Lexicera Request a demo

Platform

All of it, and what it does not do.

67 capabilities, grouped by the part of a practice they belong to. Each one carries its deliberate limits directly underneath it[1] — a gap named once at the bottom of a page is a gap that was hidden.

This page is generated from the same registry the product is built against, so it cannot describe a feature that does not exist, and a capability cannot ship without its entry here.

How it works

When a document arrives

1 It arrives Upload it, or forward it to the matter's own email address. It is encrypted before it leaves your building, and charged per page — the same rate whichever way it came.
2 It is read Once, ever. The document becomes individual facts, each carrying the exact sentence and page that supports it.
3 It is compared Against everything already in the file: contradictions, duplicates, gaps, dates that cannot both be true.
4 It is usable Ask the file a question and get an answer with its citations. Nothing in it needed re-reading.

That ordering is the whole economic argument. Getting a document in and reading it are the two operations you pay for, once each; everything afterwards works from the facts reading produced, which is why a question against a ten-thousand-page file costs cents.[2]

Why this rather than a document reader

Four things that are structural, not settings

The screen is enforced in one place

Wall a matter and it disappears everywhere at once — search, briefings, calendars, exports — because every read passes through a single seam.[3] To someone off the list it returns the same answer as a matter that does not exist.[4] The AI cannot be asked about it either, which is usually the question a conflicts partner is really asking.

Running out of credit does not lock your files

A zero balance pauses AI work and nothing else. Documents, downloads, search and everything already extracted stay available.[5] A firm that cannot pay this month still owns its practice.

The prices live in one file

A price that is not in that file may not appear on this site, and the test suite checks both directions — every published figure must appear, every retracted one must be gone.[1] It is a strange thing to build. It is why nothing here is quietly out of date.

Florida is counted as Florida

State matters count under Rule 2.514, including the start-day skip and the five-day service extension where federal practice adds three. An unrecognized counting mode throws rather than quietly computing federal dates for a state case.[6]

Intake and conflicts

Intake, conflicts, and limitations

You know within minutes of the phone call whether you can take the case and how long you have to file it — before a matter exists and before anyone has put a day into it.

An intake is not a matter. Conflicts are checked by name similarity — not exact match — across every party in every matter the firm has ever had. The SOL calculator computes from versioned, cited statutes and says plainly when accrual is a question of fact rather than a date. The matter is created last, after a signed engagement letter.

  • A prospective client who fails a conflict check never causes a matter row to exist.
  • SOL rules ship as drafts until an attorney confirms them.

Inquiries from your own website

An inquiry from your website arrives as an inquiry rather than as an email somebody has to re-key, and the first thing you see about it is whether you can take it. The conflict that would have surfaced on day three, after a partner had already replied warmly, surfaces before anyone reads the name.

Your website posts to an address belonging to your firm. The conflict check runs on submission — it is a name comparison in the database, it costs nothing and calls no model — so the inquiry lands already carrying its conflict status. The limitations analysis deliberately does NOT run here: that one is a model call and this address is reachable by anyone on the internet, so wiring it in would let a bot inside the rate limit burn your prepaid balance to no purpose. It runs when a person at the firm opens the inquiry, which is the moment it is worth anything. Nothing submitted is ever rendered back — every field is treated as hostile, stored and never reflected.

  • It is an address, not a form. What your visitors see is your website's own form; we give you where to send it and what it accepts.
  • The limitations analysis does not run until a person at the firm opens the inquiry, deliberately — an anonymous form that can spend your balance is a hole a rate limiter narrows rather than closes.
  • It is rate-limited per address and overall. A burst is dropped rather than queued, and a dropped inquiry is logged without its contents — so a genuine flood of real inquiries is something to tell us about rather than something to discover.

Clients

Client detail confirmation, and the firm's review of it

The address a bill goes to and the name on a legal notice are checked by the person they belong to, once for every case, without anyone at the firm chasing them for it. And you get the one thing nobody can collect any other way: mobile numbers your clients have expressly agreed may be texted — which is what the carriers now require before a single billing text is allowed to leave.

The first time a client opens anything for a case — their portal, an engagement letter, an invoice or its payment link — a popup over the page shows the four details you hold for them, each with its own Edit link. If nothing is wrong, one click on "These are correct" confirms them; if they change something, the changed line is marked with what it used to say and the button becomes "Save changes". It is required: the popup has no close button, and on an invoice the Pay button stays disabled until it is answered. Clients who have already paid are asked once too, on their next visit, and the button just saves. It is asked once per client per case, so a client on two cases confirms once for each. "These are correct" is refused while there is no mailing address on file — a street, a city and a ZIP — so a client cannot confirm, or pay, past a missing address; they add it in the same popup. ONE RULE DECIDES WHAT APPLIES AT ONCE: only the signed-in portal changes the record directly. A payment link and a signing link are links anyone holding them can open — they can be forwarded, and a payment link can lead to the signing page — so on both, the mobile number and the email are shown masked and cannot be edited, and a corrected mailing address waits for approval like a name (it still counts as given, so the client can pay). In the portal, a corrected mailing address or mobile number is saved to the client record straight away and recorded in the audit trail with what it was before. A correction to name or email goes into a queue for somebody at the firm to approve or reject — nothing a client types changes who your bills are addressed to or where they are emailed until a human has looked at it, but the client has done their part and is not asked again. A corrected email is the client's sign-in, so a one-time code goes to the NEW address and the firm cannot approve the change until it has been typed back. Ticking the box that agrees to billing texts is the client's own act and applies at once on every page; on a link it is recorded against the number on file, and with no number on file a payment link offers no box, pointing to the portal instead. A client who has told the carrier to stop texts sees a sentence saying so and no box at all — nothing here can undo that, and nothing here tries. Afterwards a quiet line under the total says the details are confirmed and lets the client update them any time. Staff can correct the mailing address themselves too, from "Edit contact details" on the client's page. An approved name, address or email correction also changes that client's unpaid bills; paid bills keep theirs, and the bill keeps a record of what it said when it was issued.

  • A client's name or email edit never changes the record on its own. Someone at the firm approves it. That is deliberate: a typo — or a malicious edit on a forwarded link — would otherwise redirect a firm's bills and sign-ins with nobody checking.
  • Only the signed-in portal changes a client's record without review. On a payment or signing link — either can be forwarded — the number and email are masked and fixed, and an address waits for approval. Portal address corrections filed before this rule shipped are applied by a one-time command when they carry nothing but an address and the record still says what the client corrected; ones from a link stay in the queue.
  • The fields are the same for every firm: name, email, mobile, mailing address. Firms cannot add their own questions to this page in this version.
  • It asks once per case. After a client confirms for a case, the popup does not come back on its own for that case — there is no re-confirmation schedule.
  • An email address can be corrected only from the client portal, and code emails are limited to one a minute and five a day per client, and fifty a day per firm.
  • An intake does not count as a confirmation today: the intake form collects name, email and phone but no mailing address and no "these are correct" step, so a client who came in through intake is asked once like everybody else.
  • It is not identity verification. It confirms what the person signed in as says their details are; it does not prove who they are.

Client portal

The client sees every document filed with the court on their case, by title, with a stage marker your staff move by hand — so "what has been filed?" stops being a phone call — and, where you have switched it on for them, can send you documents straight from the portal, with no link to issue and nothing attached to an email. They also see everything they have sent and when it arrived, so "did you get it?" stops being one too. The first thing a client sees is what the firm needs from them — a letter to sign, a bill to pay, details to confirm — and it empties as they do each one.

A separate credential type in its own tables, with access granted per matter. There is no "all matters" value and no way to express one, so the worst a scope bug can do is grant the wrong single matter. Court filings are the documents staff mark as filed with the court: only marked documents are shown, by title only, and they are on by default for every case — a firm turns them off on the case page.

  • Nothing marks a document as a court filing automatically — not a docket match, not a document fetched from a court notice. Staff mark each one.
  • Clients see titles only; the platform writes no summary of a filing or of the case.
  • Access is granted per CASE, not per matter: a client on a case reaches every matter of it. Each matter is still its own row and there is no "all matters" value; what this means is that narrowing further — to one client's own letters, or their own uploads — is each screen's own job rather than the access table's.
  • Nothing in the product ends a case membership yet, so access is opened by the roster and closed only by hand.
  • A client can only send to the matters of the cases they are on, and only while you have their upload permission open for that matter. Files that reached you by email, or through an anonymous case link, are not attributed to anybody and so are not listed for anybody.
  • The upload switch changes a client's existing access to a matter; it never creates access. Where a client has no access to a matter there is no switch to press, and a request to close uploads there is refused and says why — because recording "uploads off" for someone with no access would, in the same act, give them the matter.

Document requests

Instead of chasing a client by phone for the letter you need, you ask once from their page and it sits at the top of what they see when they open their portal. They send the one file, it is filed into the matter you chose, and the request shows Received with a link to the document. On a class case you can ask everybody at once and see who has sent it and who has not.

A request names one client, one matter and what you need. It appears in the client's "What we need from you" list with an Upload button; uploading asks them to confirm it is them first, and the one file they send answers the request in the same step that files it. Requests follow the ethical wall: nobody screened from the matter sees or can create one on it. Nothing is emailed or texted when you ask.

  • One file answers a request. A request for several documents is several requests.
  • There are no due dates or reminders yet, and asking sends no email or text: the client sees the request the next time they open their portal.
  • Where a client may not upload on the chosen matter, they see the request without an Upload button and are told the firm will explain how to send it.

Signing the engagement letter

The client can sign on the phone in their car, and you do not chase a scan. You can also see whether they have even opened it, which is the question that used to be a phone call. What you keep afterwards is better than a scan: if anyone ever edits the letter after it was signed, the record says so, rather than leaving you to argue about which version was agreed.

Your firm has one engagement letter. Sending it fills in the client, the matter, the fee basis and the fee terms, and your own signature block, and freezes the result — so the letter that goes out is already signed by the firm and needs one signing pass, not two. The client gets an email with the link inside it; the link needs no login, is single-use, and expires. The signer reads the letter, ticks that they agree to it, ticks that they agree to do this electronically — two separate consents, because the law asks for both — and types their email and full legal name. What is stored is both consents, the name, the address and browser it came from, the moment, and a SHA-256 of the exact words that were on the screen. That last one is the point: a letter altered after signature no longer matches its own seal, and the inquiry says so plainly instead of quietly. The signed letter is emailed back to the client as a file at the moment they sign, filed into the matter as a document, and — once they have a portal login — stays visible to them there. On a case with several clients on it each of them sees their own letter and nobody else's. A matter cannot be opened until a signature exists — the button stays disabled. A firm can also hold payment behind the letter: with "Sign before paying" on in Settings, a client whose letter for a matter has been sent and not signed is asked to review and sign it before they can pay an invoice for that matter — on the payment link and in their portal — and comes straight back to the invoice to pay once they have. A letter that was voided or declined never holds a payment, nor does another matter's letter, and a client who signed the paper copy is released by "Mark signed on paper" on their client page. Sending a new letter for the same client and matter voids the older unsigned one, so only the newest is ever waiting, and once any letter for that matter is signed nothing holds.

  • It is a typed-name signature with an intent record. It proves what was agreed to, when, and from where; it does not prove who was at the keyboard, and it is not a notarisation or an identity check.
  • One letter per firm. The fee section is filled in per client when you send it, but the words around it are the same letter every time, and changing them is a thing we do for you rather than a screen you edit.
  • The link expires and is single-use. A client who loses it needs a new one issued — there is no way to reopen a link that has been used.
  • The signed copy is a web page rather than a PDF. It prints correctly and carries its own seal; the PDF arrives when the rest of the product's PDF machinery does.
  • There is no decline button on the signing page. A client who does not want to sign tells you, and you deal with it the way you would on paper.
  • "Signed on paper" is a marker, not a signature. It releases the payment hold and says who marked it and when; it does not make the letter "signed" here, and no signed copy or seal exists for it — keep the paper.
  • This is the engagement letter and nothing else. No other document in the product goes out for signature: settlement authority, releases and substitutions of counsel travel the way they do today.

Documents

Secure document depot

Everything filed in a matter sits in one place and is findable by a phrase you half-remember, instead of spread across an inbox, a shared drive, and somebody's desktop. What you hand back is the file you were sent, not a copy somebody re-saved.

