of the Services, or we may introduce new features or impose limits on certain features or restrict access to parts or all of the Services. We’ll try to give you notice when we make a material change to the Services that would adversely affect you, but this isn’t always practical.”

AI system description: vendor-evidenced, not yet independently corroborated.

Testing & evaluation: not publicly evidenced.

Model10% of the score60
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Partial
Evidence — Model & provider transparency
Vendor publishedtl;dv Security Information ↗retrieved Oct 5, 2026
“We partner with Anthropic and have added mechanisms that keep your data safe and secure: We are anonymizing any metadata we share with Anthropic. Your e-mail address, company name, and first and last name will be anonymized before being processed.”
Externally corroboratedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“All our services are hosted in Europe (within the European Economic Area) with the exception of part of our service involving artificial intelligence, depending on your choice of hosting location. tldx may use large language models provided by Anthropic via Google Cloud Vertex AI to generate written summaries or other derived content.”
Vendor publishedtl;dv Security Information ↗retrieved Oct 5, 2026
“You have full sovereignty over the data that you record. To further enhance this control, you can now choose where your AI is hosted –Europe or the US– ensuring compliance with regional data protection standards.”

Model provider transparency: vendor-evidenced, not yet independently corroborated.

Customer data15% of the score60
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
Vendor publishedtl;dv Security Information ↗retrieved Oct 5, 2026
“We are chunking your meetings into small pieces and randomizing the sequence order with Anthropic . Anthropic will never be able to access more than a short sequence of your meeting at once and also not be able to know which segments belong to the same meeting.”
Vendor publishedtl;dv Security Information ↗retrieved Oct 5, 2026
“No customer data is used to train the AI.”
Vendor publishedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“Tldx Solutions GmbH does not use Customer Content, including meeting recordings, transcripts, notes, files, or other data processed through the Services, to train, fine-tune, or improve foundation models, large language models, or other generative AI models for the benefit of tldx Solutions GmbH or any third party. Where we use third-party AI service providers to deliver features of the Services, Customer Content is processed solely to provide the requested functionality and is not used by tldx Solutions GmbH or such providers to train or improve their general-purpose AI models.”
Vendor publishedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“Video and audio recording, written transcriptions Site and application Provision of the main service, sharing and collaboration Free user: 3 months Paying user: until account deletion”
Vendor publishedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“Tldx Solutions GmbH does not access your recordings and transcriptions at any time, unless you personally share access with individual employees for technical assistance . Even in this case, only the recordings and transcriptions for which access rights have been granted to the support team member will be accessible.”
Vendor publishedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“For the purpose of providing the requested AI-powered features, in accordance with applicable data protection laws and the safeguards described in this Privacy Policy, limited portions of meeting transcripts may be processed either: within the European Union (e.g. Google Cloud regions located in the EU), or within the United States of America depending on the AI hosting location that you select in your account’s preferences .”
Externally corroboratedtl;dv Security Information ↗retrieved Oct 5, 2026
“Data is stored and protected by restricted security groups in S3 on Wasabi servers and processed in our private Google Cloud Platform (GCP) data centers and our own & dedicated servers on Hetzner. All our data centers are located in Europe.”
Vendor publishedAI Notetaker-Vergleiche - tl;dv ↗retrieved Oct 5, 2026
“Bei tl;dv sind Ihre Daten durch Ende-zu-Ende-Verschlüsselung, GDPR-Konformität und SOC 2-zertifizierte Sicherheit geschützt. Ihre Aufnahmen und Transkripte gehören Ihnen (nicht uns). Und wir werden sie niemals für das Training von KI verwenden. Niemals.”

Customer data treatment: vendor-evidenced, not yet independently corroborated.

AI supply chain10% of the score60
Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Partial
Evidence — Subprocessors & supply chain
Externally corroboratedtl;dv Security Information ↗retrieved Oct 5, 2026
“tl;dv hosts its software in Google Cloud Platform, Amazon Web Services (AWS) facilities and Hetzner . Google, AWS and Hetzner data centers are certified as ISO 27001, PCI DSS Service Provider Level 1, and/or SOC 1 and 2 compliant.”
Externally corroboratedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“Category of subcontractor Name of the subcontractor(s) Hosting/infrastructure/storage providers Google Cloud, Hetzner, Wasabi Payment processors Stripe Analysis tool providers Mixpanel, Cloudflare, Sentry Customer support tool providers Intercom, Sentry Marketing and email tool providers CustomerIO, Gmail Internal communication tool providers Slack, Gmail”
Externally corroboratedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“Artificial Intelligence provider Anthropic, Google Vertex Human Resources tool provider Deel Sales tool provider, customer tracking (CRM) Hubspot Platform-as-a-Service provider used to build, manage, and operate customer-authorized integrations with third-party applications Paragon Transcription provider AssemblyAI, ElevenLabs”

Subprocessors & supply chain: vendor-evidenced, not yet independently corroborated.

Security foundation15% of the score45
Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Partial
Evidence — Vulnerability & incident handling
Vendor publishedtl;dv Security Information ↗retrieved Oct 5, 2026
“If you have discovered a privacy or security issue that we should address, please always let us know at [email protected] . Our security team will respond within 24 hours.”
Vendor publishedtl;dv Security Information ↗retrieved Oct 5, 2026
“tl;dv regularly scans production infrastructure, applications, and networks for vulnerabilities using off-the-shelf tools to identify potential vulnerabilities.”
Vendor publishedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“Finally, when a personal data breach likely to create a high risk for your rights and freedoms is detected, you will be informed of this breach as soon as possible.”
Independent assurance evidence10% of the score35
Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Partial
Evidence — Independent assurance
Vendor publishedtl;dv Security Information ↗retrieved Oct 5, 2026
“tl;dv is SOC2 compliant. Our SOC 2 (Type II) shows our commitment towards a continuous effective build and improvement of our system and organization controls regarding security, privacy, availability, and confidentiality. This report explains the extreme care we take to earn and maintain our users’ trust in tl;dv, its systems, and product. Request your report here.”
Apparent contradictiontl;dv Security Information ↗retrieved Oct 5, 2026
“Access our Vanta Trust Report NDA link for our SOC 2 SOC2 COMPLIANT GDPR COMPLIANT HOSTED AND STORED IN THE EU PRIVATELY HOSTED AI ON REQUEST EU US PRIVACY SHIELD EU AI ACT COMPLIANT”

None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.

