I
iCONECT
iCONECT is a document review and data analysis platform from iCONECT Development, LLC, founded in 1999. It is sold for eDiscovery, cyber breach response and data governance to law firms, corporations, public sector organizations and the legal service providers that host it. The eDiscovery product covers processing, search, deduplication, email threading, automated redaction and production. Its machine learning includes continuous active learning and Oversight, a quality control tool in standard licensing that looks for tagging errors after a reviewer seeds a model.
Generative AI features include document summaries, document and image classification, entity redaction, image description, audio transcription and translation. The cyber data mining product finds and extracts personal information for breach notification and lets users send documents to a model of their choice, including models from OpenAI, Microsoft and Google. iCONECT can run on premises, in the cloud on Azure, Google Cloud or AWS, in a hybrid setup, through hosting partners or as its own SaaS on Microsoft Azure. Its SaaS platform holds a SOC 2 Type 2 report from A-LIGN. No customer agreement and no pricing figures are published.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
Machine learning runs core review and breach response work on a document review platform that would still function without it. iCONECT's eDiscovery product is built around processing, Elasticsearch search, deduplication, redaction and production. The models sit in several core capabilities: continuous active learning through Sentio technology; Oversight, which the vendor says is included in standard eDiscovery licensing and finds false negatives and false positives in reviewer tagging; AI email threading; and AI assisted identification and extraction of personal information in the cyber data mining product, where users can send documents to a model of their choice.
Generative AI features listed on the eDiscovery and law firm pages add document summaries, classification by content or legal relevance, entity redaction, image description, transcription and translation. The vendor describes itself as a data intelligence AI platform, and in August 2026 announced an integration with eDiscovery AI that is still under development. Take the models away and a full review and production system remains, which places the AI at the engine of core capabilities rather than at the whole of the product.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted without measurement, and grounding is described only for extracted personal data. The Oversight post of 17 May 2024 says the tool reaches a level of precision once thought unattainable and helps teams rectify discrepancies, with no recall, precision, elusion or validation figures and no test set. The cyber data mining page says each extracted data element is linked through audit trails to its original source file, creating a defensible chain of custody, which lets a reviewer trace a notification entry back to the document.
Nothing published describes how the generative features are grounded: whether a document summary cites passages, how classification by legal relevance is checked, or how automatic privilege redaction is validated. No statement on error rates or invented content is published on the eDiscovery, law firm, platform or cyber data mining pages, or in the posts on AI trends and on searching with AI, all read. A reviewer can trace extracted personal data, and cannot test the precision claim or check a summary against its source.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Human review is described for one machine learning tool, and verification is optional for the rest. The Oversight post of 17 May 2024 says a subject matter expert, attorney or experienced reviewer seeds a model with as few as fifty documents, and that Oversight reports tagging errors for the team to correct. The cyber data mining page lets a team define its criteria so that verification, whether manual or automatic, fits its needs, and says GenAI reviews are used where appropriate.
The eDiscovery page says redaction, including of an entire document because of privilege, can happen automatically, and that document classification sorts documents by legal relevance automatically, with no review step described for either. Nothing states what the generative features may not be used for, when a person must check their output, or what happens when a classification or redaction is wrong. Oversight is a real check on human review; for the generative features, oversight is a setting the customer chooses rather than a published control.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Named service providers are published as customers, with dates and without figures. Releases on iCONECT's site record that ProFile Discovery selected the platform for its law firm and corporate legal department environments (26 January 2021) and that Everest Discovery launched a cyber breach response service built on it (27 January 2025), with a quote from Everest's owner and president; other releases name Pictera Solutions, Right Discovery and Iota Analytics as customers.
The Why iCONECT page names NASA and the FDIC among users. The law firm page presents seven large matters, among them the Vioxx, Yasmin and Pradaxa litigation, Oracle v. SAP and the Columbia investigation, without naming the firm, iCONECT's role or a result. No case study with a measured result is published on the site. A buyer can call named providers that run iCONECT for law firms and corporate legal departments, and cannot read what the platform or its AI changed in any review.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Confidentiality is asserted in general terms, and no agreement a buyer can read before signing is published. The only legal documents on the site are a terms of use (31 July 2024) and a privacy policy (June 2024), both written for the website. No customer agreement, data processing addendum or statement on training with customer documents is published. The eDiscovery and law firm pages cite SOC 2 certification, rigorous data protection and handling protocols and controlled access, and the SOC 2 Type 2 report on the SaaS platform covers the confidentiality criterion.
