Lexicera Request a demo

Platform

All of it, and what it does not do.

59 capabilities, grouped by the part of a practice they belong to. Each one carries its deliberate limits directly underneath it[1] — a gap named once at the bottom of a page is a gap that was hidden.

This page is generated from the same registry the product is built against, so it cannot describe a feature that does not exist, and a capability cannot ship without its entry here.

How it works

When a document arrives

1 It arrives Upload it, or forward it to the matter's own email address. It is encrypted before it leaves your building, and charged per page — the same rate whichever way it came.
2 It is read Once, ever. The document becomes individual facts, each carrying the exact sentence and page that supports it.
3 It is compared Against everything already in the file: contradictions, duplicates, gaps, dates that cannot both be true.
4 It is usable Ask the file a question and get an answer with its citations. Nothing in it needed re-reading.

That ordering is the whole economic argument. Getting a document in and reading it are the two operations you pay for, once each; everything afterwards works from the facts reading produced, which is why a question against a ten-thousand-page file costs cents.[2]

Why this rather than a document reader

Four things that are structural, not settings

The screen is enforced in one place

Wall a matter and it disappears everywhere at once — search, briefings, calendars, exports — because every read passes through a single seam.[3] To someone off the list it returns the same answer as a matter that does not exist.[4] The AI cannot be asked about it either, which is usually the question a conflicts partner is really asking.

Running out of credit does not lock your files

A zero balance pauses AI work and nothing else. Documents, downloads, search and everything already extracted stay available.[5] A firm that cannot pay this month still owns its practice.

The prices live in one file

A price that is not in that file may not appear on this site, and the test suite checks both directions — every published figure must appear, every retracted one must be gone.[1] It is a strange thing to build. It is why nothing here is quietly out of date.

Florida is counted as Florida

State matters count under Rule 2.514, including the start-day skip and the five-day service extension where federal practice adds three. An unrecognized counting mode throws rather than quietly computing federal dates for a state case.[6]

Intake and conflicts

Intake, conflicts, and limitations

You know within minutes of the phone call whether you can take the case and how long you have to file it — before a matter exists and before anyone has put a day into it.

An intake is not a matter. Conflicts are checked by name similarity — not exact match — across every party in every matter the firm has ever had. The SOL calculator computes from versioned, cited statutes and says plainly when accrual is a question of fact rather than a date. The matter is created last, after a signed engagement letter.

  • A prospective client who fails a conflict check never causes a matter row to exist.
  • SOL rules ship as drafts until an attorney confirms them.

Inquiries from your own website

An inquiry from your website arrives as an inquiry rather than as an email somebody has to re-key, and the first thing you see about it is whether you can take it. The conflict that would have surfaced on day three, after a partner had already replied warmly, surfaces before anyone reads the name.

Your website posts to an address belonging to your firm. The conflict check runs on submission — it is a name comparison in the database, it costs nothing and calls no model — so the inquiry lands already carrying its conflict status. The limitations analysis deliberately does NOT run here: that one is a model call and this address is reachable by anyone on the internet, so wiring it in would let a bot inside the rate limit burn your prepaid balance to no purpose. It runs when a person at the firm opens the inquiry, which is the moment it is worth anything. Nothing submitted is ever rendered back — every field is treated as hostile, stored and never reflected.

  • It is an address, not a form. What your visitors see is your website's own form; we give you where to send it and what it accepts.
  • The limitations analysis does not run until a person at the firm opens the inquiry, deliberately — an anonymous form that can spend your balance is a hole a rate limiter narrows rather than closes.
  • It is rate-limited per address and overall. A burst is dropped rather than queued, and a dropped inquiry is logged without its contents — so a genuine flood of real inquiries is something to tell us about rather than something to discover.

Clients

Client portal

The client can see where their case stands without ringing you, and — where you have switched it on for them — can send you documents straight from the portal, with no link to issue and nothing attached to an email. They also see everything they have sent and when it arrived, so "did you get it?" stops being a phone call. Nothing reaches them until an attorney has read it and said so.

A separate credential type in its own tables, with access granted per matter. There is no "all matters" value and no way to express one, so the worst a scope bug can do is grant the wrong single matter. Status updates are drafted by AI and cannot publish without an attorney approving them.

  • Access is granted per CASE, not per matter: a client on a case reaches every matter of it. Each matter is still its own row and there is no "all matters" value; what this means is that narrowing further — to one client's own letters, or their own uploads — is each screen's own job rather than the access table's.
  • Nothing in the product ends a case membership yet, so access is opened by the roster and closed only by hand.
  • A client can only send to the matters of the cases they are on, and only while you have their upload permission open for that matter. Files that reached you by email, or through an anonymous case link, are not attributed to anybody and so are not listed for anybody.

Signing the engagement letter

The client can sign on the phone in their car, and you do not chase a scan. You can also see whether they have even opened it, which is the question that used to be a phone call. What you keep afterwards is better than a scan: if anyone ever edits the letter after it was signed, the record says so, rather than leaving you to argue about which version was agreed.

Your firm has one engagement letter. Sending it fills in the client, the matter, the fee basis and the fee terms, and your own signature block, and freezes the result — so the letter that goes out is already signed by the firm and needs one signing pass, not two. The client gets an email with the link inside it; the link needs no login, is single-use, and expires. The signer reads the letter, ticks that they agree to it, ticks that they agree to do this electronically — two separate consents, because the law asks for both — and types their email and full legal name. What is stored is both consents, the name, the address and browser it came from, the moment, and a SHA-256 of the exact words that were on the screen. That last one is the point: a letter altered after signature no longer matches its own seal, and the inquiry says so plainly instead of quietly. The signed letter is emailed back to the client as a file at the moment they sign, filed into the matter as a document, and — once they have a portal login — stays visible to them there. On a case with several clients on it each of them sees their own letter and nobody else's. A matter cannot be opened until a signature exists — the button stays disabled.

  • It is a typed-name signature with an intent record. It proves what was agreed to, when, and from where; it does not prove who was at the keyboard, and it is not a notarisation or an identity check.
  • One letter per firm. The fee section is filled in per client when you send it, but the words around it are the same letter every time, and changing them is a thing we do for you rather than a screen you edit.
  • The link expires and is single-use. A client who loses it needs a new one issued — there is no way to reopen a link that has been used.
  • The signed copy is a web page rather than a PDF. It prints correctly and carries its own seal; the PDF arrives when the rest of the product's PDF machinery does.
  • There is no decline button on the signing page. A client who does not want to sign tells you, and you deal with it the way you would on paper.
  • This is the engagement letter and nothing else. No other document in the product goes out for signature: settlement authority, releases and substitutions of counsel travel the way they do today.

Documents

Secure document depot

Everything filed in a matter sits in one place and is findable by a phrase you half-remember, instead of spread across an inbox, a shared drive, and somebody's desktop. What you hand back is the file you were sent, not a copy somebody re-saved.

Each file is encrypted on the server with a key unique to that file, which is itself locked with a key belonging only to your firm. Only ciphertext reaches the storage vendor — they hold bytes they cannot read. A SHA-256 of the original is kept as a seal, and every download is checked against it, so alteration is detectable rather than silent. The seal is also what makes the second copy free: Within a matter, the same document is never ingested, read, or billed twice. A file already in the matter — the same bytes, arriving again by upload, by email, or in a bulk import, from a production, a client dump, or a second custodian — is recognized by its seal and costs nothing: it is neither read again nor charged again.

  • A recording is filed here and transcribed by the media lane; the picture itself is stored and indexed by key frames, never watched or described.
  • A single upload is capped at 200MB. A file over it is refused rather than truncated, and the way to bring something larger in is the bulk import — which is an operator command, so it is a conversation rather than a retry.
  • A zip archive is opened and filed as the documents inside it, each read and searchable in its own right, with the archive itself kept as it arrived. Only the top level: a zip inside a zip is filed whole. An archive that is password-protected, damaged, over 500 files, or that would expand out of all proportion to its size is kept exactly as it arrived, with a line on the document saying which of those it was — nothing is ever half-unpacked.

Email into a matter

The thread and its attachments end up in the file because you forwarded an email, not because you downloaded three attachments, renamed them, and uploaded them again. Whatever arrives is read and compared against the record like anything else.

Each matter gets its own address on your firm's own subdomain. Mail is received by a machine of ours that holds no documents, no database and no key material — a dedicated receiver that hands each message to the platform over an authenticated channel, where it is encrypted. No outside mail company reads your clients' mail, and opening a mail port on the machine holding privileged documents is still not a trade worth making, which is why it is a second machine. Duplicates are collapsed by Message-Id.

  • Requires INBOUND_WEBHOOK_TOKEN, and an MX record for the firm's subdomain. Fails closed when unconfigured.
  • The address is on our domain and is INTERNAL USE ONLY until the firm verifies its own domain — a filed address outlives the relationship, and one on our domain cannot be repointed by a firm that leaves.

Arrivals

You can answer "did that get here, and what happened to it" without asking anyone. And nothing lands in the wrong client's file quietly: the folder is a guess you can correct in a second, the case never is, so a document we are not certain about sits in one visible queue until a person says where it belongs.

Everything that arrives writes one row: the channel it travelled on, the sender, the subject, what became of it — filed, a recognized duplicate, ignored, held — and who made the call. "Who" is the point: the address it came to, a rule that matched, the model, or a named person. A document that arrived at the case's own address is certain and files instantly, with the model free to choose its folder. A document whose case was inferred is held: its file is encrypted and parked, no case is stamped on it, and it appears here with the suggested matter, the confidence and the reasoning, for one click to accept or a picker to override. Mail sent to an address that matches no case is logged too, and belongs to no firm — it is never guessed onto one. Arrivals for matters you are screened off do not appear, including the held ones whose only link to a matter is the suggestion. Adding a document does not mean going and finding the matter first. "Add documents" is in the menu on every screen and on the dashboard, and a file dragged onto any page opens the same panel with the file already attached — with the case pre-selected when you are looking at one. You choose the files first and the case second, and nothing is uploaded until you confirm, so a file dropped by accident costs nothing. Choosing the case files it instantly and certainly, exactly as uploading on the matter always did. Choosing "I am not sure yet" holds the file here instead, encrypted and unfiled, until somebody names the case.

