Compliance and AI transparency

Controls you can verify, gaps we will not hide

This page reports current engineering controls and open assurance work. It is not a certification, legal opinion, or claim that every rule applies in the same way to every deployment.

Data protection

GDPR and ePrivacy

Engineering controls

Local-first capture, explicit upload, authenticated exports, durable deletion requests, bounded retention, session revocation, and no non-essential tracking cookies in the current beta.

AI transparency

EU AI Act

Engineering controls

AI endpoints require an authenticated same-origin request, identify local versus external generation, return provenance, and require human review before publishing.

Hosted content

Digital Services Act

Intake baseline

Anyone can submit a structured illegal-content notice for a TechCast public share URL and receive a durable reference. Operational decision, appeal, and transparency reporting remain launch gates.

Accessibility

European Accessibility Act

Audit required

Keyboard, labels, focus, responsive layouts, and semantic status output are product requirements. A qualified WCAG accessibility audit and accessibility statement remain required.

Software security

Cyber Resilience Act

Readiness program

Secure defaults, vulnerability intake, incident handling, dependency evidence, signed desktop distribution, and update/support commitments are tracked. CRA classification and conformity evidence require final product/legal review.

Subscriptions

EU consumer law

Launch gated

Paid self-service remains closed until trader identity, total pricing, renewal, withdrawal, cancellation, refund, tax, and support terms receive legal and production acceptance.

How AI is used

TechCast can send the title, transcript, or other content you select to a configured AI provider to draft transcripts, chapters, metadata, publishing copy, SEO feedback, or coaching. Generated material is a draft and is never a substitute for factual, legal, rights, or safety review.

External assurance still required

Before market launch, TechCast still needs verified controller/trader identity, legal bases and records, processor agreements and transfers, a DPIA decision, accessibility conformance, incident ownership, provider retention proof, security testing, and qualified legal review in the launch countries.