P
PointOne
PointOne is an AI timekeeping and billing platform for law firms and government legal offices. Its Time product captures a lawyer's working day across documents, email, calls and the web and writes the time entries itself, with retroactive capture over any date range and AI-generated narratives for those who prefer timers. Review is a pre-bill workflow in which the AI marks up bills, flags problems and suggests fixes, with configurable routing through reviewers, and Rules turns uploaded outside counsel guidelines into structured billing rules that are enforced against every entry and pre-bill.
Intelligence reports on how time is spent, who is available and what comparable matters cost. PointOne syncs with billing and practice management systems including Aderant, Elite 3E, Clio, Filevine, Actionstep, Surepoint, MyCase, LeanLaw and QuickBooks. PointOne Technologies, Inc. is a venture-backed company based in New York City, and its customers include O'Hagan Meyer, Scarinci Hollenbeck, Bell Nunnally, McCathern, Lydecker and the Minnesota Attorney General's Office, which deployed it across more than 300 timekeepers in April 2026.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
Take the models out and there is no product. PointOne's pitch is that a lawyer stops writing time entries altogether: the software captures the working day across documents, email, calls and the web, works out which matter each task belongs to, and writes the narrative, with retroactive capture over any date range for people who reconstruct at week or month end and generated narratives for those who still prefer timers.
The same models turn uploaded outside counsel guidelines into structured billing rules, check every entry against them, and mark up pre-bills with flagged problems and suggested fixes. What would remain without them is a timer and an export to Aderant or Clio. Verified 20 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is the whole claim and none of it is measured. The product writes billing narratives from captured activity rather than legal assertions, so the question is whether an entry describes what the lawyer actually did and lands on the right matter. Customers say on the homepage that it is accurate, the April 2026 release says the office stress-tested whether PointOne could correctly identify a wide range of billable and non-billable tasks, and the security page promises auditability of AI outputs.
No accuracy rate, sample, benchmark or error rate is published anywhere, and nothing describes what an entry is built from or how a reviewer can tell a mis-attributed entry from a correct one before it reaches a client's bill. Verified 20 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
The system drafts and people approve, and the approval path is published in detail. Time entries are generated automatically, then move through Review, where the AI marks up the pre-bill and a firm sets its own reviewers, routing and permissions: the worked example runs a bill from legal assistant to responsible partner to billing administrator, with comments and tagging to resolve queries. Billing rules drawn from client guidelines are enforced against every entry before it gets that far.
What is not published is any limit the system places on itself: no threshold at which it declines to classify a task, no statement of what an unreviewed entry may not be used for, and nothing on what happens when capture misreads the matter. Verified 20 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
One deployment is named, dated and sized, and no result is measured. PointOne's April 2026 release states that the Minnesota Attorney General's Office rolled the platform out across its entire office of more than 300 timekeepers after a pilot that tested multi-agency billing, dynamic review flows and classification of billable and non-billable tasks, and quotes Assistant Attorney General Eric J. Kolbeck by name. The homepage carries logos and attributed quotes from firms including O'Hagan Meyer, Scarinci Hollenbeck, Bell Nunnally, McCathern, Lydecker, Elevare Law and Bevilacqua PLLC, and the customers include partners, a CFO and a COO speaking on the record.
What no published material gives is a figure: no measured capture uplift, no time saved, no realisation change, with the only quantities being customer counts and the size of one office. Verified 20 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
The commitments are specific and they are published on a security page rather than in a contract. That page states full data segregation, zero training on firm data, zero data retention by the AI models, customisable data retention, single-tenant options for enterprise deployments, customisable geolocation, the ability to run models inside a private Azure cloud, and compatibility with on-premises systems. The Privacy Policy dated 7 April 2026 says in terms that it does not apply to Customer Data, which is governed by contracts with customers that are not published, and the published Terms of Service cover the website only.
Nothing addresses privilege or work product in what is captured, which matters here more than for most products: PointOne watches a lawyer's documents, email and calls all day, so what it holds is a map of client matters. Verified 20 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
A position on the professional duty is published, and it sits in the wrong place to earn more. A guide of 15 July 2026 states that no AI time tracking software should submit entries without human review, that the firm reviews, edits if necessary and approves every entry before it goes anywhere, and that this is both an ethical requirement and a practical quality control measure. The same page puts the question of whether entries can be submitted without review to the buyer as one of quality control and ethics, and says nothing goes to billing without the timekeeper's approval.
That engages the duty this product actually raises, which is that the lawyer bills for time actually spent, signs the bill and stays answerable for every entry on it, while the words describing the work are drafted by software. Three things hold it here. The position lives in a guide on the vendor's blog, not in the Terms of Service of 7 April 2026, the product pages or anything a customer signs. No rule of professional conduct and no ethics opinion is named anywhere on the estate, so no standard is tied to this product.