  • A case is never guessed on your behalf. A document whose case is inferred waits for a person — which means an arrivals queue nobody works is a stack of documents nobody has filed. The oldest held item's age is printed at the top of the page for exactly that reason.
  • Held files have no expiry and are not counted against your storage allowance. The holding area is bounded only by the queue being worked.
  • A document parked with "I am not sure yet" has no case on it, so it is visible to everyone at the firm in the confirm queue until somebody names one — the same visibility a letter addressed to nobody in particular already has. If a document is sensitive, choose the case instead of parking it; the panel says so at the point of the decision. Its contents are never readable from the queue: the filename and the sender are listed, the file itself stays encrypted until it is filed.
  • A parked file is limited to 16MB, because it is held whole in memory while it is encrypted. An upload with the case chosen is far larger — that limit is about the holding area, not about the document.
  • Mail to an address that matches no case is recorded but belongs to no firm, so it does not appear here. It is never attributed by guesswork — matching a sender's domain to a firm would be a cross-tenant mistake with a plausible excuse.
  • The record of an arrival is append-only. Discarding deletes the file and leaves the row saying it arrived and was discarded, by whom and when.
  • The ledger starts on the day it was switched on. Documents filed before that carry no arrival row, because the channel and sender of a document already in the system cannot be reconstructed honestly.

Auto-filing at ingest

Opening a matter shows the file the way a firm keeps one: by section, titled by what the document is, sorted by the document's own date — not a flat list of upload filenames.

The reading pass that extracts facts also files the document (one model call, not two). Filing is virtual — nothing moves. A hand-filed section is never overwritten by the model; clearing it back to Unfiled lets the next reading re-file it. The vocabulary lives in a table, so a firm's own organization is an edit, not a rebuild.

  • The eight-section vocabulary is a starting point pending the firm's own filing conventions; it is edited live, per platform, not per firm yet.
  • Documents ingested before this shipped stay Unfiled until re-read or hand-filed.

Bringing an existing case in

The banker's box stops being the reason you never moved the case. Hand over the folder exactly as it came off the scanner and by morning it is a matter: every page read, the chronology built, the duplicates gone, and a set of searchable PDFs back in your hands to keep whatever you decide about us afterwards. Nobody at the firm renames a file or clicks upload four hundred times.

An operator points the import at the directory. It walks the tree in a fixed order, skips the scanner's stray dotfiles and anything empty, and identifies each file by its actual bytes rather than by trusting its name. Before anything is encrypted it hashes the file and checks it against the matter, so a duplicate costs no storage and no fee — this is the import path's share of the deduplication promise, enforced at the cheapest possible point. What is new is encrypted with the same per-file key scheme as an ordinary upload and queued for reading BEHIND every interactive job, so a large import never makes a document somebody just uploaded wait. PDF pages are counted at import so the dry run can tell you what the case will cost, and each file then bills at that same count as it is read in. Where a case arrived as one long scanned bundle, a cheap model proposes where each document inside it begins and parks the proposal for review; the cut happens only from page ranges an operator types, and the original bundle is kept, excluded from AI, with its facts retired — pages are never moved between documents.

  • The unitization cut is operator-confirmed — the model only proposes.
  • Splitting a bundle can yield fewer documents than ranges. Where two ranges hold byte-identical pages — two blank separator sheets, the same cover page twice — the second is collapsed into the first rather than filed again, because a matter holds one copy of a given set of bytes. The run reports which ranges collapsed, and the original bundle is kept whole either way.
  • Non-PDF files count as one page for the fee, however long they are. Audio and video count as no pages at all: a recording pays the per-hour transcription rate instead.
  • Bulk extraction runs behind all interactive work — a large case takes hours by design.
  • It is an operator command, not a screen. A firm cannot start an import itself.

Recordings become text you can cite

The deposition video sitting on a disc in the drawer becomes part of the case file instead of a thing somebody has to sit through. You search a phrase you half remember and get the passage, the segment number, and the second of the recording it happens at — so the clip you need for the motion takes a minute to find rather than an afternoon of scrubbing.

A recording is measured for its length, then transcribed by a speech model running on our own server — nothing is sent to a transcription vendor. Each segment of the transcript is filed as a page of the document, which is what lets everything else in the platform treat it like any other document: search indexes it, facts cite it by page, and quote verification checks the words against the transcript. Beside each of those pages is the start and end time in milliseconds, so a citation to "page 7" resolves to a position in the recording. A video also has its key frames extracted and stored encrypted beside it as a contact sheet of where the picture changed.

  • This is automatic speech recognition, not a certified transcript. It is a search and drafting aid, never a substitute for the court reporter's record, and it must not be quoted to a court as the transcript.
  • English only. The model is an English one, and a non-English recording produces nonsense rather than a translation.
  • Speakers are not labelled. Telling two voices apart is not something this can do honestly, and a transcript that attributes testimony to the wrong person is worse than one that attributes it to nobody.
  • A recording with no speech produces no transcript, no pages, and no charge.
  • Video is indexed by key frames, capped per recording. Nothing watches or describes the picture.

What the file knows

The front of the file, correctable

A typo in a case number stops being permanent. A judge who changes stops being wrong on every document the file produces. A party who was never really on the matter comes off it without the firm losing the record that they were once looked at — which is the record a conflict check searches. And the setup checklist stops nagging for fields nobody could fill in.

The Court identity card on a case is a form for an attorney or a firm administrator and a plain table for everybody else. Saving records one audit entry listing every field that actually changed — a re-save that changes nothing records nothing. Changing the JURISDICTION is treated as the significant edit it is: it selects the rule chain every computed deadline on the file was counted from, so every rules-engine date on every matter of that case is marked unverified for an attorney to re-confirm. Nothing is recomputed and no date moves — the same rule that governs every other suggested deadline in this platform. The parties page under a matter's case setup adds, renames, re-roles and removes. Adding and renaming run the firm-wide conflict check FIRST and show what they found before anything is written; changing a role or removing somebody do not, because neither changes a name. Removing takes a party off the matter's roster and leaves them in the firm's conflict history, permanently.

  • Removing a party is never a delete. The row stays in the firm's conflict record permanently and a conflict check will still return it — FL Bar 4-1.7/4-1.9 is why, and there is no screen that removes it from that record.
  • A jurisdiction change marks the computed dates unverified and stops. It does not re-run the rules engine, and no date, status or working is changed — a human re-confirms each one, exactly as they did the first time.
  • The caption is a property of the CASE, so editing it changes it for every matter filed under that case. That is what a court file is; two matters in one court file cannot answer to two different courts.
  • Changing the jurisdiction clears the assigned judge on every matter of the case, because a judge from the old rule chain would otherwise still be dispatched on. The judge has to be set again.
  • The practice area and the billing rates still have no form. Two of the five case-setup steps remain uneditable from the product, and the setup page says so.

The fact ledger

A ten-thousand-page production becomes something you can ask questions of rather than something you have to read. The reading happens once, overnight, and every answer afterwards arrives with the page it came from attached.

A document is read a single time by the cheapest capable model and decomposed into one row per assertion, each carrying a verbatim quote and a page number. Nothing afterwards re-reads the document — digests, chat, forensics, timelines, and drafting all query the ledger. That is what makes a 10,000-page matter affordable to ask questions of. A page whose OCR confidence falls below the policy floor is re-read with vision; a document whose facts fail quote verification beyond the policy ratio is re-read once on a stronger model — once, never a loop.

  • A document marked AI-excluded is never read — not by the reading pass, not by the escalation, not by anything that queries facts. What is missing is the MARKING: there is no control anywhere in the product that sets it. It is applied at import, or by us on request, and the badge you see on a document is showing you a decision made somewhere other than that page. If you need a document kept out of AI context, that is a message to us today.
  • Re-reading supersedes prior facts rather than duplicating them.
  • Facts whose quotes cannot be found on their cited page are excluded from drafting and flagged for review.
  • The vision re-read of poor pages is capped at twenty pages per document. Past that, low-confidence pages keep the text the scanner produced rather than being re-read — a badly scanned five-hundred-page exhibit is a bounded charge by design, and the pages beyond the cap are searchable but rougher.

Automatic forensic pass

The contradiction you would have found in month six turns up the week the document arrives, while there is still time to do something with it. It also catches the dull expensive things — Bates gaps, a date that cannot be right.

Two kinds of detector. Deterministic ones — Bates gaps, a file modified before it was created, dates in the future — cost nothing and run always. Exact duplicates are not among them: a matter holds one copy of a given set of bytes, refused at the database rather than reported afterwards. The AI comparison looks for contradictions and reconciliation failures against a retrieved slice of the ledger. Findings are deliberately over-inclusive; dismissing one teaches the matter so it is not raised again.

  • Deterministic findings still run with no API key and a zero balance.

Dual timelines

The chronology you would otherwise build by hand the week before a hearing already exists, sourced line by line, and prints as an exhibit. Reading the two spines together is where the awkward questions surface.

The cause timeline is built from dated facts, merging several documents describing the same event into one entry. The case timeline is derived deterministically from filings. A rebuild only ever touches rows it created: once a lawyer edits an event, the machine never overwrites it again.

