Casepoint vs Nextpoint: how they compare in 2026
Casepoint and Nextpoint are both cloud ediscovery platforms selling into different rooms. Casepoint's pitch is government grade authorisation, and it sits in the top two bands on fourteen of fifteen axes. Nextpoint's is a flat per user price with nothing charged for data, and it sits on eight. Casepoint publishes FedRAMP High and Moderate, Department of Defense Impact Levels 4, 5 and 6 with authorities to operate from the Defense Information Systems Agency, and SOC 1, 2 and 3 alongside ISO 27001:2022, which matters because those government authorisations are independently assessed and listed by the authorising bodies rather than asserted. Its agreement then carries an AI clause classifying inputs and outputs as confidential information, preventing cross tenant and cross matter retrieval, restricting personnel review, and enumerating five named limitations of the AI. Nextpoint answers on commercials and on candour, itemising the eight things it never charges for and publishing an instruction to treat generated summaries as starting points and verify them.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models drive a core capability and the platform underneath them is a complete product without them. CaseAssist Active Learning is the engine of prioritised review: it learns continuously from reviewer decisions to surface likely-relevant documents first, and the vendor attributes its 95 per cent faster identification claim to it. The generative layer adds chat-based search over customer data, document summarisation and automatic classification. Strip all of it out and what remains is a full eDiscovery platform that would still be sold: legal hold, in-place preservation and collection from Microsoft 365, Teams, Slack and Google Vault, processing of more than 600 file types, review, production, FOIA workflows, chain of custody and the FedRAMP and Department of Defense hosting that is the company's central pitch. Two things fix this below the top band. The vendor bundles rather than meters the AI, stating that CaseAssist comes built in at no extra cost, so it is not the thing a buyer purchases. And the platform's own framing puts security architecture and workflow unification first and AI third. Graded level with UniCourt and above Docket Alarm and Bloomberg Law, where the machine learning sits further from the core.
Machine learning is present, real and peripheral, and the vendor's own marketing says so by omission. The flagship eDiscovery product page was read in full on 31 Aug 2026 and contains no mention of AI, machine learning, technology-assisted review or predictive coding. Every capability it names is deterministic or classical text processing: deduplication, email family threading, near-duplicate detection, OCR, search hit reports, coding panels, folders, Bates stamping, production and privilege log templates, and auto-redactions that match social security numbers, phone numbers and custom terms. The privilege workflow is explicitly human: documents are tagged privileged during review using custom categories and the system generates the log from those coded documents. What does exist sits on the trust page and the blog: search and ranking on models the vendor hosts in its own cloud, and AI Transcript Summaries, a generative feature running on Amazon's managed foundation-model service. Remove all of it and the product a buyer is actually paying for, unlimited data hosting at a flat per-user rate across discovery and trial preparation, remains intact. This is the only vendor in this pull that under-markets its AI rather than over-marketing it, which is worth recording, but it does not change the grade.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is documented and the measurement is absent, with one unusual strength and one unusual restriction on either side of the line. The strength is that the failure modes are named, and named in the agreement rather than in marketing: the terms tell the customer that AI features including machine learning, technology-assisted review and large language models have limitations affecting output reliability, and enumerate five, being variation in training data quality and diversity, errors from human or machine inputs such as vague prompts, variation in natural language including nuance and sarcasm, factual inaccuracy of models or datasets, and lack of common sense. Almost nothing else in this pull names its failure modes at all, let alone contractually. Grounding itself is real: retrieval-augmented generation is named, answers are drawn from the customer's own data with source citations, and transparency logs are said to record every AI decision, so a reviewer can open the document behind an answer. What is missing is any number. No accuracy figure, recall or precision statistic, validation protocol or test description was located on 31 Aug 2026, which is a conspicuous gap in eDiscovery specifically, where technology-assisted review validation statistics are the currency courts examine. The restriction cuts the other way and belongs on this axis: the terms forbid a customer from disclosing software performance benchmark results to any third party without written consent, which forecloses the independent testing this axis asks about. One limb does not apply rather than failing: a citator or good-law check is out of scope for a platform that searches the customer's own collected documents rather than primary law.
Accuracy is addressed honestly and never measured. The trust page states that every AI feature is validated through extensive testing before release, and then says something most vendors avoid: that generated summaries and results are meant as starting points and the customer is encouraged to trust but verify. That is a franker posture than the no-hallucination absolutes seen elsewhere in this pull, and it is still an assertion. Searched the eDiscovery platform page, the pricing page, the trust and security page and the terms of use on 31 Aug 2026 and located no accuracy figure, no test set description, no recall or precision statistic, no error rate and no published evaluation of any kind, so nothing supports the extensive testing claim from outside. Grounding is not described either: nothing states whether a transcript summary cites or links back to the passages it rests on, which is the verification surface a reader would need to act on the trust-but-verify instruction. The source material is at least inherently at hand, since a summary is generated from a transcript the customer already holds. One limb does not apply and is neither credited nor penalised: a citator or good-law check is out of scope for a platform operating on the customer's own collected evidence. The AI summarisation blog post and the downloadable AI overview PDF were not opened and are the rebuttal route.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
A stated design posture with contractual backing, short of the failure path. The posture is explicit: the vendor says technology should amplify human judgment rather than replace it, describes human-in-the-loop processes where appropriate, and commits in the agreement that it prioritises developing and deploying AI features with human-in-the-loop functionality. Control sits with the customer in a way few vendors state: all generative features are optional and the customer controls adoption. Review surfaces are real and specific, being source citations on generated answers plus transparency logs said to document every AI decision, and active learning is human-supervised by construction since the model is trained by the reviewers' own calls. The agreement also instructs the customer not to rely solely on any output for a purpose with material consequences or affecting anyone's rights. What is not published, checked across the AI strategy page, the platform page, the pricing page, the security page and the full terms on 31 Aug 2026: no threshold at which a feature declines to answer, no described behaviour when the data does not support a result, and no route for reporting or correcting a wrong output. The oversight model describes who is in the loop and not what happens when the loop fails.
