Ajax vs PointOne: how they compare in 2026

A
Ajax profile
P
PointOne profile
Last verifiedSeptember 25, 2026

Ajax and PointOne sell the same kind of product: passive timekeeping that watches a lawyer's working day across documents, email and calls and writes the time entries itself. Ajax sits in the top two bands on ten of fifteen axes and PointOne on nine of fifteen, with identical grades on ten. The difference is where each puts its promises. Ajax's data processing addendum of 5 August 2026 makes the ban on training with customer data a contract term, binds the model providers it names, OpenAI, Anthropic and Google Gemini, to the same, and deletes raw data after 30 days and processed data after 60. PointOne's security page commits to zero training and zero model retention too, but as a policy: its privacy policy excludes customer data, and the contracts that govern that data are not published. PointOne pulls ahead on deployment, offering single tenant options, a choice of geolocation and models run inside a private Azure cloud, where Ajax states no region or tenancy model. It also names Aderant and Elite 3E among its billing integrations, and Ajax's list of eight includes neither.

At a glance

Category
AjaxLegal Ops & Spend
PointOneLegal Ops & Spend
Founded
AjaxNot published
PointOneNot published
Headquarters
AjaxNew York, United States
PointOneNew York, New York, United States
Last verified
AjaxSep 20, 2026
PointOneSep 20, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

Ajax
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.

Take the models out and there is nothing to sell. The capture layer produces a stream of activity across documents, email, browser, calls, calendar and meetings; everything the buyer is actually paying for happens after that, when a model reads the content of the work, decides which matter it belongs to, groups fragments that belong together and writes a narrative in the timekeeper's own voice with an activity code attached. The vendor draws the line itself when it separates its product from tools that record activity without writing entries, and calls that the previous generation of the category. The rules engine that turns a client's outside counsel guidelines into constraints on the wording is model work too. What remains without any of it is a timesheet of raw activity that a lawyer still has to write up. Verified 20 September 2026.

PointOne
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.

Take the models out and there is no product. PointOne's pitch is that a lawyer stops writing time entries altogether: the software captures the working day across documents, email, calls and the web, works out which matter each task belongs to, and writes the narrative, with retroactive capture over any date range for people who reconstruct at week or month end and generated narratives for those who still prefer timers. The same models turn uploaded outside counsel guidelines into structured billing rules, check every entry against them, and mark up pre-bills with flagged problems and suggested fixes. What would remain without them is a timer and an export to Aderant or Clio. Verified 20 September 2026.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Ajax
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

On a timekeeping product this axis asks whether an entry is right: the right work, the right matter, the right duration, a narrative that describes what actually happened. The method is described better here than on either comparable record. The vendor states that it reads the content of the work rather than window titles or calendar subject lines, that it clusters activity scattered across the day on one matter into a single entry, and that it identifies the client and matter by matching what is on screen against a live map of the firm's matters. It also publishes a figure, twice in one explainer of 7 July 2026: matter matching is right about 92 per cent of the time, and improves as the system learns a firm's people, documents and topics. Publishing a number that is not 100 is more candour than either comparable record offers, and it is still short of measurement a reader can test. There is no sample, no period, no stated method and no definition of a correct match, and nothing describes what happens to the entries in the remainder beyond the lawyer's review catching them. For the narratives themselves, as distinct from matter assignment, no figure is published at all. Verified 20 September 2026.

PointOne
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Accuracy is the whole claim and none of it is measured. The product writes billing narratives from captured activity rather than legal assertions, so the question is whether an entry describes what the lawyer actually did and lands on the right matter. Customers say on the homepage that it is accurate, the April 2026 release says the office stress-tested whether PointOne could correctly identify a wide range of billable and non-billable tasks, and the security page promises auditability of AI outputs. No accuracy rate, sample, benchmark or error rate is published anywhere, and nothing describes what an entry is built from or how a reviewer can tell a mis-attributed entry from a correct one before it reaches a client's bill. Verified 20 September 2026.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

Ajax
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

The review step is structural rather than advisory, which is the strongest thing on this record. Nothing the model writes reaches the firm's billing system on its own: entries are drafted throughout the day, they are visible to the timekeeper alone until that person releases them, and the release is a deliberate act. The timekeeper can edit any entry, delete any entry outright, and stop capture entirely with one click, with the vendor stating that nothing is captured until they choose to resume. The FAQ answers the supervision question in the other direction too, saying the firm cannot see a timekeeper's hours before release. What is not published is the rest of the control structure: no threshold at which the model declines to write an entry, nothing on what happens after an entry goes out wrong, and no statement of what the system may not be used for. Verified 20 September 2026.