  • Export is a print-ruled page rather than a generated PDF — better typography, working links, and no PDF dependency on a privileged-data server.
  • Editing an event by hand is supported by the data model but has no screen yet; the rebuild already refuses to touch a hand-edited row.

Working in one file

You stop filtering. Choose the file you are working in and the navigation becomes that file: its matters, its clients and their shares, its agreements, its productions, its recoverable costs, and a morning read of where it stands. Leave the mode and the firm-wide views are where they always were.

The rail carries a case selector. Choosing a file adds an "In this file" group; choosing "Firm — all files" clears it. The mode is remembered as you move around and survives a refresh, and it is presentation only — it changes which links are drawn and where they point, never what a query returns or who may see it. A link appears in that group only where a genuinely case-filtered view exists behind it, which is why the group grew one entry at a time rather than arriving whole: a link that showed the firm-wide list under one file's name would be worse than no link.

  • A screen on a matter applies here exactly as everywhere else: a matter you are walled off does not appear in its own case's lists, and a case you cannot see cannot be picked.
  • The mode is remembered on the device you chose it on, not on your account.
  • A capability your firm does not have does not appear in the group — the same decision that withholds its firm-wide link.

The case digest

Opening a case you have not touched since March starts with a paragraph rather than with a document list. It was written from the record instead of from whoever last remembered, and it carries the date it was written so you know whether to trust it.

The digest is written from the fact ledger rather than from the documents — the documents were read once and are never re-read, which is what makes a matter with ten thousand pages in it affordable to summarize at all. It is refreshed as the record grows, and the card shows when it was last refreshed and which model wrote it, because a summary whose age you cannot see is a summary you cannot weigh.

  • It is a summary, not a source. The facts underneath it each carry a quote and a page; the digest's own sentences do not, and nothing in it should be quoted anywhere without going back to the fact it came from.
  • It describes what has been READ. A document uploaded an hour ago and not yet through extraction is not in it, and the digest does not say which documents it was working from.
  • A matter with no readings has no digest, and the card is simply absent rather than empty.

Deadlines, dates and your day

Morning briefing and matter health

You open the laptop already knowing what moved overnight and what needs you today, instead of reconstructing it from an inbox and a memory of last week. The dates and the counts on it are counted rather than guessed, so you can act on them without checking them first.

Health signals are computed hourly from the record — matters gone quiet, unreviewed AI, critical findings, stuck documents, matters with no parties recorded, overdue tasks, a thinning balance. The briefing assembles those deterministically and a model writes only the opening paragraph, so the numbers are never a model's invention and the briefing still arrives with no AI configured. Each person chooses, on their own briefing page, whether they want that written paragraph, the computed briefing without it, or no briefing at all — and only the paragraph costs anything, so turning it off keeps every deadline, hearing and finding for free. A firm administrator can see who has the written summary on; they cannot set it for anyone else. Nobody is briefed until they have signed in at least once, and an account dormant for a month drops back to the free version by itself.

  • By default your briefing is about YOUR matters — the ones you have actually touched, worked out from your own activity rather than from an assignment table a firm of three would never maintain. It can be set to every matter instead. A file you have never opened is not on your briefing, so a quiet briefing means a quiet week for you and not necessarily for the firm.
  • The briefing hour and timezone are set at provisioning or invite time; the briefing page carries the only per-person preference there is.
  • What can be turned off is the written paragraph, not the briefing: on the facts setting every deadline, hearing, finding and arrival still arrives, because all of them are counted rather than composed — and that half is free and always will be.
  • An account that has never been signed into is never briefed, and one dormant for thirty days gets the free version until somebody signs in again. Neither is settable: the briefing is written when it is built rather than when it is read, so nobody should be paying for prose no one has opened.

Court-rules deadline engine

The dates that follow from what just happened are worked out for you, each showing the rule and the counting behind it, so calendaring is a two-minute review instead of an hour with the rules open. Nothing reaches your calendar until you say so.

Rules are versioned, cited data, not code, and the counting mode is one of those fields rather than a hardcoded assumption. Federal matters count under FRCP 6(a); Florida matters count under Fla. R. Gen. Prac. & Jud. Admin. 2.514, which since 2019 also skips a weekend or holiday at the START of a forward period, not only the end. In both, the trigger day is excluded and a last day on a non-court day rolls — forward after an event, backward before one. The service extension is the ruleset's own: three days federal, five in Florida, added after the period would otherwise expire; electronic service adds none. Every date stores its own arithmetic, and an unknown counting mode throws rather than quietly computing federal dates for a state matter.

  • Nothing is ever auto-calendared — enforced by a database constraint.
  • A ruleset the firm has not confirmed produces soft, unverified dates only.
  • Local clerk holidays, standing orders, and tolling are NOT encoded.
  • A confirmed date that passes is marked MISSED by itself, on the hourly pass, and shows as missed on the matter and the calendar. Nothing marks it done for you and nothing forgives it: the sweep records that the day arrived, which is what makes "we thought that one was handled" a question the record can answer.

Calendar and ICS feed

Your court dates turn up in the calendar you already look at, with reminders, so a deadline cannot hide inside a system you only open at your desk. Lose the phone and you revoke one URL.

A per-person subscription URL, hashed at rest and revocable. It carries titles and dates only — never facts, quotes, or documents — because a litigation calendar syncing to a personal phone is a foreseeable disclosure surface.

Orders that set their own deadlines

The document most likely to contain a deadline stops being the document nobody re-reads. And when the court amends it, you are not left comparing two orders by eye to find what moved.

The order is read for the triggering events it records — service, entry of judgment, a conference held — and each is handed to the same rules engine everything else uses, which owns the arithmetic, the jurisdiction's counting mode and the holiday table. The model cannot invent an event: it chooses only from the triggers this jurisdiction's loaded rules actually key off, and the choice is re-checked before it reaches the engine. Everything produced is a SUGGESTION in the review queue. Marking a new order as superseding an old one cancels the old one's unconfirmed dates and leaves anything an attorney already confirmed exactly where it is — a confirmed date an amendment moves is a conflict for a person, not something to resolve quietly.

  • It proposes; it never calendars. Every date still passes through the review queue and a named attorney, enforced by a database constraint.
  • It can only propose events the loaded rules recognize for that jurisdiction. An order setting a date no rule keys off is read and produces nothing, deliberately, rather than being forced into the nearest fit.

The federal docket, pulled in

The docket stops being a tab somebody remembers to open. What was filed turns up on the case timeline beside everything else that happened, and a filing that starts a clock is offered to the rules engine rather than noticed a fortnight later.

A matter carrying a federal court and docket number is checked hourly against CourtListener's RECAP archive, and new entries are written to the case timeline. An entry that names a filing is offered to the same rules engine everything else uses — as a proposal, never as a calendared date, exactly like every other deadline in this platform. It is one free API call per matter per pass; no model is involved at any point.

  • PACER itself is never called. RECAP is a mirror of what other people have already purchased — free, often complete, NOT authoritative, and it lags. Paid PACER access bills per page to the matter, which is the firm's decision to make rather than a default we switch on quietly.
  • The Florida ePortal has no public API and nothing here talks to it. Florida state matters are followed by forwarding the ePortal's own service emails to the matter's address, which needs no credentials from anybody.
  • There is no screen to set a matter's docket reference. It is set for you, and a matter without one is silently not followed. The court itself is editable, on the case's Court identity card, but that field is not what this pass reads.
  • It needs a CourtListener token configured. Without one nothing is pulled, and nothing pretends to have been.

Walking in cold, prepared

Somebody else's hearing lands on you at five o'clock and by the time you have made coffee you know who the parties are, what the case is about, what has moved lately, what is coming, and what you must not agree to. And before your own hearing there is the shorter version, sized for the corridor rather than the desk.

Both are built the way the morning briefing is, and for the same reason: the parties, the dates, the counts and the figures are assembled from the record by query, and a model writes only the prose over the top — so nothing a model produced is ever the source of a number. The coverage packet is the long form, meant for an attorney opening a matter cold. The hearing one-pager is the short form, generated against a specific hearing on the calendar. Both are generated on request and kept, so the one you read is dated and you can see how old it is.

  • Both are a snapshot taken when you asked for one. Neither refreshes itself, and the date it carries is the whole of the guarantee.
  • A model writes the prose. The dates, parties and counts in it were computed, but the sentences joining them were not — read it as a briefing from a colleague who has skimmed the file, which is exactly what it is.
  • The one-pager is generated against a hearing that exists on the matter. A hearing nobody recorded gets no packet, because there is nothing to generate one against.

Discovery

Discovery and productions

Productions go out with Bates numbers that still resolve two years later, a privilege log that wrote itself, and a receipt of exactly what was sent and when. The check that stops you producing today what you withheld last spring runs before the production can lock.

The model pre-sorts documents against parsed requests; an attorney confirms every call. A production cannot lock while it contains an unreviewed document, a document still marked privileged, or anything that contradicts a prior production — producing what you withheld before is a waiver argument, and it is invisible without cross-production comparison. Bates numbering is matter-wide and permanent.

  • Numbers are burned onto the page when the bundle is assembled, which is an operator command rather than a button on the production screen.
  • Redactions are recorded as coordinates and are not burned into pixels. A production containing a redacted document is refused rather than produced unredacted — see the assembly capability for why.
  • Request parsing, the responsiveness pre-sort, confirming calls, and deficiency analysis exist in src/lib/discovery.ts but have no screen and no caller yet — the production build, Bates, privilege log, consistency check, lock, and delivery steps are the part a lawyer can reach today.

The production bundle that leaves the building

The production goes out as a set the other side can load on the first try, with the number visible on every page it is cited by. Nobody at the firm stamps a PDF by hand at nine at night, and if anyone ever disputes what was sent, the manifest hashes the file that actually left rather than the one in the system.

