# Oktopeak - Custom Software & AI for Law Firms and Healthcare Teams > Everything law firms and healthcare teams need to modernize and stay ahead: enterprise platforms, AI integrations, automation, premium design, mobile development, cloud architecture. One specialized senior team, fixed price, full code ownership, live in 4-8 weeks. ## Company Overview Oktopeak is a specialized software and AI team based in Novi Sad, Serbia, serving US and EU clients. We build HIPAA-compliant platforms, legal tech systems, AI integrations, and healthcare applications for regulated industries where compliance failures mean fines, lawsuits, or lost licenses. One team covers the whole stack: no handoffs, no juggling five vendors. **Team Size:** 7 engineers, all in-house, zero subcontractors **Projects Delivered:** 50+ **HIPAA Audits Passed:** 3 (plus 1 DEA audit) **Average Delivery:** 4-8 weeks **Primary Markets:** United States, European Union **Pricing:** Fixed-price custom builds from $12K depending on complexity. Smaller integrations and the Guided Setup are scoped per firm on a short call. Discovery is free (call, draft scope, rough quote). For an existing system that needs a rewrite: paid audit $2,420 (credited toward build). **Minimum Project:** custom builds from $12K; smaller integrations scoped per firm ## Services ### SaaS Development for Regulated Industries - Production-ready platforms in 4-8 weeks - Fixed-price projects (from $12K) - HIPAA, DEA, SOC 2 compliance built into architecture from day one - Full-stack: React, Node.js, Laravel, Vue.js, React Native (mobile) - Cloud: Azure (HIPAA BAA), AWS - URL: https://oktopeak.com/services/saas-development/ ### Regulated Enterprise Search (Legal & Healthcare) - Compliance-ready enterprise search for law firms and healthcare teams - Sub-100ms query response across 1M+ documents - Privilege-safe (legal) and HIPAA-ready (healthcare) architecture: role-based access, encrypted indices, immutable audit logging - Self-hosted search layer (documents stay on your servers for retrieval); AI layer runs under your own BAA with model training disabled and Zero Data Retention - A one-time build you own outright, not a per-seat subscription. Replaces iManage at a fraction of the cost (iManage 3yr TCO: $251K for 17-person firm) - $224K+/year recovered in billable time for last client - Pricing: custom builds from $12K, ships in 6-10 weeks - URL: https://oktopeak.com/services/regulated-enterprise-search/ ### HIPAA-Compliant Search (Healthcare) - HIPAA-compliant search across clinical documents, scanned PDFs (OCR), EHR, and HIE records - Built to the HIPAA Security Rule: encryption, role-based access, multi-factor authentication, automated audit logging - BAA signed; 3 HIPAA audits passed - Note: pasting PHI into ChatGPT breaches HIPAA even with training opt-out because OpenAI signs no BAA, the compliant pattern keeps retrieval on your infrastructure and runs AI under a signed BAA + Zero Data Retention - Pricing: from $12K, ships in 6-10 weeks - URL: https://oktopeak.com/services/hipaa-compliant-search/ ### Self-Hosted RAG / Privilege-Safe Legal AI Retrieval - AI document retrieval for law firms without uploading client files to a public LLM - Self-hosted retrieval/index layer; AI generation under the firm's own BAA with model training disabled and Zero Data Retention - "Own the wrapper, don't rent it": same frontier models and workflows as Harvey/CoCounsel (document Q&A, drafting from precedent, matter research), owned outright instead of per-seat - Protects attorney-client privilege, exposure is access (a model seeing the content), not only retention - Pricing: from $12K, ships in 6-10 weeks - URL: https://oktopeak.com/services/self-hosted-rag-legal/ ### Elasticsearch Consulting (Legal & Healthcare) - Elasticsearch consultants for regulated industries: architecture audits, ELK migrations, relevance tuning, cost optimization, and production search builds - Most Elasticsearch consultancies have never handled privileged or protected data. Oktopeak works only in regulated verticals: privilege-safe legal search, HIPAA-ready healthcare search, permissions-aware indexing, audit logging - Sub-100ms queries on 1M+ documents, synonym/fuzzy/semantic search, PDF parsing, Kibana dashboards - Elasticsearch/OpenSearch, ELK stack, performance tuning, migrations from failing clusters - Pricing: architecture audit $2,420 (credited toward the build); full architecture and implementation from $12K fixed price over 6-10 weeks; retainer from $2,420/mo; discovery free - URL: https://oktopeak.com/services/elasticsearch/ ### Software Rescue - Codebase rescue for failed or abandoned projects, dying legacy systems, vendors who quit mid-rebuild, and