Each file is encrypted on the server with a key unique to that file, which is itself locked with a key belonging only to your firm. Only ciphertext reaches the storage vendor — they hold bytes they cannot read. A SHA-256 of the original is kept as a seal, and every download is checked against it, so alteration is detectable rather than silent. The seal is also what makes the second copy free: Within a matter, the same document is never ingested, read, or billed twice. A file already in the matter — the same bytes, arriving again by upload, by email, or in a bulk import, from a production, a client dump, or a second custodian — is recognized by its seal and costs nothing: it is neither read again nor charged again.

  • A recording is filed here and transcribed by the media lane; the picture itself is stored and indexed by key frames, never watched or described.
  • A single upload is capped at 200MB. A file over it is refused rather than truncated, and the way to bring something larger in is the bulk import — which is an operator command, so it is a conversation rather than a retry.
  • A zip archive is opened and filed as the documents inside it, each read and searchable in its own right, with the archive itself kept as it arrived. Only the top level: a zip inside a zip is filed whole. An archive that is password-protected, damaged, over 500 files, or that would expand out of all proportion to its size is kept exactly as it arrived, with a line on the document saying which of those it was — nothing is ever half-unpacked.

Email into a matter

The thread and its attachments end up in the file because you forwarded an email, not because you downloaded three attachments, renamed them, and uploaded them again. Whatever arrives is read and compared against the record like anything else.

Each matter gets its own address, named by you and unique within your firm, on your firm's own subdomain — and the firm has one more, file@ or another name picked from a short list, for mail whose case you would rather choose later: it waits in the arrivals queue until someone picks the case. Addresses are resolved firm first, so two firms can use the same name and mail can never cross between them. Renaming an address retires the old one; it stops working and is never given to another matter. Mail is received by a machine of ours that holds no documents, no database and no key material — a dedicated receiver that hands each message to the platform over an authenticated channel, where it is encrypted. No outside mail company reads your clients' mail, and opening a mail port on the machine holding privileged documents is still not a trade worth making, which is why it is a second machine. Duplicates are collapsed by Message-Id. A federal court notice (a CM/ECF Notice of Electronic Filing from a uscourts.gov sender that passes SPF) does not attach its document — it links to it, and the link allows one free look before PACER fees apply — so the platform follows each document link the moment the notice arrives, keeps the PDF encrypted, and files it: into the case automatically when the notice's case number matches exactly one of your cases in that same court (the case's court must be filled in) with one open matter, otherwise held with the notice until someone picks the case.

  • Requires INBOUND_WEBHOOK_TOKEN, and an MX record for the firm's subdomain. Fails closed when unconfigured.
  • Tier 0: every address is on <firm>.lexicera.com, which is our domain, and is INTERNAL USE ONLY until the firm verifies its own domain — a filed address outlives the relationship, and one on our domain cannot be repointed by a firm that leaves.
  • Mail is not received at <firm>.lexicera.com for any firm: each firm's portal address there is a CNAME to our server, and a mail (MX) record cannot sit beside a CNAME, so creating a firm records its firm address and publishes no mail record on our domain. The mail server's own list of accepted domains is not wired yet either (LEX-377).
  • Court notices: only federal CM/ECF notices are fetched today (uscourts.gov senders that pass SPF, links on ecf.<court>.uscourts.gov). The court's link allows one free look, so a document is never fetched twice; a link that was already used, has expired or needs a PACER login is marked "download this document manually" in the arrivals list and is not retried — no PACER login is ever used, so no fee can be incurred. PDFs only, up to 35 MB.
  • Replies do not file themselves yet: the rule that would add a self-filing Reply-To applies only to staff-facing matter mail, no such mail is sent today, mail with an attachment never carries one, and mail to your own clients never carries one while your addresses are on our domain.

Arrivals

You can answer "did that get here, and what happened to it" without asking anyone. And nothing lands in the wrong client's file quietly: the folder is a guess you can correct in a second, the case never is, so a document we are not certain about sits in one visible queue until a person says where it belongs.

Everything that arrives writes one row: the channel it travelled on, the sender, the subject, what became of it — filed, a recognized duplicate, ignored, held — and who made the call. "Who" is the point: the address it came to, a rule that matched, the model, or a named person. A document that arrived at the case's own address is certain and files instantly, with the model free to choose its folder. A document whose case was inferred is held: its file is encrypted and parked, no case is stamped on it, and it appears here with the suggested matter, the confidence and the reasoning, for one click to accept or a picker to override. Mail sent to an address that matches no case is logged too, and belongs to no firm — it is never guessed onto one. Arrivals for matters you are screened off do not appear, including the held ones whose only link to a matter is the suggestion. Adding a document does not mean going and finding the matter first. "Add documents" is in the menu on every screen and on the dashboard, and a file dragged onto any page opens the same panel with the file already attached — with the case pre-selected when you are looking at one. You choose the files first and the case second, and nothing is uploaded until you confirm, so a file dropped by accident costs nothing. Choosing the case files it instantly and certainly, exactly as uploading on the matter always did. Choosing "I am not sure yet" holds the file here instead, encrypted and unfiled, until somebody names the case.

  • A case is never guessed on your behalf. A document whose case is inferred waits for a person — which means an arrivals queue nobody works is a stack of documents nobody has filed. The oldest held item's age is printed at the top of the page for exactly that reason.
  • Held files have no expiry and are not counted against your storage allowance. The holding area is bounded only by the queue being worked.
  • A document parked with "I am not sure yet" has no case on it, so it is visible to everyone at the firm in the confirm queue until somebody names one — the same visibility a letter addressed to nobody in particular already has. If a document is sensitive, choose the case instead of parking it; the panel says so at the point of the decision. Its contents are never readable from the queue: the filename and the sender are listed, the file itself stays encrypted until it is filed.
  • A parked file is limited to 16MB, because it is held whole in memory while it is encrypted. An upload with the case chosen is far larger — that limit is about the holding area, not about the document.
  • Mail to an address that matches no case is recorded but belongs to no firm, so it does not appear here. It is never attributed by guesswork — matching a sender's domain to a firm would be a cross-tenant mistake with a plausible excuse.
  • The record of an arrival is append-only. Discarding deletes the file and leaves the row saying it arrived and was discarded, by whom and when.
  • The ledger starts on the day it was switched on. Documents filed before that carry no arrival row, because the channel and sender of a document already in the system cannot be reconstructed honestly.

Auto-filing at ingest

Opening a matter shows the file the way a firm keeps one: by section, titled by what the document is, sorted by the document's own date — not a flat list of upload filenames.

The reading pass that extracts facts also files the document (one model call, not two). Filing is virtual — nothing moves. A hand-filed section is never overwritten by the model; clearing it back to Unfiled lets the next reading re-file it. The vocabulary lives in a table, so a firm's own organization is an edit, not a rebuild.

  • The eight-section vocabulary is a starting point pending the firm's own filing conventions; it is edited live, per platform, not per firm yet.
  • Documents ingested before this shipped stay Unfiled until re-read or hand-filed.

Bringing an existing case in

The banker's box stops being the reason you never moved the case. Hand over the folder exactly as it came off the scanner and by morning it is a matter: every page read, the chronology built, the duplicates gone, and a set of searchable PDFs back in your hands to keep whatever you decide about us afterwards. Nobody at the firm renames a file or clicks upload four hundred times.

An operator points the import at the directory. It walks the tree in a fixed order, skips the scanner's stray dotfiles and anything empty, and identifies each file by its actual bytes rather than by trusting its name. Before anything is encrypted it hashes the file and checks it against the matter, so a duplicate costs no storage and no fee — this is the import path's share of the deduplication promise, enforced at the cheapest possible point. What is new is encrypted with the same per-file key scheme as an ordinary upload and queued for reading BEHIND every interactive job, so a large import never makes a document somebody just uploaded wait. PDF pages are counted at import so the dry run can tell you what the case will cost, and each file then bills at that same count as it is read in. Where a case arrived as one long scanned bundle, a cheap model proposes where each document inside it begins and parks the proposal for review; the cut happens only from page ranges an operator types, and the original bundle is kept, excluded from AI, with its facts retired — pages are never moved between documents.

  • The unitization cut is operator-confirmed — the model only proposes.
  • Splitting a bundle can yield fewer documents than ranges. Where two ranges hold byte-identical pages — two blank separator sheets, the same cover page twice — the second is collapsed into the first rather than filed again, because a matter holds one copy of a given set of bytes. The run reports which ranges collapsed, and the original bundle is kept whole either way.
  • Non-PDF files count as one page for the fee, however long they are. Audio and video count as no pages at all: a recording pays the per-hour transcription rate instead.
  • Bulk extraction runs behind all interactive work — a large case takes hours by design.
  • It is an operator command, not a screen. A firm cannot start an import itself.

Recordings become text you can cite

The deposition video sitting on a disc in the drawer becomes part of the case file instead of a thing somebody has to sit through. You search a phrase you half remember and get the passage, the segment number, and the second of the recording it happens at — so the clip you need for the motion takes a minute to find rather than an afternoon of scrubbing.

A recording is measured for its length, then transcribed by a speech model running on our own server — nothing is sent to a transcription vendor. Each segment of the transcript is filed as a page of the document, which is what lets everything else in the platform treat it like any other document: search indexes it, facts cite it by page, and quote verification checks the words against the transcript. Beside each of those pages is the start and end time in milliseconds, so a citation to "page 7" resolves to a position in the recording. A video also has its key frames extracted and stored encrypted beside it as a contact sheet of where the picture changed.

  • This is automatic speech recognition, not a certified transcript. It is a search and drafting aid, never a substitute for the court reporter's record, and it must not be quoted to a court as the transcript.
  • English only. The model is an English one, and a non-English recording produces nonsense rather than a translation.
  • Speakers are not labelled. Telling two voices apart is not something this can do honestly, and a transcript that attributes testimony to the wrong person is worse than one that attributes it to nobody.
  • A recording with no speech produces no transcript, no pages, and no charge.
  • Video is indexed by key frames, capped per recording. Nothing watches or describes the picture.

What the file knows

The front of the file, correctable

A typo in a case number stops being permanent. A judge who changes stops being wrong on every document the file produces. A party who was never really on the matter comes off it without the firm losing the record that they were once looked at — which is the record a conflict check searches. And the setup checklist stops nagging for fields nobody could fill in.

The Court identity card on a case is a form for an attorney or a firm administrator and a plain table for everybody else. Saving records one audit entry listing every field that actually changed — a re-save that changes nothing records nothing. Changing the JURISDICTION is treated as the significant edit it is: it selects the rule chain every computed deadline on the file was counted from, so every rules-engine date on every matter of that case is marked unverified for an attorney to re-confirm. Nothing is recomputed and no date moves — the same rule that governs every other suggested deadline in this platform. The parties page under a matter's case setup adds, renames, re-roles and removes. Adding and renaming run the firm-wide conflict check FIRST and show what they found before anything is written; changing a role or removing somebody do not, because neither changes a name. Removing takes a party off the matter's roster and leaves them in the firm's conflict history, permanently.

  • Removing a party is never a delete. The row stays in the firm's conflict record permanently and a conflict check will still return it — FL Bar 4-1.7/4-1.9 is why, and there is no screen that removes it from that record.
  • A jurisdiction change marks the computed dates unverified and stops. It does not re-run the rules engine, and no date, status or working is changed — a human re-confirms each one, exactly as they did the first time.
  • The caption is a property of the CASE, so editing it changes it for every matter filed under that case. That is what a court file is; two matters in one court file cannot answer to two different courts.
  • Changing the jurisdiction clears the assigned judge on every matter of the case, because a judge from the old rule chain would otherwise still be dispatched on. The judge has to be set again.
  • The practice area and the billing rates still have no form. Two of the five case-setup steps remain uneditable from the product, and the setup page says so.

The fact ledger

A ten-thousand-page production becomes something you can ask questions of rather than something you have to read. The reading happens once, overnight, and every answer afterwards arrives with the page it came from attached.

A document is read a single time by the cheapest capable model and decomposed into one row per assertion, each carrying a verbatim quote and a page number. Nothing afterwards re-reads the document — digests, chat, forensics, timelines, and drafting all query the ledger. That is what makes a 10,000-page matter affordable to ask questions of. A page whose OCR confidence falls below the policy floor is re-read with vision; a document whose facts fail quote verification beyond the policy ratio is re-read once on a stronger model — once, never a loop.