A locked production is separated into pages, each page is stamped with its own Bates number — and an optional confidentiality legend — and the stamped pages are written out both individually, named by Bates number the way a review platform expects, and re-united as the produced document. The Concordance DAT and Opticon OPT load files are generated from the same pass, in the delimiter conventions review platforms have used for thirty years. The SHA-256 recorded against each document is of the produced bytes, stamping included, so the manifest's promise is checkable. Nothing here calls a model: numbering is arithmetic and load files are a fixed format.

  • Redactions are recorded as coordinates and are not burned into pixels; a production containing redactions is refused rather than produced unredacted. Producing a document whose redactions exist only as numbers in a table would deliver the material somebody marked for withholding.
  • Non-PDF documents are produced un-stamped, as their native files, and marked so in the manifest — a spreadsheet has no pages to burn a number onto.
  • It is an operator command, not a button on the production screen.
  • A document whose real page count disagrees with its assigned Bates range stops the run rather than being stamped with numbers that point at the wrong pages.
  • A Bates-stamped copy of a document already in the matter is a DIFFERENT document and is filed and billed in full. The free-second-copy promise is byte-exact: it rests on a SHA-256 of the file, and burning a number onto every page changes the file. That is deliberate — two versions that differ by a produced number are two things you may have to produce separately, and collapsing them would lose one.

Work product

Case chat with citations

You can ask the file a question at four in the afternoon and have a cited answer before you leave, instead of blocking out a morning to re-read a box. Every claim links to its page, so you check it before you rely on it.

The question is matched against the fact ledger, and the model answers using only the facts retrieved. Citations are parsed back into document and page links, so any claim can be checked in two clicks. It is told to say what is missing rather than infer.

  • Answers are informational and never enter the review queue.
  • Retrieval is full-text over facts; no embeddings until a checkpoint proves need.
  • It is a CONVERSATION, not a series of questions: a thread keeps the exchange, so "what about the second one?" works. Threads are per person as well as per matter — two attorneys on the same file are having two different conversations, and stitching them into one would put one lawyer's half-formed thinking into the other's context.

Drafting with cite-check and red team

A first draft that already cites this matter's own record, plus a read of the other side's best answer, before you have spent an afternoon on it. What comes back is a draft to edit — every legal citation in it is resolved against a public opinion database, and one that does not resolve is marked unciteable.

Drafts are written from the fact ledger with inline citations. The cite-check pass tests every factual assertion against that ledger — and reports EVERY legal citation, resolving each against CourtListener for existence and accuracy. That is not treatment: a citation that resolves can still be bad law, and the page says so. The red team argues the other side's best response and names what the record supports that the draft missed.

  • The model is instructed to write [CITATION NEEDED] rather than cite anything it was not given; what it does cite is resolved against CourtListener for existence and accuracy only — not Westlaw, no treatment, no Shepard's.
  • Editing an approved draft revokes the approval, by database trigger.
  • The pre-filing checklist is ADVISORY and always will be. It reads the requirements of the court and the judge your matter sits in, measures what can be measured, and says plainly what it could not check rather than calling it clean. A failing line does not stop you approving, exporting or filing anything: signing off records that an attorney read it. A requirement from a rule set your firm has not confirmed still appears, marked unverified — never dropped, and never shown as verified.
  • The firm keeps a memory of how it writes and what it has decided — its voice, notes on a judge or an opposing counsel, arguments and objections it has used, and the findings it has told the platform to stop raising. That memory reaches drafts, engagement letters, the forensic pass, the morning briefing and answers about a matter, so the product sounds like your firm rather than like a model. It is added by us or learned from a dismissal you explained; there is no screen to edit it, so what is in it is a question to ask rather than a page to open.

Chambers

The thinking you would do with a senior colleague on a Tuesday afternoon, with the whole fact ledger already in view: simulate opposing counsel, value the case, outline a deposition, argue a theory until it breaks — without any of it touching the file. Nothing said in Chambers becomes a fact, a deadline, a filing, a draft, or a time entry.

A thread runs over this matter's facts with citations back to the page each one came from. A hard question can be escalated to a more capable model for that turn only, at exactly twice the rate — the doubling is the model's own price in the rate card, not a markup added in the interface, and the checkbox says so before you send. The verbs (simulate, value, outline a depo) are the trial notebook's existing one-shots said as sentences; their results are stored where they always were, as internal decision support. Ethical walls bind Chambers exactly as they bind the matter page: a screened matter cannot be discussed, because its facts never enter the prompt. Every case citation in an answer is resolved against CourtListener, and one that does not resolve is marked unciteable.

  • Chambers writes NOTHING into the record — no fact, no deadline, no filing, no draft, no time entry. It recommends; the attorney acts through the product's own review paths.
  • Threads persist as firm records — there is no delete, by design. The application database role holds no DELETE on either table.
  • Never client-visible and excluded from the export bundle by rule.
  • Turn content is not covered by the per-document crypto-shred story; it lives in the database and its encrypted backups.
  • Staff can read a thread; posting a turn is attorney-only.

Getting a filing past the portal

Nobody is at a free conversion website at eleven at night with a client's filing in it, because the two mechanical reasons a portal rejects a document are handled before it goes near one. Neither of those reasons has anything to do with the law, and neither should cost anyone an evening.

The document is converted to PDF/A, which is the archival format portals insist on, and if it is over the ceiling that portal allows it is split into parts that each fit. A bookmark outline can be built two levels deep — the section of the file the document sits in, and the title its reading gave it — because a clerk opening a two-hundred-page exhibit set will look for one. The plaintext exists only inside a private working directory that is removed when the run ends, whatever the outcome.

  • It is an operator command, not a button on a screen. Ask us and it happens; there is no way for a firm to run it itself.
  • The outline is as deep as the record is: two levels, from the file section and the document's own title. There is no per-page heading extraction anywhere in this platform, so there is no honest way to emit a bookmark per exhibit — and inventing one from a model would put made-up structure into a court filing.
  • It does not file anything and does not talk to any portal. It produces a package that will be accepted; a person still uploads it.

Trial and strategy

Trial notebook and simulation

Witnesses, exhibits, offers, and the authority you hold are in the one place you actually open before a hearing. And you can hear the other side's best argument while there is still time to change yours.

Simulations put your argument to a simulated opposing counsel, bench, or jury panel. They are labelled internal decision support at the database level and can never become approved work product. Valuation asks the model for outcomes and probabilities and computes the expected value in code.

  • A simulation is a model imagining people. It is useful for finding weak points and worthless as a prediction, and the interface says so.
  • Depositions are here and are worth knowing about: a witness on the list can have an outline built for them from the matter's own record — organized by topic, each topic naming the admission it is for and the document that impeaches a denial. It is run from Chambers rather than from this page, which is where the strategy verbs live.
  • Exhibits and settlement offers are recorded and read back; the trial-item and matter-budget tables in the same migration have no screen and no code behind them at all. They are schema, not capability, and nothing in the product will fill them.

Getting paid

Passive time capture and billing

Time you already worked but would never have written down gets proposed to you, with the minutes taken from timestamps rather than from what you can remember on Friday. You accept or discard; nothing bills itself.

Activity is clustered into work sessions deterministically; only the billing narrative is written by a model. Nothing bills until you accept it. Technology costs appear as their own invoice lines, never folded into fees; file storage is included in the firm's platform arrangement and is shown for reference rather than billed to a matter.

  • A session of a single action is never billable.
  • IOLTA and trust accounting are out of scope by decision, not unbuilt: billing covers work already performed, into the firm's operating account. A firm holding client funds keeps doing that in its own trust systems.

The meter and the prepay gate

You can see what the AI cost on each matter and decide whether the client pays for it. If the balance runs out, the AI pauses and your documents, search, and downloads carry on working. Work that arrived while the balance was empty is not lost: it resumes on its own when you top up.

Raw (what Anthropic charged), platform (what the firm is charged), and client-billable (what the firm may pass on). When the balance reaches zero, AI features pause and nothing else does: documents, downloads, and search stay available. A firm that runs out of credit does not lose access to its own files. A pause is not a loss: documents uploaded while the balance is empty are stored, extracted and searchable straight away, and their AI reading runs automatically once credit arrives — nothing has to be uploaded again. AI runs only on live, billable accounts — a demo or a brand-new firm is shown canned examples or a short note that AI runs on live accounts, and never spends.

  • The monthly platform fee posts itself against the prepaid balance on the first of the month, at the published price, and the SEATS IT COUNTS ARE THE ACTIVE, NON-PORTAL PEOPLE AT THE MOMENT IT POSTS. An invited person who has never accepted is free — charging for an invitation nobody opened costs more goodwill than it earns — a disabled one costs nothing, and client-portal logins are free and unlimited because they are a different credential in a different table. There is no proration: the month you are active in is a month.
  • ANYTHING ELSE AGREED WITH YOU — a website we host, a service we run — is a NAMED LINE ON A DATED SCHEDULE, and it bills IN ADVANCE: it posts on the first of the month it covers, and its first month is prorated to the day if it did not start on the 1st. The platform subscription above bills the other way, for the month that ran, so one statement can carry a subscription line for last month beside a service line for this one. Every line names its own period for exactly that reason. A rate we agree to change is never an edit: the old line closes on its last billed day and a new one opens the day after, so a statement you were sent months ago still adds up from the schedule that produced it. One-off agreed work posts as its own dated line under Fees and carries no schedule at all.
  • OUR OWN TESTS ARE NEVER BILLED TO YOU. The nightly suite runs against a real firm, and every row it creates in the four metered tables is marked as test data at the moment it is written — the mark travels with the data rather than with the run, because the reading happens in a worker and the briefing in the server and neither can see an environment variable set in a test process. Deleting afterwards was the old design and it is a promise; not posting is a property.
  • The balance covers AI usage and the monthly infrastructure postings both. A zero balance pauses AI and nothing else — documents, search and downloads are unaffected, and a firm that runs out of credit does not lose access to its files.