A human is said to review and nothing describes where that happens. The published position is short and clear: the AI is built to accelerate review rather than replace judgement, generated summaries and results are starting points, and the customer should trust but verify. That places responsibility with the lawyer, which is the right instinct, but it is a caution rather than a control structure. Searched the eDiscovery platform page, the trust and security page, the pricing page and the terms of use on 31 Aug 2026 and located nothing on what the system does when the transcript does not support a summary, no confidence or uncertainty indicator surfaced to the user, no threshold at which a feature declines, no correction or feedback route, and no description of a review step inside the product where generated text is checked before it is used. Two real control surfaces exist on the platform and are not tied to the AI in anything published: tamper-resistant per-document activity logging covering view, edit and markup history with timestamps, and six permission levels reaching case, folder and document level. Both bands have some purchase here and the lower is taken, because what is published states that a person should check the output without describing what they would be looking at.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
The deepest production evidence located anywhere in this pull, and it is attributed. Named organisations with named individuals and titles appear on the platform page: Marriott International through its senior vice president and assistant general counsel, Mayo Clinic, the West Virginia Office of Technology through its chief information officer, Kramer Levin through two named litigation support managers, Beveridge & Diamond through its chief information officer, Larkin Hoffman through two named staff, and Lewis Roca through a named partner. The pairing that matters most is Lewis Roca, an Am Law 200 firm named alongside a quantified result of more than 90 per cent reduction in document review time attributed specifically to the advanced analytics and AI. Further quantified case studies sit behind their own pages: a 57 per cent reduction in discovery-related costs at a Fortune 500 construction company, a FOIA response-time reduction at a major defence agency, a time-to-insight reduction at a firm that won a motion, and a federal regulatory agency migrating up to a petabyte from a legacy on-premises system. Deployment scale is stated at more than 250 government agencies and roughly 80 per cent of federal agencies. Two qualifications belong in the record. The case studies themselves were not opened on 31 Aug 2026, so their method and dates are unverified. And the pattern across the set is that the quantified studies mostly describe organisations by category rather than name, while the named organisations mostly give qualitative quotes, with Lewis Roca the bridge between the two.
Substantial named deployment evidence, short of dated outcomes. The vendor claims more than 600 law firms and legal teams and backs it with an unusually large attributed set rather than a bare logo wall. Named organisations appearing with logos include McDermott, Foley & Mansfield, Jackson Walker, Seyfarth Shaw, Simmons Hanly Conroy, Clyde & Co, O'Hagan Meyer, Bates Carey, Maron Marvel, Cline Williams, Bell Davis Pitt, Miller Starr, Stein Ray, McCarthy Lebit, Williams Kastner, Kercsmar, Yates Construction and Augusta University. Eight testimonials carry a full attribution of name, job title and firm, which is more than most vendors in this pull manage even once. One of them carries a figure: a litigation support services manager at Foley & Mansfield describes migrating 180 databases and running close to 250, and reports significantly decreased training time against the firm's previous review platform. What is missing is the measured outcome. The recurring claims of up to 50 per cent cost reduction and review time cut in half are unattributed to any customer, no case study was opened, and no testimonial carries a date. Checked the eDiscovery platform page and the pricing page on 31 Aug 2026; the case studies library was not opened and is the rebuttal route.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Every element this axis asks for is in the agreement, which is the first time in this pull that is true. Privilege is named rather than implied: the confidentiality clause defines Confidential Information to include information protected by statute or regulation such as Attorney Work Product, Attorney-Client Privilege, personally identifiable information and protected health information. A dedicated clause governs AI specifically. It classifies AI Inputs and Outputs as both Customer Data and Confidential Information; limits their use to providing, securing and supporting the services; commits that AI features will enforce the customer's own access controls and matter or workspace permissions, prevent cross-tenant and cross-matter retrieval, and log administrative access; and commits that Casepoint personnel will not review AI Inputs or Outputs except as necessary for customer-requested support or a security incident, under least-privilege, time-bounded access with audit logging. Segregation is therefore stated at the level this buyer segment requires, at matter level, in writing. Support access is governed to the same standard, with no standing or default remote access, enablement only by the customer, named individual support personnel under multi-factor authentication, and audit logs made available to the customer. One tension is recorded rather than ignored: a separate clause grants Casepoint a transferable licence over Customer Data and usage data to improve its products and services, which reads broadly, though the AI clause carves AI Inputs and Outputs out of exactly that use. A buyer should read the two together and understand that the carve-out protects prompts and outputs specifically rather than the whole collected corpus.
Substantive published commitments on both confidentiality and training use, short of contractual force. The training position is the clearest in this pull: the trust page states flatly that AI features run entirely inside the vendor's secure Amazon environment, that customer case data is never used to train or improve any AI model, and that inputs and outputs are never shared with or retained by any outside model provider. The terms of use help rather than undercut it, which is unusual. They describe the service as a platform for attorney-client privileged data and work product, confirm that the customer or the party that entrusted the data to them owns all user content, and limit the vendor's own use to what is necessary to provide the service, with no licence to improve products or services anywhere in the document. Segregation is granular and documented: six permission levels reaching case, folder and document level for internal teams and outside parties, mandatory multi-factor authentication on every user and device, single sign-on through Okta or Azure AD, employee access restricted to a subset of staff with a documented request and approval trail and prompt revocation, and confidentiality agreements for employees and third-party associates. What holds it below the top band: the training commitment lives in a website FAQ rather than in the agreement, the terms contain no AI clause at all, no retention period is stated for prompts or generated output held by the vendor, and the master services agreement that actually governs the relationship is not published.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
A real position on tooling versus judgement, published where it binds, and silent on the professional framework around it. The agreement tells the customer that it should not rely solely on any output from the software including AI features for any purpose that may have material consequences or affect the rights of any person or entity, and elsewhere that the customer alone is responsible for its reliance on the results of its use, including their completeness, accuracy and content. The competence and supervision dimension is present rather than assumed, through the enumerated AI limitations, the human-in-the-loop commitment and the vendor's stated position that technology should amplify human judgment rather than replace it. What is absent, checked across the AI strategy page, the platform and security pages and the terms on 31 Aug 2026: no bar or ethics authority is named anywhere, including ABA Formal Opinion 512 and any state guidance; no jurisdictional limit is stated; and nothing addresses the professional obligations of the reviewers who will act on the output. One limb does not apply and is not penalised: the product has no consumer-facing surface, since it is sold to legal departments, agencies and firms and reached through an authenticated platform, so consumer disclosure is not a question it raises.
Nothing published addresses the advice line. Searched the eDiscovery platform page, the pricing page, the trust and security page and the complete terms of use, updated June 2026, on 31 Aug 2026. Nothing states that generated output is not legal advice, nothing addresses whether an attorney-client relationship arises with the vendor, nothing allocates responsibility for a summary a lawyer relies on, no bar or ethics authority is named including ABA Formal Opinion 512, and no jurisdictional limit is stated. The terms come closest without arriving: their disclaimer expressly denies any representation that information obtained through the service will be accurate or reliable, which allocates risk rather than describing the line between tooling and advice. One thing does exist and is recorded rather than credited, because it is the inverse of what this band usually describes: a supervision and competence posture is published, in that the AI is stated to accelerate review rather than replace judgement and output is framed as a starting point to verify. There is a supervision statement and no disclaimer, where the band above describes a disclaimer with no supervision statement. The exposure is also narrower than for a research tool, since the platform advises on nothing, though the summarisation feature does produce work a lawyer acts on.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A framework whose substance sits in the agreement rather than on the poster, and a complete silence on the second half of this axis. The public framework is TRUST, with five named principles, and read alone it would be principles rather than mechanism: transparency about data use, methodologies and an opt-out; reliability framed as transparent, auditable and defensible; user-centricity through human-in-the-loop processes and source citations; security; and a stated refusal to chase hype. What lifts it is that the commitments recur in binding form. The terms limit the purposes for which AI Inputs and Outputs may be used, restrict personnel review of them, require enforcement of access and matter permissions inside AI features, and mandate logging of administrative access. Transparency logs recording every AI decision are an auditable artifact rather than a claim, and a separate clause gives customers above a stated spend an annual audit right over privacy and security controls. That is a mechanism a buyer can hold the vendor to. What is missing is everything about bias. No fairness or uneven-output evaluation, no testing regime described, no accountable owner named, and no acknowledgement anywhere that a system which decides the order in which a human reviews documents can be uneven across custodians, languages or document types. For a review-prioritisation engine, that is the governance question, and it is not addressed.