The cyber data mining page lets users send documents to a model of their choice, including models from OpenAI, Microsoft and Google, and nothing published states what those providers may keep or use. The platform can be deployed on premises, which keeps documents in a firm's own environment, but nothing addresses privilege handling, segregation between matters, or what happens to documents sent to a model.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
A boilerplate disclaimer covers the website, and nothing addresses the advice line for the product. The terms of use say information on iCONECT's pages is distributed on the understanding that the authors are not rendering legal, accounting or other professional advice. That sentence governs website content, not the review platform. The product classifies documents by legal relevance, redacts for privilege and summarizes documents for law firms, corporations, public sector organizations and service providers, and nothing published states that its output is not legal judgment, that a supervising lawyer must review it, or how it fits a lawyer's competence and supervision duties.
No ethics opinion or court decision on technology assisted review is named on any page or post read, including the posts on AI trends and AI search. The one published position is the website disclaimer.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
No governance position on the AI is published beyond a sentence about responsible adoption. The platform page and the post of 10 May 2024 on AI search describe iCONECT's path as a responsible adoption of generative AI that enhances the platform without compromising data integrity or security. Checked the platform, eDiscovery, law firm, cyber data mining and Why iCONECT pages and the posts on AI trends and AI search: none names a person accountable for model behavior, describes testing before a release, publishes evaluation results, or sets out principles.
The SOC 2 Type 2 report covers information security controls and not the conduct of the models. Uneven output is a live question for a product that classifies documents by legal relevance and identifies personal information across languages and document types, and nothing published addresses it. Users choosing between models from OpenAI, Microsoft and Google for personal information identification are not told how iCONECT evaluated them.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Security practices are described in general terms, and nothing is published on retention, deletion or subprocessors. The eDiscovery and law firm pages cite SOC 2 certification, regular security training and penetration testing, workstation and server security, data protection and handling protocols and controlled access, and the platform page cites encryption, access controls, regular security audits and adherence to GDPR and HIPAA standards.
The SOC 2 Type 2 audit of the SaaS platform, completed on 22 September 2025 by A-LIGN, covers security, availability, processing integrity, confidentiality and privacy. The cyber data mining page says ingestion, extraction, review and modification actions are logged with audit trails. The privacy policy (June 2024) covers the website and not data processed in the platform. No retention period, deletion commitment, breach notice timing, subprocessor list or statement on what model providers keep when documents are sent to them is published.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Nothing published addresses who bears the loss when the platform's output is wrong. No customer agreement, license terms or SaaS terms are published. The terms of use (31 July 2024, California law) disclaim liability for direct, indirect, special, incidental or consequential damages arising from the website and its content; they do not govern the software. Checked the home, platform, eDiscovery, law firm, cyber data mining, Why iCONECT and support pages, the terms of use and the privacy policy: no indemnity, warranty, cap or allocation of risk for missed documents, wrong classifications, failed redactions or errors in personal data extraction is published.
For a product used to decide what is produced to an opposing party and who is notified after a breach, a buyer has no published term to hold the vendor to.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Integrations are named, and one is described by what it moves. iCONECT's release of 10 June 2021 says its Ligl integration, available then, lets organizations identify, hold, preserve and collect enterprise documents in Ligl, process and cull them, and push relevant documents to iCONECT for review. The cyber data mining page lets users send selected documents to a model of their choice, including models from OpenAI, Microsoft and Google.
The partners page shows Microsoft, Nuix, LexisNexis, Sentio, Opus 2 and Heureka Software as technology partners, as logos without descriptions, alongside more than 25 hosting partners. An integration with eDiscovery AI was announced on 24 August 2026 as under development, with availability to follow. The platform page says iCONECT integrates with the most common applications in its three markets, without naming them.
Nothing describes connections to a firm's document management, matter management or litigation support systems, and no integration documentation is public.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Deployment options are stated clearly, and region and residency are not. The eDiscovery page offers on premises, hybrid, cloud and SaaS deployment. The post of 19 July 2024 on system architecture describes in house deployment, cloud deployment on Microsoft Azure, Google Cloud, AWS or other providers, and hosting through iCONECT's network of legal service providers. The release of 23 August 2023 launching iCONECT SaaS says it runs on Microsoft Azure.