PointOne
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

The system drafts and people approve, and the approval path is published in detail. Time entries are generated automatically, then move through Review, where the AI marks up the pre-bill and a firm sets its own reviewers, routing and permissions: the worked example runs a bill from legal assistant to responsible partner to billing administrator, with comments and tagging to resolve queries. Billing rules drawn from client guidelines are enforced against every entry before it gets that far. What is not published is any limit the system places on itself: no threshold at which it declines to classify a task, no statement of what an unreviewed entry may not be used for, and nothing on what happens when capture misreads the matter. Verified 20 September 2026.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Ajax
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

This is the strongest deployment evidence in the pull and it stops short of the top band on two specific things. Ten firms are named with their practice area, their city and a figure each: Almazan Law in Florida at 1.1 extra billable hours a day, Poole Huffman in Georgia at $32,000 recovered a month, Kirker Davis in Austin at $4,639 per timekeeper a month, Pines Federal at $42,000 a month, King Law at 121 active users across 24 offices, Quill & Arrow at 270 professionals. Named attorneys are quoted in each. Sixteen further testimonials carry names, titles and firms, and the vendor states that fourteen customers went on to invest personally. Against that: not one case study carries a date, and no method is stated behind the return multiples, so figures like 67x and 58x cannot be checked or compared by a reader. Verified 20 September 2026.

PointOne
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

One deployment is named, dated and sized, and no result is measured. PointOne's April 2026 release states that the Minnesota Attorney General's Office rolled the platform out across its entire office of more than 300 timekeepers after a pilot that tested multi-agency billing, dynamic review flows and classification of billable and non-billable tasks, and quotes Assistant Attorney General Eric J. Kolbeck by name. The homepage carries logos and attributed quotes from firms including O'Hagan Meyer, Scarinci Hollenbeck, Bell Nunnally, McCathern, Lydecker, Elevare Law and Bevilacqua PLLC, and the customers include partners, a CFO and a COO speaking on the record. What no published material gives is a figure: no measured capture uplift, no time saved, no realisation change, with the only quantities being customer counts and the size of one office. Verified 20 September 2026.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Ajax
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

For a product that reads everything on a lawyer's screen, the published commitments are substantial and one gap is structural. The addendum of 5 August 2026 prohibits training, retraining or fine-tuning on customer data and binds the named model providers to the same; raw data is deleted after 30 days and processed data after 60; everything is deleted within 30 days of termination. Confidentiality runs mutually in the terms. Access is answered at the level this product raises it: drafted entries are visible to the timekeeper alone until released, and capture stops on one click, which is the control a lawyer working on a sensitive matter actually needs. The vendor acknowledges in its own words that its users handle privileged client data. What is not published is any treatment of privilege or work product as such, and nothing addresses matter-level separation, which matters where a timekeeper is screened off a matter the capture would otherwise read. Verified 20 September 2026.

PointOne
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

The commitments are specific and they are published on a security page rather than in a contract. That page states full data segregation, zero training on firm data, zero data retention by the AI models, customisable data retention, single-tenant options for enterprise deployments, customisable geolocation, the ability to run models inside a private Azure cloud, and compatibility with on-premises systems. The Privacy Policy dated 7 April 2026 says in terms that it does not apply to Customer Data, which is governed by contracts with customers that are not published, and the published Terms of Service cover the website only. Nothing addresses privilege or work product in what is captured, which matters here more than for most products: PointOne watches a lawyer's documents, email and calls all day, so what it holds is a map of client matters. Verified 20 September 2026.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

Ajax
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

A real position on review before billing is published, and it lives in the wrong place to earn more. An explainer of 7 July 2026 states that the lawyer's job shrinks to review, check the drafts, fix what's wrong, release to billing; that this does not mean the software bills for you; and, answering whether the output is accurate enough to bill from, that the entries are drafts until a lawyer approves them, which is what keeps billing defensible. The same page answers whether lawyers still review entries before they are billed with a plain yes, and says drafts stay drafts until the lawyer approves them. That engages the duty this product actually raises, which is the lawyer's responsibility for a narrative the client will read as their own account of their work. Three things hold it here. The position sits in a category explainer on the blog, not in the terms, the product pages or anything a customer signs. The fee rules the vendor names elsewhere are never connected to its own product. And nothing addresses found time, flat fees, or what a client is told about how the entry was written. Verified 20 September 2026.

PointOne
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

A position on the professional duty is published, and it sits in the wrong place to earn more. A guide of 15 July 2026 states that no AI time tracking software should submit entries without human review, that the firm reviews, edits if necessary and approves every entry before it goes anywhere, and that this is both an ethical requirement and a practical quality control measure. The same page puts the question of whether entries can be submitted without review to the buyer as one of quality control and ethics, and says nothing goes to billing without the timekeeper's approval. That engages the duty this product actually raises, which is that the lawyer bills for time actually spent, signs the bill and stays answerable for every entry on it, while the words describing the work are drafted by software. Three things hold it here. The position lives in a guide on the vendor's blog, not in the Terms of Service of 7 April 2026, the product pages or anything a customer signs. No rule of professional conduct and no ethics opinion is named anywhere on the estate, so no standard is tied to this product. And nothing addresses found time, flat fees, or what a client is told about how the narrative on the bill was written. Checked the home page and its four product sections, the security and about pages, the Terms, the Privacy Policy, the April 2026 release and five posts from the vendor's own blog on 20 September 2026. Verified 20 September 2026.

