Compliance isn't a feature
we added later.
Recruitment is a high-risk area under the EU AI Act. We designed for that review from day one, not after it. This page is written for the people who run that review: legal, security, data protection, works councils.
- EU AI Act classification
- Built to meet the Annex III (employment) obligations. We do not rely on an exemption.
- Automated decisions
- None. Signals and a score for a human to review. No Article 22 decision-making.
- GDPR roles
- Customer is the controller. TalentShield is the processor under a DPA with a named sub-processor list.
- Data location
- Application and database in Frankfurt, reports in Nuremberg. AI processing in Microsoft's EU Data Zone, with stored data in Sweden.
- Model training on customer data
- No. Inputs and outputs are not retained by model providers.
- Audit trail
- Signal library version, detected signals, score, badge and timestamp for every verification.
- Candidate rights
- Exercised through the customer as controller; requests reaching us are forwarded within five business days.
- Certifications
- ISO 27001 and SOC 2 not held yet; compensating controls described in the Security & Architecture Overview.
Six things that are true
on every report.
No automated decisions
TalentShield produces information for a recruiter to review. It does not reject, rank out or filter anyone on its own. Every recorded verdict is a person's.
Every signal has a reason
Recruiters see which checks passed, which raised a flag and why. Candidates can get a meaningful explanation, as the AI Act requires.
Hosted and processed in the EU
Application data is stored on EU infrastructure. AI processing runs on Azure OpenAI Service in Microsoft's EU Data Zone, with no retention and no training on your data.
Processor, not controller
You stay the controller of candidate data. TalentShield acts as your processor under a Data Processing Agreement with a named sub-processor list.
We log what we did
Signal version, detected signals, score and timestamp for every verification. Ready for a DPIA, a candidate request or an auditor.
Only what the check needs
Deterministic checks run locally. Open questions go to the model with identifying data reduced to what the specific check needs. Configurable per customer.
We don't pretend to be low-risk.
AI systems used to filter or evaluate job applications are listed in Annex III of the AI Act. Some vendors in this space describe themselves as "assistive" to stay out of that box. We do the opposite: we assume the classification applies and build for the obligations that come with it. That is a better place to be when your legal team asks, and it is the honest description of what the product does.
- Human oversight by design. Outputs are information for a person. The system has no path to reject, rank out or filter a candidate on its own.
- Transparency to the people affected. Every signal is written so it can be shown to a candidate: what we found, why it matters, how to check it.
- Logging. For every verification we record the signal library version, detected signals, score, badge and timestamp. The recruiter's review (who, what, when) is recorded separately in the decision history, as the recruiter's own.
- Documentation for the deployer. Instructions for use, the description of checks and their data flows, and the division of responsibilities between us and you are part of the customer documentation.
Obligations for Annex III systems apply from December 2027 after the 2026 amendment of the Act. We are not waiting for the date.
You are the controller. We are the processor.
Candidate data lives in your ATS. TalentShield processes it on your documented instructions, under a Data Processing Agreement that lists every sub-processor by name, location and purpose. Public professional profile information is personal data too, and we treat it that way: it is processed under your legitimate interest, only for the checks you switch on, and never bought or enriched for other purposes.
- No automated decision-making in the meaning of Article 22: the product informs a human decision, it does not make one.
- Data minimisation per check: deterministic checks run locally; open checks send the model only what that check needs; enrichment sources are configurable per customer and off by default in pilots.
- Candidate rights (access, rectification, erasure, objection, human intervention) are exercised through you as the controller; requests that reach us are forwarded to you within five business days.
- DPIA support: we provide the description of processing, data flows and safeguards your assessment needs.
Hosted in the EU. Processed in the EU.
The application and its database run in Frankfurt. Verification reports are stored in Nuremberg. AI processing runs on Azure OpenAI Service in Microsoft's EU Data Zone, with our resource and stored data in Sweden; inputs and outputs are not retained and are not used for training. Transactional email leaves through an EU region. Encryption in transit (TLS 1.2+) and at rest (AES-256), access controls with multi-factor authentication, and separate accounts per system are the baseline, not the premium tier.
We do not hold ISO 27001 or SOC 2 yet. We say so, and the Security & Architecture Overview describes the compensating controls in detail.
Sub-processors for candidate data.
Every third party that can receive candidate data, by name. The full list with transfer mechanisms and dated prior versions is Annex 3 of the DPA.
| Provider | Purpose | Location |
|---|---|---|
| Render Services, Inc. | Application hosting, database, backups | Frankfurt, Germany |
| Hetzner Online GmbH | Storage of verification reports | Nuremberg, Germany |
| Microsoft Ireland Operations Ltd. (Azure OpenAI Service) | Language model for document parsing and open-ended checks; no retention, no training | EU Data Zone (resource and stored data in Sweden) |
| Sinch AB | Telephone number type lookup; receives the number only | Sweden |
| Mailgun Technologies (Sinch Email), EU region | Transactional email to your users; never candidate data | EU |
| Public profile retrieval provider (named in the DPA) | Only for customers who enable profile checks; receives the profile URL only | Stated in the DPA |
Last updated 5 October 2026.
What you get for your review.
- Security & Architecture Overview
- Data Processing Agreement with Annexes (processing description, technical and organisational measures, sub-processors)
- AI Governance Statement
- Terms of Service, Design Partner Agreement for pilots
- Answers to standard security questionnaires, on request
- Privacy Policy
The Privacy Policy is public. The DPA, Security & Architecture Overview and AI Governance Statement are sent on request, usually the same day. Ask for the pack in the demo form or write to privacy@talentshield.app.
Questions from legal,
security and DPOs.
Systems used to filter or evaluate job applications fall under Annex III of the AI Act, and we treat TalentShield as such. We do not claim an exemption. The product is built for the obligations that follow: human oversight by design, explainability of every output, logging, and documentation for the deployer.
Our customer. TalentShield processes candidate data on the customer's instructions as a processor, under a Data Processing Agreement with a named sub-processor list. We do not use candidate data for our own purposes and we do not contact candidates.
Application data and reports are stored on EU infrastructure (Frankfurt and Nuremberg). AI processing runs on Azure OpenAI Service in Microsoft's EU Data Zone (EU and EFTA countries), with stored data in Sweden, without retention and without training on customer data.
No. It produces information for a recruiter to review: a score, a badge and the reasons. There is no automatic rejection, ranking out or filtering. Every recorded verdict in the system is a person's. No text shown to recruiters or candidates is generated by a language model; every signal explanation is a fixed template written by us.
A meaningful explanation of what was checked and what was found. Every signal in a report is written to be shown to the candidate: what we found, why it matters, how to verify it.
Security & Architecture Overview, Data Processing Agreement with sub-processor list, AI Governance Statement, Privacy Policy, and our answers to standard security questionnaires. Ask for the compliance pack in the demo form.
Security questions and vulnerability reports: security@talentshield.app (acknowledged within 2 business days). Data protection, DPA and candidate requests: privacy@talentshield.app. Page last updated 5 October 2026.
See it on your own pipeline.
Leave your email and the ATS you use. We come back within one business day to book a 30-minute demo, on your own applicants if you want. Just have questions? Talk to Mateusz, 30 minutes, no slides.