  • A document marked AI-excluded is never read — not by the reading pass, not by the escalation, not by anything that queries facts. What is missing is the MARKING: there is no control anywhere in the product that sets it. It is applied at import, or by us on request, and the badge you see on a document is showing you a decision made somewhere other than that page. If you need a document kept out of AI context, that is a message to us today.
  • Re-reading supersedes prior facts rather than duplicating them.
  • Facts whose quotes cannot be found on their cited page are excluded from drafting and flagged for review.
  • The vision re-read of poor pages is capped at twenty pages per document. Past that, low-confidence pages keep the text the scanner produced rather than being re-read — a badly scanned five-hundred-page exhibit is a bounded charge by design, and the pages beyond the cap are searchable but rougher.

Automatic forensic pass

The contradiction you would have found in month six turns up the week the document arrives, while there is still time to do something with it. It also catches the dull expensive things — Bates gaps, a date that cannot be right.

Two kinds of detector. Deterministic ones — Bates gaps, a file modified before it was created, dates in the future — cost nothing and run always. Exact duplicates are not among them: a matter holds one copy of a given set of bytes, refused at the database rather than reported afterwards. The AI comparison looks for contradictions and reconciliation failures against a retrieved slice of the ledger. Findings are deliberately over-inclusive; dismissing one teaches the matter so it is not raised again.

  • Deterministic findings still run with no API key and a zero balance.

Dual timelines

The chronology you would otherwise build by hand the week before a hearing already exists, sourced line by line, and prints as an exhibit. Reading the two spines together is where the awkward questions surface.

The timeline belongs to the case: one timeline for the whole court file, with events that concern only one client's matter labelled with that matter. Every dated fact goes onto it the moment its document is read; the cause timeline then merges several documents describing the same event into one entry. The case timeline is derived deterministically from filings and the docket, and the same filing uploaded to two matters is one entry. A rebuild only ever touches rows it created: once a lawyer edits an event, the machine never overwrites it again. The cause timeline is told to leave filings, service, hearings and orders to the case timeline, and a standing check counts any event that still appears on both spines with the same date and title.

  • Export is a print-ruled page rather than a generated PDF — better typography, working links, and no PDF dependency on a privileged-data server.
  • Editing an event by hand is supported by the data model but has no screen yet; the rebuild already refuses to touch a hand-edited row.
  • A cause timeline built before the case timeline took over the litigation may still show a filing on both spines until its next rebuild.

Working in one file

You stop filtering. Choose the file you are working in and the navigation becomes that file: its matters, its clients and their shares, its agreements, its productions, its recoverable costs, and a morning read of where it stands. Leave the mode and the firm-wide views are where they always were.

The rail carries a case selector. Choosing a file adds an "In this file" group; choosing "Firm — all files" clears it. The mode is remembered as you move around and survives a refresh, and it is presentation only — it changes which links are drawn and where they point, never what a query returns or who may see it. A link appears in that group only where a genuinely case-filtered view exists behind it, which is why the group grew one entry at a time rather than arriving whole: a link that showed the firm-wide list under one file's name would be worse than no link.

  • A screen on a matter applies here exactly as everywhere else: a matter you are walled off does not appear in its own case's lists, and a case you cannot see cannot be picked.
  • The mode is remembered on the device you chose it on, not on your account.
  • A capability your firm does not have does not appear in the group — the same decision that withholds its firm-wide link.

The case digest

Opening a case you have not touched since March starts with a paragraph rather than with a document list. It was written from the record instead of from whoever last remembered, and it carries the date it was written so you know whether to trust it.

The digest is written from the fact ledger rather than from the documents — the documents were read once and are never re-read, which is what makes a matter with ten thousand pages in it affordable to summarize at all. It is refreshed as the record grows, and the card shows when it was last refreshed and which model wrote it, because a summary whose age you cannot see is a summary you cannot weigh.

  • It is a summary, not a source. The facts underneath it each carry a quote and a page; the digest's own sentences do not, and nothing in it should be quoted anywhere without going back to the fact it came from.
  • It describes what has been READ. A document uploaded an hour ago and not yet through extraction is not in it, and the digest does not say which documents it was working from.
  • A matter with no readings has no digest, and the card is simply absent rather than empty.

Deadlines, dates and your day

Morning briefing and matter health

You open the laptop already knowing what moved overnight and what needs you today, instead of reconstructing it from an inbox and a memory of last week. The dates and the counts on it are counted rather than guessed, so you can act on them without checking them first.

Health signals are computed hourly from the record — matters gone quiet, unreviewed AI, critical findings, stuck documents, matters with no parties recorded, overdue tasks, a thinning balance. The briefing assembles those deterministically and a model writes only the opening paragraph, so the numbers are never a model's invention and the briefing still arrives with no AI configured. Each person chooses, on their own briefing page, whether they want that written paragraph, the computed briefing without it, or no briefing at all — and only the paragraph costs anything, so turning it off keeps every deadline, hearing and finding for free. A firm administrator can see who has the written summary on; they cannot set it for anyone else. Every morning the same briefing is emailed to each member of the firm — on by default, with a button to suggest an improvement and a link to the settings where each person changes the hour or turns the email off — and the email carries no tracking and no remote images. Repeated signals fold into one line, so twenty stuck documents read as one. Nobody is briefed until they have signed in at least once. An account dormant for a month drops back to the free version, except an attorney or a firm administrator, and except anyone whose briefing is emailed — the inbox is then the reader.

  • By default your briefing is about YOUR matters — the ones you have actually touched, worked out from your own activity rather than from an assignment table a firm of three would never maintain. It can be set to every matter instead. A file you have never opened is not on your briefing, so a quiet briefing means a quiet week for you and not necessarily for the firm.
  • The timezone is set at provisioning or invite time. The hour, the written summary and the morning email are each person's own choice, on their briefing page; an administrator cannot set them for anyone else.
  • The email goes to staff accounts only, never to a client-portal login, and only once that person has signed in at least once.
  • What can be turned off is the written paragraph, not the briefing: on the facts setting every deadline, hearing, finding and arrival still arrives, because all of them are counted rather than composed — and that half is free and always will be.
  • An account that has never been signed into is never briefed, and one dormant for thirty days gets the free version until somebody signs in again — unless it belongs to an attorney or a firm administrator, or its briefing is emailed. Neither rule is settable: the briefing is written when it is built rather than when it is read, so nobody should be paying for prose no one will see.

Court-rules deadline engine

The dates that follow from what just happened are worked out for you, each showing the rule and the counting behind it, so calendaring is a two-minute review instead of an hour with the rules open. Nothing reaches your calendar until you say so.

Rules are versioned, cited data, not code, and the counting mode is one of those fields rather than a hardcoded assumption. Federal matters count under FRCP 6(a); Florida matters count under Fla. R. Gen. Prac. & Jud. Admin. 2.514, which since 2019 also skips a weekend or holiday at the START of a forward period, not only the end. In both, the trigger day is excluded and a last day on a non-court day rolls — forward after an event, backward before one. The service extension is the ruleset's own: three days federal, five in Florida, added after the period would otherwise expire; electronic service adds none. Every date stores its own arithmetic, and an unknown counting mode throws rather than quietly computing federal dates for a state matter.

  • Nothing is ever auto-calendared — enforced by a database constraint.
  • A ruleset the firm has not confirmed produces soft, unverified dates only.
  • Local clerk holidays, standing orders, and tolling are NOT encoded.
  • A confirmed date that passes is marked MISSED by itself, on the hourly pass, and shows as missed on the matter and the calendar. Nothing marks it done for you and nothing forgives it: the sweep records that the day arrived, which is what makes "we thought that one was handled" a question the record can answer.

Calendar and ICS feed

You see which case every date belongs to and can open the order it was read from in one click, so a date is checked against its source instead of trusted. Pick one case and the calendar shows that case and nothing else. Your court dates also turn up in the calendar you already look at, so a deadline cannot hide inside a system you only open at your desk. Lose the phone and you revoke one URL.

The calendar opens on an agenda: each entry names its case first, then the event, the time, the judge and the courtroom, and a link to the document the date was read from — a PDF opens in a tab of its own. A month grid shows the same dates with the same filters, and Comfortable or Compact is remembered for you. Confirmed dates are drawn solid; a date proposed from an order or by the rules is dashed, with Confirm and Dismiss beside it and the line of the order it came from one click away; a date that has already passed is never offered for confirmation. Choosing a case, in the filter or in the Case file picker while on the calendar, narrows the query itself, and an ethical wall still removes a screened matter's dates row by row. Every case also has its own Calendar tab, with its trial, calendar call and next deadline up top. The subscription URL is per person, hashed at rest and revocable, and can carry your matters, every matter, or one case. It carries titles and dates only — never facts, quotes, or documents — because a litigation calendar syncing to a personal phone is a foreseeable disclosure surface. You make one from Add to your calendar beside Agenda and Month, or on a case's Calendar tab for that case only; Security lists your own links, and a firm admin sees the whole firm's in Settings, each with Revoke and Reset. Disabling someone revokes every link they hold, and a link stops working the moment its owner is disabled. A hearing's time is the firm's local time — the timezone a firm admin sets in Settings — and goes out as the exact moment, so a 10:00 AM hearing is 10:00 AM on every subscriber's phone; a hearing whose order states no time goes out as an all-day event.

Orders that set their own deadlines

The document most likely to contain a deadline stops being the document nobody re-reads. And when the court amends it, you are not left comparing two orders by eye to find what moved.

The order is read for the triggering events it records — service, entry of judgment, a conference held — and each is handed to the same rules engine everything else uses, which owns the arithmetic, the jurisdiction's counting mode and the holiday table. The model cannot invent an event: it chooses only from the triggers this jurisdiction's loaded rules actually key off, and the choice is re-checked before it reaches the engine. The same read lists the hearings, conferences and trials the order sets, each stored as a PROPOSED hearing. It runs by itself once per document when the file says the document is an order, whether the reading pass filed it there or a person did — and an order the reading pass filed elsewhere is still read when the court entered it, when its title is a notice of hearing or scheduling order, or when its caption reads as an order and it came through court e-service. When something it needs is missing — the case has no jurisdiction, no rules are loaded, the text is not extracted yet, AI reading is off for the firm — the order is HELD, the document says so in plain words, and it is read automatically the moment the cause is fixed; nobody has to read it again. A file whose text could not be extracted, or a read the AI provider could not answer, is retried by the platform on its own and, if it still fails, LEXICERA is alerted — never the firm. Everything produced is a PROPOSAL: on the calendar marked "Proposed — confirm" and in the review queue, confirmed or dismissed with one click. An amended notice of hearing cancels the earlier proposal for the same appearance rather than adding a second. Marking a new order as superseding an old one cancels the old one's unconfirmed dates and leaves anything an attorney already confirmed exactly where it is — a confirmed date an amendment moves is a conflict for a person, not something to resolve quietly. A filing that asks the court for dates — a motion to extend or continue, a joint scheduling report, a response proposing other dates, or a party's proposed order — is read once for the dates it asks for, from either side. Each is shown on the calendar, the matter page and the review queue in its own dashed outline as "Requested — pending ruling", with who asked and the current date that still governs, and it is never written as a deadline: an unruled motion does not move a date. When the order arrives, the same automatic read rules on each pending request — granted, granted with different dates, denied, moot or withdrawn — and any new date arrives as a proposal; a confirmed date is never moved by the machine, and a person chooses to move it or keep it. A request with no ruling for 30 days is flagged, and one whose current date is within a week rises to the top of the review queue, the dashboard and the briefing.

  • It proposes; it never confirms. A proposed date shows on the calendar marked proposed and counts as confirmed nowhere until a person confirms it, enforced by a database constraint.
  • It can only propose events the loaded rules recognize for that jurisdiction. An order setting a date no rule keys off is read and produces nothing, deliberately, rather than being forced into the nearest fit.

The court docket, checked against the file

A notice served before anyone was watching the inbox does not become a missed hearing. Each case says how many docket entries it has, how many have their document in the file, and which do not — notices of hearing first, then orders — and the morning briefing says so the day a case gains one.