A governance position with a real mechanism behind it, and complete silence on bias. The trust and security page carries a dedicated artificial intelligence section answering five questions directly: whether case data trains the models, where documents are actually processed, how the arrangement differs from using a consumer chatbot on case files, whether generated output can be trusted, and which compliance framework covers the AI. The last is the substantive one. AI features built within the platform are stated to fall inside the vendor's SOC 2 Type II compliance and its annual IT risk assessment, which puts model behaviour inside an existing third-party-audited scope rather than in a separate unaudited space, and that is a mechanism a buyer can ask an auditor about. A downloadable document titled Security, Compliance, Privacy and AI at Nextpoint is published without a form or gate and is said to set out the principles, architecture and safeguards behind every AI feature; it was not opened on 31 Aug 2026 and nothing in it is credited here. What is absent is the second half of the axis. No accountable owner is named, the extensive pre-release testing is asserted without a single result, and nothing anywhere addresses bias, fairness or uneven output across custodians, document types or languages.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Most of the ground is covered contractually and with more precision than anything else in this pull, and one element is missing. Incident practice is the standout: the agreement commits to written notification within seventy-two hours of a validated security incident, with periodic updates covering the cause, the mitigation under way, the anticipated impact on the customer and the expected remediation timeframe. Deletion and return are specified, with an export of all Customer Data on termination in a common format, a seven-day window, and an explicit statement that backup media copies may persist under standard procedures. Access control is described at several levels: role-based access controls, zero-trust network architecture with continuous threat detection, encryption in transit and at rest, and a remote-support regime with no standing access and customer-controlled enablement. Personnel controls are unusually specific, with ten-year criminal background checks, OFAC screening, and social security, employment and education verification. Disaster recovery and backup plans are reviewed and tested annually with copies available on request. What holds this below the top band is the subprocessor list: the agreement commits Casepoint to maintaining a list of material third-party components and subprocessors, and no such list was located as published on 31 Aug 2026. One research limit to state: the privacy policy and the data processing agreement were not opened, and either could carry the list.
Detailed, specific and current across most of the ground, with one artifact missing. Access control is the strongest element: six permission levels from view-only to dashboard administrator with granular control at case, folder and document level, mandatory multi-factor authentication for every user and device, single sign-on through Okta or Azure AD with custom integrations available, Amazon environment access IP-restricted and locked after five failed attempts, and application access limited to a subset of employees under a documented request-and-approval trail with prompt revocation. Deletion is specific rather than gestured at: customers export and download without limit at any time, deletion follows a Data Archive Form, and decommissioned media are sanitised under DoD 5220.22-M or NIST 800-88, with degaussing or physical destruction where those procedures cannot run. Incident practice is published in detail, including daily review of firewall notifications and operating system event logs, notification of affected users as soon as possible without compromising investigation, four enumerated cooperation obligations, and a provision leaving the customer with sole right to decide whether and how a breach is notified onward. A public status dashboard publishes service state and incident reports. Also published: background checks and security training on hire plus annual retraining, confidentiality agreements, a secure development lifecycle, an annual IT risk assessment, redundant multi-location storage at no charge and eleven nines of stated object durability. Missing: no named subprocessor list beyond Amazon as infrastructure, no retention period for customer data during the term, and no breach notification timeframe.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
The strongest published liability position in this pull, and it still stops short of standing behind the output. What a buyer gets in writing: a general cap at fees paid under the relevant order in the six months preceding the claim; a materially higher cap of five times annual fees plus direct damages for breaches of confidentiality, data breaches, gross negligence and wilful misconduct, which is the risk that actually matters when a vendor holds a firm's collected evidence; named carve-outs for personal injury or death, fraud and anything not excludable by law; a defence and indemnity from Casepoint against claims that the software infringes a US copyright or misappropriates a trade secret, with a defined procedure and named remedies of modification, licensing, substitution or refund; an affirmative sixty-day warranty that the software will perform substantially in accordance with its documentation; a services warranty of professional and workmanlike performance; and a 99.5 per cent uptime commitment with a published service-credit formula. That is considerably more than a disclaimer. What is not there is the thing this axis asks for last. No warranty attaches to AI output, and the agreement instead disclaims reliance on it and places responsibility for accuracy on the customer. No insurance position was located. And the general indemnity runs from the customer to Casepoint on data, legality and breach caused by customer systems. The allocation is precise, readable before signing, and asymmetric on the question of whether the AI was right.
Liability is addressed through a standard limitation package and nothing runs toward the buyer. The terms of use, updated June 2026, cap aggregate liability at the total amounts paid in the twelve months preceding the event, exclude indirect, incidental, special, consequential and exemplary damages including lost profits, revenue, goodwill, content and data, and impose a one-year limitation period, under Illinois law with exclusive venue in Chicago. The disclaimer is broad and provided on an as-is basis, expressly denying any representation that information obtained through the service will be accurate or reliable, which is the exposure a generative summary creates, stated as a disclaimer rather than as an allocation. A separate release runs from the customer to the vendor with a California Civil Code 1542 waiver, and the only indemnity in the document runs from the customer to the vendor covering user content and breach. What is not there: no carve-outs from the cap are named at all, no vendor indemnity of any kind, no warranty on output, no insurance position and no AI-specific term anywhere in the agreement. This sits a band below the eDiscovery and research vendors in this pull that publish caps with named carve-outs, and a band above the one that publishes no agreement at all. The commercial terms that would carry more, the Subscription Agreement and Master Services Agreement, are referenced repeatedly in the published terms and are not themselves published.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Real, named connections into the systems where the data actually lives, described at the level of what they collect rather than how they are configured. Named on the vendor's own pages: Microsoft 365, Microsoft Teams, Slack and Google Vault, with collection performed in place and directly from the source rather than through manual export by the customer's IT function, and support for more than 600 file types on processing. An API is described as automating collection from those platforms. The most current addition is the Casepoint MCP Server, offered as a way to connect an organisation's own approved AI systems to the platform, which is an integration surface pointed outward at the buyer's AI stack rather than at its document systems. What is absent is the other half of a firm's estate: no document management integration is named, with nothing located for iManage or NetDocuments, and nothing for matter management, e-billing or court filing. No public API documentation was located, and the terms restrict use of APIs not supported by Casepoint. Two research limits: the data connectors page and the MCP Server page were not opened on 31 Aug 2026, and either could carry the configuration and direction detail this grade turns on.
