SECOND LENS Hiring Ledger
v1.0.0

Second Lens

Hiring Ledger

Check a job advert or a pre-offer document against named provisions of UK law, decide what to do about each flag, and walk away holding a dated record of both.

If a complaint about one of your adverts arrives in eighteen months, the question will not be whether the wording was perfect. It will be whether you can show, quickly, that somebody looked. This produces that record as a by-product of the check, so nobody has to remember to make one.

Your document is never stored. No sign in. No candidate data is ever accepted.

Green means you can do it on this instance today Grey means it needs the application running inside your own network

Two kinds of role, and only one of them can be checked here

An externally advertised role is about to be published to the world, so its wording can safely leave your network. An internal-only role is described in documents your data loss prevention policy will not release, and it should not have to. Watch what happens to each.

    Three things, in the order that matters

    1. 01

      It names the provision

      Every flag carries the specific section behind it, not a bias score. The section is attached from a versioned rule set after the check, never written by the engine, so it cannot be a section that does not exist.

    2. 02

      It covers the whole pre-offer pack

      Adverts, application forms, assessment briefs and monitoring forms. Most exposure sits in the documents after the advert, and those are the ones nobody reviews.

    3. 03

      It produces the record

      Every flag gets accepted, amended or overridden by a person, with a typed reason when it is overridden. That log is the product. The check is how you get it.

    What this is, and what it is not

    What it is

    • A check on employer written recruitment wording against public UK legal sources.
    • A record of what was checked, against which version of the rule set, and what a named person decided about each flag.
    • A tool that proposes. Every flag is accepted, amended or overridden by a person, and overriding is a legitimate answer.
    • Honest about what it did not examine. Every record lists the rules that were not checked and why.

    What it is not

    • Not legal advice, and not a formal legal audit. Verify any point of law with a qualified adviser.
    • Not a candidate tool. It never accepts a CV, an application or anything naming an applicant, and it does not screen, rank, match or shortlist people.
    • Not a guarantee of compliance. It records that a check happened and what was decided.
    • Not tamper proof. The record is tamper evident, which is a different and smaller claim, set out below.

    What it can do

    Eight things, each available on this instance today

    Take the document however you have it

    Paste it, or drop in a Word file, a text file, a Markdown file or a saved web page. It is read in your browser and only the plain text is sent on.

    Check against 15 rules

    Indirect discrimination, reasonable adjustments, pre-offer health questions, occupational requirements, coded language, culture wording, document accessibility and pay transparency.

    Quote the exact wording

    Each flag highlights the phrase in place in your document. A flag whose quoted wording is not found in your text is discarded before you see it.

    Offer a rewrite you can paste

    Accept it, edit it, or reject it. The document rebuilds as you go, and you can copy the corrected version out at the end.

    Record an override properly

    Overriding is allowed. Overriding silently is not. An override needs a typed reason, and the reason is the part that is worth having later.

    Switch jurisdiction properly

    Northern Ireland is a different framework, not a different footnote. Selecting it changes the whole citation set, and the two are never mixed in one record.

    Seal and download the record

    A dated PDF with the record reference, the rule set version, a content hash, every flag, every decision, every reason, and what was not checked.

    Show its own working

    Every record states the rules that were skipped and why, and how many proposed findings were discarded for failing verification.

    How it works

    Paste, check, decide, seal
    1. 1

      Paste or upload

      One document at a time. Tell it what kind of document it is and where the role sits.

    2. 2

      Check

      The wording is compared against the rule set. Every quoted phrase is verified against your text before it is shown.

    3. 3

      Decide

      Fix it, replace it, remove it, override it with a reason, or defer it. Nothing is decided for you.

    4. 4

      Seal

      The record closes with a content hash and downloads as a dated PDF.

    Anyone can copy the list

    What a copy does not come with

    The provisions this checks against are public law. The rule set is published in this application at What is checked, in full, on purpose, because you cannot rely on a check whose rules you are not allowed to read. So yes, the list can be copied, and a general purpose assistant can produce something that looks like it in a minute. That is worth saying plainly, because the thing that matters is what a copy does not come with.

    • A copy is accurate on the day it is made, and not after

      Recruitment law moves. The Employment Rights Act 2025 changes the harassment duty from reasonable steps to all reasonable steps on 30 October 2026, and adds a duty not to permit harassment by third parties on the same date. This rule set carries a version, the date it was derived, a review date, and a record of which source was read and when, all shown at What is checked. A copied list carries none of that, and nothing in it says when it stopped being right.

    • The list is the easy part. Knowing how each provision behaves is not

      Section 60 restricts pre-offer health questions in Great Britain and has no Northern Ireland equivalent, so it is carried there as good practice rather than as law. The Disability Discrimination Act 1995 was repealed for Great Britain in 2010 and is still in force in Northern Ireland, so a Northern Ireland record cites it and never cites the Equality Act. A driving licence requirement is a problem in one role and correct in another. That judgement is what the rule set encodes, and a list of section numbers does not contain it.