And nothing addresses found time, flat fees, or what a client is told about how the narrative on the bill was written. Checked the home page and its four product sections, the security and about pages, the Terms, the Privacy Policy, the April 2026 release and five posts from the vendor's own blog on 20 September 2026. Verified 20 September 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
The security page has a section headed Responsible use of AI, and everything in it is a data control: zero training on firm data, zero retention by the models, customisable base models, private Azure execution and auditability of AI outputs. Those protect the firm's data; they say nothing about how PointOne builds and tests the models that classify a lawyer's day. No accountable owner is named, nothing describes what is tested before a release ships, no evaluation result is published, and nothing addresses whether classification or narrative quality varies by practice area, seniority, working pattern or language.
Checked the homepage and all four product sections, the security and about pages, the Terms, the Privacy Policy and the April 2026 release on 20 September 2026. Verified 20 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Retention, deletion and access are addressed with real specifics, short of a complete picture. The security page publishes customisable data retention, full data segregation, zero data retention by the AI models and single-tenant options. The Privacy Policy dated 7 April 2026 goes further than most on the capture surfaces: data taken through the Zoom integration, including meeting attendance, participant names and call logs, is discarded immediately once time entries are generated; data accessed through Google Workspace APIs is not used to develop or train AI or machine learning models, is retained only as long as needed, and is deleted on request through an automated process.
What is missing is the rest of the set: no subprocessor list beyond analytics providers, no incident or breach notification commitment for firm data, and no published agreement, since the Privacy Policy excludes Customer Data. Verified 20 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
The only published allocation of loss is a short disclaimer in website terms. Section 5 of the Terms of Service dated 7 April 2026 says that in the event of data loss or business interruption resulting from use of the services PointOne is not liable for damages, and that users are responsible for safeguarding their own data; section 11 caps total liability at one hundred dollars and excludes consequential damages, and section 10 runs an indemnity from the user to PointOne.
Those Terms govern the website. No warranty, indemnity or insurance position covering the product is published, and nothing addresses who bears the loss if a wrong narrative reaches a client's bill or a client's billing guidelines are breached by an automated entry. Verified 20 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
The connections are named on both sides of the product and partly described. PointOne captures context from the applications a lawyer works in, including documents, email, calls and the web, and the Privacy Policy sets out exactly what two of those carry: the Zoom integration collects meeting attendance, participant names and email addresses and phone call logs, and Google Workspace data is accessed under stated restrictions.
On the output side it syncs with billing and practice management systems named on the homepage, Aderant, Elite 3E, Clio, Filevine, Actionstep, Surepoint, MyCase, LeanLaw and QuickBooks, and the security page says it works with on-premises systems. What is missing is depth for an implementer: no integrations page, no documentation or API reference, and nothing on what syncs in which direction or what a firm must configure. Verified 20 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The tenancy model is stated plainly and the geography is offered without being specified. The security page lists flexible deployment options for large firms: full data segregation, single-tenant options for enterprise deployments, customisable geolocation, compatibility with on-premises systems, and the ability to run models within a private Azure cloud, which is the clearest statement located of where the AI processing can be placed.
No region is named, nothing says which tier or contract carries single tenancy or a private model environment, and the Privacy Policy says personal information may be transferred, processed and stored anywhere in the world. Verified 20 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
The certifications are named and the evidence is not reachable. The security page states SOC 2 Type 2 certification with independently audited controls, full ISO 27001 certification, GDPR compliance by design and that PointOne meets HIPAA requirements for firms in healthcare-adjacent practices. No auditor, scope statement, report period or date appears, there is no trust portal or report request route, and no penetration test is mentioned.
A firm's security reviewer would be asking for the SOC 2 report and the ISO certificate scope, and neither is obtainable from the published site. Verified 20 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
What runs underneath is left to the buyer to ask about. The security page offers customisable base models and the ability to run models within a private Azure cloud, and commits to zero data retention by the AI models, which implies terms with a provider without identifying one. No model, version or provider is named on any page read, nothing states where inference runs by default as opposed to in the private option, and no commitment to notify customers when the models behind their time entries change was located. Verified 20 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No price, rate or unit of charge is published. Checked the homepage and all four product sections, the navigation and footer, the security, about and careers pages, the Terms of Service, the Privacy Policy and the news posts on 20 September 2026: there is no pricing page, no tier, no per-timekeeper rate and no trial, and every route ends at a demo request. One customer quote says the software more than pays for itself, which is the closest the estate comes to a commercial statement. Verified 20 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
The range of buyer is evidenced rather than asserted, and the edges are not drawn. Named customers run from small firms and boutiques (Elevare Law, Bevilacqua PLLC, North City Law, Legal Scale) to larger national firms (O'Hagan Meyer, Scarinci Hollenbeck, McAngus Goudelock & Courie, Bell Nunnally, Lydecker) and a state Attorney General's office with more than 300 timekeepers, and the product pages say the review workflow is flexible enough for firms of all sizes while the security page addresses the needs of the world's largest firms.
Worked examples span trademark prosecution, insurance defence, patent litigation and M&A. Nothing states which practice types or billing arrangements the capture handles poorly, and the customer count differs between pages: the homepage says more than 200 firms, the April 2026 release says more than 100. Verified 20 September 2026.