AI Governance and Bias Disclosure

Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

Ajax
DD on AI Governance and Bias DisclosureNo governance position published for a system whose output affects legal outcomes.

Nothing is published about how the models are governed. No one is named as accountable for what they write, nothing describes what is tested before a change ships, no evaluation results appear, and the privacy policy states plainly that the vendor does not test, verify or endorse AI outputs. Nothing addresses whether entry quality holds evenly across practice areas, seniority, or the kinds of work that leave a thin digital trace, which is the obvious question for a product whose output becomes a bill. The one thing on the estate that resembles a governance surface is the outside counsel guideline feature, where extracted rules are shown to the firm with a link back to the source page before they take effect, but that governs the client's rules rather than the model. Checked the home page, the security page, the terms, the privacy policy and the addendum on 20 September 2026. Verified 20 September 2026.

PointOne
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

The security page has a section headed Responsible use of AI, and everything in it is a data control: zero training on firm data, zero retention by the models, customisable base models, private Azure execution and auditability of AI outputs. Those protect the firm's data; they say nothing about how PointOne builds and tests the models that classify a lawyer's day. No accountable owner is named, nothing describes what is tested before a release ships, no evaluation result is published, and nothing addresses whether classification or narrative quality varies by practice area, seniority, working pattern or language. Checked the homepage and all four product sections, the security and about pages, the Terms, the Privacy Policy and the April 2026 release on 20 September 2026. Verified 20 September 2026.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Ajax
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

All five things this band asks for are published and specific. Retention: raw data deleted after 30 days, processed data after 60, stated identically in the terms, the privacy policy and the addendum, and alterable only by written customer instruction. Deletion: everything deleted or irreversibly anonymised within 30 days of termination. Access: SAML 2.0 and SCIM provisioning through the firm's identity provider, centralised control, automated onboarding and offboarding, and entries visible only to their author until release. Subprocessors: seven named, including the model providers. Incidents: notice to the customer within 48 hours of becoming aware, with remediation committed. Encryption is AES-256 at rest and TLS 1.2 or better in transit. One inconsistency belongs on the record: the security FAQ says the vendor does not store customer data, while the agreement and addendum publish the 30-day and 60-day windows above. Verified 20 September 2026.

PointOne
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

Retention, deletion and access are addressed with real specifics, short of a complete picture. The security page publishes customisable data retention, full data segregation, zero data retention by the AI models and single-tenant options. The Privacy Policy dated 7 April 2026 goes further than most on the capture surfaces: data taken through the Zoom integration, including meeting attendance, participant names and call logs, is discarded immediately once time entries are generated; data accessed through Google Workspace APIs is not used to develop or train AI or machine learning models, is retained only as long as needed, and is deleted on request through an automated process. What is missing is the rest of the set: no subprocessor list beyond analytics providers, no incident or breach notification commitment for firm data, and no published agreement, since the Privacy Policy excludes Customer Data. Verified 20 September 2026.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Ajax
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

What is published disclaims the exposure rather than allocating it. The service is provided as is, with no warranty of any kind and no undertaking that it will be error-free; AI outputs are expressly not guaranteed to be accurate, complete or suitable for any purpose, and the privacy policy adds that the vendor does not test or verify them. Liability is capped at the fees paid in the preceding twelve months and indirect, incidental, special, consequential and punitive damages are excluded. No indemnity of any kind runs from the vendor to the customer, not even for intellectual property, and no insurance is mentioned. For a product whose output is a bill a client will scrutinise and a lawyer will sign, nothing published says what happens if an entry is wrong. Verified 20 September 2026.

PointOne
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

The only published allocation of loss is a short disclaimer in website terms. Section 5 of the Terms of Service dated 7 April 2026 says that in the event of data loss or business interruption resulting from use of the services PointOne is not liable for damages, and that users are responsible for safeguarding their own data; section 11 caps total liability at one hundred dollars and excludes consequential damages, and section 10 runs an indemnity from the user to PointOne. Those Terms govern the website. No warranty, indemnity or insurance position covering the product is published, and nothing addresses who bears the loss if a wrong narrative reaches a client's bill or a client's billing guidelines are breached by an automated entry. Verified 20 September 2026.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Ajax
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

The integrations are real and named, and the depth stops at a sentence each. Eight billing and practice management systems are supported by name, each with its own page: Clio, MyCase, Filevine, PracticePanther, SurePoint, Centerbase, Actionstep and Soluno, with the claim that most other billing systems work too. What moves is clear enough: released time entries with matter, activity code and narrative already applied, out of Ajax and into the system of record. An explainer of 7 July 2026 goes further and calls two-way sync with all eight table stakes, without saying what comes back the other way, or what happens to an entry edited in the billing system after release. On the capture side the product connects to work email, Microsoft Teams or Slack, calendar, Zoom and supported VoIP platforms, with RingCentral, Dialpad and VXT named. What an implementer would need next is not published: no field mapping, no sync behaviour on edits or deletions, no error handling, and no API documentation, which the vendor offers to share with a technical team on request. Verified 20 September 2026.