A matter carrying a federal court and docket number is checked hourly against CourtListener's RECAP archive, and new entries are written to the case timeline. For a state case, staff import the clerk's case record (the markdown the clerk's case search exports, or a CSV of the docket) on the case's Documents tab; it is keyed by entry number, so importing the same record again changes nothing. Every entry is then matched to a document on the same matter — by the federal "Document NN Filed" header or a Florida e-filing number, by the clerk's SEQ or DIN in the filename, or by the filing date and a title that agrees — and the basis is recorded beside the link. An entry the docket shows with no document image (a judge assigned, the clerk's own service email) is never counted missing. The clerk's hearing list goes on the calendar as proposals, never as confirmed dates. No model is involved at any point.

  • PACER itself is never called. RECAP is a mirror of what other people have already purchased — free, often complete, NOT authoritative, and it lags. Paid PACER access bills per page to the matter, which is the firm's decision to make rather than a default we switch on quietly.
  • The Florida ePortal and the clerks' case search sites have no public API and nothing here talks to them. A state case's docket is as current as the last clerk record somebody imported; between imports, the ePortal's own service emails forwarded to the matter's address are what arrives.
  • Matching is by numbers, stamps, dates and words, not by reading. A document filed under a name that carries none of the clerk's numbers, no stamp, and a title unlike the docket's can show as missing when it is in the file; one that only resembles the entry is not linked. Documents are matched on their own matter only.
  • There is no screen to set a matter's docket reference. It is set for you, and a matter without one is silently not followed. The court itself is editable, on the case's Court identity card, but that field is not what this pass reads.
  • It needs a CourtListener token configured. Without one nothing is pulled, and nothing pretends to have been.

Walking in cold, prepared

Somebody else's hearing lands on you at five o'clock and by the time you have made coffee you know who the parties are, what the case is about, what has moved lately, what is coming, and what you must not agree to. And before your own hearing there is the shorter version, sized for the corridor rather than the desk.

Both are built the way the morning briefing is, and for the same reason: the parties, the dates, the counts and the figures are assembled from the record by query, and a model writes only the prose over the top — so nothing a model produced is ever the source of a number. The coverage packet is the long form, meant for an attorney opening a matter cold. The hearing one-pager is the short form, generated against a specific hearing on the calendar. Both are generated on request and kept, so the one you read is dated and you can see how old it is.

  • Both are a snapshot taken when you asked for one. Neither refreshes itself, and the date it carries is the whole of the guarantee.
  • A model writes the prose. The dates, parties and counts in it were computed, but the sentences joining them were not — read it as a briefing from a colleague who has skimmed the file, which is exactly what it is.
  • The one-pager is generated against a hearing that exists on the matter. A hearing nobody recorded gets no packet, because there is nothing to generate one against.

Discovery

Discovery and productions

Productions go out with Bates numbers that still resolve two years later, a privilege log that wrote itself, and a receipt of exactly what was sent and when. The check that stops you producing today what you withheld last spring runs before the production can lock.

The model pre-sorts documents against parsed requests; an attorney confirms every call. A production cannot lock while it contains an unreviewed document, a document still marked privileged, or anything that contradicts a prior production — producing what you withheld before is a waiver argument, and it is invisible without cross-production comparison. Bates numbering is matter-wide and permanent.

  • Numbers are burned onto the page when the bundle is assembled, which is an operator command rather than a button on the production screen.
  • Redactions are recorded as coordinates and are not burned into pixels. A production containing a redacted document is refused rather than produced unredacted — see the assembly capability for why.
  • Request parsing, the responsiveness pre-sort, confirming calls, and deficiency analysis exist in src/lib/discovery.ts but have no screen and no caller yet — the production build, Bates, privilege log, consistency check, lock, and delivery steps are the part a lawyer can reach today.

The production bundle that leaves the building

The production goes out as a set the other side can load on the first try, with the number visible on every page it is cited by. Nobody at the firm stamps a PDF by hand at nine at night, and if anyone ever disputes what was sent, the manifest hashes the file that actually left rather than the one in the system.

A locked production is separated into pages, each page is stamped with its own Bates number — and an optional confidentiality legend — and the stamped pages are written out both individually, named by Bates number the way a review platform expects, and re-united as the produced document. The Concordance DAT and Opticon OPT load files are generated from the same pass, in the delimiter conventions review platforms have used for thirty years. The SHA-256 recorded against each document is of the produced bytes, stamping included, so the manifest's promise is checkable. Nothing here calls a model: numbering is arithmetic and load files are a fixed format.

  • Redactions are recorded as coordinates and are not burned into pixels; a production containing redactions is refused rather than produced unredacted. Producing a document whose redactions exist only as numbers in a table would deliver the material somebody marked for withholding.
  • Non-PDF documents are produced un-stamped, as their native files, and marked so in the manifest — a spreadsheet has no pages to burn a number onto.
  • It is an operator command, not a button on the production screen.
  • A document whose real page count disagrees with its assigned Bates range stops the run rather than being stamped with numbers that point at the wrong pages.
  • A Bates-stamped copy of a document already in the matter is a DIFFERENT document and is filed and billed in full. The free-second-copy promise is byte-exact: it rests on a SHA-256 of the file, and burning a number onto every page changes the file. That is deliberate — two versions that differ by a produced number are two things you may have to produce separately, and collapsing them would lose one.

Work product

Case chat with citations

You can ask the file a question at four in the afternoon and have a cited answer before you leave, instead of blocking out a morning to re-read a box. Every claim links to its page, so you check it before you rely on it.

The question is matched against the fact ledger, and the model answers using only the facts retrieved. Citations are parsed back into document and page links, so any claim can be checked in two clicks. It is told to say what is missing rather than infer.

  • Answers are informational and never enter the review queue.
  • Retrieval is full-text over facts; no embeddings until a checkpoint proves need.
  • It is a CONVERSATION, not a series of questions: a thread keeps the exchange, so "what about the second one?" works. Threads are per person as well as per matter — two attorneys on the same file are having two different conversations, and stitching them into one would put one lawyer's half-formed thinking into the other's context.
  • It knows about EVERY feature of this software, one line each. Ask how to do a particular thing by name and it is given that feature's full steps for the question you asked; ask about something it was not given steps for and it says so and points you at the guide rather than inventing them. It will never make up a screen that does not exist.

Drafting with cite-check and red team

A first draft that already cites this matter's own record, plus a read of the other side's best answer, before you have spent an afternoon on it. What comes back is a draft to edit — every legal citation in it is resolved against a public opinion database, and one that does not resolve is marked unciteable.

Drafts are written from the fact ledger with inline citations. The cite-check pass tests every factual assertion against that ledger — and reports EVERY legal citation, resolving each against CourtListener for existence and accuracy. That is not treatment: a citation that resolves can still be bad law, and the page says so. The red team argues the other side's best response and names what the record supports that the draft missed.

  • The model is instructed to write [CITATION NEEDED] rather than cite anything it was not given; what it does cite is resolved against CourtListener for existence and accuracy only — not Westlaw, no treatment, no Shepard's.
  • Editing an approved draft revokes the approval, by database trigger.
  • The pre-filing checklist is ADVISORY and always will be. It reads the requirements of the court and the judge your matter sits in, measures what can be measured, and says plainly what it could not check rather than calling it clean. A failing line does not stop you approving, exporting or filing anything: signing off records that an attorney read it. A requirement from a rule set your firm has not confirmed still appears, marked unverified — never dropped, and never shown as verified.
  • A template is lifted only from a filing your firm authored, never from a pleading served on you, and it is not offered to anyone until an attorney has read the proposed structure and confirmed it. Your templates are yours: there is no sharing surface between firms, and nothing you confirm is ever lifted back into ours. When our version of a form moves on you are shown what changed and choose — nothing is merged into your copy.
  • The firm keeps a memory of how it writes and what it has decided — its voice, notes on a judge or an opposing counsel, arguments and objections it has used, and the findings it has told the platform to stop raising. That memory reaches drafts, engagement letters, the forensic pass, the morning briefing and answers about a matter, so the product sounds like your firm rather than like a model. It is added by us or learned from a dismissal you explained; there is no screen to edit it, so what is in it is a question to ask rather than a page to open.
  • Pleadings — complaints and answers built from a section tree, with the allegation ledger beside them — are their own capability, "The pleading builder". This entry is the prose drafting beside it.

The pleading builder

The paragraph numbers, the Count re-allegation ranges and the caption stop being things a lawyer re-checks by hand every time a paragraph moves. Every allegation the firm makes is written down beside what the firm will stand behind it with, before the pleading leaves the building rather than after the other side asks. And the court-formatted document is filed to the matter the moment it is exported, so the copy that went out is the copy the file keeps.

A pleading starts from a template — the platform's Florida circuit civil complaint, its answer, or one the firm lifted from its own filing and confirmed — and from the matter: the court identity, the parties, the counts chosen from causes of action a lawyer has signed off for that jurisdiction, and, for an answer, the affirmative defenses. The template is a tree of sections: fixed text, values the matter supplies, choices, computed paragraphs and prose the lawyer writes. The engine numbers the paragraphs and computes every "realleges paragraphs 1 through N" range, and an empty slot renders as a visible bracketed placeholder rather than a sentence with a hole in it. No model is called to start, edit, mark or export a pleading. When the pleading is started, each numbered paragraph it asserts is written to the Allegations ledger as unreviewed; an attorney marks each one supported, will be supported (which requires naming the source), information and belief, or strike. For an answer, the served complaint's numbered paragraphs are imported deterministically and each is answered admit, deny or without knowledge — every one arrives as without knowledge, and the matter's own facts that bear on a paragraph are shown beside it as a reading aid. Exporting renders the .docx for the court: the page, the face, the caption shape, the signature block and the jury demand come from that court's encoded rules where they exist and from the firm's default where they do not, and the export dialog says which is which. The same bytes are filed to the matter as a document, and a PDF/A copy is queued for the worker to produce.

  • Formatting follows this court's encoded rules only. Where a rule for a field is not encoded, the firm's default is used and the export dialog says so, field by field — nothing is borrowed from another court's rules.
  • It produces the filing and does not file it. Nothing here logs into a court portal, files with the clerk or serves anyone: the export puts a copy in the matter on this platform, and the attorney files with the court.
  • An allegation is never a fact. The ledger records what the firm says and what it will stand behind; nothing in it is written to the fact ledger or read back into a draft as a source, and a paragraph marked supported is an attorney's judgment, not a finding.
  • Nothing marks a paragraph for you. Every allegation starts unreviewed, and only an attorney changes that.
  • The ledger is re-derived on every section save: an unchanged paragraph keeps its disposition and takes its new number; a changed one starts again unreviewed; a removed one is closed out, and earlier judgments stay readable as history.
  • Prose inside a repeated section — one Count, or one affirmative defense — is drafted in the text below the section tree, not in the section editor.
  • Causes of action and affirmative defenses are offered only for jurisdictions where a lawyer has read and signed off their elements; a court with none signed off is offered none, and the page says so.
  • The PDF/A copy is typeset from the filed document's text in the platform's standard faces, not from the court's encoded profile; the profile governs the .docx.

Chambers

The thinking you would do with a senior colleague on a Tuesday afternoon, with the whole fact ledger already in view: simulate opposing counsel, value the case, outline a deposition, argue a theory until it breaks — without any of it touching the file. Nothing said in Chambers becomes a fact, a deadline, a filing, a draft, or a time entry.

A thread runs over this matter's facts with citations back to the page each one came from. A hard question can be escalated to a more capable model for that turn only, at exactly two and a half times the rate — the multiple is the model's own price in the rate card, not a markup added in the interface, and the checkbox says so before you send. The verbs (simulate, value, outline a depo) are the trial notebook's existing one-shots said as sentences; their results are stored where they always were, as internal decision support. Ethical walls bind Chambers exactly as they bind the matter page: a screened matter cannot be discussed, because its facts never enter the prompt. Every case citation in an answer is resolved against CourtListener, and one that does not resolve is marked unciteable.

  • Chambers writes NOTHING into the record — no fact, no deadline, no filing, no draft, no time entry. It recommends; the attorney acts through the product's own review paths.
  • Threads persist as firm records — there is no delete, by design. The application database role holds no DELETE on either table.
  • Never client-visible and excluded from the export bundle by rule.
  • Turn content is not covered by the per-document crypto-shred story; it lives in the database and its encrypted backups.
  • Staff can read a thread; posting a turn is attorney-only.