Named connections that work, described at the level of what they do rather than how they are configured. Data import integrations are named and their function stated: OneDrive, Dropbox and Google Drive for pulling evidence directly from cloud storage without manual export, with drag-and-drop as the alternative. Identity integration is named and specific: single sign-on through Okta or Azure Active Directory, with custom SSO integrations available through Client Success, and multi-factor authentication mandatory for every user and device. That identity layer is the deepest enterprise integration on this record and is genuinely useful to a firm's IT function. Beyond it the estate is thin. No document management system integration is named, with nothing located for iManage or NetDocuments, and nothing for matter management, e-billing, court filing, Word or Outlook. An application programming interface exists but is referenced only as an invitation to talk about custom integrations, with no public documentation, no endpoint list and no schema located on 31 Aug 2026. Checked the eDiscovery platform page, the pricing page, the trust and security page and the navigation.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The deployment model is stated clearly and residency is answered for some data and not for the rest. Three delivery options are described in the agreement rather than merely implied: Casepoint-hosted software with a 99.5 per cent uptime commitment; customer-operated or third-party-hosted installation, permitted subject to named conditions on notification, secure storage and flow-down of terms; and separately certified government environments. Which certifications attach to which environment is stated, with SOC 1, SOC 2, SOC 3, ISO 9001, ISO 27001 and the NIST publications as the base commercial offering and GovRAMP, FedRAMP Moderate, FedRAMP High and Department of Defense Impact Levels 4, 5 and 6 for certain environments and applications, so a buyer can tell what changes between tiers. Residency is committed for one defined class of data: for export-controlled material the agreement requires storage and processing only within the United States in Casepoint-controlled environments with no replication to non-US locations, and restricts access to US persons. What is not published is the general case. No region list for the commercial offering, no tenancy model statement, and no distinction between where data is stored and where it is processed outside the export-control clause. A Canada government offering is referenced in the navigation without a residency statement attached.
The infrastructure is described in unusual technical detail and the residency question is never asked. What is published: the platform runs on Amazon Web Services; objects are stored redundantly across multiple facilities with eleven nines of stated durability and integrity verified by checksums; data is designed to survive the concurrent loss of two facilities with a tertiary facility activating without downtime; network isolation uses Virtual Private Cloud, monitoring uses CloudWatch, and employee access uses Identity and Access Management with IP restriction. Nextpoint's own office holds client data in a keyed office within a keyed building with a security system, and server access requires a password over a secure virtual private network, which is a candid disclosure most vendors omit. What is not published is anything a buyer would need on residency: no region is named, no residency option is offered, no tenancy model is stated, and nothing distinguishes where data is stored from where processing or model inference happens beyond the statement that AI runs inside the same Amazon environment. Amazon GovCloud appears once, in a paragraph about Amazon's own physical access controls, without being offered as a deployment option. One unexplained lead recorded for a later pass: custom account headquarters is listed as an Advanced plan feature and is nowhere defined.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Current independent attestation, with scope named and verifiable without asking the vendor anything. The security page lists fourteen certifications and authorisations, each with explanatory text rather than a bare badge: FedRAMP High and FedRAMP Moderate, Department of Defense Impact Levels 4, 5 and 6 with authorities to operate from the Defense Information Systems Agency, GovRAMP, SOC 1 Type II issued under SSAE 18, SOC 2 Type II, SOC 3, the Shared Assessments SIG questionnaire self-assessed annually, ISO 9001:2015, ISO 27001:2022, NIST 800-53, NIST 800-171 and the EU-US Data Privacy Framework. The government authorisations are the decisive point for this axis, because a FedRAMP authorisation and a DISA authority to operate are third-party assessed and independently listed by the authorising bodies, so a buyer can confirm the status without a sales conversation and without relying on the vendor's own page. Scope and period are stated for the SOC 2 Type II, described as an independent third-party assessment issued annually against the AICPA Trust Services Criteria covering security, confidentiality, availability, processing integrity and privacy over a twelve-month period. The agreement then restates the whole set contractually and distinguishes which certifications apply to the base commercial offering from those applying to certain environments, which is a scope statement most vendors never make. Two honest gaps: no auditor is named for the SOC or ISO work, and no report date appears on the page, with the reports and the SIG available to customers on request under the audit clause.
A real, current, annually renewed attestation with its scope stated, and no date or auditor attached to it. The trust and security page states that the vendor's independent security certification is SOC 2 Type II, describes it as an annual third-party audit of its own security controls, and names the criteria it covers as security, availability, confidentiality and privacy. It then does something rare and creditable by stating the access tiers explicitly rather than leaving a buyer to discover them: SOC 3 reports are available on request, and SOC 2 reports require an executed non-disclosure agreement. It also draws a distinction most vendors blur, separating its own certification from the certifications of the infrastructure it runs on, noting that Amazon Web Services maintains SOC 1, SOC 2, SOC 3, ISO 27001 and FedRAMP for the underlying cloud without implying that any of those attach to Nextpoint. Supporting material sits alongside it: a public status dashboard with incident reports, an annual IT risk assessment described as maintaining the certification, and an ungated overview document. What holds it below the top band is narrow but real: no auditor is named, no report date or coverage period appears anywhere, and the SOC 2 itself is behind an executed agreement rather than a self-service request.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The architecture is described and the providers are not. What is published: retrieval-augmented generation named as the mechanism for generative answers, with the retrieval corpus identified as the customer's own data rather than an external body of content; the technology classes named in the agreement as machine learning, technology-assisted review and large language models; and a contractual commitment that Casepoint will ensure proper licensing of third-party software, patch critical vulnerabilities in it, and maintain a list of material third-party components and subprocessors. That commitment is more than most vendors make, and the list itself was not located as published on 31 Aug 2026. What a buyer cannot establish: no model or provider is named anywhere, no version is given, no inference location is stated as distinct from the data residency commitments, and no notice obligation attaches to a change of model or training data. One structural feature cuts across this axis and is worth recording: the separately offered MCP Server is described as connecting the organisation's own approved AI ecosystem to the platform, which lets a buyer supply models it has already vetted and shifts part of the supply-chain question onto its own governance rather than answering it.