PointOne
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

The connections are named on both sides of the product and partly described. PointOne captures context from the applications a lawyer works in, including documents, email, calls and the web, and the Privacy Policy sets out exactly what two of those carry: the Zoom integration collects meeting attendance, participant names and email addresses and phone call logs, and Google Workspace data is accessed under stated restrictions. On the output side it syncs with billing and practice management systems named on the homepage, Aderant, Elite 3E, Clio, Filevine, Actionstep, Surepoint, MyCase, LeanLaw and QuickBooks, and the security page says it works with on-premises systems. What is missing is depth for an implementer: no integrations page, no documentation or API reference, and nothing on what syncs in which direction or what a firm must configure. Verified 20 September 2026.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Ajax
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Cloud delivery is obvious and neither half of the question is answered. There is a desktop application and a hosted service behind it, and nothing published names a hosting provider, a region, a data centre or a tenancy model; nothing distinguishes where the software runs from where captured work product sits. The addendum comes closest, saying customer data may be processed in the United States and other countries where the vendor operates, which names no country beyond the first and offers no choice, and committing to standard contractual clauses for European transfers and to Australian privacy law for Australian ones. For a product that reads the content of privileged documents across a firm's whole working day, a security reviewer has nothing published to start from. Checked the home page, the security page, the terms, the privacy policy and the addendum on 20 September 2026. Verified 20 September 2026.

PointOne
BB on Deployment Model and Data ResidencyDeployment model is stated clearly with partial residency detail, or residency is offered without the processing location being addressed, or the tenancy model is stated on its own with no residency detail published.

The tenancy model is stated plainly and the geography is offered without being specified. The security page lists flexible deployment options for large firms: full data segregation, single-tenant options for enterprise deployments, customisable geolocation, compatibility with on-premises systems, and the ability to run models within a private Azure cloud, which is the clearest statement located of where the AI processing can be placed. No region is named, nothing says which tier or contract carries single tenancy or a private model environment, and the Privacy Policy says personal information may be transferred, processed and stored anywhere in the world. Verified 20 September 2026.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Ajax
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

The certification is stated plainly and the evidence behind it is not reachable. The security page claims SOC 2 Type II certification, describing independently audited security controls, data handling and infrastructure, and the terms add CASA certification alongside it; independent audits, penetration testing and 24/7 endpoint monitoring are also claimed. None of it carries the detail the top band asks for: no auditor is named, no report period or scope is published, no date appears, there is no trust portal and no route to the report itself. The only offer is a security review conversation, which is the same booking form as the sales demo. Verified 20 September 2026.

PointOne
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

The certifications are named and the evidence is not reachable. The security page states SOC 2 Type 2 certification with independently audited controls, full ISO 27001 certification, GDPR compliance by design and that PointOne meets HIPAA requirements for firms in healthcare-adjacent practices. No auditor, scope statement, report period or date appears, there is no trust portal or report request route, and no penetration test is mentioned. A firm's security reviewer would be asking for the SOC 2 report and the ISO certificate scope, and neither is obtainable from the published site. Verified 20 September 2026.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

Ajax
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

The providers are named, which is uncommon, and the disclosure stops there. The addendum lists seven subprocessors and three of them are model providers: OpenAI, Anthropic and Google Gemini, alongside BaseTen for model serving, Amazon Web Services, Vercel and PostHog. The same section binds all of them not to retain or use customer data for their own training or fine-tuning, which is the part a firm's client would ask about. What is absent is everything downstream of the name: no model or version is identified, nothing states which provider handles which part of the work, nothing says where inference runs, and no commitment is given to notify customers when any of it changes. Verified 20 September 2026.

