The fair question about any document-review tool is "how do I audit it to know it's accurate?" This page answers it: what a rule is, what a finding must contain before you see it, who reviews the library, and what the scanner does not catch.
DefensibleHR does not review documents against an opinion of what good HR practice looks like. It reviews them against a versioned library of rules, each of which rests on a published authority: a statute, a regulation, agency guidance, or a decided case. A rule with no verifiable citation is marked unverified and is never applied to a document. We would rather run fewer rules you can check than more rules you have to take on faith.
Each rule carries:
| Jurisdiction | Federal, or the state the rule arises under. State rules run only for the states you operate in, or that the document itself references. |
|---|---|
| Document types | Which kinds of document the rule applies to (severance agreements, termination letters, handbooks, and so on). A rule is never applied to a document type it was not written for. |
| Category | Required when a statute or regulation mandates language or a process. Recommended when the risk is real but depends on circumstances, or rests on guidance or case law. Optional for best practice with little legal exposure. There is no severity score; the category is a statement about the authority, not a verdict about your document. |
| Authority | The citation, its name, and a link to the canonical public source where one exists. |
| Effective date | When the underlying law took effect. |
| Last reviewed | When a person last confirmed the rule is current. Shown on every finding. A stale date is a signal to you, not something we hide. |
| Applies when | Conditions such as headcount thresholds, employee age, or group programs, stated in plain language. |
| Version | Every finding records the rule version that produced it, permanently. If a rule changes later, your report still points at the rule as it stood when you ran the scan. |
The most common reason people stop using review tools is that verifying the output costs as much as doing the review. So a finding is not shown unless it can be verified on its own:
Personal identifiers in nine structured categories (Social Security numbers, phone numbers, email addresses, dates of birth, driver's license numbers, bank account numbers, card numbers, EINs, and passport numbers) are redacted before any text leaves our systems. The document is then classified by type and by the states it references, the applicable rules are selected, and the document is reviewed against those rules only. Identical text always produces identical findings: results are keyed to a fingerprint of the text and the rule library version, so a re-scan of the same document returns the same report.
Extracted text is purged 90 days after the scan, or sooner when you delete the document; a workspace can be set to delete text at the end of each scan job. Findings keep the lines they point at. Details are on the Trust page.
Rules are authored and maintained by the DefensibleHR editorial process against primary sources, and each rule records who last reviewed it and when. Treat the library as a well-sourced checklist, not a legal opinion. Each rule records the primary source it rests on and the date it was last reviewed. Law changes are tracked daily from official federal and state sources and employment-law alert publications: a monitoring agent reads each item, drafts a proposed edit to the affected rule with the source link, and places it in a review queue. Nothing changes until a person has reviewed and approved it. Heavy review cycles run each January and July, quarterly sweeps in between, with an urgent lane for court decisions. When a rule changes, its version increments and its last-reviewed date advances; older findings keep the version they were produced under. Approved changes are published in the change digest, which names the document type and clause each change touches.
If a finding looks out of date, tell us. Every finding in a report carries a "this rule looks out of date" control that sends the rule id and your note straight to the review queue; you can also email the rule id to [email protected].
The short version: a finding is a quoted line, a cited rule, and a question for your reviewer. If any of the three is missing, you will not see it.
Upload one document, see which line is the problem and the authority it rests on. No account needed.
Run a free scanAll scan results are AI-generated, without human review. DefensibleHR.ai is an AI-powered assistant, not a law firm, and does not provide legal advice. AI can make mistakes. Scan results may be incomplete or inaccurate. DefensibleHR LLC is not responsible for any decisions or outcomes based on scan results. Always seek the advice of a qualified employment attorney. This page is general information, not legal advice.