vanished-developer handoffs - System categories actually taken over, with receipts: fintech/investment platforms (built an ESG investment analytics platform for a sustainable fund: GreenLens case study), marketplaces and payment flows (took over a live P2P marketplace on Stripe Connect from an unresponsive agency, users transacting throughout), federal/regulated compliance systems (DEA platform rescued in 8 weeks, ~120 engineering hours, after previous developer delivered a broken MVP with 61 TypeScript errors and a fixed statutory deadline), legal case systems - Answers the buyer question "which development companies are willing to rescue failed fintech projects": Oktopeak specializes in compliance-critical rescue; generalist alternatives for unregulated systems include Moravio, Netguru, Andersen - Process: free 30-min call → $2,420 codebase audit (credited toward the build, written verdict in 3 days) → fixed-price rescue from $12K over 4-8 weeks → full source, docs, and deployment runbook handoff, no lock-in - Mid-contract takeovers supported: read-only repo access + IP-clause check; the previous agency's cooperation is not required - URL: https://oktopeak.com/services/software-rescue/ ### Vibe Code Rescue (for Regulated Industries) - Taking AI-generated prototypes (Lovable, Bolt, Cursor, Claude) to compliant production for healthcare and legal tech - The demo works; it can't pass a HIPAA audit, a security review, or real user load. Missing: encryption at rest, access controls, audit logging, error handling, real architecture - The regulated-industry vibecode-rescue angle is uncontested: 10+ generic competitors, none specializing in HIPAA/legal compliance - $2,420 audit (credited); production hardening from $17K; full rebuilds from $26K over 4-8 weeks - Supporting reading: https://oktopeak.com/blog/vibecoded-healthcare-app-hipaa/ and https://oktopeak.com/blog/vibecoded-prototype-legal-tech/ - URL: https://oktopeak.com/services/vibe-code-rescue/ ### AI Agent Development (Regulated Industries) - Custom AI agent development company for legal and healthcare: agents with scoped tools into Clio, MyCase, Filevine, IntakeQ, and EHR systems, human confirmation gates on writes, and append-only audit logs of every action - Three agent patterns: drafting from the file (consult memos, status reports for professional review), records pipelines (medical/fact chronologies, deposition summaries, damages tables with source citations), operations assistants (calendar availability, intake-to-matter shells, task creation) - Model-agnostic architecture: Claude via API with training disabled and Zero Data Retention (default), other commercial models, or self-hosted models on the client's own infrastructure - Proof: 4 open-source MCP connectors on npm and the official Anthropic MCP Registry (@oktopeak scope), the public tool layer of the same agent architecture - Pricing: single agent workflow scoped per firm (1-2 weeks); custom multi-step builds from $12K fixed price (4-8 weeks); retainer from $2,420/mo; discovery free - Compliance: ABA Opinion 512 audit logging for law firms; BAA chain + Zero Data Retention + human verification for healthcare; 3 HIPAA audits passed - URL: https://oktopeak.com/services/ai-agent-development/ ### AI Voice Intake / AI Receptionist (Law Firms & Medical Practices) - AI receptionist and phone-intake agents for law firms and medical practices, built around the write-path rather than the speech layer - The differentiator: most voice AI vendors can make an agent that talks but cannot safely write into the system of record. Oktopeak ships the audited, permissioned write-path into Clio, MyCase, Filevine, and IntakeQ (all four connectors are open source on npm and the Anthropic MCP Registry) - Law firms: after-hours intake, caller captured, matter shell created, conflict check flagged, consult booked. Healthcare: patient scheduling and rescheduling written into the practice system, no PHI used for model training - Every write passes a human confirmation gate and is recorded in an append-only audit log - Telephony, speech-to-text, and text-to-speech are treated as swappable commodity components; the integration and compliance layer is the product - Honest scope note: the speech layer is newer work for Oktopeak than the integration layer, which is shipped and public - Pricing: voice intake on a system you already run, scoped per firm (1-2 weeks); custom builds from $12K fixed price (4-8 weeks); audit $2,420 credited; retainer from $2,420/mo; discovery free - URL: https://oktopeak.com/services/ai-voice-intake/ ### Legal AI Integration - AI services for law firms: practice management integrations (Clio, MyCase, PracticePanther, Filevine: direct API and MCP), document