R
Referent
Referent is AI native practice management for solo lawyers and small firms, built by AI Lawtech sp. z o.o. of Radom, Poland, the team behind the consumer product AI Lawyer. It combines a legal CRM for leads, intake and matters with AI agents that run routine work from the firm's live matter context. A prospective client talks to an AI at an intake link that screens fit, opens the matter and prepares the engagement. Agents file email to the right matter with drafted replies, track deadlines, draft letters and documents, capture time, prepare bills and run follow ups.
Anything client facing or high risk waits in the lawyer's approval queue, and every agent action goes to an audit trail. It connects to Gmail, Google Calendar and Google Drive, with Outlook and Microsoft 365 listed as coming, and runs a Model Context Protocol server so firms can work from ChatGPT, Claude, Gemini and other assistants. The company is based in Poland and building for US firms, and its security page says data is hosted on Google Cloud with US and EU regional separation. Referent starts with a free plan, and paid plans include AI usage; paid prices are not published.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The agents are what Referent sells, running on top of a CRM that would still hold records without them. The company calls the product AI native practice management and describes it as a system of action rather than a system of record. Agents build the workspace from the firm's inbox, file every email and attachment to the right matter, draft replies, letters and documents from the matter's context, watch court dates and limitation periods, capture time, prepare bills, run follow ups, and screen new clients at an intake link.
A Model Context Protocol server extends the same work into ChatGPT, Claude and other assistants. Underneath sits a legal CRM for leads, clients, matters, tasks and documents, which a firm could still use by hand if the agents were switched off.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
For a practice management agent, accuracy means whether a drafted reply, a filed email, an extracted deadline or a prepared bill is right, since each reaches a client or a court. Referent claims grounding and measures nothing. Its pages say drafts and answers are prepared from the matter's full context and that answers through its protocol server are grounded in the firm's practice. The architecture it describes, with an isolated workspace per firm and agents reading the matter file, is plausible grounding.
But no accuracy figure, test, error rate or evaluation is published for any agent, nothing describes how a draft cites back to the email or document it came from, and nothing says what happens when a deadline is extracted wrongly. Section 6.2 of the Terms says Referent does not review output for accuracy, completeness or currency and that output may be incomplete, inaccurate or unsuitable. Section 6.9 warns that transcripts may misattribute speakers or omit passages. The product is not presented as a case law research tool.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
What runs alone, where it must stop and how the lawyer checks it are all stated. Agents do the inward work on their own: filing email and attachments to matters, tracking deadlines, capturing time and preparing drafts. Everything that faces a client or carries risk waits in an approval queue. The company states the limit categorically: nothing is sent, filed or billed without the lawyer's sign off, and drafts sit in the queue to be approved, edited or rejected.
Every agent action goes to an audit trail recording what was done, when and on whose approval, and the protocol server is described as working under the same permissions, approvals and trail. The Terms carry this into the agreement. Section 6.1 says the AI features assist users and make no decision with legal or similarly significant effect on a solely automated basis, and section 6.4 makes human review of all output mandatory.
The legal harness page ties the audit trail to the supervision a lawyer owes a nonlawyer assistant under Model Rule 5.3.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
No named firm, customer quote, case study, usage figure or dated result is published. The company's own comparison page describes Referent's maturity in 2026 as invitation only with hands on onboarding, set against a competitor's 150,000 professionals and public reviews, which candidly concedes there is no track record yet. The about page points to the team's earlier consumer product, AI Lawyer, as one of the most widely used consumer legal AI products.
That is a different product sold to a different buyer and says nothing about Referent running a firm's practice. The site offers a free plan and open registration, so production use may exist; it is simply not published.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Written commitments cover training, model providers and deletion, privilege is acknowledged, and walls inside a firm are not addressed. The Terms say Referent does not use customer content to train generalized language models and contractually bars its AI providers from using it to train or improve their general purpose models. Section 14.3 of the Data Processing Agreement repeats both, and Referent also excludes model providers established in China.
The security page says every model provider works under zero retention and no training agreements, and that each firm has its own encrypted workspace never mixed with another firm's. Section 14.4 of the Terms recognizes that content may be subject to legal professional privilege or professional secrecy and says it is treated accordingly. Section 13 of the Data Processing Agreement deletes or returns data on termination, with backups overwritten within 60 days.
Access inside a workspace is described only as role based for authorized firm members, with no walls or ethical screens at matter level, and the zero retention claim on the security page is broader than the provider terms the agreement sets out.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
A clear line is drawn on advice and on the lawyer's review duty, and disclosure to the firm's clients is left to the firm. Section 6.3 of the Terms says Referent is a software provider, not a law firm, does not practice law or give legal advice, and creates no lawyer client relationship with the firm or its clients. Section 6.4 requires the firm to review all output for accuracy and for compliance with professional conduct and fiduciary duties before relying on or disclosing it, and section 4.4 leaves confidentiality and privilege obligations with the firm.
