The bar practitioners set is "the same protections as data that already exists in our tenant." Here is, in plain terms, what happens to a document you upload, what we keep, where it is processed, and what we will put in a contract.
No training on your documents
Identifiers redacted before analysis
Text purged after 90 days
Every finding cited
Data handling, in the terms a firm needs before it can adopt a tool
Answers to "will you train on my data?", "how long do you keep it?", "where is it processed?", and "what about privilege?"
No training on your documents. We do not use your documents, extracted text, or scan results to train any model. Our AI provider (Anthropic) does not use API-submitted data to train its models. This is a term of our Terms of Service and Data Processing Addendum, not only a policy statement. Note for reviewers: the Terms reserve a right to use de-identified, aggregated data to improve the service; an Enterprise opt-out is available in writing.
Retention: 90 days. The original file is never stored; it is discarded once its text is extracted. Extracted document text is kept so you can use the in-document viewer and rescan, and it is purged automatically 90 days after the scan, or immediately when you delete the document. An account or client workspace can instead choose to delete text as each scan finishes; rescans then need a fresh upload. Findings keep the quoted lines they rest on, plus the rule and citation. A cryptographic hash of the file and of its text is kept as a dispute record, with the other scan metadata (timestamps, rule and model versions, counts) described in the Privacy Policy. On the free scan, the pending window is 24 hours.
Client workspaces. An account can hold several client workspaces. Documents, scans, reports and settings — states of operation, headcount, retention — are isolated per client workspace. What that means for consultants uploading their clients' documents is set out in Working on behalf of clients below.
Where it is processed. Hosted and processed in the United States. Application and database on Railway (US), edge and DDoS protection by Cloudflare, AI processing by Anthropic's API. We do not offer processing outside the United States and do not accept data subject to EEA, UK, or Swiss data-protection law.
Privilege and work product. Using DefensibleHR does not create an attorney-client relationship, and we make no representation that scan results are privileged. If your review is being conducted under counsel's direction, have counsel decide whether and how the tool is used within that engagement; our reports are structured so that findings can be handed to counsel as a marked-up draft rather than a conclusion. We will support a firm's own confidentiality and supervision obligations with the templates below.
Supervision record. Every account keeps an activity record of who uploaded, reviewed, exported and changed settings, and when. It is append-only at the database level, retained for 365 days, and an account admin can view it and export it as a CSV file. It supports a firm's supervision duty; nothing more is claimed for it.
What a finding contains. Every finding rests on a versioned rule from our rule library (federal plus California, Colorado, Illinois, Massachusetts, New Jersey, New York, Texas and Washington). It shows the category the rule falls into for that jurisdiction — required, recommended or optional — the authority citation and link, the jurisdiction, the effective date, the rule's last-reviewed date, and the rule id and version, and it quotes the exact line of your document it points at. We no longer show Critical / Warning / Informational severity ratings. Findings describe where a document appears to be in tension with an authority and what a reviewer should confirm; they do not declare a document unlawful, and each report carries one counsel note counting the Required findings to confirm with an employment attorney before the document goes out. Each rule records the primary source it rests on and the date it was last reviewed. Read the methodology.
Your documents are safe
Built from the ground up for sensitive HR data.
When you upload a document, it is reviewed against our rule library and the original file is never stored on our servers. Structured personal identifiers — Social Security numbers, phone numbers, email addresses, dates of birth, driver's licence, bank account, card, EIN and passport numbers — are automatically redacted before analysis. Names, job titles and narrative text are not redacted and are included in the text sent for analysis, so review what you upload. Extracted text is purged 90 days after the scan, and you can delete any document and its data at any time; a client workspace can also be set to delete text as each scan finishes.
AI-powered, not AI-trained
Your documents are never used to train AI models.
Our AI analysis is powered by an enterprise-grade API with strict contractual data protections. This is fundamentally different from consumer AI tools like ChatGPT:
No model training: Your data is never used to train or improve AI models
Temporary processing only: AI inputs are retained in accordance with Anthropic's then-current data retention policy, then deleted — never used for training
Encrypted in transit: All data is encrypted during transmission
No cross-contamination: Your documents are never visible to other users or mixed into shared contexts
Enterprise-grade security
Defense-in-depth protections at every layer.
✓Encryption for all data in transit
✓Secure authentication with encrypted password storage
✓Session protection against cross-site attacks
✓Injection prevention via content security policies
✓Abuse prevention with rate limiting on all endpoints
✓Organization isolation — users see only their own data
✓Append-only activity record of security-relevant actions, exportable by account admins
✓File validation to prevent malicious uploads
✓Multi-factor authentication (authenticator app plus recovery codes) and login lockout
✓Bot protection on contact and demo forms via Cloudflare Turnstile
Data retention policy
We keep data only as long as it's needed.