The most specific model disclosure in this pull, and the service is now named. The vendor states that its AI features are built on Amazon Bedrock, Amazon's fully managed service for foundation models, and splits the architecture between that and models it hosts itself, with search and ranking running on the vendor's own models inside its private cloud and generative features such as transcript summaries running on Bedrock within the same environment. Naming the service rather than gesturing at a cloud provider lets a buyer read the downstream terms directly. Three protections are published against it and each is specific: Bedrock does not use customer data to train or improve foundation models; it does not store or log prompts or completions; and input and output data are never shared with model providers. Those answer the questions a firm is asked about a generative feature in the order they are usually asked. What is still not established: which foundation model within that service actually generates a summary, since Bedrock hosts many and none is named; no model version appears; and no commitment obliges the vendor to notify customers when the model or its configuration changes, which matters because the service makes substitution easy. The published security and AI overview documents were read only in extract on 31 Aug 2026 and are the rebuttal route for a named model.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
A page titled Transparent Pricing that contains no price, and the gap between the two is the finding. What the pricing page does publish is the shape of the deal: pricing is described as tailored across an extensible platform and specialised government products, priced to the applications and use cases actually taken, with the explicit statement that a customer does not pay for a product it does not use. The purchasable units are named across the site as Casepoint eDiscovery, Legal Hold, FOIA, Filestore, Casepoint AI, Investigator, the MCP Server and Data Connectors, alongside five separately named government products, so the modular structure is visible. The agreement adds real billing mechanics a buyer can read in advance: usage-based fees calculated on the greater of maximum actual usage or the agreed cap, with the units named as data storage, processing and user counts; net-thirty payment; interest at 1.5 per cent per month; one-year initial terms with automatic annual renewal and sixty days' notice to prevent it; and suspension rights at forty-five days past due. What is nowhere published is a number. No rate, no per-gigabyte or per-user figure, no band and no starting point, and the single call to action on the pricing page is a demo request. Checked the pricing page, the platform page and the full terms on 31 Aug 2026.
The shape is published completely and the number is nowhere. Three plans are named with per-tier feature splits: Essential for smaller-scale review, production and deposition practice; Advanced adding discovery analytics, per-document auto-redactions, custom and standard production templates, advanced permissions and activity reporting; and Apex as a customised enterprise plan that may include near-duplicate scoring, search hit reporting, universal auto-redactions, global account search and migration services. The unit of charge is stated plainly as a flat monthly rate per user, and what is never charged is itemised: data storage, processing, hosting, OCR, deduplication, productions, exports and sharing, against an industry norm of per-gigabyte fees that the page sets out in a comparison table. Discounts for upfront annual payment and volume pricing for larger firms are acknowledged. No figure appears at any tier, and every plan's call to action is to talk to an expert. One discrepancy belongs in the record: the marketing describes unlimited data throughout, while the terms of use state that the service is offered under user-based or plan types and that each tier determines the data hosting and processing limits, as detailed in a master services agreement that is not published. A buyer reading only the pricing page would not know that data limits exist.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segments and use cases are documented in unusual detail and the boundary is left open. Coverage is published along two axes. By market: federal civilian, federal defence, state, local and education, Canada, and corporate and enterprise. By team: corporate legal, government legal, FOIA and public records, government audit and investigations, and information technology and information security. A law firm solution page sits alongside them, so all three buyer types are addressed rather than assumed. The use cases are enumerated rather than gestured at: legal hold, investigations, litigation, eDiscovery, data subject access requests, third-party subpoena responses, FOIA and public records requests, and congressional inquiries. Depth claims are quantified, with more than 600 file types processed and named collection sources. What is missing is any statement of where the platform stops. No practice area is excluded, no data source is identified as unsupported, no matter size or volume threshold is named, and the Canada offering appears in the navigation without a description of how its coverage differs. Checked the platform page, the pricing page, the security page and the site navigation on 31 Aug 2026; the individual solution pages were not opened.
Coverage is documented along three axes with real substance, and the boundary is left open. By buyer: law firms, corporations, government agencies and education institutions, each with its own page. By specialty: construction litigation, insurance defence, mass tort and intellectual property litigation. By use case: data collection, internal investigations, Freedom of Information Act requests and transcript management. Data coverage is enumerated rather than claimed, naming email formats PST, MSG, EML and MBOX, Office documents, images, audio and video, compressed archives, and specialised formats including source code, CAD files and building information models, with automatic text extraction and OCR applied to images and scanned material. Scale is addressed directly, with the platform stated to handle millions of documents and multi-party MDL matters, and the mass tort page describing reuse of processed data across hundreds of related cases. What is absent is any statement of where the product stops: no practice area is excluded, no matter size floor or ceiling is given, no jurisdiction is named as unsupported, and the only limiting language located is that specialised formats may require more specific processing workflows. Checked the eDiscovery platform page, the pricing page and the navigation on 31 Aug 2026.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The agreement sets the default to no training and reserves an approval route. Its AI clause states that Casepoint will use AI Inputs and Outputs solely to provide, secure and support the services, and will not use them for product improvement, analytics unrelated to service delivery, or AI training without Customer approval. AI Inputs are defined broadly to include prompts, instructions, queries, Customer Data and metadata submitted to AI features. Recorded as opt-in because approval is the mechanism the contract creates. Two things a buyer should read alongside it. The vendor's AI strategy page states flatly that customer data is never used to train models, which is stronger than what the agreement says, so the marketing and the contract do not match and the contract is the more permissive of the two. And a separate clause grants Casepoint a transferable licence over Customer Data and usage data to improve its products and services, from which the AI clause carves out AI Inputs and Outputs specifically rather than the whole collected corpus.
A categorical no, published in plain language and not in the agreement. The trust and security page asks directly whether the AI uses case data to train its models and answers that it does not: features run entirely inside the vendor's secure Amazon environment and are never used to train or improve any AI model, with inputs and outputs never shared with or retained by any outside model provider. The same page contrasts this with general-purpose consumer tools that may use inputs to improve their models depending on the plan. Recorded as policy-never rather than contractual-never for one reason: the terms of use, updated June 2026 and read in full, contain no artificial intelligence clause of any kind, so the commitment lives in a website FAQ that the vendor reserves the right to change. The terms do support it indirectly, granting the vendor no licence to improve its products or services and limiting its use of user content to what is necessary to provide the service.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Retention is addressed by classification rather than by a clock. The agreement makes AI Inputs and Outputs Customer Data and Confidential Information, which places prompts and generated results inside the customer's own data estate, owned by the customer and governed by the same rights as everything else it uploads. End-of-life is specified: on termination Casepoint provides an export of all Customer Data in a common format, and after delivery or seven days from notice may delete its copies, with an explicit acknowledgement that copies may persist on backup media under standard procedures. What is not stated anywhere located on 31 Aug 2026 is any retention period during the term, any separate lifecycle for prompts and outputs as distinct from collected documents, and any customer-configurable or zero-retention setting for AI interactions.