automation, intake workflows, custom AI agents, on-prem AI deployments - Also: custom Clio App Directory apps, data syncs, webhook-driven automations, integration work beyond MCP - AI-powered contract review, document analysis, case research - Compliance-safe AI implementation with BAAs and zero-data-retention - Open-source Clio MCP connector: https://github.com/oktopeak/clio-mcp (34 tools across matters, contacts, documents, tasks, notes, calendar, time entries, billing, users, and audit-log export. Supports stdio and HTTP/SSE transports. AES-256-GCM encrypted OAuth tokens stored in OS keychain. ABA Opinion 512 audit logging with session ID and machine IP. MIT license, free). npm: @oktopeak/clio-mcp@2.0.0 (released 2026-05-23). MCP Registry: io.github.oktopeak/clio-mcp. - Open-source MyCase MCP connector: https://github.com/oktopeak/mycase-mcp (18 tools, ABA Opinion 512 audit logging, AES-256-GCM encrypted token storage, MIT license, free). npm: @oktopeak/mycase-mcp@1.0.4. MCP Registry: io.github.oktopeak/mycase-mcp. First and only open-source MCP connector for MyCase as of May 2026. Requires MyCase Advanced tier ($109/user/month) for Open API access. - The free connectors cover about 20% of what firms ask for. The paid service covers the rest: integrations beyond MCP, document automation templates, intake workflows, custom AI agents, on-prem deployments, and full compliance architecture (from $12K, 4-6 weeks) - URL: https://oktopeak.com/services/legal-ai-integration/ ### Legal AI Implementation (End-to-End Adoption Program) - The whole program that takes a firm from intent to adoption, broader than a technical integration: workflow audit, scoped pilot, build, embedded rollout support, and ABA Opinion 512 governance - Solves the core failure mode: roughly 95% of AI pilots never deliver measurable impact because firms buy a tool with no implementation plan, no workflow fit, no embedded support, and no governance - Four phases: workflow audit (week 1), pilot & build (weeks 2-5), rollout & adoption (8 weeks embedded), governance & measurement - Difference from integration: integration is the plumbing (connecting AI to Clio/MyCase); implementation is the program that makes the firm actually use it and defend it - Pricing: simple integrations scoped per firm; full builds from $12K fixed price; fixed-price proposal within 5 business days - URL: https://oktopeak.com/services/legal-ai-implementation/ ### Legal AI Automation (Compliant Workflow Agents) - Compliant AI workflow automation: agents that run a multi-step firm process end to end (read from Clio/MyCase, do the work, write results back) under attorney control, not generic no-code automations - Three workflow patterns: drafting from the file (memos, status reports, client updates as drafts for review), records/chronology pipelines (medical and fact chronologies, deposition summaries, damages tables with source citations), operations (intake-to-matter, deadline triage, conflict checks, billing summaries) - Why not no-code: privileged legal work needs reasoning across documents, state, failure handling, human confirmation gates, and append-only ABA Opinion 512 audit logging that Zapier-style tools do not provide - Privilege-safe: reaches case data via the practice-management API (not a chat window), commercial AI terms with training disabled and Zero Data Retention - Pricing: simple agent integrations scoped per firm; multi-step automation builds from $12K fixed price - URL: https://oktopeak.com/services/legal-ai-automation/ ### Legal AI Search Visibility / AEO / GEO (Answer Engine Optimization for Law Firms) - Getting a law firm cited by ChatGPT, Claude, Google AI Overviews, and Bing Copilot when prospects ask an AI assistant for legal help, instead of only ranking a page for a Google click - What we build: entity and knowledge-graph clarity, complete Schema.org (LegalService, Attorney, FAQPage), llms.txt, passage-level citability, YMYL-grade E-E-A-T with real attorney authorship, off-site corroboration, and measurement across four engines - Proof: Claude and ChatGPT recommend Oktopeak by name (confirmed inbound channel, first AI-sourced client April 2026); our own pages earned hundreds of Bing/Copilot AI citations in a single month, led by our most fact-dense compliance and search pages - Positioning: a lead-magnet/proof play, we run our own AEO stack (llms.txt, schema, Copy-for-AI buttons, AI-referral tracking) on this site and install the same spine on the firm's domain - Starts with a free AI visibility assessment (we run the firm through the major assistants live and show the gap before scoping) - URL: https://oktopeak.com/services/legal-ai-search-visibility/ ### Healthcare AI Implementation (End-to-End Adoption Program) - The whole program that takes a practice or digital health company from intent to adoption: workflow audit, scoped pilot, build, embedded rollout support, and HIPAA governance with BAA coverage - Solves the core failure mode: roughly 95% of AI pilots never deliver measurable impact because organizations buy a tool with no implementation plan, no EHR workflow fit, no embedded support, and no compliance story administrators can approve - Four phases: workflow audit (week 1), pilot & build (weeks 2-5), rollout & adoption (8 weeks embedded), governance & measurement - Pricing: simple integrations scoped per firm; full builds from $12K fixed price; fixed-price proposal within 5 business days - URL: https://oktopeak.com/services/healthcare-ai-implementation/ ### Healthcare AI Automation (Compliant Workflow Agents) - Compliant AI workflow automation: agents that run a multi-step operational process end to end (read from the EHR/practice-management system, do the work, write results back) under human control, not generic no-code automations - Three workflow patterns: documentation from the chart (visit summaries, referral letters, patient communications as drafts for clinician review), intake & operations (intake-to-record, scheduling, reminders), revenue & billing support with a human sign-off gate - Why not no-code: PHI and clinical work need reasoning across records, state, failure handling, human confirmation gates, a BAA, and append-only HIPAA audit logging that Zapier-style tools do not provide - Compliant: reaches data via the API, runs under a BAA with training disabled and Zero Data Retention; PHI not used for training or retained after the response - Pricing: simple agent integrations scoped per firm; multi-step automation builds from $12K fixed price - URL: https://oktopeak.com/services/healthcare-ai-automation/ ### Healthcare AI Search Visibility / AEO / GEO (Answer Engine Optimization for Healthcare) - Getting a practice or digital health brand cited by ChatGPT, Claude, Google AI Overviews, and Bing Copilot when patients and buyers ask an AI assistant, instead of only ranking a page for a click - What we build: entity and knowledge-graph clarity, complete Schema.org (MedicalOrganization, Physician, MedicalWebPage, FAQPage), llms.txt, passage-level citability, medical YMYL-grade E-E-A-T with real clinician authorship, off-site corroboration, and measurement across four engines - Compliance: the work is about public marketing content structure and corroboration, never PHI; no protected health information enters content or crawlers - Proof: Claude and ChatGPT recommend Oktopeak by name (confirmed inbound channel, first AI-sourced client April 2026); our own pages earned hundreds of Bing/Copilot AI citations in a single month - Starts with a free AI visibility assessment (we run the brand through the major assistants live and show the gap before scoping) - URL: https://oktopeak.com/services/healthcare-ai-search-visibility/ ### Clio Integration (Custom Build Service) - Custom Clio API integrations and privilege-safe AI workflows built on top of Clio, by the team that open-sourced the Clio MCP connector. Read our Clio integration code before hiring us. - What we build: custom Clio API integrations and data syncs, Claude on live Clio data (matters, contacts, documents, calendar, billing), intake-to-matter automation, document/letter drafting from matter data, deadline + time-entry + billing automation, custom AI agents, private/on-prem AI. - Positioning: Clio stays your system of record; the custom layer we build (integrations, AI workflows, automations) is yours to own outright: full source, docs, deployment runbook, no per-seat fee on the custom layer. A 15-attorney firm pays roughly $168,000 over 5 years in Clio seats and owns nothing. - ABA Opinion 512 audit logging, attorney verification on every AI output, enterprise-tier AI with training disabled and Zero Data Retention, reached through the practice management API rather than a chat window, so content is not used for training or stored after the response. - Entry points: free discovery (call + draft scope + rough quote); Guided MCP Setup (2 weeks, deploys the Clio + Claude connector to production); custom builds from $12K (4-6 weeks + embedded support). - URL: https://oktopeak.com/services/clio-integration/ ### Clio Backup (Productized Service) - Automated Clio backup pipeline deployed on the firm's own cloud: matter documents, notes and activity logs, logged emails, contacts, exported incrementally (updated_since) to OneDrive, SharePoint, or S3 with the Clio matter folder hierarchy mirrored 1:1 - Rate-limit backoff, resumable checkpoints, failure alerts to