Disbursement statements

Case costs stop being an overhead you absorb silently and become a line you can show a client, itemized, with the work that produced it.

The statement lists AI work grouped by what it was for, drawn from the figure stored at the time of each call rather than recomputed later, plus the flat close-out and export fees when they apply. Storage appears as context — how much this matter holds — and never as an allocated dollar line, because dividing a flat storage tier across matters would reintroduce per-gigabyte pricing through the back door. Whether a kind of work may appear at all is a property of the work: internal operations like the morning briefing are marked never-billable, and anything unclassified defaults to not billable.

  • It states what a matter cost. Those costs now reach the client's bill through the period close, so the statement and the invoice agree — but it still calculates no tax and talks to no outside billing system; the CSV is that handoff.
  • Passing costs to a client at anything other than cost requires an engagement letter with cost-recovery terms on file — and the platform drafts those terms into the letter, keyed to the jurisdiction and carrying the ethics opinion behind them, so what is required of the firm is reading and signing rather than drafting.

Spend limits and alerts

Nobody runs up a bill you did not agree to, and you find out at eighty per cent rather than on the statement.

A per-person limit is soft by default — it raises a signal to the firm rather than stopping anyone. A hard limit refuses interactive work once the month's spend passes it. Overnight document work is NEVER blocked by a limit: starving the reading pipeline to enforce a chat budget damages the asset every other feature runs on. The firm-level alert fires a health signal at eighty per cent of the level you set and blocks nothing at all.

  • Limits govern interactive AI only. Overnight document reading continues by design.
  • A limit is a monthly figure, not a per-matter budget.

The cost-recovery clause, written for you

You can charge a client for what a case actually cost to run without writing the clause yourself or guessing whether it is defensible. The words arrive in the engagement letter with the opinion they rest on named beside them, so the conversation with a client — or with a bar committee — starts from a citation rather than from your drafting.

The platform keeps jurisdiction-keyed clause language for cost recovery, Florida first, each version carrying the authority it was written against — ABA Formal Opinion 512 and Florida Bar Opinion 24-1 on charging clients for generative AI. When an engagement letter is drafted, the clause for that matter's jurisdiction is pulled in as an INPUT to the draft, never as an output nobody read: the letter is reviewed before it is sent, like every other draft, so the clause is read by an attorney before a client ever sees it. Language is versioned by the date it takes effect and a new version is a new row rather than an edit, so a letter signed last year keeps the words it was signed with.

  • Florida and federal language only. A matter in another jurisdiction gets a letter with no clause rather than Florida's words in the wrong state.
  • It is language, not advice. The clause and its citation are a starting point an attorney reads and takes responsibility for — the platform does not know your client, your fee agreement, or your bar.
  • Recovery at anything other than cost is set with us rather than on the settings page, and it requires a signed letter carrying these terms. That is not a missing feature: a rail you can drive around in a form is scenery.

Sending the bill, and chasing it politely

The bill reaches the client without anybody copying a PDF into an email, and an unpaid one is followed up without anybody remembering to. The reminders are deliberately few and deliberately mild — three over six weeks, ending in a request to talk rather than a threat — because the relationship with that client is yours and a collections tone sent under your name is not something you can take back. You can turn the whole ladder off for one client or one whole case in a click, and you see exactly what would be sent and when before it is.

A send is a row, not a flag, so one invoice keeps ONE number however many times it goes out — which matters because a returned payment re-opens the same invoice and sends it again. Each reminder step fires once per invoice ever, enforced by the database rather than by the code remembering, so an hourly job cannot turn into an hourly email. State is re-read at the moment of sending, not when the reminder was scheduled: a payment landing in between means the reminder simply does not go. And a payment that bounces PAUSES the ladder for that invoice and hands the decision back to you — chasing somebody whose payment just failed is a phone call, not an email. The invoice says so on its own page, and restarting is a deliberate act with your name and the time on it; nothing resumes by itself, and a second bounce pauses it again.

  • The reminder schedule and its wording are yours: up to five reminders, your days and your words, edited in Settings under Payment reminders. Three at 7, 21 and 42 days are the default you start with. The last reminder always carries our one sentence saying it is the last — it moves by itself if you add another.
  • Links, HTML and the name of a payment company are refused in reminder copy. The message already carries the one button that opens the invoice, and a chasing email carrying a second link is the shape a phishing message imitates.
  • Reminders never resume by themselves after a payment is returned. That invoice stops being chased automatically, on purpose.
  • An invoice with no due date is never chased — it is reported instead, because guessing a date to chase somebody on is not a fix.
  • No read receipts and no tracking pixels, ever. We cannot tell you whether a client opened the email, and would not add that if we could.

Automatic monthly payments, authorized by the client

Fifty clients on a monthly arrangement stop being fifty payment links a month. You send one invitation; the client sets it up themselves — bank details, verification and permission are all captured on the secure page, never by you and never by us — and from then on their invoices are charged when they fall due. They still receive every invoice before it is charged, they can stop it at any time by replying, and you can stop it from their client page in one press. Nothing is ever charged that you have not billed.

The authorization is held by the payment processor and named here by a reference — there is no card number, no bank number and nothing this system could charge on its own. Every charge goes back through the processor, against an invoice you issued, for the amount outstanding on it. Authorizations are kept as history rather than overwritten, so "which permission was this charge made under, and when did they give it" is a question with an answer. A client who re-authorizes supersedes the old permission; one who stops leaves a record that they once gave it.

  • The charge is made against an invoice you have issued, for what is outstanding on it. There is deliberately no way to charge a client an arbitrary amount — that is a different permission and this system does not have it.
  • One active authorization per client. A client who authorizes a second card replaces the first rather than holding both.
  • A declined charge is reported and the invoice stays unpaid. Nothing retries by itself, because a bill marked paid on a charge that never completed is worse.
  • Whether invoices are charged automatically as part of a monthly run is not built yet — the arrangement exists and can be charged against; scheduling it is separate.

Clients, cases, and who is paying for what

Billing one client is one screen: choose them, see exactly what the bill would hold — or the reason there is nothing to send — add any line that is not recorded yet, and issue and send it in a single step. A client gets one bill covering everything you did for them, instead of one per file. On a case with many co-plaintiffs, work done for the case as a whole is split by the shares you set and each person sees only their own share — never who else is on the case. And nothing gets quietly missed: work no agreement covers is listed by name at close rather than silently left off.

Every rule — the fee bases, the allocation policy, cost pass-through, holds and write-downs — is applied ONCE, when work becomes a charge, and every screen afterwards reads those rows. That is what stops the disbursement statement and the invoice disagreeing about the same money, which is exactly what they used to do when each worked the answer out for itself. Case-wide work becomes a parent charge that is split into one child per client, and the children sum to the parent to the cent — the remainder goes to the first child rather than being rounded away. A close is safe to run twice: the second run creates nothing, refused by the database rather than by the engine remembering.

  • A bill covers one client. An insurer paying for an insured, or any second payer on one bill, is not supported.
  • Work with no agreement covering it is never billed at a guess. It is named at close and stays unbilled until an agreement exists — which means somebody has to read that list.
  • The close is run by a person. There is no schedule that issues bills on its own, deliberately: a bill going out without anybody looking is the failure this design refuses.
  • This system holds and disburses no client funds of any kind. Everything is earned when it is billed, and there is nowhere for money that is not yet earned to sit.

What the client agreed to pay, in plain language

What a client agreed to pay is written down in words they would recognize, so a fee conversation starts from the agreement rather than from somebody's memory. Changing terms never overwrites what was agreed before: a change is a new agreement that supersedes the old one, and the old one stays exactly as it was signed — which is the question a fee dispute is actually about.

Six steps: who is paying, what for, how, the specifics of the basis you chose, which costs this client sees, and a review that shows the plain-language card before you save. Hourly, flat, recurring, contingency and hybrid each carry one sentence and a worked example. The card the review step draws is the SAME component the agreement page draws afterwards, from the same terms — so what you read before saving is what is there after. A saved agreement can be kept as a template and applied to a whole roster in one transaction, which either applies to everybody or to nobody.

  • An agreement is never edited in place. Changing terms writes a new one and marks the old one replaced — destroying what was agreed before is the one thing a fee record must not do.
  • Contingency tier escalators are stored but have no editor yet. Unequal shares do have one, on the case roster.
  • The worked examples in the wizard are illustrations, not this platform's prices.

Fees the other side pays, demarcated as you work

Fee awards stop being lost quietly. Courts require fees to be demarcated to be recoverable, and the demarcation has to have happened while the work was being done — so the money is usually gone before anybody goes looking for it. Work held for an award never lands on your client's bill; if the claim is denied you decide, charge by charge, whether it goes to the client or is written off, and a released charge appears on the next bill however many months old it is.

A claim on a case records what it rests on — an order reserving fees, a sanction, a prevailing-party or fee-shifting entitlement, a contract, a proposal for settlement — the authority relied on, the order date, and one of two treatments. "Hold it until an award" means charges are born held and are invisible to invoice assembly by their state, not by a filter somebody has to remember. "Bill it now and track it" bills normally and still reports. Time is tagged in the accept flow and costs on the case's costs card. Resolving the claim needs a reason: an award moves every held charge to recovered, and any other outcome asks for a decision on each one and refuses to proceed while any is missing. The report prints the claim header, every tagged charge with its narrative and rate, a lodestar by timekeeper, and totals — with a CSV twin.