4 public documents
The public pages on file for PointOne, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.
-
pointone.com/security5 signals
Client Data in Training, Prompt and Output Retention, Ethical Walls and Matter Segregation and 2 more
Read Sep 20, 2026
-
Bar Guidance Alignment
Read Sep 20, 2026
-
pointone.com/privacy1 signal
Third Party Request and Subpoena Notice
Read Sep 20, 2026
-
Fabricated Citation Record
Read Sep 20, 2026
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
A public policy or trust page states no training on customer content, with no matching term located in the published agreement.
The security page commits to zero training on firm data and zero data retention by the AI models. The Privacy Policy separately affirms that data accessed through Google Workspace APIs is not used to develop, improve or train AI or machine learning models. No customer agreement is published to carry the commitment: the Terms of Service cover the website, and the Privacy Policy states that Customer Data is governed by contracts not published.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
The customer controls the retention window, by product configuration or by contractual instruction, but zero retention is not stated as available.
The security page offers customisable data retention and states that the AI models retain nothing. The Privacy Policy adds that data captured through the Zoom integration, including meeting attendance, participant details and call logs, is discarded immediately once time entries are generated. No zero-retention setting is stated for the platform's own store of captured activity and entries, and no default window is published.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Segregation is asserted in public materials with no published detail on how it is enforced.
The security page claims full data segregation with single-tenant options for enterprise deployments, and the Review workflow lets a firm set reviewers, routing and permissions. Nothing published describes how access is enforced between timekeepers or matters, or whether captured activity for one matter can be seen by anyone reviewing another.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.
The Privacy Policy dated 7 April 2026 says PointOne may access, preserve and disclose information it stores to comply with law enforcement or national security requests and legal process, such as a court order or subpoena, and makes no commitment about notifying anyone. It covers the website rather than Customer Data, so a firm has no published position on what happens if PointOne is served for its captured time data.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies the corpus behind the product’s answers.
Checked the homepage and its four product sections, the security and about pages, the Terms of Service and the Privacy Policy on 20 September 2026. The product works from a firm's own captured activity and its own uploaded client billing guidelines; no external legal corpus is involved or described.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
Checked the same pages on 20 September 2026. PointOne writes time narratives and billing rules rather than citing legal authority, so no subsequent-history check arises and none is described.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
Checked the homepage and its four product sections, the security page, the Terms, the Privacy Policy and the April 2026 release on 20 September 2026. Nothing describes what the product does when it cannot tell which matter a task belongs to or cannot describe the work: no abstention path, no uncertainty flag and no confidence score is published. The published controls are auditability of AI outputs and human review before billing, which come after an entry is written.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.
Searched the AI Hallucination Cases database maintained by Damien Charlotin on 20 September 2026 on the product name PointOne and the corporate name PointOne Technologies, Inc. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product, which writes time entries rather than legal citations.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Public materials refer to professional responsibility in general terms without naming guidance.
Professional responsibility is engaged in general terms and no guidance is named. A published guide to AI time capture, dated 15 July 2026, states that no AI time tracking software should submit entries without human review, that the firm reviews, edits if necessary and approves every entry before it goes anywhere, and that this is both an ethical requirement and a practical quality control measure. That is the duty referred to without a rule, an opinion or a bar behind it.
Nothing names a rule of professional conduct, an ethics opinion or any bar guidance, on billing for machine-drafted narratives or on anything else, and nothing engages the newer guidance on generative AI and fees. The absence stays pointed on a product of this kind, because the guidance that governs billing is long established rather than new. The compliance features enforce clients' outside counsel guidelines, which are contractual rather than ethical.
Checked the home page, the terms of service, the full footer, the three solution pages and five posts from the vendor's own blog, including its rankings of timekeeping and AI tools, on 2 and 20 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure, and the product sits inside a fee relationship between a lawyer and a client where those savings would change the bill.
The published case for the product is that a firm bills more, by capturing time that previously went unrecorded, and nothing addresses what a client is told when the narrative on the bill was drafted by software. The nearest things to a record of the machine's work fall short of one: the security page promises auditability of AI outputs in a single line, without saying what is recorded or where a firm would see it, and the review trail shows who approved an entry, which records the human step rather than the AI's. Billing rules drawn from the client's own guidelines are enforced against every entry, which is a control on the output rather than a record of it.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
No located public material supports a client side disclosure obligation.
Checked the security page, the homepage, the Terms of Service and the Privacy Policy on 20 September 2026. No subprocessor list, model provider list or client-facing disclosure pack was located, and there is no trust portal or documented route to request one; the Privacy Policy names service providers for the website only. The product manages clients' outside counsel guidelines, which is a separate matter from what PointOne discloses about itself.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
Elements of a record exist, built for billing rather than for a court. The security page promises auditability of AI outputs, entries carry the rules they were checked against, and the review workflow records who approved what. Nothing records which model produced a narrative, and no per-document export covering model use, sources and human verification is described.