Data type
Retention
Original uploaded files (PDF, DOCX, TXT)
Deleted immediately — never stored on our servers
Extracted document text
Purged 90 days after the scan, instantly on user deletion. An account or client workspace can choose to delete text as each scan finishes. Free scan: 24-hour pending window.
Scan results and findings
Findings hold only the quoted lines and offsets, category, citation, and rule id and version. Narrative findings and example language are purged 90 days after each scan; instantly on user deletion. Scan metadata (category and internal severity value, rule and model version identifiers, document filename, file and text hashes, timestamps, counts) is kept up to 3 years after account closure for security and dispute-resolution purposes — see the Privacy Policy.
AI provider inputs
Retained per Anthropic's then-current data retention policy, then deleted — never used for training
Supervision record (account activity record)
Append-only; 365 days, then automatically purged. Viewable and exportable as CSV by an account admin.
Website funnel events (page and step events keyed to a session identifier)
90 days
Account information
Deleted within 90 days of account closure
DefensibleHR vs. general-purpose AI
Why pasting documents into ChatGPT puts your organization at risk.
Privacy factor
DefensibleHR.ai
ChatGPT (free/Plus)
Data used for AI training
No
Yes by default
PII redacted before AI
Automatic
No
Visible to other users
No — org-isolated
Possible
Record of what was reviewed
Scan record plus append-only supervision record
None
Data retention control
Text purged after 90 days
Indefinite
HR-specific compliance scan
Purpose-built
Generic advice
Consistent output format
Structured results
Varies
Jurisdiction-specific rules
Federal + 8 states, each rule cited and versioned
No
Working on behalf of clients
For consultants and firms that upload documents belonging to their clients.
Client workspaces. Each client's documents, scans, reports and settings (states of operation, headcount, retention opt-in) sit in their own workspace, isolated from every other client on the account. You are responsible for having the authority to upload a client's documents and for what you deliver to that client.
Batch audits. Up to 50 documents in one upload, producing a consolidated report ordered required-first with a "what was not checked" section, so the limits of the audit are stated on the report itself.
Branded and white-label outputs. PDF reports can carry your logo, colours and name. On the Consultant 3 plan the "Prepared with DefensibleHR" attribution line is removed. Every output, branded or not, keeps the disclaimer that it was produced by an AI-powered assistant and is not legal advice.
Word outputs. A comment redline (.docx with anchored comments) and, where a finding carries example replacement language, a tracked-changes redline. Both are generated from the analyzed text rather than from your original file, and example language is labelled "example language — review with counsel before use".
Keeping the rule library current
How rules change, who approves a change, and where changes are published.
Our rule library is versioned. A monitoring process checks public sources such as the Federal Register and the Department of Labor each day and drafts proposed rule edits into a review queue. Nothing in the library changes without a person reviewing and approving it. Approval bumps the rule's version and last-reviewed date.
Public change digest. Every approved change is published at /changes (with an RSS feed): jurisdiction, document types, clause affected, authority citation and link, effective date, review date, and rule id and version. Reviewer names are not published, and the digest carries a not-legal-advice note.
"This rule looks out of date." Signed-in users have this control on every finding. It files the finding, your note, and your user and organization ids into the same review queue. Reports are internal and are not published.
Website forms, lead capture and analytics
What the public pages collect before you sign in.
Sample audit. The full sample report is shown after you give a name, work email, firm and role. We store those details as a lead and send one personal follow-up.
Demo requests. The consultant and firm demo-request forms create a contact record tagged with its source.
Bot protection. Contact and demo forms use Cloudflare Turnstile, a third-party script loaded on those pages.
Funnel measurement. We record page and step events on the server against a session identifier, with a bot classification, to measure conversion. No cookies are added beyond those described in the Privacy Policy, and funnel events are kept for 90 days. This page also loads a Google Ads tag configured with ad-personalization signals off and restricted data processing.
Compliance readiness
Designed with regulatory frameworks in mind.
CCPA/CPRA: User data deletion on request, no selling of personal data, right to access and portability
SOC 2: We are not SOC 2 certified. We maintain a readiness mapping of our controls (access control, activity logging, encryption, retention, incident response) to the SOC 2 criteria; ask us about it during procurement
Data-handling principles: Data minimization, purpose limitation, and storage limitation by design (Services are offered exclusively within the United States; all processing takes place in the United States)
Data processor role: We act as a data processor on behalf of our customers, processing employee data — including documents a consultant or firm uploads on behalf of its own clients — solely at your direction
Questions?
If you have questions about our security practices, need a Data Processing Addendum (DPA), or require additional documentation for your procurement process, contact us at [email protected].
For our complete privacy practices, see our Privacy Policy. For terms governing use of the platform, see our Terms of Service.