Retention is answered for the model provider and left open for the vendor. The trust page commits that inputs and outputs are never shared with or retained by any outside model provider, which closes the question that worries most buyers about generative features. What it does not do is state how long Nextpoint itself keeps a prompt or a generated summary. Nothing published gives a retention period, a configurable setting or a zero-retention option for AI interactions. The surrounding data lifecycle is customer-controlled in a way that partly answers it: customers export and download without limit at any time, and deletion follows a Data Archive Form that archives, permanently deletes or exports the database. Against that, document activity logs are stated to be retained permanently unless the database is archived or deleted. Checked the trust and security page, the terms of use and the pricing page on 31 Aug 2026; the privacy policy was not opened.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The strongest segregation commitment located in this pull, and it is contractual rather than marketing. The agreement states that AI features will enforce the customer's access controls and matter and workspace permissions, prevent cross-tenant and cross-matter retrieval, and log administrative access to AI Inputs and Outputs. Because Casepoint is itself the system of record holding the collected documents, the AI inherits the platform's own permission model rather than operating beside it, which is what a firm running two teams on opposite sides of a matter needs. Support access is walled to the same standard: no standing or default remote access, enablement only by the customer's own administrators, access limited to the identified tenant, workspace or matter relevant to the issue, named individual personnel under multi-factor authentication, and audit logs made available to the customer. Not located: any description of how the boundary is enforced technically, and any statement about separation between the base commercial environment and the separately certified government environments.
A documented permission model that operates at matter level, with the AI's relationship to it unstated. The trust page describes six permission levels running from view-only to dashboard administrator, giving granular control at case, folder and document level for both internal teams and outside parties, which is the structure a firm needs to keep two teams apart on the same platform. It is reinforced by mandatory multi-factor authentication on every user and device, single sign-on through Okta or Azure Active Directory, and employee-side controls limiting application access to a subset of staff under a documented request and approval trail with prompt revocation. Every document's view, edit and markup history is logged with timestamps in tamper-resistant records. The gap is specific and worth a buyer's attention: nothing published states that the AI features respect those permissions, so whether a transcript summary or a search ranking could reach across a wall the platform otherwise enforces is not addressed.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
A notice commitment with an affirmative duty to resist attached, which is the strongest form of this value located in the pull. The confidentiality clause permits disclosure as required by law, regulation, court order, subpoena or other compulsory process only on three conditions: that the receiving party immediately notifies the other and provides relevant documentation on request; that it actively resists, restricts and limits disclosure, expressly including by making lawful objections, obtaining confidentiality agreements and protective orders, and using redactions and confidentiality markings; and that it fully cooperates with the disclosing party's lawful efforts to protect the information. Immediate notice plus a duty to object goes beyond the reasonable-efforts formulations seen elsewhere. A reciprocal provision requires a government customer subject to FOIA or another open records law to give Casepoint notice and an opportunity to object before releasing its confidential information. No transparency report or disclosure statistics were located on 31 Aug 2026, which is what holds this short of the top value.
Nothing located addresses third-party demands for customer data. Searched the terms of use, updated June 2026 and read in full, together with the trust and security page, the eDiscovery platform page and the pricing page on 31 Aug 2026. No clause or statement covers subpoenas, court orders, warrants or government requests: nothing commits to notifying the customer, nothing addresses seeking a protective order or narrowing a demand, nothing describes what the vendor would do if notice were legally prohibited, and no transparency report or disclosure statistics exist. The adjacent commitment the vendor does make runs the other way and is recorded because it shows the question was thought about in a different context: on a security breach, the customer holds the sole right to decide whether notice is given to individuals, regulators or law enforcement and what it says. The privacy policy was not opened and is the rebuttal route.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
This question does not arise for this product and the reason is structural rather than an omission. Casepoint operates on documents the customer collects and uploads from its own systems, so there is no vendor-assembled corpus of primary law, no third-party content licence and no upstream data supplier to identify. The agreement confirms the direction of ownership, stating that the customer owns all Customer Data and retains all rights and title to it, with Casepoint holding only a limited licence to provide and support the services. What the vendor does describe is the collection surface rather than a corpus: named sources including Microsoft 365, Teams, Slack and Google Vault, and processing of more than 600 file types. Recorded as not addressed because that is the honest value, with the reason stated so it does not read as a gap. Searched the platform page, the AI strategy page, the security page and the full terms on 31 Aug 2026.
The question does not arise for this product. Nextpoint operates on evidence its customers collect and upload from their own systems and matters, so there is no vendor-assembled corpus of primary law, no third-party content licence and no upstream data supplier to identify. The terms of use confirm the direction of ownership, stating that the customer, or the party that entrusted the data to them, owns all user content, with the vendor's access limited to what is necessary to provide the service. Recorded as not addressed because that is the honest value, with the reason stated so it does not read as an omission. Nothing published describes any training corpus for the models either, which would be the adjacent question if the vendor trained its own; it states instead that generative features run on Amazon's managed foundation-model service. Searched the platform, pricing, trust and terms surfaces on 31 Aug 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Not applicable to this product class, and neither credited nor penalised. Casepoint searches and analyses the customer's own collected documents rather than retrieving primary law, so there is no authority whose continued validity would need checking and no citator is claimed anywhere. Searched the platform page, the AI strategy page, the pricing page, the security page and the full terms on 31 Aug 2026 and located no citator, treatment signal or currency check. The adjacent accuracy question that does bite on this product is validation of technology-assisted review, and it is recorded on the Citation Accuracy axis rather than here, because no recall, precision or elusion statistic was located.
Not applicable to this product class, and neither credited nor penalised. The platform searches, reviews and summarises a customer's own collected documents and deposition transcripts; it does not retrieve primary law or assert propositions whose continued validity would need checking, and no citator or treatment signal is claimed anywhere. Searched the eDiscovery platform page, the pricing page, the trust and security page and the terms of use on 31 Aug 2026. The accuracy question that does apply to this product is whether a generated transcript summary faithfully represents the transcript, and it is recorded on the Citation Accuracy axis, where no measurement of any kind was located.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
Nothing published describes what the generative features do when the data does not support an answer. Searched the AI strategy page, the platform page, the security page and the full terms on 31 Aug 2026. There is no abstention path, no confidence or grounding indicator described as surfaced to the user, and no statement of behaviour where a chat query returns nothing from the collected corpus. The agreement approaches the subject from the opposite direction, telling the customer that outputs have limitations and should not be relied on alone, which allocates the risk rather than describing a system behaviour. One adjacent mechanism exists and is not the same thing: CaseAssist active learning ranks documents by predicted relevance, so a reviewer sees an ordering rather than a binary answer, but the vendor describes this as prioritisation and publishes nothing about how uncertainty in that ranking is exposed.