The legal harness page frames the approval queue and audit trail as the record Model Rule 5.3 asks a lawyer to keep over nonlawyer assistance. The one public surface is the intake link, where a prospective client talks to an AI. Section 6.6 makes the firm responsible for telling people AI is in use, including under Article 50 of the EU AI Act, with Referent supplying disclosure text. Whether the intake link identifies itself as AI by default is not stated, and apart from recording consent, which section 6.9 says varies by US state, no jurisdiction limits are named.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Principles are published, and the machinery behind them is not. The about page sets out three commitments: AI multiplies lawyers rather than replacing them and the company refuses to sell replacement, the lawyer approves every critical step, and confidentiality is a design constraint rather than a feature. The Terms reinforce the second with a clause barring solely automated decisions with legal effect, and the company says it is building under EU law, where the AI Act's transparency duties apply.
What is missing is any account of how agent behavior is governed inside the company. No one is named as accountable for what the agents draft and send for approval, and nothing describes what is evaluated before a new agent, model route or prompt reaches firms. No finding is published on how drafts or intake screening perform across matter types, clients or languages. Security certification work is described separately and does not answer these questions.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Every part of data stewardship is published in the agreement, with dates and numbers attached. The Data Processing Agreement, effective 5 August 2026, names ten subprocessors in Annex 3 with each one's function, processing location and transfer safeguard, from Google Cloud hosting and Cloudflare to the AI providers. Section 7 commits to notify the firm in advance of any addition or replacement, with the name, location, function and certifications, and gives a 14 day right to object, shortened to 48 hours' notice where a subprocessor fails suddenly.
Section 11 commits to breach notification within 72 hours with the details a firm needs for its own reporting. Section 13 deletes or returns data on termination, overwrites encrypted backups within 60 days and confirms deletion in writing on request. The Privacy Policy sets retention by category, such as account data for the contract term plus six months, and the security page limits production access to a small number of engineers, logged and reviewed. One reservation is that the security page's summary does not always match the annex beneath it.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
The agreement is direct about AI output, and what it says is that the firm carries the risk. Section 6.2 of the Terms provides the AI features and their output as is. Section 6.5 says Referent is not responsible for any decision, advice, filing, omission, deadline or outcome based on or influenced by output, or for any resulting loss, professional liability or regulatory consequence. Section 6.10 has the firm defend and indemnify Referent against claims arising from its use of the AI features, their use toward its clients and any failure to make required disclosures.
Section 12.3 caps each party's liability at fees paid in the twelve months before the claim, section 12.4 lifts the cap only for the firm's payment obligations and indemnities, and section 12.5 excludes loss the firm could have avoided with backups. Referent's own indemnity in section 13.1 covers intellectual property claims against the service and expressly excludes output. For a product that tracks court deadlines and drafts client correspondence, a missed deadline is the firm's alone.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
The Google side of a small firm is connected in depth, and most of a legal stack is not connected yet. With Gmail access Referent files incoming client correspondence to the right matter and sends replies the lawyer has approved. Google Calendar syncs hearings, meetings and deadlines in both directions, and Google Drive is connected. Referent says it connects only to the Google services a firm chooses, and its Data Processing Agreement names Nango as the service that manages the access tokens.
Outlook and Microsoft 365 are marked as coming soon. A Model Context Protocol server lets a firm work with its matters from ChatGPT, Claude, Perplexity, Gemini and other assistants under the same permissions, approvals and audit trail, and the company says it migrates clients, matters, tasks and files from existing tools. No document management system, accounting or trust accounting package, electronic billing format or court filing service is connected, and its own comparison page concedes that Referent is not an accounting system.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Regions and processing locations are published in detail, and two of Referent's own documents disagree about where US data is stored. The security page says Referent runs on Google Cloud with regional separation, so US firms' data is stored in US data centers and EU firms' data in EU data centers, and each firm has its own encrypted, isolated workspace. The Terms say AI processing for customers in the EEA and the UK happens within the EEA.
The Privacy Policy notes that text to speech runs through xAI in the US. Annex 3 of the Data Processing Agreement gives a processing location for each subprocessor, with OpenAI running in an EU region for EU and UK customers and otherwise in the US. The same annex lists Google Cloud hosting only in europe-west1 in Belgium and names no US region. A US firm reading the agreement it signs would conclude its data is hosted in the EU, and one reading the security page would conclude the opposite. No single tenant or private deployment option is offered.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
No attestation exists yet, and Referent says so plainly. The security page has a section on certifications, headed as where the company stands, honestly: SOC 2 is in preparation with the control set mapped, ISO 27001 is in preparation with requirements adopted before the certificate, penetration tests are conducted and findings fixed, and single sign on is on the roadmap. Its FAQ answers whether it is SOC 2 certified with "Not yet" and promises updates as certifications complete.
Section 12 of the Data Processing Agreement commits to provide third party audit reports and certifications where available and to answer security information requests within seven business days, and security questionnaires are answered by email. No tester or date is named for the penetration tests.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The providers, what each does and where it runs are named in the agreement, with a commitment to notice of change, and the published lists do not match. Annex 3 of the Data Processing Agreement names OpenAI for generation, transcription and embeddings, in an EU region for EU and UK customers and otherwise in the US. It also names Mistral AI for character recognition in France, xAI for text to speech in the US, Turbopuffer for the vector index and E2B for the isolated environments agents run in.
