Trust centre

Taali makes decisions about people’s careers. This page states how those decisions are made, what a person can do about one, where the data sits, and which obligations apply to us — in enough detail to be checked rather than believed.

Last updated 20 August 2026

How decisions get made

Taali scores candidates against criteria your team writes and can read. Every score cites the verbatim CV evidence it rests on, and every verdict names the rule that produced it — there is no opaque model score you are asked to take on trust.

Advancing a candidate is always queued for a person to approve. Rejection at the pre-screen stage can be automatic: where a candidate does not meet the screening rules your recruiter wrote, or scores below the pre-screen threshold, the rejection applies without a human step. That behaviour is on by default and the hiring organisation can turn it off for any role.

Anyone affected by an automated decision can ask for human review. Contact the organisation that advertised the role, or write to us and we will route it to them as the controller.

What human review actually means here

Regulators are explicit that human involvement cannot be a rubber stamp — the reviewer needs authority to change the outcome and access to the evidence behind it. Taali is built for that: the reviewer sees the score, the citations, the rule path and the criteria version the decision was made under, and can override any verdict.

Every override is recorded. Criteria changes, threshold moves and decision-policy revisions are written to an append-only history per role, so what the bar was on any given day is a matter of record rather than recollection.

Where data lives, and who touches it

Taali runs on US infrastructure. For customers in the UK and EU that makes every candidate record a restricted international transfer, so transfers rest on the EU–US Data Privacy Framework where a subprocessor is certified, and on Standard Contractual Clauses (with the UK Addendum) where one is not.

For candidate data your organisation is the controller and Taali is the processor, acting on your instructions. Taali is a controller only for its own account, billing and usage data.

See every subprocessor and its transfer mechanism

Regulatory position

Recruitment AI is Annex III high-risk under the EU AI Act. Following the Digital Omnibus, those obligations apply from 2 December 2027. The Act’s transparency duty — telling people they are interacting with an AI system — has applied since 2 August 2026, and Taali discloses AI involvement on every candidate-facing surface.

In the UK, the DUAA reforms to automated decision-making (Articles 22A–22D) have been in force since 5 February 2026. They permit solely automated significant decisions subject to safeguards: information about the decision, the ability to make representations, human intervention, and a route to contest.

We describe this as preparation, not certification. Taali holds no AI Act conformity assessment today, because the obligations it would attest to do not yet apply.

How long data is kept

Unsuccessful candidate records default to six months after a process closes in the UK — the Equality Act claim window — and are configurable by customer. Assessment telemetry, interview transcripts and candidate reports run on the same clock as the candidate record they belong to.

Decision and audit history is deliberately kept beyond the candidate record: it is the evidence that a decision was made properly, and destroying it would remove the ability to answer for it.

Contesting a decision

A candidate who wants a decision reviewed can go to the organisation that advertised the role, or write to hello@taali.ai. Taali does not decide the merits — we acknowledge within three working days and route the request to the customer as controller, who resolves it within thirty days.

Security practices

Access to customer data is scoped per organisation and enforced server-side on every request. Candidate data is never used to train or tune a shared model across customers.

Anything not on this page

If you are diligencing Taali and need something this page does not cover, write to hello@taali.ai. We would rather tell you we do not have something yet than imply we do.

Diligence it against a real pipeline.

Bring your own compliance questions and one live role. Everything on this page is checkable in the product.