Getting a filing past the portal

Nobody is at a free conversion website at eleven at night with a client's filing in it, because the two mechanical reasons a portal rejects a document are handled before it goes near one. Neither of those reasons has anything to do with the law, and neither should cost anyone an evening.

The document is converted to PDF/A, which is the archival format portals insist on, and if it is over the ceiling that portal allows it is split into parts that each fit. A bookmark outline can be built two levels deep — the section of the file the document sits in, and the title its reading gave it — because a clerk opening a two-hundred-page exhibit set will look for one. The plaintext exists only inside a private working directory that is removed when the run ends, whatever the outcome.

  • It is an operator command, not a button on a screen. Ask us and it happens; there is no way for a firm to run it itself.
  • The outline is as deep as the record is: two levels, from the file section and the document's own title. There is no per-page heading extraction anywhere in this platform, so there is no honest way to emit a bookmark per exhibit — and inventing one from a model would put made-up structure into a court filing.
  • It does not file anything and does not talk to any portal. It produces a package that will be accepted; a person still uploads it.

Trial and strategy

Trial notebook and simulation

Witnesses, exhibits, offers, and the authority you hold are in the one place you actually open before a hearing. And you can hear the other side's best argument while there is still time to change yours.

Simulations put your argument to a simulated opposing counsel, bench, or jury panel. They are labelled internal decision support at the database level and can never become approved work product. Valuation asks the model for outcomes and probabilities and computes the expected value in code.

  • A simulation is a model imagining people. It is useful for finding weak points and worthless as a prediction, and the interface says so.
  • Depositions are here and are worth knowing about: a witness on the list can have an outline built for them from the matter's own record — organized by topic, each topic naming the admission it is for and the document that impeaches a denial. It is run from Chambers rather than from this page, which is where the strategy verbs live.
  • Exhibits and settlement offers are recorded and read back; the trial-item and matter-budget tables in the same migration have no screen and no code behind them at all. They are schema, not capability, and nothing in the product will fill them.

Getting paid

One email to the client, not five

A client hears from you once on bill day instead of separately about the bill, the unsigned letter and the new filing. Reminders follow your own schedule and are the same combined summary, never two automated emails in one day, and they stop as soon as nothing is outstanding. There is no read tracking in any of them.

The summary lists what is waiting on the client (an unpaid bill, a letter to sign, a document you asked for) and the court filings marked since the last one, with a button that signs them in to their own page for 30 days. Reminder days come from your payment-reminder schedule in Settings; each reminder re-reads what is still outstanding at the moment it goes. A bill that was never delivered is never chased. Pressing Send on an invoice still sends that bill straight away, as its own summary.

  • A firm moves to the summary only when the platform releases it; until then its clients receive the separate emails they always have.
  • There is no text message with the summary.
  • A bill issued more than a day ago that was never sent holds that client's automatic summary until someone sends it.

Passive time capture and billing

Time you already worked but would never have written down gets proposed to you, with the minutes taken from timestamps rather than from what you can remember on Friday. You accept or discard; nothing bills itself.

Activity is clustered into work sessions deterministically; only the billing narrative is written by a model. Nothing bills until you accept it. Technology costs appear as their own invoice lines, never folded into fees; file storage is included in the firm's platform arrangement and is shown for reference rather than billed to a matter.

  • A session of a single action is never billable.
  • IOLTA and trust accounting are out of scope by decision, not unbuilt: billing covers work already performed, into the firm's operating account. A firm holding client funds keeps doing that in its own trust systems.

The meter and the prepay gate

You can see what the AI cost on each matter and decide whether the client pays for it. If the balance runs out, the AI pauses and your documents, search, and downloads carry on working. Work that arrived while the balance was empty is not lost: it resumes on its own when you top up.

Raw (what Anthropic charged), platform (what the firm is charged), and client-billable (what the firm may pass on). Only work a person asks for carries a platform charge; the automatic processing every document goes through is covered by the per-page fee and is recorded at our real cost with no charge to the firm. When the balance reaches zero, AI features pause and nothing else does: documents, downloads, and search stay available. A firm that runs out of credit does not lose access to its own files. A pause is not a loss: documents uploaded while the balance is empty are stored, extracted and searchable straight away, and their AI reading runs automatically once credit arrives — nothing has to be uploaded again. AI runs only on live, billable accounts — a demo or a brand-new firm is shown canned examples or a short note that AI runs on live accounts, and never spends.

  • A bank (ACH) top-up is not in the balance until it clears — usually 3–5 business days — and Account & usage shows it as pending until then. Automatic top-ups charge a saved card; a bank account can be saved for them, but it is not debited until bank debits for automatic top-ups are switched on.
  • The monthly platform fee posts itself against the prepaid balance on the first of the month, at the published price, and the SEATS IT COUNTS ARE THE ACTIVE, NON-PORTAL PEOPLE AT THE MOMENT IT POSTS. An invited person who has never accepted is free — charging for an invitation nobody opened costs more goodwill than it earns — a disabled one costs nothing, and client-portal logins are free and unlimited because they are a different credential in a different table. There is no proration: the month you are active in is a month.
  • ANYTHING ELSE AGREED WITH YOU — a website we host, a service we run — is a NAMED LINE ON A DATED SCHEDULE, and it bills IN ADVANCE: it posts on the first of the month it covers, and its first month is prorated to the day if it did not start on the 1st. The platform subscription above bills the other way, for the month that ran, so one statement can carry a subscription line for last month beside a service line for this one. Every line names its own period for exactly that reason. A rate we agree to change is never an edit: the old line closes on its last billed day and a new one opens the day after, so a statement you were sent months ago still adds up from the schedule that produced it. One-off agreed work posts as its own dated line under Fees and carries no schedule at all.
  • OUR OWN TESTS ARE NEVER BILLED TO YOU. The nightly suite runs against a real firm, and every row it creates in the four metered tables is marked as test data at the moment it is written — the mark travels with the data rather than with the run, because the reading happens in a worker and the briefing in the server and neither can see an environment variable set in a test process. Deleting afterwards was the old design and it is a promise; not posting is a property.
  • The balance covers AI usage and the monthly infrastructure postings both. A zero balance pauses AI and nothing else — documents, search and downloads are unaffected, and a firm that runs out of credit does not lose access to its files.

Disbursement statements

Case costs stop being an overhead you absorb silently and become a line you can show a client, itemized, with the work that produced it.

The statement lists AI work grouped by what it was for, drawn from the figure stored at the time of each call rather than recomputed later, plus the flat close-out and export fees when they apply. Storage appears as context — how much this matter holds — and never as an allocated dollar line, because dividing a flat storage tier across matters would reintroduce per-gigabyte pricing through the back door. Whether a kind of work may appear at all is a property of the work: internal operations like the morning briefing are marked never-billable, and anything unclassified defaults to not billable.

  • It states what a matter cost. Those costs now reach the client's bill through the period close, so the statement and the invoice agree — but it still calculates no tax and talks to no outside billing system; the CSV is that handoff.
  • Passing costs to a client at anything other than cost requires an engagement letter with cost-recovery terms on file — and the platform drafts those terms into the letter, keyed to the jurisdiction and carrying the ethics opinion behind them, so what is required of the firm is reading and signing rather than drafting.

Spend limits and alerts

Nobody runs up a bill you did not agree to, and you find out at eighty per cent rather than on the statement.

A per-person limit is soft by default — it raises a signal to the firm rather than stopping anyone. A hard limit refuses interactive work once the month's spend passes it. Overnight document work is NEVER blocked by a limit: starving the reading pipeline to enforce a chat budget damages the asset every other feature runs on. The firm-level alert fires a health signal at eighty per cent of the level you set and blocks nothing at all.

  • Limits govern interactive AI only. Overnight document reading continues by design.
  • A limit is a monthly figure, not a per-matter budget.

The cost-recovery clause, written for you

You can charge a client for what a case actually cost to run without writing the clause yourself or guessing whether it is defensible. The words arrive in the engagement letter with the opinion they rest on named beside them, so the conversation with a client — or with a bar committee — starts from a citation rather than from your drafting.

The platform keeps jurisdiction-keyed clause language for cost recovery, Florida first, each version carrying the authority it was written against — ABA Formal Opinion 512 and Florida Bar Opinion 24-1 on charging clients for generative AI. When an engagement letter is drafted, the clause for that matter's jurisdiction is pulled in as an INPUT to the draft, never as an output nobody read: the letter is reviewed before it is sent, like every other draft, so the clause is read by an attorney before a client ever sees it. Language is versioned by the date it takes effect and a new version is a new row rather than an edit, so a letter signed last year keeps the words it was signed with.

  • Florida and federal language only. A matter in another jurisdiction gets a letter with no clause rather than Florida's words in the wrong state.
  • It is language, not advice. The clause and its citation are a starting point an attorney reads and takes responsibility for — the platform does not know your client, your fee agreement, or your bar.
  • Recovery at anything other than cost is set with us rather than on the settings page, and it requires a signed letter carrying these terms. That is not a missing feature: a rail you can drive around in a form is scenery.

Texting clients from your own number

A client who would never open the billing email sees the bill on their phone, from a name they recognise: yours. The carriers register your firm as the sender, so the texts arrive from your own local or toll-free number rather than from software they have never heard of, and only clients who asked for texts ever get one.

An administrator fills in the Text messaging card once: picks a number from the carrier's live inventory (local by area code or city, or toll-free), enters the firm's legal details exactly as on its IRS letter, and signs the authorization. LEXICERA checks it and files it with the carriers, and the card shows each step as it is approved. Nothing is bought or billed before LEXICERA files it. Once it is live, an invoice that is emailed is also texted to a client who has opted in — never an amount, only the secure link — and a client who replies STOP to your number is never texted by your firm again until they reply START. Separately, each staff member can opt in on their own Security page to LEXICERA account notices by text from LEXICERA's 888 line: when the prepaid balance is at or below $0, when a top-up fails, and when the firm's texting registration is live or needs a fix.

  • Texts are sent only to clients who opted in themselves, in the portal, on the signing page or on a pay page. Entering a client's mobile number does not sign them up.
  • Only the first notice for an invoice is texted. Payment reminders are never texted.
  • A text never names an amount or anything about the case: only your firm's name, the invoice number and the secure link.
  • Carrier approval is not instant and can be refused: usually days for a local number and weeks for a toll-free one. Nothing texts until it is approved.
  • A toll-free number has to be bought before its verification can be filed, so it is purchased when LEXICERA files the registration rather than after approval.

Sending the bill, and chasing it politely

The bill reaches the client without anybody copying a PDF into an email, and an unpaid one is followed up without anybody remembering to. The reminders are deliberately few and deliberately mild — three over six weeks, ending in a request to talk rather than a threat — because the relationship with that client is yours and a collections tone sent under your name is not something you can take back. You can turn the whole ladder off for one client or one whole case in a click, and you see exactly what would be sent and when before it is.

A send is a row, not a flag, so one invoice keeps ONE number however many times it goes out — which matters because a returned payment re-opens the same invoice and sends it again. Each reminder step fires once per invoice ever, enforced by the database rather than by the code remembering, so an hourly job cannot turn into an hourly email. State is re-read at the moment of sending, not when the reminder was scheduled: a payment landing in between means the reminder simply does not go. And a payment that bounces PAUSES the ladder for that invoice and hands the decision back to you — chasing somebody whose payment just failed is a phone call, not an email. The invoice says so on its own page, and restarting is a deliberate act with your name and the time on it; nothing resumes by itself, and a second bounce pauses it again.

  • The reminder schedule and its wording are yours: up to five reminders, your days and your words, edited in Settings under Payment reminders. Three at 7, 21 and 42 days are the default you start with. The last reminder always carries our one sentence saying it is the last — it moves by itself if you add another.
  • Links, HTML and the name of a payment company are refused in reminder copy. The message already carries the one button that opens the invoice, and a chasing email carrying a second link is the shape a phishing message imitates.
  • Reminders never resume by themselves after a payment is returned. That invoice stops being chased automatically, on purpose.
  • An invoice with no due date is never chased — it is reported instead, because guessing a date to chase somebody on is not a fix.
  • No read receipts and no tracking pixels, ever. We cannot tell you whether a client opened the email, and would not add that if we could.