Section 7.3 commits Referent to notify customers in advance before any subprocessor is added or replaced, and the Terms exclude model providers based in China. The security page, however, says models come from providers including OpenAI and Anthropic, routed by task, and Anthropic appears nowhere in the annex that governs. No model family or version is named for any task.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The entry point is free and stated, and what a firm pays after that is not published. Referent says registration is open to solo lawyers and small firms with no credit card, that the product starts free, and that paid plans include AI usage rather than billing it as an add on. It makes that a point of contrast with competitors whose per user prices it quotes, such as a comparison page citing about $39 per user per month for Clio.
The Terms describe subscriptions that renew automatically, seats that can be added or removed, no refund for canceling during a term, and price changes on 30 days' notice before renewal, so the mechanics of a paid plan are published. The plan itself is not. No pricing page exists, since the address returns a not found page, and no plan name, figure, unit of charge or AI usage limit appears on any page read. A firm can start without talking to anyone and cannot learn what it will pay to stay.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
The buyer is defined precisely and the practice is not. Registration is open to solo lawyers and small firms, which the company describes as roughly two to ten lawyers needing matters, clients, documents, deadlines and billing in one place, plus shared context and permissions. Boutique firms are addressed, and a tier for large firms is marked as coming. The company says it is based in Poland and building for US firms, while its data terms also serve EU and UK firms with EU residency.
It states some limits plainly: it is not an accounting system, Outlook and Microsoft 365 are not yet connected, and access in 2026 is described as invitation only with onboarding help. No practice area is stated. No page says which kinds of matters its intake screening, deadline tracking and drafting are built for, whether it handles litigation calendaring rules by jurisdiction, or where it should not be used. The only matter types visible are examples in a product screenshot.
5 public documents
The public pages on file for Referent, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.
-
referent.law/terms-of-use3 signals
Client Data in Training, Prompt and Output Retention, Third Party Request and Subpoena Notice
Read Sep 29, 2026
-
referent.law/legal-harness2 signals
Bar Guidance Alignment, Billing and Fee Posture
Read Sep 29, 2026
-
referent.law/dpa1 signal
Outside Counsel Guideline Readiness
Read Sep 29, 2026
-
referent.law/security1 signal
Court Disclosure Support
Read Sep 29, 2026
-
Fabricated Citation Record
Read Sep 29, 2026
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The published terms prohibit training on customer content. Not a policy page, the agreement.
The Terms say Referent does not use customer content to train generalized large language models and contractually prohibits its AI providers from training on it, and section 14.3 of the Data Processing Agreement repeats both. Usage data that does not identify the customer, a user or any individual may be used to improve the service.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
The customer controls the retention window, by product configuration or by contractual instruction, but zero retention is not stated as available.
Section 6.9 of the Terms refers to retention controls available to the firm in the service, and the security page says every model provider works under zero retention agreements, so content is processed and discarded. The Data Processing Agreement deletes data on termination, with backups overwritten within 60 days. A zero retention setting for content Referent itself stores is not described.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
No located public material addresses walls or matter level segregation.
Checked the security, home and legal harness pages, the Terms and the Data Processing Agreement on 29 September 2026. Each firm has its own isolated workspace and access is role based for firm members, which is separation between firms; nothing describes walls between matters or users within a firm.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Terms commit to notice where lawfully permitted. No transparency report located.
Section 14.3 of the Terms commits the receiving party, where lawful, to give prompt notice of a legally compelled disclosure and to disclose only what is required. No transparency report was located.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies the corpus behind the product’s answers.
Checked the home, legal harness and legal CRM pages on 29 September 2026. The agents work from the firm's own matters, email and documents, and no body of primary law behind the product's output is identified.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
Checked the home, legal harness and legal CRM pages on 29 September 2026. Nothing addresses checking cited authority for later treatment.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
Checked the home, legal harness and security pages and the Terms on 29 September 2026. Drafts wait for the lawyer's approval, but nothing describes what an agent does when it cannot ground an answer or complete a task.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.
Searched the AI Hallucination Cases database maintained by Damien Charlotin on 29 September 2026 for Referent, and no recorded case was returned. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Public materials engage with at least one named ethics opinion.
The legal harness page says every agent action is logged so the supervision Rule 5.3 asks of a lawyer for a nonlawyer assistant has a record, and describes its approval rules as the Model Rules encoded. No ethics opinion on AI, such as ABA Formal Opinion 512, is named.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
A usable record of AI assisted work exists with no published fee guidance.
Referent captures time and prepares bills in the background for the lawyer to review, and its audit trail records what every agent did, when and on whose approval. No guidance is published on how AI assisted work should be billed or disclosed to clients.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A current subprocessor or model provider list is published.
Annex 3 of the Data Processing Agreement lists ten subprocessors, including the AI providers, with function and processing location. Section 6.6 of the Terms says Referent makes model disclosure text available to customers, which is not published.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
The audit trail records what each agent did, when and on whose approval, which covers the human verification element of a disclosure. Nothing ties it to court disclosure or records the model and sources used for each document.