    • Nothing here is decided by the software

      Every flag is put to a person, who accepts it, replaces the wording, removes it, defers it or overrides it. An override will not close without a typed reason. The engine proposes and a person decides, always, and that is why the output is a record of a human judgement rather than a machine opinion about your advert.

    • The oversight is visible, not asserted

      The record shows what was checked, what was skipped and why, how many proposed findings were discarded for failing verification, who decided each flag and what reason they gave. An answer pasted out of a chat window shows you the answer and nothing else. Being able to show the working, eighteen months later, is the whole product.

    Three things this does not claim. Attribution is currently "Anonymous, this session", because there is no sign-in yet, and a record that cannot name who decided is not finished evidence. The review is a quarterly review of public sources by the people who maintain the rule set, not a solicitor signing off your advert. And not every source could be reached when the rule set was last reviewed: the ones that could not are listed as such under What is checked rather than quietly presented alongside the ones that were. This is not legal advice and does not replace taking any.

    Two ways to run it, and what changes

    Hosted here, or inside your own network

    The difference is not a licence key. It is where the document goes. An advert about to be published to the world can safely leave your network. An internal role description, or your own recruitment policy, usually cannot, and your DLP policy is right to say so.

    Hosted

    What you are using now

    Your network

    The advert

    Outside

    Public model API
    • Your document is never stored, anywhere, at any point.
    • Operational events are kept: presses, errors and the shape of each check. Never the document.
    • The record lives in your browser tab and is lost on refresh.
    • Suitable for anything you are about to publish. Not suitable for confidential documents.

    Inside your boundary

    Enterprise, not available on this instance

    Your network, and nothing crosses this line

    The advert Your policies The application Your model Your guardrails Your record store
    • Inference happens where your other inference happens, under the same contract and the same residency terms.
    • Your content filters, logging, rate limits and approved model list all apply. The controls this product enforces sit underneath yours, not instead of them.
    • Internal-only roles and Layer 1 policy checking become available, because the documents they need never have to leave.
    • Records are written to your storage under your retention schedule, so the archive does not depend on a supplier account continuing to exist.

    The enterprise controls are shown on the check screen rather than hidden, greyed out with the reason attached. You cannot evaluate what you cannot see, and the reason each one is unavailable is a data boundary rather than a price.

    Stated plainly

    What this does not do, and what is not built yet
    The record is tamper evident, not tamper proof.
    Sealing takes a SHA-256 hash over the ordered record. That makes silent alteration detectable by anyone holding an earlier copy. It is not a trusted timestamp and it does not prove to a third party who was not holding a copy that the record existed at the stated time.
    The rule set is derived from public sources and is reviewed quarterly.
    Equality Act 2010, the EHRC Employment Statutory Code, EHRC advert and pre-offer health question guidance, ACAS recruitment guidance, and for Northern Ireland the Disability Discrimination Act 1995 and the separate Orders. Some Northern Ireland citations name the instrument without pinning the article, and where that is so the flag says it on its face.
    Some rules fire on an absence.
    A missing route to request an adjustment is a flag. Because there is no wording to quote, the passage nearest to where it should have appeared is quoted instead, and the flag says so.
    This version keeps nothing.
    The working record lives in the memory of this browser tab for as long as it is open. Refreshing loses it. Download the PDF before you close the tab. Server held records, retrieval by reference, and a chain across records arrive in the next phase.
    No live enterprise use is claimed.
    This is a first working build. No adoption has occurred and none is implied anywhere in this product.

    Privacy and data protection

    Fifteen questions, answered plainly

    Where an answer is not settled, it says so rather than guessing. A confident answer from a supplier who cannot actually guarantee it is worse than no answer.

    Where does my document go?

    On this hosted instance the text you paste is sent over TLS to a model API outside your network, checked, and the answer comes straight back to your browser. It is not written to a database, a file or a log at any point in that journey, including the operations log described in the next answer, which has no field capable of holding it. Running the application inside your own network changes this: the text never leaves, because the model endpoint is yours as well.

    Do you store anything at all?

    Yes, and it is worth being exact about what. This instance keeps an operations log so that whoever runs it can see faults rather than wait to be told about them. Each entry is one of: a control was pressed, a screen was opened, a check completed, or something returned an error. A check entry holds counts and timings, so the number of flags, the score, how long it took and how many characters long the document was. That is all.