Payment reports for the firm, a case or a client

Pick a period and see what you billed, what came in and what is still owed, with the outstanding balance broken into current, 1–30, 31–60, 61–90 and over 90 days and compared with the period before. The clients whose balances are getting out of hand are listed by name. One click filters the list to Paid, Unpaid, Partial, Overdue or Returned or refunded — on a class action, who has not paid this month is one press. Click any row to see what happened on that bill: when it was sent and to which address, when the payment page was opened, every payment and every return.

Every figure is added up by the database from the real invoices, payments, refunds and returns, and the report checks itself before it is shown: the payments listed must sum to Collected, the aging must sum to Outstanding, and the case and client rows must sum to the totals — a report that does not add up is refused rather than shown. Periods are your firm's own calendar days. A bank payment still in flight is shown as pending and is not counted until it settles. Figures are gross — what the client paid — with no processor fees. The PDF is the same document as the screen, printed by our render service a few minutes after you ask for it, and it can be downloaded only by the person who asked.

  • Attorneys and firm administrators only — the people who can already see the firm's invoices. A bill on a matter or case you are screened from is not in your report at all, its payments and balance included, and the totals are the totals of what you can see.
  • No processor fees and no net figures: these reports show what clients paid.
  • An invoice that covers two cases is counted under the case with the larger share of it.
  • "Opened the payment page" is a visit to the pay link on our server. Whether an email was opened is never tracked, and a card declined on the processor's own page is not recorded.
  • A PDF is a snapshot of the report when you asked for it, ready a few minutes later; Print gives you paper straight away.

Record a payment the firm received

Press Record payment on any unpaid bill and the amount is already filled in with what is owed. Pick how it arrived — check, ACH, wire, cash, a card taken on your own terminal, or something else — type the check number, who paid and a note for the file, and the sheet shows what will still be owed before you press Record. Tick one box and the client gets a receipt. A payment entered by mistake is reversed with a reason, and if the client was sent a receipt they are told it no longer applies.

The payment is written against the invoice in the same step that moves its balance and status, and the database refuses anything more than is still owed — an overpayment would be a credit balance, which this system never holds. A payment dated after today is refused. The receipt is composed from the ledger just written and sent only after the payment is saved, so a payment that fails to save has never told a client they paid. Reversing a payment never deletes it: the reversal is a second, dated record with the reason and the person who made it, and the invoice goes back to what was owed before. Recording a payment is not holding money: the firm received it directly, and LEXICERA holds no client funds.

  • Attorneys and firm administrators only — the people who can already see the firm's invoices. A bill on a matter you are screened from cannot be paid or reversed by you.
  • No overpayments and no credit balances: anything above what is owed is refused, and the difference is returned to the client outside LEXICERA.
  • Reverse takes back the whole payment. A partly wrong payment is reversed and the right one recorded. A payment taken online is refunded through the payment page's own processor instead, which records its own reversal.
  • There is no undo window: a mistake is a reversal, kept on the record with its reason.
  • Six ways in are offered: check, ACH, wire, cash, a card taken on the firm's own terminal, and other — "other" with its reference is how anything else is recorded.

Automatic monthly payments, authorized by the client

Fifty clients on a monthly arrangement stop being fifty payment links a month. You send one invitation; the client sets it up themselves — bank details, verification and permission are all captured on the secure page, never by you and never by us — and from then on their invoices are charged when they fall due. They still receive every invoice before it is charged, they can stop it at any time by replying, and you can stop it from their client page in one press. Nothing is ever charged that you have not billed.

The authorization is held by the payment processor and named here by a reference — there is no card number, no bank number and nothing this system could charge on its own. Every charge goes back through the processor, against an invoice you issued, for the amount outstanding on it. Authorizations are kept as history rather than overwritten, so "which permission was this charge made under, and when did they give it" is a question with an answer. A client who re-authorizes supersedes the old permission; one who stops leaves a record that they once gave it.

  • The charge is made against an invoice you have issued, for what is outstanding on it. There is deliberately no way to charge a client an arbitrary amount — that is a different permission and this system does not have it.
  • One active authorization per client. A client who authorizes a second card replaces the first rather than holding both.
  • A declined charge is reported and the invoice stays unpaid. Nothing retries by itself, because a bill marked paid on a charge that never completed is worse.
  • Whether invoices are charged automatically as part of a monthly run is not built yet — the arrangement exists and can be charged against; scheduling it is separate.

Clients, cases, and who is paying for what

Billing one client is one screen: choose them, see exactly what the bill would hold — or the reason there is nothing to send — add any line that is not recorded yet, and issue and send it in a single step. A client gets one bill covering everything you did for them, instead of one per file. On a case with many co-plaintiffs, work done for the case as a whole is split by the shares you set and each person sees only their own share — never who else is on the case. And nothing gets quietly missed: work no agreement covers is listed by name at close rather than silently left off.

Every rule — the fee bases, the allocation policy, cost pass-through, holds and write-downs — is applied ONCE, when work becomes a charge, and every screen afterwards reads those rows. That is what stops the disbursement statement and the invoice disagreeing about the same money, which is exactly what they used to do when each worked the answer out for itself. Case-wide work becomes a parent charge that is split into one child per client, and the children sum to the parent to the cent — the remainder goes to the first child rather than being rounded away. A close is safe to run twice: the second run creates nothing, refused by the database rather than by the engine remembering.

  • A bill covers one client. An insurer paying for an insured, or any second payer on one bill, is not supported.
  • Work with no agreement covering it is never billed at a guess. It is named at close and stays unbilled until an agreement exists — which means somebody has to read that list.
  • The close is run by a person. There is no schedule that issues bills on its own, deliberately: a bill going out without anybody looking is the failure this design refuses.
  • This system holds and disburses no client funds of any kind. Everything is earned when it is billed, and there is nowhere for money that is not yet earned to sit.

What the client agreed to pay, in plain language

What a client agreed to pay is written down in words they would recognize, so a fee conversation starts from the agreement rather than from somebody's memory. Changing terms never overwrites what was agreed before: a change is a new agreement that supersedes the old one, and the old one stays exactly as it was signed — which is the question a fee dispute is actually about.

Six steps: who is paying, what for, how, the specifics of the basis you chose, which costs this client sees, and a review that shows the plain-language card before you save. Hourly, flat, recurring, contingency and hybrid each carry one sentence and a worked example. The card the review step draws is the SAME component the agreement page draws afterwards, from the same terms — so what you read before saving is what is there after. A saved agreement can be kept as a template and applied to a whole roster in one transaction, which either applies to everybody or to nobody.

  • An agreement is never edited in place. Changing terms writes a new one and marks the old one replaced — destroying what was agreed before is the one thing a fee record must not do.
  • Contingency tier escalators are stored but have no editor yet. Unequal shares do have one, on the case roster.
  • The worked examples in the wizard are illustrations, not this platform's prices.

Fees the other side pays, demarcated as you work

Fee awards stop being lost quietly. Courts require fees to be demarcated to be recoverable, and the demarcation has to have happened while the work was being done — so the money is usually gone before anybody goes looking for it. Work held for an award never lands on your client's bill; if the claim is denied you decide, charge by charge, whether it goes to the client or is written off, and a released charge appears on the next bill however many months old it is.

A claim on a case records what it rests on — an order reserving fees, a sanction, a prevailing-party or fee-shifting entitlement, a contract, a proposal for settlement — the authority relied on, the order date, and one of two treatments. "Hold it until an award" means charges are born held and are invisible to invoice assembly by their state, not by a filter somebody has to remember. "Bill it now and track it" bills normally and still reports. Time is tagged in the accept flow and costs on the case's costs card. Resolving the claim needs a reason: an award moves every held charge to recovered, and any other outcome asks for a decision on each one and refuses to proceed while any is missing. The report prints the claim header, every tagged charge with its narrative and rate, a lodestar by timekeeper, and totals — with a CSV twin.

  • A held charge is invisible to billing because of its STATE, not because of a filter — that is what makes it safe. The corollary is that nothing except resolving the claim can release it.
  • The lodestar and the demarcated total are printed side by side and are not reconciled. They come from different tables and differ legitimately when costs are demarcated too, or when the newest work has not been through a billing run.
  • Costs are demarcated from the case's costs card rather than the matter's. The case card already lists every cost on the case, and two places to set one fact is two places for them to disagree.
  • Resolved claims cannot be edited, and new work cannot be tagged to one. Changing the basis under a claim a court has ruled on would rewrite the record of what was argued.

The settlement statement, computed from the agreement

The arithmetic that decides the largest fee on a contingency case stops living in a spreadsheet. The percentage is applied to the basis the agreement actually names, costs the firm advanced are itemized rather than summarized, and on a hybrid matter the fees already invoiced are subtracted with the subtraction shown. Costs that were held pending the award are released onto the same invoice as the fee, so the client receives one bill rather than two. Recording the same settlement twice cannot bill it twice.

A recovery records what was recovered — settlement, verdict, award or other — the gross figure, the date and the client. The fee is computed as the agreement says: the percentage applies to the gross, or to the gross less costs advanced when the agreement is net-of-costs, and staged escalators are applied band by band when the agreement carries them. On a hybrid agreement that credits fees already paid, the fees invoiced on that case are subtracted and the arithmetic is a line of its own. One contingency charge is created, guaranteed once per recovery by the database rather than by care, and every cost that was waiting on the award is released to be billed alongside it. The settlement statement prints the gross, the fee with its percentage shown, the costs itemized and the net to the client.

  • The firm holds and disburses no client money through this system, and the settlement statement says so in words. It records what was recovered and what the fee and costs come to; it is not an accounting of money held on a client's behalf, because none is held.
  • Liens and medical payoffs are not handled. They are the part of a settlement that needs somewhere to hold money on a client's behalf, and the statement says it does not account for them rather than leaving the absence to be read as "there are none".
  • Staged escalators are applied as amount bands, marginally — 33% of the first million, 40% above. A ladder keyed on whether suit had been filed cannot be computed from a recovery that resolves a whole case, which is when the fee is largest. There is no editor for them yet; a ladder the system does not recognize is refused rather than computed at a flat percentage.
  • The credit on a hybrid agreement cannot make the fee negative. Where fees already invoiced exceed the contingency fee, the fee floors at zero and the full subtraction is still shown, rather than becoming a credit nobody agreed to.

The bill you read before the client does

You see the bill before the client does, and you can fix it while it is still a draft: knock money off a line and say why, take work off this month, reword something a client would ring about. Nothing is spent until you press Issue — a draft carries no number, so an abandoned bill leaves no gap in the series you have to account for later.

A draft is assembled from the charges ledger and nothing else, so one set of rules decided every figure on it once. Reviewing a line writes a write-down onto the CHARGE, which is why a reduction survives a rebuild and is still legible after the bill is issued; excluding a line simply takes it off this bill and the work returns to the next one, so nothing is ever lost by tidying a draft. Issuing takes the next number out of your own series under a lock, dates the bill, sets the due date from the terms snapshotted onto it, and flips the underlying work to invoiced in the same transaction — an issue that fails part-way consumes no number. The printed bill is print-ruled HTML rather than a generated PDF, and reads the same stored totals the screen does, so the two cannot disagree.

  • Review is for drafts only. Once a bill is issued the client has a numbered, dated document, and changing a line would make your record disagree with the copy in their hand — void it and rebuild instead.
  • An excluded line comes back if the draft is rebuilt. Exclusion is a decision about THIS bill; a reduction that must survive is a write-down, and work that should never be billed to anyone is held at the charge instead.
  • Delivery is not here. The bill is printed or saved from the browser and sent the way you send things today — emailing it, and a client-portal view of it, are named follow-ons rather than omissions.
  • Recording a payment is not holding money. This system holds and disburses no client funds of any kind, and there is deliberately no table it could.

What it actually saved you

At renewal you are not arguing from a feeling on either side. You can see what the software did, what it cost, and what that is worth at your own blended rate — and because the assumption behind the conversion is on the page, you can disagree with the assumption instead of with the number.

The counts come from the audit trail — things that demonstrably happened, not an estimate of them — so every figure can be walked back to the events behind it. The hours are a RANGE rather than a point, and the assumption used to convert counts into hours is stored inside the snapshot rather than applied and forgotten, so a figure produced in March can still be argued with in September against the assumption it was actually built on. The whole thing is deliberately conservative: a report caught flattering itself once is a report nobody believes again, and this one has to survive being read by a skeptical partner.