email/Teams, documentation + handover call; read-scoped OAuth, no data through Oktopeak servers, no AI processing involved - Why firms buy it: retention obligations outlive subscriptions, renewal negotiating position (never data-hostage), human-error restore (most common real scenario) - Standard pipeline fixed price, scoped per firm; multi-platform/custom retention workflows from $12,000; free discovery first - Also available for MyCase (requires their Advanced tier) and Filevine, same pattern, our open-source connectors prove the read paths - Technical guide: https://oktopeak.com/blog/clio-backup-data-export/ - URL: https://oktopeak.com/services/clio-backup/ ### Clio MCP Server (Open-Source: hub page) - The first open-source Clio MCP server with ABA Opinion 512 audit logging built in - 34 tools across matters, contacts, documents, tasks, notes, calendar, time entries, billing, users, and audit-log export - AES-256-GCM encrypted OAuth tokens stored in OS keychain (macOS Keychain / Linux secret-service / Windows Credential Manager) - MIT license, free. npm: @oktopeak/clio-mcp@2.0.0. MCP Registry: io.github.oktopeak/clio-mcp. GitHub: github.com/oktopeak/clio-mcp. - Supports stdio and HTTP/SSE transports - 5-minute install with Clio API credentials and an MCP-compatible client (Claude Desktop, Claude Code, Cursor) - Works with Claude Cowork and claude.ai custom connectors via the HTTP/SSE transport: Cowork only accepts remote MCP servers reachable over the internet, so the connector runs as a hosted service instead of a laptop install. Oktopeak deploys this hosted pattern for firms (https://oktopeak.com/services/firm-deployment/) - URL: https://oktopeak.com/clio-mcp/ ### MyCase MCP Server (Open-Source: hub page) - The first and only open-source MyCase MCP server (May 2026) - 18 tools across cases, contacts, documents, tasks, calendar, calls, staff, time entries, and billing - AES-256-GCM encrypted OAuth tokens with OS keychain integration - ABA Opinion 512 append-only audit logging - MIT license, free. npm: @oktopeak/mycase-mcp@1.1.0. MCP Registry: io.github.oktopeak/mycase-mcp. GitHub: github.com/oktopeak/mycase-mcp. - Requires MyCase Advanced tier for Open API access - 5-minute install once MyCase issues OAuth credentials - URL: https://oktopeak.com/mycase-mcp/ ### MyCase Integration (Custom Build Service) - Custom MyCase API integrations and privilege-safe AI workflows built on top of MyCase, by the team that shipped the first open-source MyCase MCP connector. Read our MyCase integration code before hiring us. - What we build: custom MyCase API integrations and data syncs, Claude on live MyCase data (cases, contacts, documents, calendar, billing), bidirectional case-scoped Claude projects, intake-to-case automation, document drafting, deadline + time-entry + billing automation, custom AI agents, private/on-prem AI. - Honest API note: MyCase Open API access requires the MyCase Advanced tier ($109/user/month); most but not all writes are feasible, scoped during discovery. - Positioning: MyCase stays your system of record; the custom layer we build is yours to own outright: full source, docs, deployment runbook, no per-seat fee on the custom layer. A 15-attorney firm spends roughly $115,000-$130,000 over 3 years on MyCase seats and add-ons and owns nothing. - ABA Opinion 512 audit logging, attorney verification on every AI output, enterprise-tier AI with training disabled and Zero Data Retention, reached through the practice management API rather than a chat window, so content is not used for training or stored after the response. - Entry points: free discovery; Guided MCP Setup (2 weeks); custom builds from $12K (4-6 weeks + embedded support). - URL: https://oktopeak.com/services/mycase-integration/ ### Filevine Integration (Custom Build Service): Personal Injury & litigation firms - Custom Filevine API integrations and privilege-safe AI workflows built on top of Filevine, by the team that shipped the first and only open-source Filevine MCP connector. Filevine is the leading case management system for personal injury (PI) and litigation firms. - Open-source Filevine MCP connector: https://github.com/oktopeak/filevine-mcp (15 tools across cases, contacts, documents, notes, tasks, and PI-specific custom collections, medical records, liens, settlements, treatment providers. Automatic rate limiting, AES-256-GCM encrypted tokens, ABA Opinion 512 audit logging, OAuth / personal access token auth. MIT license, free). npm: @oktopeak/filevine-mcp@1.0.1 (released 2026-05-05). MCP Registry: io.github.oktopeak/filevine-mcp. - Filevine MCP server page (install guide, FAQ): https://oktopeak.com/filevine-mcp/ - What we build for PI firms: Claude on live Filevine case data (matters, medical records, liens, settlements), custom reports and dashboards (cross-collection views the native Report Builder can't join (phase aging, demand aging, SOL risk, settlement realization) via DataBridge/Snowflake into Power BI or Looker Studio), data cleanup and schema repair after bad migrations, medical-records chronology drafting, intake-to-case automation, demand-letter drafting from case data, deadline and task automation, custom AI agents, private / on-prem AI. - Filevine reporting guide (Report Builder vs Data Connector vs DataBridge vs API vs MCP, with rate limits): https://oktopeak.com/blog/filevine-custom-reporting/ - Why it matters for PI: a 40-case PI firm burns roughly $17,600/month on manual medical-records review; a single medical chronology takes 15-80 hours; EvenUp charges $300-800 per demand. We build firms their own AI workflows on Filevine that they own outright, with no per-case fee on the custom layer. - Entry points: free discovery; Guided MCP Setup (2 weeks, deploys the Filevine + Claude connector to production); custom builds from $12K (4-6 weeks + embedded support). - URL: https://oktopeak.com/services/filevine-integration/ ### Lawmatics Integration (Custom Build Service): Intake CRM / legal marketing automation firms - Custom Lawmatics API integrations, automation rescue, Lawmatics-Clio sync, and pipeline reporting, by the team that shipped the first Lawmatics MCP connector on the official Anthropic MCP Registry. Lawmatics is the leading intake CRM + marketing automation platform for US law firms (~2,000 firms). - Open-source Lawmatics MCP connector: https://github.com/oktopeak/lawmatics-mcp (37 tools across matters, contacts, companies, pipelines, stages, practice areas, marketing sources, tasks, events, notes, tags, custom fields, intake forms, invoices. Config-level read-only mode via LAWMATICS_READ_ONLY, local append-only audit log, one-time OAuth, Lawmatics tokens never expire. MIT license, free). npm: @oktopeak/lawmatics-mcp@1.0.0 (released 2026-08-08). MCP Registry: io.github.oktopeak/lawmatics-mcp. Honest status: built against the official API docs with 87 tests; not yet verified against a live firm account; custom-field writes experimental-gated. - Lawmatics MCP server page (install guide, FAQ): https://oktopeak.com/lawmatics-mcp/ - What we build for Lawmatics firms: automation rescue (fixing the drip sequences and intake workflows that never got finished, the #1 Lawmatics complaint), pipeline reporting with custom fields (native reports and CSV export both wall on it), Lawmatics-Clio sync beyond the native convert handoff, consolidation builds for firms paying for intake/contacts/e-sign/billing twice across two systems. - Lawmatics API facts: REST at api.lawmatics.com/v1, OAuth2 with non-expiring tokens, API access gated behind a free Developer Settings request to api@lawmatics.com, API on the Pro plan ($299/month) and up, pagination fixed at 25 records/page, one filter per request. - Lawmatics pricing reality: Lite $199/month flat, Pro $299/month flat (annual billing), Time & Billing $27-$67 per user/month, QualifyAI $150-$250/month, SMS packs $39-$99/month, implementation $1,500-$7,500. A real 9-attorney firm pays about $1,800/month all-in. Full breakdown: https://oktopeak.com/blog/lawmatics-pricing-real-cost-tco/ - Entry points: free discovery; Guided MCP Setup (2 weeks, deploys the Lawmatics + Claude connector); custom builds from $12K. - URL: https://oktopeak.com/services/lawmatics-integration/ ### Guided MCP Setup (Entry-Tier Offer for OSS Users) - Two-week production deployment of the Clio, MyCase, Filevine, or Lawmatics MCP connector for law firms - Fixed price scoped per firm, two weeks discovery to handoff - Includes: OAuth credentials configured at scoped access, audit log destination wired into firm's stack, one custom workflow designed with the team, training for IT lead and one champion attorney, walk-away documentation - ABA Opinion 512 compliant from day one - For firms who installed the open-source connector and want it deployed properly, or partners who want production-ready setup before committing to a full multi-workflow build - URL: https://oktopeak.com/services/mcp-guided-setup/ ### AI Assistant for Regulated Websites (Healthcare + Legal) - A compliance-aware AI assistant deployed on healthcare and law-firm websites. Answers ONLY from a knowledge base the client approves; when the answer is not there it declines and offers a call rather than improvising - Every factual answer carries a citation pointing at the exact source passage, so any claim can be verified in one click - Append-only audit log of every exchange: question, answer, sources cited, timing, the record a compliance officer