A firm can therefore keep the platform and its documents on its own infrastructure. Not stated are where iCONECT's SaaS stores or processes data, which regions are available, and whether SaaS customers are separated at the tenant level. Nor is it stated where documents go when they are sent to a model from OpenAI, Microsoft or Google for personal information identification, or whether the generative features work in an on premises deployment.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
A current attestation is stated with auditor, scope and date, and the report is not reachable. iCONECT's release of 29 September 2025 says A-LIGN completed a SOC 2 Type 2 audit of its SaaS platform on 22 September 2025 covering security, availability, processing integrity, confidentiality and privacy, and the home page carries an A-LIGN badge. No audit period is stated, no trust center is published, and no page read offers the report for download or on request.
The eDiscovery and law firm pages add regular penetration testing and security training, and the platform page claims adherence to GDPR and HIPAA standards without any certification behind them. A buyer knows the standard, the auditor, the product covered and the date, and must ask for the report.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Model providers are named as options for one feature, and nothing is committed about them. The cyber data mining page lets users send selected documents for personal information identification to a model of their choice, including models from OpenAI, Microsoft and Google. The platform page says iCONECT integrated Sentio technology, which carries its continuous active learning, and acquired AI source code from Ayfie in 2021.
Nothing published names the model behind document summaries, classification, image description, transcription or translation, states whether iCONECT or the customer holds the model provider relationship, says where those models run, or commits to notice when a model changes. A buyer can see which providers are offered for one feature, and not what sits under the rest.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The shape of pricing is published and no figure is. The law firm page offers flexible pricing with monthly or annual terms, the Why iCONECT page describes predictable pricing through monthly and yearly plans, and the release of 23 August 2023 launching iCONECT SaaS describes Price Protect, which applies discounts automatically as data volume grows without renegotiating the contract. That points to data volume as a driver and term length as a choice, without stating the unit, the rate or what the generative features add.
No price, rate per gigabyte, user fee or tier is published on any page read, and every route to a number runs through a demo request.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Who iCONECT serves is described with substance, and the limits are not. The site addresses law firms, corporations, public sector organizations and service providers, each with its own page, across three products: eDiscovery, cyber data mining for breach response, and data governance. The law firm page covers litigation, investigations and responsive actions, the cyber data mining page covers breach notification work for incident response professionals, and the release of 24 August 2026 names law firms, corporations, legal service providers and public sector organizations as customers.
Named users include NASA and the FDIC. What is not stated is which languages the generative features and personal information identification support, which privacy regimes the breach tools are built around beyond references to GDPR and HIPAA, and which deployment options carry the generative features. A buyer can see that its segment is served and cannot see where the product stops.
5 public documents
The public pages on file for iCONECT, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.
-
iconect.com/ediscovery5 signals
Ethical Walls and Matter Segregation, Primary Law Corpus Provenance, Good Law Verification and 2 more
Read Oct 2, 2026
-
iconect.com/cyber-data-mining2 signals
Outside Counsel Guideline Readiness, Court Disclosure Support
Read Oct 2, 2026
-
iconect.com/privacy-policy2 signals
Prompt and Output Retention, Third Party Request and Subpoena Notice
Read Oct 2, 2026
-
iconect.com/terms-of-use2 signals
Client Data in Training, Bar Guidance Alignment
Read Oct 2, 2026
-
Fabricated Citation Record
Read Oct 2, 2026
No published figureUSD, as published, never converted
- iCONECT does not show its prices; you ask for a quote.
- You can pay month to month or sign up for a year.
- You can run it yourself or use iCONECT's cloud service.
- Discounts apply automatically as your data grows.
- What the AI features cost is not stated.
Quote on request. Monthly or annual terms, with SaaS or on premises deployment. Price Protect, described at the SaaS launch on 23 August 2023, applies discounts automatically as data volume grows without renegotiating the contract. The unit of charge is not stated.
Implementation: Not stated.
Confidentiality and data terms: Not stated. The platform page claims adherence to HIPAA standards; no business associate agreement is published.