  • It is an estimate with its assumption shown, not a measurement. The counts are real; the hours they convert into are a judgment, and the range is wide because narrowing it would be pretending.
  • It counts what the platform DID. The largest thing it cannot count is the case that settled better because a contradiction surfaced in week two instead of month six, and it does not try to put a number on that.
  • A snapshot is built when you ask for one and is a picture of that moment. It does not update itself, and two snapshots of the same period built on different days can differ if work happened in between.

Confidentiality and access

What must not be filed in the clear

A social-security number, a bank account or a date of birth does not reach a public docket because somebody was reading the argument instead of the exhibit list. The check runs on every version you write, whether or not you remember to ask for it, and it tells you the compliant form for each one.

Fed. R. Civ. P. 5.2 and Fla. R. Gen. Prac. & Jud. Admin. 2.420 and 2.425 leave the last four digits of a number, a minor's initials and the birth year. The detectors are deterministic and anchored on context, because the failure that matters is the false positive: a checker that flags your case number teaches you to click through the panel, including on the day it finds a real one. A second pass reads for a person identified in narrative rather than by a number, and everything it finds is marked for you to read rather than acted on. Applying the suggestions writes a new version to review as a diff and withdraws any approval — nothing is ever rewritten in place.

  • Advisory. It reports and the attorney signs off — nothing is redacted without a person pressing the button, and nothing is filed by this check either way.
  • A minor is caught by narrative pattern and marked for reading, because the firm has nowhere to record that a party is a minor yet. The detector already reads that flag, so it becomes exact the day the party wizard asks.
  • Drafts and pleadings only. Produced documents are not covered by this pass.

Sealed tenants

Another firm's matters cannot turn up in yours, and no screen in this platform shows the person running it a client document — what he sees is queue depth, spend and storage growth. When a client asks who else can see this, the answer is short — and it does not rest on anyone here remembering a policy.

A storage bucket of its own per firm; PostgreSQL row-level security that the application role cannot bypass; and firm predicates in the application itself. The test suite asserts that a query with no firm context returns zero rows — not that it should, that it does.

  • Thirteen narrow, individually reviewed functions are allowed to cross the tenant boundary, and nothing else is. Eleven resolve a credential before any tenant context exists: a session cookie, a portal hostname, a login by email, a calendar-feed token, a matter's inbox address, a delivery link, a client session, a client login, a signature link, a backup appliance's check-in, and a firm's public intake slug. The other two read the sales inbox, which belongs to no firm.
  • The storage buckets are per firm but the credential is not: src/lib/storage.ts signs every request with one R2_ACCESS_KEY_ID, so a stolen key reaches every firm's ciphertext rather than one firm's. Per-firm scoped keys are due before a second firm is onboarded (OPEN-ISSUES #6). Keys are unaffected — every master key is per firm and none of them is in object storage.

Ethical walls

You can take the case with the conflict in it. The screen is provable rather than promised: who was walled off, from what, from when, and who let them back in, is a record you can hand to the Bar.

The firm is open by default; walling is the exception. Walling a matter restricts it to an allowlist, and a new wall starts EMPTY — nobody sees the matter until someone is added, and the person raising the screen is not added automatically, because the person raising a screen is often exactly the person being screened. Enforcement is a single seam every read passes through, so a walled matter is absent from search results, morning briefings, calendars and exports rather than merely hidden on its own page. To someone off the list the matter returns a 404 — indistinguishable from one that does not exist. Walls bind administrators too: an admin manages a wall from the settings page without gaining any access to the matter behind it.

  • A wall is per matter, not per document. A document in a walled matter is walled; there is no way to screen one document inside an open matter.
  • Releasing a wall restores access for everyone; there is no partial release. The wall row and its history are never deleted — that record is the screening proof.

Records and retention

Append-only audit trail

When someone asks who saw a privileged document and when, the answer is one screen away — reads included, not just changes. Nobody can edit it after the fact, which is the only reason it is worth producing.

A trigger prevents update and delete — including by the platform operator. Actors are distinguished as user, AI, platform, system, or external, so "who outside the firm touched this matter" is one query.

Closing a case out

You stop paying full rate to store a case that finished four years ago, without the file leaving the system. The chronology, the parties, the facts and the audit trail are all still there and still answer questions; only the documents themselves take hours instead of seconds to get back, and only if you ask. And when a client — or successor counsel — compels the file, what leaves is the CASE and not your strategy: the export is five tables by rule, so your Chambers threads, your simulations, your valuations and your draft checks are not in the bundle and cannot be added to it by a change of mind at the keyboard.

Archiving copies every document's sealed bytes to a second, cheaper store, checks each copy arrived at the size it should be, writes a manifest hash, and only then removes the live copy — in that order, so a failure before the manifest is committed leaves the matter untouched and nothing deleted. What does NOT move is the case record: facts, timeline, parties, deadlines, hearings and the audit trail stay in the database, so an archived matter is still searchable, still answerable by case chat, and still raises a conflict against a future intake. Getting a document back is a restore request, which runs in the background and tells you when it lands — the cold copy is not consumed by it. A matter under a litigation hold cannot be archived at all.

  • Closing and reopening a matter are in the interface now (the close-out card on the matter page), and the cold-storage destination is configured and its full round trip verified — so archive and restore work end to end rather than refusing. The archive still runs on an operator-triggered basis rather than any schedule, which is deliberate while the platform holds no real client files.
  • The $75 close-out and $50 export fees are settled prices rather than placeholders now, but a closed matter holding no documents at all is still archivable and still charged.
  • Storage is metered from stored document sizes and charged on the first of the month. A month the platform was down for entirely is not caught up later — the catch-up only looks back one month.
  • A document uploaded to a matter after it was archived stays live INDEFINITELY while being billed at the archived rate. Nothing ever moves it cold — archiving refuses an already-archived matter, and the sweeper only finishes a committed delete phase — so it is a permanently cheap live copy, not a temporary state.
  • The export bundle is produced from the command line by the operator, as root. There is no screen a firm can click to export their own matter.
  • The export scope is an ALLOWLIST of five tables — documents, facts, events, audit events and parties — rather than a list of exclusions. Work product is out because it was never queried, not because somebody remembered to leave it out, and the audit CSV additionally drops the strategy rows (who opened Chambers, what kind of simulation ran) because audit detail is exported verbatim and the shape of the row is itself the strategy. Widening it means editing that one file, which is the point of it being one file.

Knowing it is right

Quote verification

The thing that makes a fact ledger worth trusting is that its citations are real. This is the check that they are, run on every fact, rather than a promise that the model is careful.

A fact is only recorded with a verbatim quote and a page. After a document is read, each quote is located in the text of the page it cites — a string search, no model, no cost. There are three verdicts, and the middle one carries the weight: exact, normalized (it matches once the artifacts of PDF extraction are folded — broken lines, hyphenation, ligatures, curly quotes — and is still genuine support), and absent, which is the finding. "Not yet checked" is stored distinctly from "checked and not found", because we have not looked and we looked and it is not there are different statements.

  • Unsupported facts are excluded from drafting and flagged on the matter and document pages; superseding the document's reading clears them.
  • A quote shorter than a dozen characters is reported absent rather than passed: a two-word match proves nothing, and blessing one would empty the check of meaning.
  • It proves the words are on the page. It does not judge whether the fact drawn from them is a fair reading — that is what an attorney is for.

Monthly fact spot-check

The claim "extraction is accurate" becomes a number the firm measured itself: an attorney marks each sampled fact correct, incorrect or unclear against its quote, and those verdicts are divided into an error rate you can read on screen and watch over twelve months.

The hourly tick creates one review item per firm per month: facts sampled with weight toward low confidence and quotes that only matched after normalization. It lands in the review queue with a companion task. Each sampled fact is shown beside its quote with a link to the page it came from and three buttons — correct, incorrect, unclear — and the month cannot be closed until every sampled fact carries one. The rate is computed from the verdicts every time it is displayed, never stored, so it can always be reconstructed from the facts an attorney actually read.

  • The sample size is per firm per month (default 12) and set in firm settings (0 – 50); 0 disables the check and the measurement with it.
  • The rate is incorrect verdicts divided by facts judged. An "unclear" counts in the denominator and not as an error, so it can only pull the rate down — which is why the unclear count is always shown beside it rather than folded into it.
  • It measures the sample, not the file. Twelve facts a month is a number a firm will actually get through, not an audit of everything extracted, and a small sample moves a lot on one error.
  • A month nobody has reviewed reads "not measured" rather than zero — an unjudged sample is not a clean one.
  • Verdicts are three buttons and an optional note. There is no structured taxonomy of what went wrong, so the notes are still free text.
  • Sampled facts that were later deleted cannot be judged and are left out of the arithmetic rather than counted either way.

Citation checking

The failure that has sanctioned lawyers — a confident citation to a case that does not exist — is caught before you read past it. A citation either resolves to a real opinion or it is shown in red as unciteable.

Reporter citations are extracted from the text by pattern, deterministically, and looked up in CourtListener's free opinion database in one call. No model is involved in the verdict. There are four outcomes and each renders differently: resolved (with a link to the opinion), unresolved, ambiguous — more than one case answers to that citation — and not checked, which is what a caller sees when CourtListener is unreachable or unconfigured. The deterministic pass is the floor in the draft cite-check: every citation found in the body is reported whether or not the model mentioned it, so the model can add findings and can never hide one.

  • Verified against CourtListener's free opinion database — not Westlaw, no treatment, no Shepard's. Existence and citation accuracy only.
  • A resolved citation can still be bad law. That judgment stays with the lawyer.
  • When CourtListener is unreachable or unconfigured, citations are marked not-checked — never silently passed.
  • Federal and Florida reporters are recognized; a citation in an unlisted reporter is not extracted at all rather than given a wrong verdict.

The review gate

Every piece of AI output that could reach a court, a client, or your calendar stops in one queue and waits for an attorney. You can answer the supervision question a bar committee actually asks — who reviewed this, when, and what did they approve — from one screen, for every kind of output, rather than from four different places and a memory.

Work product and reference are separated at the point of creation rather than at the point of sending. Anything with legal consequence — a draft, a status update to a client, a deadline suggested by a scheduling order, a proposed split of a scanned bundle, the monthly fact sample — is created unapproved and appears here. Anything informational — a case digest, an answer to a question about the file — is marked as such when it is written and NEVER enters this queue, because a queue that fills with things nobody needs to approve is a queue people learn to clear without reading. Approving or rejecting is attorney-only and takes a note. The approval binds the exact text that was read: editing an approved draft revokes its approval by a database trigger. A deadline that has not been confirmed cannot be calendared, enforced by a database constraint rather than by the application remembering. A trial simulation is labelled internal decision support in the database and can never be approved as work product at all. The queue is also screened: a matter behind an ethical wall does not show its items here to anyone off that wall's list.

  • It gates AI output. Work a person did by hand does not pass through it, and it is not a supervision record for anything but the model.
  • Approve and reject are the only two verdicts. There is no "approve with changes" — changing it means editing the draft, which revokes the approval and returns it here, deliberately.
  • Informational output is never queued: case digests and answers to questions about a matter are reference and are marked that way when they are written. That is a decision about what deserves an attorney's time, and it means an empty queue is not evidence that nothing was generated.
  • Nothing expires out of it. An item nobody decides waits indefinitely rather than timing out into either answer, and the dashboard's unreviewed-AI signal is what notices instead.

Is everything working?

A partner who wants reassurance at nine on a Sunday gets it in four lines instead of a phone call on Monday. Each line says what is true and when it was last checked, and an unconfirmed line says so plainly rather than showing a hopeful zero — an unread check and a healthy one must never look alike.

The page reads the same records the operator's own alarms read, against the same thresholds — forty-eight hours for the nightly copy, forty-five days for the monthly restore drill, forty-eight for a firm's own box. It shows when the documents were last backed up, when a restore was last actually tested and passed, whether the three copies are current, and how much is stored. Nothing is a hardcoded claim: every line rests on a record with a timestamp, so a leg that stops running turns that line rather than leaving a green mark behind.

  • It reports; it does not act. Nothing on this page is a button, and a failure here has already raised an operator alarm before you see it.
  • The figures are as fresh as the checks behind them: storage is measured once a day and backups run nightly, so a number can be most of a day old. Each line says when it was read rather than implying it is live.
  • The storage figure is what you are holding, not what you are billed for — the plan allowance counts archived storage at a third and lives on the usage page.