  • A held charge is invisible to billing because of its STATE, not because of a filter — that is what makes it safe. The corollary is that nothing except resolving the claim can release it.
  • The lodestar and the demarcated total are printed side by side and are not reconciled. They come from different tables and differ legitimately when costs are demarcated too, or when the newest work has not been through a billing run.
  • Costs are demarcated from the case's costs card rather than the matter's. The case card already lists every cost on the case, and two places to set one fact is two places for them to disagree.
  • Resolved claims cannot be edited, and new work cannot be tagged to one. Changing the basis under a claim a court has ruled on would rewrite the record of what was argued.

The settlement statement, computed from the agreement

The arithmetic that decides the largest fee on a contingency case stops living in a spreadsheet. The percentage is applied to the basis the agreement actually names, costs the firm advanced are itemized rather than summarized, and on a hybrid matter the fees already invoiced are subtracted with the subtraction shown. Costs that were held pending the award are released onto the same invoice as the fee, so the client receives one bill rather than two. Recording the same settlement twice cannot bill it twice.

A recovery records what was recovered — settlement, verdict, award or other — the gross figure, the date and the client. The fee is computed as the agreement says: the percentage applies to the gross, or to the gross less costs advanced when the agreement is net-of-costs, and staged escalators are applied band by band when the agreement carries them. On a hybrid agreement that credits fees already paid, the fees invoiced on that case are subtracted and the arithmetic is a line of its own. One contingency charge is created, guaranteed once per recovery by the database rather than by care, and every cost that was waiting on the award is released to be billed alongside it. The settlement statement prints the gross, the fee with its percentage shown, the costs itemized and the net to the client.

  • The firm holds and disburses no client money through this system, and the settlement statement says so in words. It records what was recovered and what the fee and costs come to; it is not an accounting of money held on a client's behalf, because none is held.
  • Liens and medical payoffs are not handled. They are the part of a settlement that needs somewhere to hold money on a client's behalf, and the statement says it does not account for them rather than leaving the absence to be read as "there are none".
  • Staged escalators are applied as amount bands, marginally — 33% of the first million, 40% above. A ladder keyed on whether suit had been filed cannot be computed from a recovery that resolves a whole case, which is when the fee is largest. There is no editor for them yet; a ladder the system does not recognize is refused rather than computed at a flat percentage.
  • The credit on a hybrid agreement cannot make the fee negative. Where fees already invoiced exceed the contingency fee, the fee floors at zero and the full subtraction is still shown, rather than becoming a credit nobody agreed to.

The bill you read before the client does

You see the bill before the client does, and you can fix it while it is still a draft: knock money off a line and say why, take work off this month, reword something a client would ring about. Nothing is spent until you press Issue — a draft carries no number, so an abandoned bill leaves no gap in the series you have to account for later.

A draft is assembled from the charges ledger and nothing else, so one set of rules decided every figure on it once. Reviewing a line writes a write-down onto the CHARGE, which is why a reduction survives a rebuild and is still legible after the bill is issued; excluding a line simply takes it off this bill and the work returns to the next one, so nothing is ever lost by tidying a draft. Issuing takes the next number out of your own series under a lock, dates the bill, sets the due date from the terms snapshotted onto it, and flips the underlying work to invoiced in the same transaction — an issue that fails part-way consumes no number. The printed bill is print-ruled HTML rather than a generated PDF, and reads the same stored totals the screen does, so the two cannot disagree.

  • Review is for drafts only. Once a bill is issued the client has a numbered, dated document, and changing a line would make your record disagree with the copy in their hand — void it and rebuild instead.
  • An excluded line comes back if the draft is rebuilt. Exclusion is a decision about THIS bill; a reduction that must survive is a write-down, and work that should never be billed to anyone is held at the charge instead.
  • Delivery is not here. The bill is printed or saved from the browser and sent the way you send things today — emailing it, and a client-portal view of it, are named follow-ons rather than omissions.
  • Recording a payment is not holding money. This system holds and disburses no client funds of any kind, and there is deliberately no table it could.

What it actually saved you

At renewal you are not arguing from a feeling on either side. You can see what the software did, what it cost, and what that is worth at your own blended rate — and because the assumption behind the conversion is on the page, you can disagree with the assumption instead of with the number.

The counts come from the audit trail — things that demonstrably happened, not an estimate of them — so every figure can be walked back to the events behind it. The hours are a RANGE rather than a point, and the assumption used to convert counts into hours is stored inside the snapshot rather than applied and forgotten, so a figure produced in March can still be argued with in September against the assumption it was actually built on. The whole thing is deliberately conservative: a report caught flattering itself once is a report nobody believes again, and this one has to survive being read by a skeptical partner.

  • It is an estimate with its assumption shown, not a measurement. The counts are real; the hours they convert into are a judgment, and the range is wide because narrowing it would be pretending.
  • It counts what the platform DID. The largest thing it cannot count is the case that settled better because a contradiction surfaced in week two instead of month six, and it does not try to put a number on that.
  • A snapshot is built when you ask for one and is a picture of that moment. It does not update itself, and two snapshots of the same period built on different days can differ if work happened in between.

Confidentiality and access

What must not be filed in the clear

A social-security number, a bank account or a date of birth does not reach a public docket because somebody was reading the argument instead of the exhibit list. The check runs on every version you write, whether or not you remember to ask for it, and it tells you the compliant form for each one.

Fed. R. Civ. P. 5.2 and Fla. R. Gen. Prac. & Jud. Admin. 2.420 and 2.425 leave the last four digits of a number, a minor's initials and the birth year. The detectors are deterministic and anchored on context, because the failure that matters is the false positive: a checker that flags your case number teaches you to click through the panel, including on the day it finds a real one. A second pass reads for a person identified in narrative rather than by a number, and everything it finds is marked for you to read rather than acted on. Applying the suggestions writes a new version to review as a diff and withdraws any approval — nothing is ever rewritten in place.

  • Advisory. It reports and the attorney signs off — nothing is redacted without a person pressing the button, and nothing is filed by this check either way.
  • A minor is caught by narrative pattern and marked for reading, because the firm has nowhere to record that a party is a minor yet. The detector already reads that flag, so it becomes exact the day the party wizard asks.
  • Drafts and pleadings only. Produced documents are not covered by this pass.

Sealed tenants

Another firm's matters cannot turn up in yours, and no screen in this platform shows the person running it a client document — what he sees is queue depth, spend and storage growth. When a client asks who else can see this, the answer is short — and it does not rest on anyone here remembering a policy.

A storage bucket of its own per firm; PostgreSQL row-level security that the application role cannot bypass; and firm predicates in the application itself. The test suite asserts that a query with no firm context returns zero rows — not that it should, that it does.

  • Thirteen narrow, individually reviewed functions are allowed to cross the tenant boundary, and nothing else is. Eleven resolve a credential before any tenant context exists: a session cookie, a portal hostname, a login by email, a calendar-feed token, a matter's inbox address, a delivery link, a client session, a client login, a signature link, a backup appliance's check-in, and a firm's public intake slug. The other two read the sales inbox, which belongs to no firm.
  • The storage buckets are per firm but the credential is not: src/lib/storage.ts signs every request with one R2_ACCESS_KEY_ID, so a stolen key reaches every firm's ciphertext rather than one firm's. Per-firm scoped keys are due before a second firm is onboarded (OPEN-ISSUES #6). Keys are unaffected — every master key is per firm and none of them is in object storage.

Ethical walls

You can take the case with the conflict in it. The screen is provable rather than promised: who was walled off, from what, from when, and who let them back in, is a record you can hand to the Bar.

The firm is open by default; walling is the exception. Walling a matter restricts it to an allowlist, and a new wall starts EMPTY — nobody sees the matter until someone is added, and the person raising the screen is not added automatically, because the person raising a screen is often exactly the person being screened. Enforcement is a single seam every read passes through, so a walled matter is absent from search results, morning briefings, calendars and exports rather than merely hidden on its own page. To someone off the list the matter returns a 404 — indistinguishable from one that does not exist. Walls bind administrators too: an admin manages a wall from the settings page without gaining any access to the matter behind it.

  • A wall is per matter, not per document. A document in a walled matter is walled; there is no way to screen one document inside an open matter.
  • Releasing a wall restores access for everyone; there is no partial release. The wall row and its history are never deleted — that record is the screening proof.

Records and retention

Append-only audit trail

When someone asks who saw a privileged document and when, the answer is one screen away — reads included, not just changes. Nobody can edit it after the fact, which is the only reason it is worth producing.

A trigger prevents update and delete — including by the platform operator. Actors are distinguished as user, AI, platform, system, or external, so "who outside the firm touched this matter" is one query.

Closing a case out

You stop paying full rate to store a case that finished four years ago, without the file leaving the system. The chronology, the parties, the facts and the audit trail are all still there and still answer questions; only the documents themselves take hours instead of seconds to get back, and only if you ask. And when a client — or successor counsel — compels the file, what leaves is the CASE and not your strategy: the export is five tables by rule, so your Chambers threads, your simulations, your valuations and your draft checks are not in the bundle and cannot be added to it by a change of mind at the keyboard.

Archiving copies every document's sealed bytes to a second, cheaper store, checks each copy arrived at the size it should be, writes a manifest hash, and only then removes the live copy — in that order, so a failure before the manifest is committed leaves the matter untouched and nothing deleted. What does NOT move is the case record: facts, timeline, parties, deadlines, hearings and the audit trail stay in the database, so an archived matter is still searchable, still answerable by case chat, and still raises a conflict against a future intake. Getting a document back is a restore request, which runs in the background and tells you when it lands — the cold copy is not consumed by it. A matter under a litigation hold cannot be archived at all.