The vendor tells the user to check the output and never says what the system does when it is unsure. The published position is that AI features are validated through extensive testing before release but that generated summaries and results are meant as starting points, with customers encouraged to trust but verify. That is an honest framing and it is a caution rather than a described behaviour. Searched the trust and security page, the eDiscovery platform page, the pricing page and the terms of use on 31 Aug 2026 and located no abstention path, no statement of what happens when a transcript does not support the summary requested, no confidence or grounding indicator surfaced to the reader, and no threshold at which a feature declines to produce output. Recorded as not addressed on that basis, with the trust-but-verify posture noted because it is the vendor's substitute for one.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of 31 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks decisions worldwide where a court addressed hallucinated AI content and records the tool implicated where known and which stood at roughly 1,994 decisions when checked, together with several independent 2026 sanctions trackers and trade coverage, searched on the product and company name. This is a statement about the public record on the date shown rather than a clearance. The exposure is also structurally different from a research tool: Casepoint's generative features answer questions about documents the customer has already collected rather than citing legal authority, so a fabricated citation reaching a filing would originate elsewhere, while a mischaracterised document would be a different failure this signal does not capture.
No court order, opinion or disciplinary record naming this product has been located as of 31 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks decisions worldwide where a court addressed hallucinated AI content and records the tool implicated where known, alongside several independent 2026 sanctions trackers and trade coverage, searched on the company and product name. This is a statement about the public record on the date shown rather than a clearance. The exposure also sits at an angle to what this signal tracks: the platform's generative output is a summary of a deposition transcript the customer already holds rather than a citation to legal authority, so a fabricated citation reaching a filing would originate elsewhere, while a summary that misrepresented testimony would be a different failure this signal does not capture.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Defensibility is the platform's most repeated claim and no authority is named behind it. The word runs through the marketing, in defensible results, defensible processes, a defensible chain of custody and one defensible system of record from preservation through production, and the agreement supports it with real audit logging and access provisions. But searched across the platform page, the AI strategy page, the pricing page, the security page and the full terms on 31 Aug 2026, no rule, standard or opinion is cited that the platform is defensible against. Nothing names the Federal Rules of Civil Procedure, Rule 502(d), Sedona Conference commentary, ABA Formal Opinion 512 or any state bar guidance, and nothing maps a platform feature to a professional obligation a reviewer or supervising lawyer is under. For a product sold on withstanding scrutiny in court, the absence of a named standard is the finding.
One ethics assertion is published and no authority is named behind it. The pricing page states that passing software costs through to clients in the manner its invoice generator supports is fully compliant with ethical guidelines and standards, and points to a Billing for eDiscovery eGuide. That is closer to this signal than anything else in the pull, and as published it cites no rule, opinion or bar authority, so a firm cannot check the claim against a source. Searched the eDiscovery platform page, the pricing page, the trust and security page and the terms of use on 31 Aug 2026 and located nothing naming ABA Formal Opinion 512, any state bar guidance, the Federal Rules of Civil Procedure or Sedona Conference commentary, and nothing mapping a platform feature to a professional obligation. The eGuide itself is published as an ungated PDF and was not opened; it is the rebuttal route and may cite the fee and expense authorities the pricing page relies on.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Cost claims are everywhere and the client's side of the bill is not addressed. Published figures include a 57 per cent reduction in discovery-related costs, identification of relevant data up to 95 per cent faster, a reduction in time to insight of up to 83 per cent, FOIA processing up to 75 per cent faster, and a stated aim of reducing outside counsel spend. Searched the pricing page, the platform page, the AI strategy page and the full terms on 31 Aug 2026 and located no per matter record of AI-assisted work intended for fee purposes and no guidance on billing, fee or client disclosure treatment where AI-assisted review informs what a client is charged. One customer quote gestures at the question without the vendor answering it, a named law firm saying it looked forward to guidance on billing and cost recapture for technology support, which is a customer expectation rather than published vendor guidance.
The vendor publishes real tooling for the cost question and none of it reaches the AI question. What exists: a custom invoice generator that lets a firm classify and allocate software costs to its clients, calculates how much should reasonably be invoiced for a project in a given month and produces a customisable client-facing invoice; an assertion that passing software costs through in this manner is fully compliant with ethical guidelines and standards; and a Billing for eDiscovery eGuide published as an ungated PDF. No other vendor in this pull publishes anything comparable, and the ethics assertion names no rule, opinion or bar authority a firm could check it against. None of it addresses what this signal asks. The question is what happens to the bill when work that took six hours takes one, and allocating a subscription cost across matters is a different question from recording and disclosing AI-assisted work. Searched the pricing page, the eDiscovery platform page, the trust and security page and the complete terms of use on 31 Aug 2026 and located no per matter record of AI-assisted work for fee purposes and no guidance on fee or client disclosure treatment where a generative summary informs the work.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
The artifacts exist and are contractually promised to customers rather than published to the world. The agreement commits Casepoint to make available, on request, copies of third-party audits and its Standardized Information Gathering questionnaire, and to maintain a list of material third-party components and subprocessors; it also points to a data processing agreement hosted alongside the security page and gives customers above a stated annual spend a yearly audit right. What a firm can take to a client without any of that is still substantial: fourteen named certifications and authorisations on the public security page, with the FedRAMP and Department of Defense authorisations independently verifiable through the authorising bodies rather than through Casepoint. Recorded at the request tier because the two things a client's AI clause usually asks for by name are not published: no subprocessor list was located despite the contractual commitment to maintain one, and no model provider is identified anywhere. Checked 31 Aug 2026.
A published pack exists, is downloadable without a form, and its contents are now partly verified rather than assumed. The trust and security page offers a document titled Security, Compliance, Privacy and AI at Nextpoint as a direct download, and a companion security overview published at the vendor's own resource domain was read in extract on 31 Aug 2026. Between them they cover the ground a client's AI clause asks about: role-based access control with six named permission levels from View Only through Dashboard Administrator, a pointer to the full privacy policy, and a compliance section. That section includes a disclosure most vendors would omit, stating that the vendor complies with the California Consumer Privacy Act for California residents and that GDPR compliance is not currently in place, which is a plainly stated limitation rather than a silence. Around the pack, the public pages independently answer the three questions most AI clauses put: case data is never used to train or improve any model, processing happens inside the vendor's own Amazon environment, and inputs and outputs are never shared with or retained by any outside model provider. Two limits: neither document was read in full, and no maintained subprocessor list exists beyond Amazon as the named infrastructure and model-service provider.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
More of the record exists than almost anywhere else in this pull, and the piece identifying the system is missing. On the record side: the vendor states that transparency logs document every AI decision and that generative output carries full source citations back into the customer's own data, the agreement requires logging of administrative access to AI Inputs and Outputs, remote support access is logged with who accessed what, when and what was performed, and those logs are made available to the customer under the standard audit logging framework. Chain of custody from preservation through production is the platform's central design claim. What cannot be established from anything located on 31 Aug 2026: no model is named or versioned, so a filing could not state which system produced a given output; nothing describes whether the transparency log is exportable in a form suitable for a standing order or a certification; and no template or guidance exists for disclosing AI use to a court or an opponent.