PointOne
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

What runs underneath is left to the buyer to ask about. The security page offers customisable base models and the ability to run models within a private Azure cloud, and commits to zero data retention by the AI models, which implies terms with a provider without identifying one. No model, version or provider is named on any page read, nothing states where inference runs by default as opposed to in the private option, and no commitment to notify customers when the models behind their time entries change was located. Verified 20 September 2026.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Ajax
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

The shape of the deal is published in detail and the number is not. There is no pricing page; the vendor answers the question in a post of its own titled how much Ajax costs, and answers it structurally: priced per seat rather than firmwide, because a firm should not pay for timekeepers who keep their own system, with a stated expectation of 70 to 80 per cent take-up; contracts are annual; a two-week pilot on the firm's real work comes before any commitment. Elsewhere the vendor frames cost against return, saying one recovered hour per user per month covers the subscription and that payback typically lands inside eleven days, and describes itself as premium-priced in its category. The exact figure depends on firm size and seat count and is quoted on a call. No list price, no tiers and no range appear anywhere on the estate. Verified 20 September 2026.

PointOne
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

No price, rate or unit of charge is published. Checked the homepage and all four product sections, the navigation and footer, the security, about and careers pages, the Terms of Service, the Privacy Policy and the news posts on 20 September 2026: there is no pricing page, no tier, no per-timekeeper rate and no trial, and every route ends at a demo request. One customer quote says the software more than pays for itself, which is the closest the estate comes to a commercial statement. Verified 20 September 2026.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Ajax
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Coverage is shown rather than claimed, through the customers. The named firms span workers' compensation and insurance defence, general practice, family law, personal injury and business litigation, multi-practice, lemon law, community association work and federal employment law, across Florida, Colorado, Virginia, Texas, the Carolinas, Tennessee, California, Georgia, Maryland and the District of Columbia, and range from solo and boutique practices to 121 users across 24 offices and 270 professionals. The product requirement is the real boundary and it is only implied: this is built for timekeepers who bill by the hour and work on a screen, so contingency practices, flat-fee work and anything done away from a computer sit outside it. Nothing published states that, or which practice areas or firm sizes the vendor does not serve. Verified 20 September 2026.

PointOne
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

The range of buyer is evidenced rather than asserted, and the edges are not drawn. Named customers run from small firms and boutiques (Elevare Law, Bevilacqua PLLC, North City Law, Legal Scale) to larger national firms (O'Hagan Meyer, Scarinci Hollenbeck, McAngus Goudelock & Courie, Bell Nunnally, Lydecker) and a state Attorney General's office with more than 300 timekeepers, and the product pages say the review workflow is flexible enough for firms of all sizes while the security page addresses the needs of the world's largest firms. Worked examples span trademark prosecution, insurance defence, patent litigation and M&A. Nothing states which practice types or billing arrangements the capture handles poorly, and the customer count differs between pages: the homepage says more than 200 firms, the April 2026 release says more than 100. Verified 20 September 2026.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Ajax
Never, in the contract

The prohibition is in the agreement, not only on a policy page, and it reaches the model providers too. The addendum of 5 August 2026 states that Ajax will not train, retrain or fine-tune any general-purpose AI or machine learning model using customer data, and that it prohibits its subprocessors, naming OpenAI, Anthropic and other LLM providers, from retaining or using customer data for their own training or fine-tuning; service improvement is confined to anonymized analytics that exclude raw or identifiable customer data.

The terms and the privacy policy carry the same commitment in their own words. Two qualifiers belong on the record: the prohibition is written for general-purpose models, and the product page describes the system learning each timekeeper's voice and preferences from their corrections, which the estate does not connect to the training language either way.

PointOne
Never, in policy only

The security page commits to zero training on firm data and zero data retention by the AI models. The Privacy Policy separately affirms that data accessed through Google Workspace APIs is not used to develop, improve or train AI or machine learning models. No customer agreement is published to carry the commitment: the Terms of Service cover the website, and the Privacy Policy states that Customer Data is governed by contracts not published.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Ajax
Customer controlled, no zero option

Specific windows are published and the customer can override them. Raw data, which for this product means the logs and screenshots behind an entry, is deleted after 30 days; processed data, meaning the structured records derived from the activity, after 60; everything remaining is deleted or irreversibly anonymized within 30 days of termination. The same figures appear in the terms, the privacy policy and the addendum, and the addendum makes them the default by allowing alternative written instructions from the customer.

Zero retention is not offered as a setting. One inconsistency is recorded as fact: the security page answers the question what happens to my data by saying the vendor does not store customer data and does not engage vendors that store it, while the three documents above publish the windows described here.

PointOne
Customer controlled, no zero option

The security page offers customizable data retention and states that the AI models retain nothing. The Privacy Policy adds that data captured through the Zoom integration, including meeting attendance, participant details and call logs, is discarded immediately once time entries are generated. No zero-retention setting is stated for the platform's own store of captured activity and entries, and no default window is published.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Ajax
Own model, documented

The product runs its own access model and documents it, at the level of the individual rather than the matter. Drafted entries are visible to their author alone until that person releases them, and the vendor states plainly that the firm cannot see a timekeeper's hours before release and that it will not become a tool for the firm to watch its people. Capture stops on one click and resumes only when the user chooses.