Note: No figure is published for any plan, data volume, user or deployment, or for the generative AI features. The structure comes from the law firm page, the Why iCONECT page and the SaaS launch release.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No customer agreement, terms of service or equivalent contract is published on any surface located, and no policy page states a position on training. Nothing is granted and nothing is withheld, so a client has no term to hold the firm to. Where a policy page does state a position, the row takes the matching policy value instead and the summary records that no agreement exists.
No customer agreement, license terms or data processing addendum is published, and no page states a position on training with customer documents. The terms of use (31 July 2024) and the privacy policy (June 2024) cover the website only. Oversight's matter model is seeded by the customer's own reviewers with its own documents, which is not vendor training, and the cyber data mining page lets users send documents to models from OpenAI, Microsoft or Google with nothing published on whether those providers may train on them. Checked the home, platform, eDiscovery, law firm, cyber data mining, Why iCONECT and support pages on 2 October 2026.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
No located public material states how long prompts and outputs are retained.
No located material states how long documents, extracted data, summaries or other AI outputs are kept, or when they are deleted, in the SaaS platform or by a model provider. The privacy policy covers website data only. Checked the platform, eDiscovery, law firm, cyber data mining and support pages, the terms of use and the privacy policy on 2 October 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
No located public material addresses walls or matter level segregation.
No located material describes walls between matters or teams, or how the generative features and continuous active learning are kept within a matter. The eDiscovery and law firm pages cite controlled access and the SaaS launch release mentions user setup and matter management, without describing how access is segregated. Checked the platform, eDiscovery, law firm and cyber data mining pages and the SaaS launch release on 2 October 2026.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
No located term or policy addresses third party requests for customer data.
No published agreement addresses legal demands for customer data held in the platform. The privacy policy (June 2024), which covers the website, says iCONECT may disclose a website user's name, city, state, telephone number and email address to law enforcement on a verified request without a subpoena; it does not reach documents processed in the platform. Checked the terms of use, the privacy policy and the product pages on 2 October 2026.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies the corpus behind the product’s answers.
iCONECT works on a customer's own documents and data and does not describe retrieval of case law or other legal sources; no outside legal corpus applies. Checked the platform, eDiscovery and law firm pages on 2 October 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
The product does not cite legal authority, so no check of subsequent history applies, and none is described. Checked the platform, eDiscovery and law firm pages on 2 October 2026.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
No located material describes what the summaries, classification or personal information identification do when a document gives them no basis for an answer, or how low confidence is shown. Checked the eDiscovery, law firm and cyber data mining pages and the Oversight post on 2 October 2026.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.
No court order, opinion or disciplinary record naming iCONECT as the source of fabricated authority was located as of 2 October 2026. The AI Hallucination Cases database maintained by Damien Charlotin returned no cases for iCONECT.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Public materials refer to professional responsibility in general terms without naming guidance.
The terms of use (31 July 2024) state that information on iCONECT's pages is distributed on the understanding that the authors are not rendering legal, accounting or other professional advice. The clause governs website content, not the review platform. No ethics opinion, bar guidance or court decision on technology assisted review is named on any product page or post read on 2 October 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure, and the product sits inside a fee relationship between a lawyer and a client where those savings would change the bill.
iCONECT's pages claim savings without addressing billing. The eDiscovery page says AI email threading and deduplication reduce the dataset and that AI automations eliminate repetitive steps, the Why iCONECT page displays a counter for ROI savings delivered, and a customer release quotes Everest Discovery on reducing costs. The platform is sold to law firms and to service providers whose review charges reach clients, and nothing published addresses how AI assisted review is billed or disclosed.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
No located public material supports a client side disclosure obligation.
No subprocessor list or disclosure material for a client's AI terms is published. The cyber data mining page names OpenAI, Microsoft and Google as model choices for one feature, which is not a list of the providers that process customer data, and the SOC 2 report is not offered on any page read. Checked the home, platform, eDiscovery, law firm, cyber data mining and support pages, the terms of use and the privacy policy on 2 October 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
Some elements of a defensibility record are described, short of a record of AI use. The cyber data mining page says ingestion, extraction, review and modification actions are logged with audit trails that link each extracted data element to its source file, creating a defensible chain of custody for regulatory inquiries and legal review. Oversight produces reports of tagging errors, and the law firm page lists reviewer productivity reporting.
Nothing records which model produced a summary or classification, and no export for disclosing AI use or validating continuous active learning to a court is described.