A strong activity record exists and nothing connects it to the AI. The platform logs every document's view, edit and markup history with timestamps, states that those logs are tamper-resistant, and retains them permanently unless the database is archived or deleted, which the vendor frames explicitly as giving a defensible record of activity in the case. That is more durable than most audit trails in this pull and would support a challenge to how a document was handled. What it does not do is answer the question this signal asks about AI. No model is named or versioned, since generative features run on an unnamed model within Amazon's managed foundation-model service, so a filing could not state which system produced a summary. Nothing states whether the activity log captures the invocation of an AI feature at all, nothing records who verified generated output, and no export, template or guidance exists for disclosing AI use to a court or an opponent. Checked the trust and security page, the platform page and the terms of use on 31 Aug 2026.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.
- Primary Law Corpus Provenance
- Good Law Verification
- Refusal and Uncertainty Behaviour
- Bar Guidance Alignment
Which one fits
Choose Casepoint if
- Your matters reach into government. Casepoint publishes FedRAMP High and Moderate, Department of Defense Impact Levels 4, 5 and 6 with authorities to operate from the Defense Information Systems Agency, GovRAMP, SOC 1, 2 and 3, ISO 27001:2022 and ISO 9001:2015, and the government authorisations are independently assessed and listed by the authorising bodies, so a buyer can confirm the status without a sales conversation.
- You want the AI governed by the contract rather than a page. Casepoint's agreement classifies AI inputs and outputs as both customer data and confidential information, limits their use to providing, securing and supporting the service, commits that AI features enforce the customer's own matter and workspace permissions and prevent cross tenant and cross matter retrieval, restricts personnel review to customer requested support or a security incident under least privilege time bounded access, and enumerates five named limitations of the AI itself.
- Collection is where chains of custody break. Casepoint collects in place directly from Microsoft 365, Teams, Slack and Google Vault without manual export, processes more than 600 file types, and runs hold, collection, review, production and FOIA workflows on one system of record, with Lewis Roca named alongside a stated reduction of more than 90 per cent in document review time.
Choose Nextpoint if
- The bill should not scale with the data. Nextpoint charges a flat monthly rate per user and itemises what is never charged: data storage, processing, hosting, OCR, deduplication, productions, exports and sharing, set against the per gigabyte hosting norm, across three named plans whose feature splits are published even though no figure is.
- You want to know which service the generative feature runs on. Nextpoint states that search and ranking run on models it hosts in its own private cloud and that AI transcript summaries run on Amazon Bedrock inside the same environment, with three specific protections published against it: no training on customer data, no storage or logging of prompts and completions, and no sharing of inputs or outputs with model providers.
- The matter should not change systems at trial. Nextpoint carries the same evidence from processing and review into deposition transcript and video review, designations, chronologies, visual timelines and a presentation mode, with six permission levels reaching individual documents, multi factor authentication mandatory on every user and device, and single sign on through Okta or Azure Active Directory.
In summary
Casepoint
Casepoint is a unified data discovery platform covering legal hold, in place collection from cloud sources, processing, AI assisted analysis, review, production, investigations and public records response on a single system of record, with CaseAssist included rather than sold as an add on. The AI Legal Index grades it in the top two bands on fourteen of fifteen capability axes, with A grades on customer evidence, privilege posture and security certifications: it publishes FedRAMP High, Department of Defense Impact Levels 4, 5 and 6 and a customer agreement whose AI clause prevents cross matter retrieval and restricts personnel review. As of 31 August 2026 the index located no accuracy statistic, no named model provider and no published price.
Nextpoint
Nextpoint is a cloud native litigation platform covering discovery through trial, sold on a flat per user subscription with nothing charged for storage, processing, OCR, deduplication, productions or sharing, carrying the same evidence from processing and review into deposition designations, chronologies, timelines and courtroom presentation. The AI Legal Index grades it in the top two bands on eight of fifteen capability axes. Machine learning is a narrow layer rather than the pitch, with search and ranking on models it hosts itself and generative transcript summaries on Amazon Bedrock inside the same environment, and three published protections about what that service may do. As of 31 August 2026 the index located no accuracy figure, no residency statement and no published price.
Questions buyers ask
Casepoint vs Nextpoint: which is better for ediscovery?
The AI Legal Index places Casepoint in the top two bands on fourteen of fifteen capability axes and Nextpoint on eight. Casepoint publishes government grade authorisations that can be verified independently and an AI clause inside its customer agreement. Nextpoint publishes a commercial model instead, charging a flat rate per user with nothing charged for data, and is unusually frank that generated output is a starting point to be verified.
What does each cost?
Neither publishes a figure. Nextpoint publishes the whole shape, naming three plans, stating the unit as a flat monthly rate per user, and itemising the eight things it never charges for against the per gigabyte industry norm. Casepoint publishes a page titled transparent pricing that carries no price, describing tailored pricing across named modules, with the billing mechanics set out in its agreement including usage based fees calculated on storage, processing and user counts. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
Who runs the AI?
Nextpoint names the service: search and ranking on models it hosts itself, and generative transcript summaries on Amazon Bedrock within the same environment, though which foundation model inside that service produces a summary is not stated. Casepoint names the architecture but not the provider, describing retrieval augmented generation over the customer's own data with source citations and transparency logs recording each AI decision, with no model, provider or version identified. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
What happens to privileged material?
Casepoint addresses it expressly, defining confidential information to include attorney work product and attorney client privileged material, and committing in the same agreement that AI features enforce matter and workspace permissions and prevent cross matter retrieval. Nextpoint describes its platform as holding privileged data and work product, confirms the customer owns it, limits its own use to providing the service, and offers six permission levels down to the document, without naming privilege in a contractual commitment. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
What do Casepoint and Nextpoint both leave unpublished?
Neither publishes an accuracy or validation statistic for its AI, which in this category means neither publishes the recall and precision figures a court would ask about. Neither names the auditor or the report date behind its attestations. Neither names an integration with a document management system such as iManage or NetDocuments. And neither publishes anything on uneven output across custodians, document types or languages, which is the live question for a system that decides what a human reviews first. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.
One clause in Casepoint's terms bears directly on what a buyer can learn: it forbids the customer from disclosing software performance benchmark results to any third party without written consent, which forecloses the independent testing this index looks for, and no accuracy, recall or validation statistic is published anywhere, which is a conspicuous gap in ediscovery specifically, where technology assisted review validation figures are what courts examine. On Nextpoint, the marketing describes unlimited data throughout while the terms of use state that the service is offered under user based or data based plan types and that each tier determines the data hosting and processing limits, as detailed in a master services agreement that is not published, so a buyer reading only the pricing page would not know that data limits exist. Both records were verified on 31 August 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.