FAQ

Questions we are asked

What firms want to know before they commit - how it is licensed, what happens to your data, and what the first month looks like. If yours is not here, ask us.

Pricing and licensing

How is it licensed?
Per seat, per month. A seat is a person who logs in - clients using the portal are not seats.
Can we change plans later?
Yes. Plans build on each other, so moving between them changes what is enabled rather than moving your data anywhere.
Is the AI add-on required?
No. Every plan works fully without it. It layers drafting and summarisation onto the plan you are already on.
What happens to our existing case data?
It comes with you. Migration from your current system is part of onboarding, not a separate project you run yourself.

More on pricing and licensing

Getting started

What happens to cases that are mid-flight?
They move with their deadlines, documents and history. The parallel period exists precisely so that nothing depends on the migration having been perfect on the first pass.
Do we have to move our closed cases?
Not immediately, and often not all of them. Closed archives are the largest and messiest part of any migration and the least urgent - separating them from the live caseload is usually the difference between a manageable move and a stalled one.
Who does the work?
We do the migration. Your team's part is answering questions about how your firm actually works - which is not delegatable, because that is the part no export contains.
What if we start and it is not working?
Your old system is still running during the parallel period, which is the point of it. We would rather you stopped early than persevered with something that was not fitting.

More on getting started

Security and your data

Do you train AI models on our case data?
No. Your case data is not used to train any model, ours or a vendor's. The AI in the platform reads documents on your cases to extract structure for your team to confirm; that is the extent of it.
Can one firm see another firm's cases?
No, and the reason is worth stating precisely: the isolation is enforced by PostgreSQL row-level security rather than by application code filtering correctly. A bug in our code cannot return data from another firm because the database will not return it.
Who at OneCounsel can see our data?
Access is limited to the people who need it to run and support the platform, and support access is logged. We are a small team and we would rather be direct about that than describe a process we do not yet have.
What happens to our data if we leave?
It is yours. Export is part of the platform rather than a favour, and we delete on request.
Are you HIPAA compliant?
HIPAA compliance is a property of how a firm operates, not something software can hold on its own - but a vendor handling PHI has to support it, and the controls above are what that support consists of. We sign a business associate agreement. We hold no certification today, and the security page sets out exactly what we do and do not have rather than making you ask.
Do you run penetration tests?
Not yet. We have not had an independent penetration test, and we would rather say so than describe a cadence we have not started. It is on the path alongside SOC 2; ask us and we will tell you where it stands.

More on security and your data

We'd like to measure how this site is doing

Analytics helps us see which pages actually help firms evaluate OneCounsel. You can refuse, and the site works exactly the same. How we handle data