Firm-side administration runs through the customer's own identity provider with SAML and SCIM, so joiners and leavers follow the firm's directory. What is nowhere addressed is the matter: nothing describes how capture behaves for a timekeeper screened off a conflicted matter, or whether a released narrative can carry content from a matter the reader of the bill should not see.

PointOne
Claimed, not documented

The security page claims full data segregation with single-tenant options for enterprise deployments, and the Review workflow lets a firm set reviewers, routing and permissions. Nothing published describes how access is enforced between timekeepers or matters, or whether captured activity for one matter can be seen by anyone reviewing another.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Ajax
Disclosure addressed, notice absent

The privacy policy tells a firm that its confidential information can leave without its approval where the law or legal process requires it, and stops there. No commitment to notify the customer is made, no discretion over notice is reserved either way, and nothing addresses challenging a request or seeking a protective order first. The terms and the addendum are silent on the subject: the addendum covers security incidents with a 48-hour notice commitment, and data subject requests, but never a government or third-party demand for customer data.

No transparency report is published. Checked the terms, the privacy policy, the addendum and the security page on 20 September 2026.

PointOne
Disclosure addressed, notice absent

The Privacy Policy dated 7 April 2026 says PointOne may access, preserve and disclose information it stores to comply with law enforcement or national security requests and legal process, such as a court order or subpoena, and makes no commitment about notifying anyone. It covers the website rather than Customer Data, so a firm has no published position on what happens if PointOne is served for its captured time data.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Ajax
Not addressed

No corpus question arises in the usual form and none is addressed. What the models read is the firm's own working day, the documents, emails, browser activity, calls and meetings of the timekeeper using the product, matched against that firm's own list of clients and matters. No external legal corpus, licensed dataset or cross-customer collection is used or claimed anywhere, and the addendum prohibits the model providers from retaining the material they see.

The one thing that resembles a source corpus is the client's outside counsel guidelines, which the firm uploads itself and which the product links back to page by page.

PointOne
Not addressed

Checked the homepage and its four product sections, the security and about pages, the Terms of Service and the Privacy Policy on 20 September 2026. The product works from a firm's own captured activity and its own uploaded client billing guidelines; no external legal corpus is involved or described.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Ajax
Not addressed

Checked the home page, the security page, the terms, the privacy policy and the addendum on 20 September 2026. The product writes time entries and files email; it does not cite legal authority or produce legal argument, so no question of subsequent history arises and nothing on the estate describes one.

PointOne
Not addressed

Checked the same pages on 20 September 2026. PointOne writes time narratives and billing rules rather than citing legal authority, so no subsequent-history check arises and none is described.

Refusal and Uncertainty Behavior

What does the product do when the answer is not in the corpus?

Ajax
Not addressed

Nothing published describes what the system does when it cannot tell what a piece of work was or which matter it belongs to. No confidence score, no flag on a low-certainty matter assignment, no described behavior for activity it cannot classify, and no account of what happens to time it captures but cannot write up. The vendor's stated position runs the other way, that it does not test, verify or endorse AI outputs and that users should review them, which allocates the duty rather than describing any abstention.

The review surface is real, since nothing releases without the timekeeper, but it is a control on the person rather than a described behavior of the model.

PointOne
Not addressed

Checked the homepage and its four product sections, the security page, the Terms, the Privacy Policy and the April 2026 release on 20 September 2026. Nothing describes what the product does when it cannot tell which matter a task belongs to or cannot describe the work: no abstention path, no uncertainty flag and no confidence score is published. The published controls are auditability of AI outputs and human review before billing, which come after an entry is written.

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

Ajax
None located

Searched on 20 September 2026 for any court order, opinion or disciplinary record naming Ajax or NapoleonScout in connection with fabricated or hallucinated material. None located. The product generates billing narratives rather than legal citations, so the usual route to such a record does not apply; the exposure this shape carries is a fee dispute or a billing challenge rather than a sanctions decision, and no such record was located either.

PointOne
None located

Searched the AI Hallucination Cases database maintained by Damien Charlotin on 20 September 2026 on the product name PointOne and the corporate name PointOne Technologies, Inc. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product, which writes time entries rather than legal citations.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Ajax
Named guidance addressed

Named guidance is engaged, in more than one place, and never connected to the product. The same two sentences appear almost word for word in at least two of the vendor's published rankings of time tracking and billing tools: that ABA Model Rule 1.5 requires reasonable, written-out fee arrangements, that ABA Formal Opinion 93-379 prohibits billing more time than was actually spent and recycling work product as original work, and that a system which lets a lawyer double-bill or block-bill creates real ethical exposure.

That is the guidance that governs this shape, named and stated correctly. A separate explainer of 7 July 2026 brings it nearest the product, saying that every serious tool in this category keeps a lawyer in the loop before anything reaches an invoice and that bar guidance expects exactly that; it is general, and it is the only place the two are tied together. Nothing maps the vendor's own machine-written narratives to the duty to bill only for time actually spent, and nothing on the live pages engages the newer guidance on generative AI and fees.