Legal & contractual10% of the score60
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
Vendor publishedTerms - tl;dv ↗retrieved Oct 5, 2026
“As you are using tldx to record meetings, you are responsible for collecting consents from all participants in the meeting prior to starting the recording. Participants have the option to leave the meeting. The transcript, which may also contain personal data, is treated the same way as the video recording. Video recordings and transcripts will not be accessed by tldx, unless upon specific request by the user who created such recordings with tldx.”
Vendor publishedTerms - tl;dv ↗retrieved Oct 5, 2026
“In any event, tldx’s total liability shall not exceed the amount paid by you for the Service during the last 12 months prior to the incident that causes the liability.”
Vendor publishedPrivacy - tl;dv ↗retrieved Oct 5, 2026
“We have ensured that appropriate guarantees are in place for these transfers, namely the use of standard data protection clauses adopted or approved by the European Commission.”

Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+4Publish independently corroborated ISO/IEC 42001 (AI management system) certificationIndependent Assurance 35 → 59
+3Complete the Governance & accountability disclosureOrganisation 40 → 60
+3Publish Testing & evaluation evidenceAI System 33 → 53
+3Complete the Vulnerability & incident handling disclosureSecurity Foundation 45 → 65
+3Corroborate SOC 2 Type II against its registry or issuing bodyIndependent Assurance 35 → 55

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 48 → up to 71 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESMODELS & AI PROVIDERSINFRASTRUCTURESUBPROCESSORSTldx Solutions GmbH (tl;dv)Tldx Solutions GmbH (tl;d…tl;dv meeting recorder and AI meeting agentstl;dv meeting recorder an…AnthropicAnthropicGoogle Cloud Platform / Vertex AIGoogle Cloud Platform / V…Amazon Web ServicesAmazon Web ServicesHetznerHetznerWasabiWasabiAssemblyAI (transcription)AssemblyAI (transcription)ElevenLabs (transcription)ElevenLabs (transcription)Paragon (integration platform)Paragon (integration plat…
View as list
Tldx Solutions GmbH (tl;dv) Uses AI Service Anthropic
Tldx Solutions GmbH (tl;dv) Contracted Subprocessor Anthropic
Tldx Solutions GmbH (tl;dv) Uses AI Service Google Cloud Platform / Vertex AI
Tldx Solutions GmbH (tl;dv) Uses Infrastructure Google Cloud Platform / Vertex AI
Tldx Solutions GmbH (tl;dv) Contracted Subprocessor Google Cloud Platform / Vertex AI
Tldx Solutions GmbH (tl;dv) Uses Infrastructure Amazon Web Services
Tldx Solutions GmbH (tl;dv) Uses Infrastructure Hetzner
Tldx Solutions GmbH (tl;dv) Contracted Subprocessor Hetzner
Tldx Solutions GmbH (tl;dv) Uses Infrastructure Wasabi
Tldx Solutions GmbH (tl;dv) Contracted Subprocessor Wasabi
Tldx Solutions GmbH (tl;dv) Contracted Subprocessor AssemblyAI (transcription)
Tldx Solutions GmbH (tl;dv) Contracted Subprocessor ElevenLabs (transcription)
Tldx Solutions GmbH (tl;dv) Contracted Subprocessor Paragon (integration platform)

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 2 — registry checks and verification ladders, click to view
SOC 2 Type IIVendor claimed only

Vendor states the report covers security, privacy, availability and confidentiality; auditor, report period and system boundary are not published. Report available on request under NDA via a Vanta trust report.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 42001Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

Sources 12 — click to view
KI-Agenten für Meetings: Automatisierung von Produktivität und Einblicken
AI Documentation · Vendor · retrieved Oct 5, 2026
tl;dv Security Information
Trust Or Security Page · Vendor · retrieved Oct 5, 2026
tl;dv Trust Center
Subprocessor List · Vendor · retrieved Oct 5, 2026
Privacy - tl;dv
Privacy Notice · Vendor · retrieved Oct 5, 2026
https://tldv.io/wp-content/uploads/2022/04/transparency.svg
Certification Or Compliance Page · Vendor · retrieved Oct 5, 2026
Terms - tl;dv
Terms · Vendor · retrieved Oct 5, 2026
tldv Blog | Meetings, Vertrieb, KI und Customer Success Inhalte
Technical Article · Vendor · retrieved Oct 5, 2026
KI-Agenten für Verkaufsgespräche - Gleiche Leute, mehr Ergebnisse
AI Documentation · Vendor · retrieved Oct 5, 2026
tl;dv Trust Center
Trust Or Security Page · Vendor · retrieved Oct 5, 2026
Vanta
Certification Or Compliance Page · Vendor · retrieved Oct 5, 2026
AI Notetaker-Vergleiche - tl;dv
AI Documentation · Vendor · retrieved Oct 5, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).

Want to go further?

This scan assesses tl;dv at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.

Scan a specific product →

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.

Monitor for changes

Get an email if its TRUSTYCYBER Score, grade or certifications change. One credit per refresh; reading the report always stays free.