    What it never holds is your document, any wording from it, its title, or the name of a file you chose. This is not a promise about careful coding: every entry is rebuilt on the server from a fixed list of permitted fields, so a field nobody named has no route into the log at all, and the one free text field is discarded outright if it reads like prose from a document. There is a test that runs the whole application and asserts the sample advert's own wording appears nowhere in anything the browser sent.

    There is no third party analytics, no advertising identifier and no third party script. The only cookie is the one that holds an operations console session after somebody signs in with the console password, and no cookie is set for an ordinary visitor. The working record still lives in the memory of your browser tab and is gone when you refresh, which is why the interface tells you to download the PDF before you leave.

    What is in the operations log, and for how long?

    One entry per thing that happened: a control was pressed, a screen was opened, a check completed, or something returned an error. With each entry go the width of the window, whether the pointer is a finger or a mouse, and whether reduced motion is switched on. Those three explain almost every layout fault and identify nobody. There is no IP address, no browser fingerprint, no advertising identifier and no account, because there are no accounts.

    Entries are deleted after thirty days, automatically, and whoever runs the instance can delete a day outright from the operations console before then. The console itself needs a password that is set in the deployment environment and never reaches this page.

    Honest limitation: like a web server access log, this exists so faults can be found. If you would rather it did not exist at all, run the application inside your own network, where the log is yours and so is the decision about keeping it.

    Is a job advert personal data?

    Usually not. An advert and an application form are employer authored documents describing a role, and they do not normally identify anyone. They can contain a recruiter's name or email, which is personal data about that person, so treat the check as processing that small amount. What this product will not take, at all, is a document about a candidate.

    Why does it refuse CVs and applications?

    Because accepting them would change what this product legally is. Screening people would bring it inside the ICO's rules on automated decision making in recruitment and inside the EU AI Act's high risk recruitment category, and would put a data protection impact assessment in front of every sale. Refusing candidate data is the architectural decision the rest of the design rests on, so it is enforced in the server and cannot be switched off.

    Are you a controller or a processor?

    For the text you submit here, a processor acting on your instruction, since the check exists only to answer your question about your document. That is the honest description of the relationship rather than a completed legal analysis, and this hosted instance is a demonstration with no contract behind it. A data processing agreement belongs with a paid tier and does not exist yet. If you need one before using it, wait, or run it inside your own network where the question does not arise.

    Is my document used to train a model?

    Not by this product, which keeps nothing and therefore has nothing to train on. What the model provider does with API traffic is governed by their terms, not by anything stated here, so check those directly rather than taking this page's word for it. This is exactly the kind of question where a confident answer from a supplier who cannot actually guarantee it is worse than no answer.

    Where does the inference physically happen?

    This has not been pinned for the hosted instance and this page will not pretend otherwise. The first party model API is global by default, and regional routing carries its own arrangements and price. If your organisation has a UK or EU data residency requirement, verify the current options with the provider before relying on the hosted instance, or run the application inside your own boundary against an endpoint whose location you already control.

    What if my DLP policy blocks this?

    Then your DLP policy is working. An internal role description or your own recruitment policy should not be sent to a third party, which is precisely why those capabilities are greyed out here rather than offered with a warning. They become available when the application runs inside your network, where those documents already are.

    Who can see a sealed record?

    Only whoever holds the PDF or the JSON you downloaded. Nothing is published, nothing is shared and there is no link anyone else can follow, because there is nowhere for it to be stored. Retrieval by reference is a later phase and is not built.

    What is in the record, and what is not?

    The record carries the document title you gave it, the wording that was flagged, the provision behind each flag, what was decided, the reason typed for any override, timestamps, the rule set version and a SHA-256 hash of the whole thing. It also carries a hash of the document text rather than the text itself where it can. It never carries a candidate name, because none was ever accepted.

    Does the hash prove anything to a court?

    It proves less than people assume, and overclaiming here would destroy the product's value faster than any bug. The hash makes silent alteration detectable by anyone holding an earlier copy. It is not a trusted timestamp and it does not prove to somebody who was not holding a copy that the record existed when it says it did. The accurate word is tamper evident.

    Can the check be talked into passing a bad advert?

    It is built on the assumption that someone will try. A document telling the engine to report no issues is treated as content and reported to you rather than obeyed, every quoted phrase is verified against your own text before you see it, and the legal citation is attached from a versioned rule set rather than written by the engine at all. A tool that could be talked into issuing a clean record would be worse than no tool, because it would manufacture false evidence.

    What is logged on the server?

    The serverless function writes operational lines only: an error class, a status code, a request identifier, and a note when a document contains wording aimed at the engine. Document text is never written to a log. The platform keeps its own request logs, as any host does.

    Can I delete my data?

    There is nothing held to delete. Close the tab and the working record is gone. If you downloaded a PDF, it is yours and only yours.

    Check something and see what it does

    It takes about a minute. Nothing is kept, and there is nothing to sign up to.