PointOne
Generic reference

Professional responsibility is engaged in general terms and no guidance is named. A published guide to AI time capture, dated 15 July 2026, states that no AI time tracking software should submit entries without human review, that the firm reviews, edits if necessary and approves every entry before it goes anywhere, and that this is both an ethical requirement and a practical quality control measure. That is the duty referred to without a rule, an opinion or a bar behind it.

Nothing names a rule of professional conduct, an ethics opinion or any bar guidance, on billing for machine-drafted narratives or on anything else, and nothing engages the newer guidance on generative AI and fees. The absence stays pointed on a product of this kind, because the guidance that governs billing is long established rather than new. The compliance features enforce clients' outside counsel guidelines, which are contractual rather than ethical.

Checked the home page, the terms of service, the full footer, the three solution pages and five posts from the vendor's own blog, including its rankings of timekeeping and AI tools, on 2 and 20 September 2026.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Ajax
Savings claims only

The premise of this product is that the bill goes up, and nothing published addresses what the client is told. The headline claim is 12 percent more billable hours captured, with payback in eleven days, and the case studies quantify it firm by firm as recovered revenue per timekeeper per month. Nothing on any page or in any agreement addresses whether a client should know that the narrative describing the lawyer's work was drafted by software, how a firm on a flat fee should treat found time, or what a lawyer should do with an entry for work they would not previously have billed.

The nearest thing to a record of the model's work is the review screen the timekeeper sees before release, and nothing describes what it retains afterwards or what it could show a client who queries an entry. Re-entry condition: a page describing a retained, viewable record of what each entry was built from, or an edit history marking the draft against the human change, would move this.

PointOne
Savings claims only

The published case for the product is that a firm bills more, by capturing time that previously went unrecorded, and nothing addresses what a client is told when the narrative on the bill was drafted by software. The nearest things to a record of the machine's work fall short of one: the security page promises auditability of AI outputs in a single line, without saying what is recorded or where a firm would see it, and the review trail shows who approved an entry, which records the human step rather than the AI's. Billing rules drawn from the client's own guidelines are enforced against every entry, which is a control on the output rather than a record of it.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Ajax
Subprocessors listed

A firm answering a client's questionnaire has most of what it needs and can read it without signing anything. The addendum names seven subprocessors, including the model providers OpenAI, Anthropic and Google Gemini, and binds them against retaining or training on customer data; the security page states the encryption standards, the certification claimed and the deletion cycle. The product also works the other way round, taking the client's own outside counsel guidelines and turning them into rules applied to every entry for that client, with each rule traceable to its page in the source document.

What is missing is the client-facing half: nothing published helps a firm tell its client that its time entries are machine-drafted, and no disclosure material exists for that conversation.

PointOne
Not addressed

Checked the security page, the homepage, the Terms of Service and the Privacy Policy on 20 September 2026. No subprocessor list, model provider list or client-facing disclosure pack was located, and there is no trust portal or documented route to request one; the Privacy Policy names service providers for the website only. The product manages clients' outside counsel guidelines, which is a separate matter from what PointOne discloses about itself.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Ajax
Not addressed

Checked the home page, the security page, the terms, the privacy policy and the addendum on 20 September 2026. Nothing addresses disclosure of AI use to a court or an adjudicator, and nothing describes a record that would support one. The product does not produce filings; where its output could reach a tribunal is a fee application or a bill of costs, and nothing published addresses that either, or describes an export showing which entries a model drafted and who approved them.

PointOne
Partial record

Elements of a record exist, built for billing rather than for a court. The security page promises auditability of AI outputs, entries carry the rules they were checked against, and the review workflow records who approved what. Nothing records which model produced a narrative, and no per-document export covering model use, sources and human verification is described.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.

Signals neither addresses in public material
  • Primary Law Corpus Provenance
  • Good Law Verification
  • Refusal and Uncertainty Behavior

Which one fits

Choose Ajax if

  • You need the training prohibition in a contract your general counsel can read. Ajax's addendum of 5 August 2026 states that it will not train, retrain or fine tune any general purpose model on customer data, prohibits its model providers from retaining or training on that data, and deletes raw data after 30 days and processed data after 60.
  • Your clients' guidelines ask which AI vendors touch their matters. Ajax's addendum names seven subprocessors, including the model providers OpenAI, Anthropic and Google Gemini and BaseTen for model serving, so a firm can answer a client questionnaire from a published document before signing anything.
  • You want to know how you will be charged before the first call. Ajax publishes the structure: per seat rather than firmwide, on annual contracts, after a two week pilot on your own work. The rate itself is quoted on a call, and no list price appears anywhere.

