We document Aleida against the AI Act with one house rule: never claim a control without showing where in the code it lives. This page follows the same rule.
Candidate data sits in Postgres at Supabase, region eu-west-1. The application runs on Vercel in arn1, Stockholm. Both model calls in the assessment run on AWS Bedrock in eu-north-1, Stockholm. Encrypted database backups are taken daily to S3 with 30 days of retention.
Aleida trains, fine-tunes and further-trains no AI model. There is no training code, no training dataset, no model weights, no fine-tuning pipeline and no stored embeddings. The models are called over API — the whole integration is a handful of HTTP calls.
Candidate data sits behind row-level security with company-scoped policies. Access control on every API route is checked against the company the candidate belongs to.
Every model call is logged with timestamp, model tier, token count, duration, retries and status — not the content. The interview itself is of course stored, for you to read. The call log is not where it lives.
Every quote the assessment leans on is verified word-for-word against what the candidate actually wrote, and struck if it cannot be found. Gendered pronouns are rewritten deterministically in the prose — never inside a quote. If a run fails its own checks it is redone, and if it fails again the placement falls back to a rule instead of the model.
The placement is a priority order, not a decision. You see the whole interview in plain text and can always go against the outcome. The candidate has the right to have a human review the assessment, to state their view and to contest it.
No video, no image, no voice. No tone of voice, no personality scoring, no sentiment analysis. The system is explicitly built not to value language or professionalism.
We assess Aleida as a high-risk system under Annex III 4(a) — an AI system intended for recruitment and candidate evaluation — and ourselves as its provider. The high-risk requirements apply from 2 December 2027. We already document against articles 9 to 14: risk management, data governance, technical documentation, logging, transparency and human oversight.
For your legal team. Mail hello@aleda.se and you get the actual documents, not a summary.
Ask for the documentationWe write about transparent recruitment, AI in hiring, and what we are building. Short, honest updates. No spam.