  • Closing and reopening a matter are in the interface now (the close-out card on the matter page), and the cold-storage destination is configured and its full round trip verified — so archive and restore work end to end rather than refusing. The archive still runs on an operator-triggered basis rather than any schedule, which is deliberate while the platform holds no real client files.
  • The $75 close-out and $50 export fees are settled prices rather than placeholders now, but a closed matter holding no documents at all is still archivable and still charged.
  • Storage is metered from stored document sizes and charged on the first of the month. A month the platform was down for entirely is not caught up later — the catch-up only looks back one month.
  • A document uploaded to a matter after it was archived stays live INDEFINITELY while being billed at the archived rate. Nothing ever moves it cold — archiving refuses an already-archived matter, and the sweeper only finishes a committed delete phase — so it is a permanently cheap live copy, not a temporary state.
  • The export bundle is produced from the command line by the operator, as root. There is no screen a firm can click to export their own matter.
  • The export scope is an ALLOWLIST of five tables — documents, facts, events, audit events and parties — rather than a list of exclusions. Work product is out because it was never queried, not because somebody remembered to leave it out, and the audit CSV additionally drops the strategy rows (who opened Chambers, what kind of simulation ran) because audit detail is exported verbatim and the shape of the row is itself the strategy. Widening it means editing that one file, which is the point of it being one file.

Knowing it is right

Quote verification

The thing that makes a fact ledger worth trusting is that its citations are real. This is the check that they are, run on every fact, rather than a promise that the model is careful.

A fact is only recorded with a verbatim quote and a page. After a document is read, each quote is located in the text of the page it cites — a string search, no model, no cost. There are three verdicts, and the middle one carries the weight: exact, normalized (it matches once the artifacts of PDF extraction are folded — broken lines, hyphenation, ligatures, curly quotes — and is still genuine support), and absent, which is the finding. "Not yet checked" is stored distinctly from "checked and not found", because we have not looked and we looked and it is not there are different statements.

  • Unsupported facts are excluded from drafting and flagged on the matter and document pages; superseding the document's reading clears them.
  • A quote shorter than a dozen characters is reported absent rather than passed: a two-word match proves nothing, and blessing one would empty the check of meaning.
  • It proves the words are on the page. It does not judge whether the fact drawn from them is a fair reading — that is what an attorney is for.

Monthly fact spot-check

The claim "extraction is accurate" becomes a number the firm measured itself: an attorney marks each sampled fact correct, incorrect or unclear against its quote, and those verdicts are divided into an error rate you can read on screen and watch over twelve months.

The hourly tick creates one review item per firm per month: facts sampled with weight toward low confidence and quotes that only matched after normalization. It lands in the review queue with a companion task. Each sampled fact is shown beside its quote with a link to the page it came from and three buttons — correct, incorrect, unclear — and the month cannot be closed until every sampled fact carries one. The rate is computed from the verdicts every time it is displayed, never stored, so it can always be reconstructed from the facts an attorney actually read.

  • The sample size is per firm per month (default 12) and set in firm settings (0 – 50); 0 disables the check and the measurement with it.
  • The rate is incorrect verdicts divided by facts judged. An "unclear" counts in the denominator and not as an error, so it can only pull the rate down — which is why the unclear count is always shown beside it rather than folded into it.
  • It measures the sample, not the file. Twelve facts a month is a number a firm will actually get through, not an audit of everything extracted, and a small sample moves a lot on one error.
  • A month nobody has reviewed reads "not measured" rather than zero — an unjudged sample is not a clean one.
  • Verdicts are three buttons and an optional note. There is no structured taxonomy of what went wrong, so the notes are still free text.
  • Sampled facts that were later deleted cannot be judged and are left out of the arithmetic rather than counted either way.

Citation checking

The failure that has sanctioned lawyers — a confident citation to a case that does not exist — is caught before you read past it. A citation either resolves to a real opinion or it is shown in red as unciteable.

Reporter citations are extracted from the text by pattern, deterministically, and looked up in CourtListener's free opinion database in one call. No model is involved in the verdict. There are four outcomes and each renders differently: resolved (with a link to the opinion), unresolved, ambiguous — more than one case answers to that citation — and not checked, which is what a caller sees when CourtListener is unreachable or unconfigured. The deterministic pass is the floor in the draft cite-check: every citation found in the body is reported whether or not the model mentioned it, so the model can add findings and can never hide one.

  • Verified against CourtListener's free opinion database — not Westlaw, no treatment, no Shepard's. Existence and citation accuracy only.
  • A resolved citation can still be bad law. That judgment stays with the lawyer.
  • When CourtListener is unreachable or unconfigured, citations are marked not-checked — never silently passed.
  • Federal and Florida reporters are recognized; a citation in an unlisted reporter is not extracted at all rather than given a wrong verdict.

The review gate

Every piece of AI output that could reach a court, a client, or your calendar stops in one queue and waits for an attorney. You can answer the supervision question a bar committee actually asks — who reviewed this, when, and what did they approve — from one screen, for every kind of output, rather than from four different places and a memory.

Work product and reference are separated at the point of creation rather than at the point of sending. Anything with legal consequence — a draft, a status update to a client, a deadline suggested by a scheduling order, a proposed split of a scanned bundle, the monthly fact sample — is created unapproved and appears here. Anything informational — a case digest, an answer to a question about the file — is marked as such when it is written and NEVER enters this queue, because a queue that fills with things nobody needs to approve is a queue people learn to clear without reading. Approving or rejecting is attorney-only and takes a note. The approval binds the exact text that was read: editing an approved draft revokes its approval by a database trigger. A deadline that has not been confirmed cannot be calendared, enforced by a database constraint rather than by the application remembering. A trial simulation is labelled internal decision support in the database and can never be approved as work product at all. The queue is also screened: a matter behind an ethical wall does not show its items here to anyone off that wall's list.

  • It gates AI output. Work a person did by hand does not pass through it, and it is not a supervision record for anything but the model.
  • Approve and reject are the only two verdicts. There is no "approve with changes" — changing it means editing the draft, which revokes the approval and returns it here, deliberately.
  • Informational output is never queued: case digests and answers to questions about a matter are reference and are marked that way when they are written. That is a decision about what deserves an attorney's time, and it means an empty queue is not evidence that nothing was generated.
  • Nothing expires out of it. An item nobody decides waits indefinitely rather than timing out into either answer, and the dashboard's unreviewed-AI signal is what notices instead.

Is everything working?

A partner who wants reassurance at nine on a Sunday gets it in four lines instead of a phone call on Monday. Each line says what is true and when it was last checked, and an unconfirmed line says so plainly rather than showing a hopeful zero — an unread check and a healthy one must never look alike.

The page reads the same records the operator's own alarms read, against the same thresholds — forty-eight hours for the nightly copy, forty-five days for the monthly restore drill, forty-eight for a firm's own box. It shows when the documents were last backed up, when a restore was last actually tested and passed, whether the three copies are current, and how much is stored. Nothing is a hardcoded claim: every line rests on a record with a timestamp, so a leg that stops running turns that line rather than leaving a green mark behind.

  • It reports; it does not act. Nothing on this page is a button, and a failure here has already raised an operator alarm before you see it.
  • The figures are as fresh as the checks behind them: storage is measured once a day and backups run nightly, so a number can be most of a day old. Each line says when it was read rather than implying it is live.
  • The storage figure is what you are holding, not what you are billed for — the plan allowance counts archived storage at a third and lives on the usage page.

Where the copies are, and how you know they are there

"What happens if your server dies" has an answer with a date on it rather than a reassurance. There is a second copy that nothing can quietly delete, a third that is slow and cheap and exists for the year nobody planned for, and a monthly drill that actually pulls a document back out — because a backup nobody has restored from is a backup nobody has tested.

Every night the sealed documents and an encrypted dump of the database are copied to a second store where each object is placed under an object lock — writable once, and the lock refuses deletion until it expires, which is what makes ransomware and a bad afternoon the same problem rather than different ones. Every week the same material goes to deep archive. Monthly, a drill takes a document out of a backup and decrypts it end to end. Every leg records the run it made, and the hourly pass raises an alarm by email when the newest SUCCESSFUL run of a leg is older than it should be — forty-eight hours for the nightly, ten days for the weekly, forty for the drill. Only a run that actually succeeded counts, which is the difference between watching backups and watching a timer.

  • What is copied is ciphertext and an encrypted database dump. Reading any of it needs the firm master key, which is why escrowing that key is the first item on the onboarding checklist and the one step there that cannot be recovered from.
  • The monthly drill proves that a document comes back and decrypts. It is a sample: it does not prove every document would, and it is not a full restore rehearsal.
  • Two legs added later — the source-code bundle and its own drill — are copied but are NOT yet in the freshness alarm, so their staleness is unwatched (OPEN-ISSUES #171).
  • This is the platform's own regime, in the platform's own storage accounts. A copy under the firm's own roof is the appliance, which is designed and not built.

Running the firm

Firm administration

You do not file a support ticket to change how your own firm works, and every change carries a name and a timestamp if anyone ever asks who did it.

Administration is a flag, not a role — an office manager can hold it without being called an attorney, and any role can. Administrators set who sees the cost ledger, turn cost recovery on or off, manage ethical walls, set per-person AI spend limits, and grant or revoke administration itself. The last administrator cannot be removed, enforced as a single atomic statement so two admins revoking each other at once cannot leave a firm with none. Every change writes an audit row in the same transaction as the change.

  • Cost recovery offers off or at-cost only. Passing AI cost through at a markup requires a signed engagement letter carrying cost-recovery terms — the platform writes that clause into the letter for you, with the opinion it rests on named beside it — and the markup itself is set with us rather than on this page, because a rail you can drive around in a form is scenery.
  • The storage tier is displayed here but changed by conversation, because a tier change is a price change.