Choose PointOne if

  • Your security team wants the AI inside your own cloud boundary. PointOne's security page offers single tenant options for enterprise deployments, customizable geolocation, compatibility with on premises systems and models run inside a private Azure cloud. No region is named and nothing says which contract carries these options.
  • You bill through Aderant or Elite 3E. PointOne names both among the billing and practice management systems it syncs with, alongside Clio, Filevine, Actionstep, Surepoint, MyCase, LeanLaw and QuickBooks, which reaches the systems larger firms run on.
  • You need bills reviewed by several people before they go out, not only released by the timekeeper. PointOne's Review marks up each bill, flags problems and routes it through reviewers and permissions the firm sets, and the Minnesota Attorney General's Office deployed the platform across more than 300 timekeepers in April 2026.

In summary

Ajax

Ajax is a passive timekeeping product for law firms that bill by the hour, sold by NapoleonScout, Inc. A desktop application reads a lawyer's working day across documents, email, calls and meetings, groups activity by matter, and drafts time entries with narratives and activity codes that the timekeeper reviews and releases into one of eight named billing systems. The AI Legal Index grades it in the top two bands on ten of fifteen capability axes, with A grades on AI centrality and on data stewardship. Its data processing addendum of 5 August 2026 bars training on customer data, binds the named model providers OpenAI, Anthropic and Google Gemini to the same, and deletes raw data after 30 days. As of 20 September 2026 the index located no published price and no accuracy measure for the narratives it writes.

Source: AI Legal Index, 2026

PointOne

PointOne is an AI timekeeping and billing platform for law firms and government legal offices, based in New York City. It captures a lawyer's working day across documents, email and calls and writes the time entries itself, then runs each bill through a review before it goes out and turns uploaded outside counsel guidelines into billing rules enforced against every entry. The AI Legal Index grades it in the top two bands on nine of fifteen capability axes, with an A on AI centrality. Its security page commits to zero training on firm data, zero retention by the models, single tenant options and models run in a private Azure cloud. The Minnesota Attorney General's Office deployed it across more than 300 timekeepers in April 2026. As of 20 September 2026 the index located no published price and no customer agreement.

Source: AI Legal Index, 2026

Questions buyers ask

Ajax vs PointOne: which is better for AI timekeeping?

The grid puts them one axis apart: Ajax sits in the top two bands on ten of fifteen AI Legal Index capability axes and PointOne on nine of fifteen, with identical grades on ten. Ajax publishes its data commitments in an addendum and names its model providers. PointOne publishes more about where the AI can run, including a private Azure option, and integrates with Aderant and Elite 3E. A firm on those billing systems, or with strict hosting rules, has more to read from PointOne.

Does PointOne train its AI on client data?

PointOne's security page says it does not: it commits to zero training on firm data and zero data retention by the AI models, and its privacy policy adds that Google Workspace data is not used to train AI or machine learning models. These are published policies. The privacy policy states that customer data is governed by customer contracts that are not published, so the commitment could not be read as a contract term. Ajax puts its training prohibition in a published addendum. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.

Which AI models does Ajax use?

Ajax names its model providers, which is uncommon among timekeeping vendors. Its data processing addendum lists seven subprocessors, three of them model providers, OpenAI, Anthropic and Google Gemini, alongside BaseTen for model serving, Amazon Web Services, Vercel and PostHog, and binds all of them not to retain or train on customer data. It does not name the models or versions, say which provider handles which task, or commit to notifying customers when that changes. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.

How accurate are the time entries Ajax and PointOne write?

Neither publishes a measured accuracy rate for its narratives. Ajax states in an explainer of 7 July 2026 that matter matching is right about 92 percent of the time, with no sample, period or method behind the figure. PointOne relies on customer quotes calling it accurate and states that the Minnesota Attorney General's Office stress tested task classification in a pilot, without publishing a result. On both products the control is the timekeeper's review before release. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.

What do Ajax and PointOne both leave unpublished?

A price, and a position on the client. Neither publishes a rate. Neither says what a client is told when the narrative on its bill was drafted by software, or how a firm on a flat fee should treat time the product finds. Neither describes what the system does when it cannot tell which matter a task belongs to. Neither commits to notify a firm before handing its captured data to a court or agency, and neither offers a warranty covering a wrong entry. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 25, 2026. No vendor pays for placement.

Disclosure

Two things cut across the grades. Ajax's own security page says the vendor does not store customer data, while its terms, privacy policy and addendum publish retention windows of 30 and 60 days; the addendum is the binding document. PointOne's commitments on training, retention and segregation are published policies, and its privacy policy states that customer data is governed by contracts that are not published, so its grades record what a buyer can read before signing, not a judgment that its controls are weaker. Neither publishes a measured accuracy rate for the narratives it writes. Both records were verified on 20 September 2026. Neither vendor reviewed this page.

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 24, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746