Where the copies are, and how you know they are there

"What happens if your server dies" has an answer with a date on it rather than a reassurance. There is a second copy that nothing can quietly delete, a third that is slow and cheap and exists for the year nobody planned for, and a monthly drill that actually pulls a document back out — because a backup nobody has restored from is a backup nobody has tested.

Every night the sealed documents and an encrypted dump of the database are copied to a second store where each object is placed under an object lock — writable once, and the lock refuses deletion until it expires, which is what makes ransomware and a bad afternoon the same problem rather than different ones. Every week the same material goes to deep archive. Monthly, a drill takes a document out of a backup and decrypts it end to end. Every leg records the run it made, and the hourly pass raises an alarm by email when the newest SUCCESSFUL run of a leg is older than it should be — forty-eight hours for the nightly, ten days for the weekly, forty for the drill. Only a run that actually succeeded counts, which is the difference between watching backups and watching a timer.

  • What is copied is ciphertext and an encrypted database dump. Reading any of it needs the firm master key, which is why escrowing that key is the first item on the onboarding checklist and the one step there that cannot be recovered from.
  • The monthly drill proves that a document comes back and decrypts. It is a sample: it does not prove every document would, and it is not a full restore rehearsal.
  • Two legs added later — the source-code bundle and its own drill — are copied but are NOT yet in the freshness alarm, so their staleness is unwatched (OPEN-ISSUES #171).
  • This is the platform's own regime, in the platform's own storage accounts. A copy under the firm's own roof is the appliance, which is designed and not built.

Running the firm

Firm administration

You do not file a support ticket to change how your own firm works, and every change carries a name and a timestamp if anyone ever asks who did it.

Administration is a flag, not a role — an office manager can hold it without being called an attorney, and any role can. Administrators set who sees the cost ledger, turn cost recovery on or off, manage ethical walls, set per-person AI spend limits, and grant or revoke administration itself. The last administrator cannot be removed, enforced as a single atomic statement so two admins revoking each other at once cannot leave a firm with none. Every change writes an audit row in the same transaction as the change.

  • Cost recovery offers off or at-cost only. Passing AI cost through at a markup requires a signed engagement letter carrying cost-recovery terms — the platform writes that clause into the letter for you, with the opinion it rests on named beside it — and the markup itself is set with us rather than on this page, because a rail you can drive around in a form is scenery.
  • The storage tier is displayed here but changed by conversation, because a tier change is a price change.

Seats, roles, and what each can do

You can put your office manager and your paralegal in the system without either of them being able to approve work product, confirm a court rule, or read the audit trail. And administering the firm is not the same thing as practicing law here: the person who manages the account does not have to be an attorney, and being one does not make them able to approve anything.

A person holds one role. Attorney is the only one that can approve or reject in the review queue, confirm a court ruleset, open the audit trail, post in Chambers, send a draft out, or complete an onboarding attestation — and each of those is checked at the act itself, in the server action, not by leaving a button off a page. Paralegal and staff can do the work: upload, file, search, ask the file questions, build productions, record time. Client-portal logins are a separate credential type in separate tables entirely and are free and unlimited. ADMINISTRATION IS A FLAG, NOT A ROLE, and that is the design decision worth knowing: any role can hold it, so an office manager can manage walls, spend limits, cost-ledger visibility and the other administrators without being called an attorney and without gaining a single attorney permission. The last administrator cannot be removed.

  • A person holds ONE role and it is set when they are invited. Changing it is a request to us rather than a control on the settings page.
  • The roles are fixed: attorney, paralegal, staff, client. There are no custom roles, no per-matter roles, and no way to grant one attorney act without granting them all — a permissions system a firm can compose is a permissions system nobody can audit, and this product would rather be legible.
  • Screening a matter from a person is a separate mechanism entirely: roles say what kind of act somebody may do, ethical walls say which matters they may see, and neither substitutes for the other.

Your own address for the portal

Your people go to your address rather than to a vendor's, and the page that greets them carries your firm's name. It also means an email address is not enough to reach your data: sign-in resolves the firm from the address it was reached at first, so a credential typed at the wrong door does not open the right one.

A firm can point a name of its own at the portal, or use its name under ours; either resolves to exactly one firm, and the mapping is unique at the database level so two firms cannot claim one address. The resolution happens BEFORE any sign-in is attempted and before any tenant context exists — it is one of the narrow functions allowed to cross the tenant boundary, and it returns the firm's name and nothing else. An address that matches no active firm is refused rather than shown a generic form, so an unknown host cannot be used to probe for which firms exist.

  • It is the ADDRESS that is yours, not the appearance. The database carries a place for a firm's colors and logo and NOTHING READS IT — no page in the product renders a firm's branding today. The portal looks the same for every firm, and saying otherwise would be selling a column.
  • One address per audience — three in total, and no more. You cannot run two names for the same audience at once, and there is no redirect from an old one if you change it.
  • The public marketing site is separate and stays ours. This is the address your people sign in at, not a website we build for you.

Accounts, sign-in, and two-factor

Nobody shares a login, so the audit trail names a person rather than a password. A passkey cannot be phished, reused across sites, or read off a sticky note, and it is two factors in one gesture rather than two ceremonies stacked on each other. A paralegal who leaves on Friday is disabled on Friday, in one switch, and every session they hold is dead on their next click. And when somebody cannot get in, their own firm administrator fixes it in one click instead of ringing us.

We create the firm; every person after that arrives by invitation, sent by email from a firm administrator. The link is single-use and time-boxed, consumed the moment it is used, so a forwarded invitation cannot be redeemed twice. There is no password to choose: accepting the invitation signs them in and asks them to add a passkey, which is stored as a public key — the private half never leaves their device, so a stolen database cannot mint a login. A passkey is bound to the exact address it was created on, which is what stops one firm's credential being offered at another's. Firms may demand a further factor after sign-in, though the recommendation is not to: a passkey unlocked by a face or a PIN is already two. A session lasts twelve hours and ends after an hour of doing nothing, whichever comes first. Your firm signs in at its own address, so the page already knows which firm it is before anyone types anything.

  • There is no self-service sign-up. There is no password reset either, because for anyone invited since passkeys there is no password: somebody locked out gets a sign-in link by email, either from their firm administrator or from the sign-in page itself. That link proves control of the mailbox and nothing more, which is the honest description of what it is.
  • An invitation is single-use AND time-boxed — it expires, and only its hash is stored, so a lost link is reissued rather than recovered. It is emailed, and it arrives from LEXICERA at a lexicera.com address rather than from the firm's own domain: the platform is the verified sender, and a firm's name over a vendor's address is the mismatch that teaches people to stop reading domains. Worth telling a new colleague to expect it, because a first message from an unfamiliar sender is exactly what a careful person treats as suspicious.
  • What a person may DO once they are in is their role, which is its own capability and its own set of refusals. Signing in and being allowed to act are separate questions and this entry only answers the first.
  • A passkey is bound to the one address it was created on, so somebody who signs in at more than one of your firm's addresses enrolls at each, and changing a firm's address means everyone enrolls again. Where a firm asks for a further factor it is an authenticator code or an emailed code; text-message codes are not supported deliberately — SMS is the factor that gets taken.
  • Client-portal logins are a separate credential type in separate tables entirely, and none of this applies to them.

Setting the firm up

The handful of steps that decide whether this is actually safe to rely on get done in the first week, instead of being the steps everyone means to come back to. A progress meter on the front page says how far along you are, each outstanding step links straight to the control that finishes it, and the one step that cannot be recovered from is done with us rather than ticked by you.

Eleven steps, seeded when the firm is created and topped up on the hourly pass, so a firm that has been running for months picks up a new step within the hour. Nearly all of them detect themselves from the data — billing rates set, staff invited, one real matter taken end to end, the billing identity filled in, the firm signature drawn, the payment rail connected, an engagement letter live, and the two DECISIONS (cost recovery, and how staff sign in) recognised from the moment somebody actually makes them. A checklist maintained by hand is a checklist that lies, so almost nothing here is a box a person ticks. Escrowing the firm master key is first, because it is the only step a firm cannot recover from having skipped — and it is completed by us, with you, once we have watched a document restore from your copy. Outstanding steps show as a progress meter on the dashboard and at the top of Settings, and stop showing the moment there are none.

  • It is a checklist rather than a gate. Nothing on this list blocks anything: a firm that skips the escrow step can still use every part of the platform, which is exactly why the step is first and worded the way it is.
  • The key-escrow step cannot be completed by the firm at all. It is confirmed by us, on the firm's record, once a document has actually been restored from the firm's own copy of the key — because a one-click attestation about the one unrecoverable step measures willingness to click.
  • The firm signature can be put on file, or cleared, only by the firm's named signer or by one of the firm's administrators acting for them — and a firm that has not named a signer refuses everybody, administrators included, so nobody inherits that authority by a signer's account being deleted. Every save records which of the two roles entered it, so an administrator putting the principal's signature on file is visible as exactly that in the audit trail and is never recorded as the principal's own act.
  • Nothing on the rail emails anybody on a schedule. The one message it can send is the hand-to-signer nudge, and only when an administrator presses the button.

What it will not do at all

Beyond the per-feature limits above, four things are absent by decision rather than by schedule, and they are the ones worth knowing before a demonstration.

It is not a case-law research service

Citations are resolved against CourtListener's free opinion database: a case either exists and matches its citation, or it is flagged unciteable — in red, on the draft's cite check and in Chambers, so the check cannot silently pass one. Removing it is the lawyer's act, not the software's. That is existence and accuracy only — not Westlaw, no treatment, no Shepard's. A citation that resolves can still be bad law, and only a lawyer can say so. Drafting is still instructed to write [CITATION NEEDED] rather than cite anything it was not given.

It does no trust accounting

If you hold client funds, this cannot be your only system. Half an IOLTA implementation is worse than none.

It does not file anything

No e-filing, no court-portal login, no docket scraping. It prepares documents; a person files them.

It does not predict outcomes

The trial simulation is a machine imagining people. It is useful for finding the weak point in your own argument and worthless as a prediction, and it is labelled that way everywhere it appears.

Sources

  1. codesrc/registry/pricing.ts — a price that is not in that file may not appear in rendered output, and the test suite asserts it in both directions: every published figure must appear, and every retracted one must not.
  2. policyWithin a matter, the same document is never ingested, read, or billed twice. A file already in the matter — the same bytes, arriving again by upload, by email, or in a bulk import, from a production, a client dump, or a second custodian — is recognized by its seal and costs nothing: it is neither read again nor charged again. The check is the plaintext SHA-256 of the file, scoped to the matter: the same production filed to a second matter is read again, because it is a second reading.
  3. codesrc/lib/access.ts — canAccessMatter() is the single seam every per-matter read passes through, and wallPredicate() the fragment every cross-matter query carries. Documents, search, the fact ledger, briefings, exports and every AI surface inherit the screen from one place rather than each remembering to apply it. Migration 041.
  4. codeA matter behind a wall returns 404 to someone off its list — the same answer as a matter that does not exist, so the existence of the screened case is not disclosed by the shape of the refusal.
  5. codesrc/lib/ai.ts assertCanSpend() — a zero prepaid balance pauses AI work and nothing else. Documents, downloads, search and everything already extracted stay available. A firm out of credit does not lose access to its own files. The pause is a WAIT, not a loss (LEX-391): assertCanSpend throws a typed SpendPausedError, src/workers/extract.ts routes it to queue.ts pauseJob() instead of failJob(), so the attempt never counts toward the five that dead-letter a job and the work re-runs by itself when the balance turns positive. Jobs stranded BEFORE that mechanism existed are not yet revived: the one-time requeue is written and held unapplied at app/db/pending/LEX-429_requeue_balance_dead_letters.sql, and running it is LEX-429's supervised act.
  6. migrationMigration 042 — Florida matters count under Fla. R. Gen. Prac. & Jud. Admin. 2.514, including the post-2019 start-day skip, with a five-day service extension where federal practice adds three. An unrecognized counting mode throws rather than quietly computing federal dates for a state matter.

Every claim on this page that could be checked, and where to check it. We do this because it is what the product does: an answer that does not carry its source is an answer you have to take on trust.