Seats, roles, and what each can do

You can put your office manager and your paralegal in the system without either of them being able to approve work product, confirm a court rule, or read the audit trail. And administering the firm is not the same thing as practicing law here: the person who manages the account does not have to be an attorney, and being one does not make them able to approve anything.

A person holds one role. Attorney is the only one that can approve or reject in the review queue, confirm a court ruleset, open the audit trail, post in Chambers, send a draft out, or complete an onboarding attestation — and each of those is checked at the act itself, in the server action, not by leaving a button off a page. Paralegal and staff can do the work: upload, file, search, ask the file questions, build productions, record time. Client-portal logins are a separate credential type in separate tables entirely and are free and unlimited. ADMINISTRATION IS A FLAG, NOT A ROLE, and that is the design decision worth knowing: any role can hold it, so an office manager can manage walls, spend limits, cost-ledger visibility and the other administrators without being called an attorney and without gaining a single attorney permission. The last administrator cannot be removed.

  • A person holds ONE role and it is set when they are invited. Changing it is a request to us rather than a control on the settings page.
  • The roles are fixed: attorney, paralegal, staff, client. There are no custom roles, no per-matter roles, and no way to grant one attorney act without granting them all — a permissions system a firm can compose is a permissions system nobody can audit, and this product would rather be legible.
  • Screening a matter from a person is a separate mechanism entirely: roles say what kind of act somebody may do, ethical walls say which matters they may see, and neither substitutes for the other.

Your own address for the portal

Your people go to your address rather than to a vendor's, and the page that greets them carries your firm's name. It also means an email address is not enough to reach your data: sign-in resolves the firm from the address it was reached at first, so a credential typed at the wrong door does not open the right one.

A firm can point a name of its own at the portal, or use its name under ours; either resolves to exactly one firm, and the mapping is unique at the database level so two firms cannot claim one address. The resolution happens BEFORE any sign-in is attempted and before any tenant context exists — it is one of the narrow functions allowed to cross the tenant boundary, and it returns the firm's name and nothing else. An address that matches no active firm is refused rather than shown a generic form, so an unknown host cannot be used to probe for which firms exist.

  • It is the ADDRESS that is yours, not the appearance. The database carries a place for a firm's colors and logo and NOTHING READS IT — no page in the product renders a firm's branding today. The portal looks the same for every firm, and saying otherwise would be selling a column.
  • One address per audience — three in total, and no more. You cannot run two names for the same audience at once, and there is no redirect from an old one if you change it.
  • The public marketing site is separate and stays ours. This is the address your people sign in at, not a website we build for you.

Accounts, sign-in, and two-factor

Nobody shares a login, so the audit trail names a person rather than a password. A passkey cannot be phished, reused across sites, or read off a sticky note, and it is two factors in one gesture rather than two ceremonies stacked on each other. A paralegal who leaves on Friday is disabled on Friday, in one switch, and every session they hold is dead on their next click. And when somebody cannot get in, their own firm administrator fixes it in one click instead of ringing us.

We create the firm; every person after that arrives by invitation, sent by email from a firm administrator. The link is single-use and time-boxed, consumed the moment it is used, so a forwarded invitation cannot be redeemed twice. There is no password to choose: accepting the invitation signs them in and asks them to add a passkey, which is stored as a public key — the private half never leaves their device, so a stolen database cannot mint a login. A passkey is bound to the exact address it was created on, which is what stops one firm's credential being offered at another's. Firms may demand a further factor after sign-in, though the recommendation is not to: a passkey unlocked by a face or a PIN is already two. A session lasts twelve hours and ends after an hour of doing nothing, whichever comes first. Your firm signs in at its own address, so the page already knows which firm it is before anyone types anything.

  • There is no self-service sign-up. There is no password reset either, because for anyone invited since passkeys there is no password: somebody locked out gets a sign-in link by email, either from their firm administrator or from the sign-in page itself. That link proves control of the mailbox and nothing more, which is the honest description of what it is.
  • An invitation is single-use AND time-boxed — it expires, and only its hash is stored, so a lost link is reissued rather than recovered. It is emailed, and it arrives from LEXICERA at a lexicera.com address rather than from the firm's own domain: the platform is the verified sender, and a firm's name over a vendor's address is the mismatch that teaches people to stop reading domains. Worth telling a new colleague to expect it, because a first message from an unfamiliar sender is exactly what a careful person treats as suspicious.
  • What a person may DO once they are in is their role, which is its own capability and its own set of refusals. Signing in and being allowed to act are separate questions and this entry only answers the first.
  • A passkey is bound to the one address it was created on, so somebody who signs in at more than one of your firm's addresses enrolls at each, and changing a firm's address means everyone enrolls again. Where a firm asks for a further factor it is an authenticator code or an emailed code; text-message codes are not supported deliberately — SMS is the factor that gets taken.
  • Client-portal logins are a separate credential type in separate tables entirely, and none of this applies to them.

Setting the firm up

The handful of steps that decide whether this is actually safe to rely on get done in the first week, instead of being the steps everyone means to come back to. A progress meter on the front page says how far along you are, each outstanding step links straight to the control that finishes it, and the one step that cannot be recovered from is done with us rather than ticked by you.

Eleven steps, seeded when the firm is created and topped up on the hourly pass, so a firm that has been running for months picks up a new step within the hour. Nearly all of them detect themselves from the data — billing rates set, staff invited, one real matter taken end to end, the billing identity filled in, the firm signature drawn, the payment rail connected, an engagement letter live, and the two DECISIONS (cost recovery, and how staff sign in) recognised from the moment somebody actually makes them. A checklist maintained by hand is a checklist that lies, so almost nothing here is a box a person ticks. Escrowing the firm master key is first, because it is the only step a firm cannot recover from having skipped — and it is completed by us, with you, once we have watched a document restore from your copy. Outstanding steps show as a progress meter on the dashboard and at the top of Settings, and stop showing the moment there are none.

  • It is a checklist rather than a gate. Nothing on this list blocks anything: a firm that skips the escrow step can still use every part of the platform, which is exactly why the step is first and worded the way it is.
  • The key-escrow step cannot be completed by the firm at all. It is confirmed by us, on the firm's record, once a document has actually been restored from the firm's own copy of the key — because a one-click attestation about the one unrecoverable step measures willingness to click.
  • The firm signature can be put on file, or cleared, only by the firm's named signer or by one of the firm's administrators acting for them — and a firm that has not named a signer refuses everybody, administrators included, so nobody inherits that authority by a signer's account being deleted. Every save records which of the two roles entered it, so an administrator putting the principal's signature on file is visible as exactly that in the audit trail and is never recorded as the principal's own act.
  • Nothing on the rail emails anybody on a schedule. The one message it can send is the hand-to-signer nudge, and only when an administrator presses the button.

What it will not do at all

Beyond the per-feature limits above, four things are absent by decision rather than by schedule, and they are the ones worth knowing before a demonstration.

It is not a case-law research service

Citations are resolved against CourtListener's free opinion database: a case either exists and matches its citation, or it is flagged unciteable — in red, on the draft's cite check and in Chambers, so the check cannot silently pass one. Removing it is the lawyer's act, not the software's. That is existence and accuracy only — not Westlaw, no treatment, no Shepard's. A citation that resolves can still be bad law, and only a lawyer can say so. Drafting is still instructed to write [CITATION NEEDED] rather than cite anything it was not given.

It does no trust accounting

If you hold client funds, this cannot be your only system. Half an IOLTA implementation is worse than none.

It does not file anything

No e-filing, no court-portal login, no docket scraping. It prepares documents; a person files them.

It does not predict outcomes

The trial simulation is a machine imagining people. It is useful for finding the weak point in your own argument and worthless as a prediction, and it is labelled that way everywhere it appears.

Sources

  1. codesrc/registry/pricing.ts — a price that is not in that file may not appear in rendered output, and the test suite asserts it in both directions: every published figure must appear, and every retracted one must not.
  2. policyWithin a matter, the same document is never ingested, read, or billed twice. A file already in the matter — the same bytes, arriving again by upload, by email, or in a bulk import, from a production, a client dump, or a second custodian — is recognized by its seal and costs nothing: it is neither read again nor charged again. The check is the plaintext SHA-256 of the file, scoped to the matter: the same production filed to a second matter is read again, because it is a second reading.
  3. codesrc/lib/access.ts — canAccessMatter() is the single seam every per-matter read passes through, and wallPredicate() the fragment every cross-matter query carries. Documents, search, the fact ledger, briefings, exports and every AI surface inherit the screen from one place rather than each remembering to apply it. Migration 041.
  4. codeA matter behind a wall returns 404 to someone off its list — the same answer as a matter that does not exist, so the existence of the screened case is not disclosed by the shape of the refusal.
  5. codesrc/lib/ai.ts assertCanSpend() — a zero prepaid balance pauses AI work and nothing else. Documents, downloads, search and everything already extracted stay available. A firm out of credit does not lose access to its own files. The pause is a WAIT, not a loss (LEX-391): assertCanSpend throws a typed SpendPausedError, src/workers/extract.ts routes it to queue.ts pauseJob() instead of failJob(), so the attempt never counts toward the five that dead-letter a job and the work re-runs by itself when the balance turns positive. Jobs stranded BEFORE that mechanism existed are not yet revived: the one-time requeue is written and held unapplied at app/db/pending/LEX-429_requeue_balance_dead_letters.sql, and running it is LEX-429's supervised act.
  6. migrationMigration 042 — Florida matters count under Fla. R. Gen. Prac. & Jud. Admin. 2.514, including the post-2019 start-day skip, with a five-day service extension where federal practice adds three. An unrecognized counting mode throws rather than quietly computing federal dates for a state matter.

Every claim on this page that could be checked, and where to check it. We do this because it is what the product does: an answer that does not carry its source is an answer you have to take on trust.