Security

Nothing here that we cannot point to in the code.

We document Aleida against the AI Act with one house rule: never claim a control without showing where in the code it lives. This page follows the same rule.

Where your data lives

Candidate data sits in Postgres at Supabase, region eu-west-1. The application runs on Vercel in arn1, Stockholm. Both model calls in the assessment run on AWS Bedrock in eu-north-1, Stockholm. Encrypted database backups are taken daily to S3 with 30 days of retention.

We train no model on your data

Aleida trains, fine-tunes and further-trains no AI model. There is no training code, no training dataset, no model weights, no fine-tuning pipeline and no stored embeddings. The models are called over API — the whole integration is a handful of HTTP calls.

Only you see your candidates

Candidate data sits behind row-level security with company-scoped policies. Access control on every API route is checked against the company the candidate belongs to.

We do not log what was said

Every model call is logged with timestamp, model tier, token count, duration, retries and status — not the content. The interview itself is of course stored, for you to read. The call log is not where it lives.

Quotes are checked in code, not trusted

Every quote the assessment leans on is verified word-for-word against what the candidate actually wrote, and struck if it cannot be found. Gendered pronouns are rewritten deterministically in the prose — never inside a quote. If a run fails its own checks it is redone, and if it fails again the placement falls back to a rule instead of the model.

A human decides

The placement is a priority order, not a decision. You see the whole interview in plain text and can always go against the outcome. The candidate has the right to have a human review the assessment, to state their view and to contest it.

The interview is text

No video, no image, no voice. No tone of voice, no personality scoring, no sentiment analysis. The system is explicitly built not to value language or professionalism.

The AI Act

We are documenting against it now, not in 2027.

We assess Aleida as a high-risk system under Annex III 4(a) — an AI system intended for recruitment and candidate evaluation — and ourselves as its provider. The high-risk requirements apply from 2 December 2027. We already document against articles 9 to 14: risk management, data governance, technical documentation, logging, transparency and human oversight.

Documentation on request

Data processing agreement
Standard contractual clauses
Technical documentation under the AI Act
Processing agreements with our subprocessors

For your legal team. Mail hello@aleda.se and you get the actual documents, not a summary.

Ask for the documentation
Newsletter

Follow the journey.

We write about transparent recruitment, AI in hiring, and what we are building. Short, honest updates. No spam.

Or write to us at hello@aleida.se
ALEIDA
© 2026 Aleida · Gothenburg, Sweden Privacy policy Svenska