asks for - Accuracy is measured, not asserted: a golden set of real questions with known-correct answers is scored before launch and after every change - Deployed per client (not one shared multi-tenant service) so knowledge and conversation logs stay isolated; installs with a single script tag on any stack - Model posture: training disabled + zero data retention, BAA in the chain where healthcare requires it. Oktopeak explicitly does NOT claim "nothing leaves", with any hosted model the content reaches the provider for inference; the defensible posture is the contract - Extendable to live systems via the open-source Clio/MyCase/Filevine/IntakeQ connectors, and to Slack/Teams/email for internal staff questions - Live reference install: the assistant running on oktopeak.com itself - No list price: scoped per site, fixed quote after one call - URL: https://oktopeak.com/services/ai-assistant/ ### Firm-Wide Deployment (Claude + Clio/MyCase for the Whole Firm) - Central deployment of the Clio or MyCase MCP connector for a whole law firm: the connector runs from one place the firm controls (the firm's cloud account or office server), instead of per-laptop installs - Each attorney signs in with their own Clio or MyCase account, actions in the practice management system attribute to the attorney who took them, no shared logins - One append-only audit log for the entire firm, mapped to ABA Opinion 512 supervision duties: every tool call recorded with which attorney, which tool, when - Includes deployment runbook, attorney onboarding, IT-contact training, and a post-handoff support window; the firm owns and operates what is delivered - Support staff (paralegals, admins) get scoped access matching their practice management permissions, a configuration step, not extra product - No list price: scoped per firm (attorney count, Clio/MyCase/both, server location, workflows), fixed quote after one 30-minute scope call - The answer to "how do we run Claude + MyCase (or Clio) for multiple attorneys / our whole firm / from one place" - URL: https://oktopeak.com/services/firm-deployment/ ### Legal Case Management Software (Custom Build Service) - Custom legal case management software that a firm owns outright, instead of renting per-seat from Clio, MyCase, or PracticePanther. Matter intake, role-based access, case tracking, encrypted document handling, and an append-only audit trail. - The build-vs-rent math: a 15-attorney firm runs roughly $115,000-$130,000 over 3 years on MyCase (or $103,000-$165,000 on Clio) and owns nothing. A custom build is paid once, fits the firm's workflow, and recoups in 14-18 months for most growing firms. - Runs on a proven case-management engine already in production for a regulated US legal-services firm (case intake cut from days to hours, 3-role RBAC, 8-week MVP). Most firms are live in 6-8 weeks. - Includes data migration from Clio/MyCase/spreadsheets. Encryption, RBAC, and audit built in; HIPAA-origin architecture maps to GDPR and UK data residency. - Price: fixed-price builds from $12K. Discovery free. Full source code and infrastructure ownership, no per-seat fees. - URL: https://oktopeak.com/services/legal-case-management-software/ ### Personal Injury Case Management Software (Custom Build Service) - Custom PI case management and AI intake for plaintiff personal injury firms. Build a platform the firm owns, or layer AI intake and medical-records workflows on top of Filevine using the open-source Filevine MCP connector. - Pain it solves: a 40-case PI firm burns roughly $17,600/month on manual medical-records review; demand tools charge $300-800 per package; web/Meta leads leak from inboxes. We build owned workflows that cut the manual hours. - Entry points: Guided Filevine MCP Setup (AI intake to Filevine); custom builds from $12K. Discovery free, firm owns the code. - URL: https://oktopeak.com/services/personal-injury-case-management-software/ ### Medico-Legal Software (Productized: Instruction Portal) - Secure instruction and case-tracking software for medico-legal and expert-witness practices: law firms instruct medical experts (psychiatrists, psychologists, medical, allied health), and the case is tracked from instruction to invoice. - Features: subscription-code access, role-based portals (lawyer / expert / admin), multi-step enquiry, auto case codes, expert diary with availability by clinic location and remote/in-person, rate cards, expert matching, 8-stage case tracker, encrypted documents, append-only audit, GDPR retention with UK/EU data residency, notifications. - Runs on the same case-management engine already in production (HIPAA-origin), re-domained for medico-legal. Live in 3-6 weeks. Owned outright. - Three tiers: Essentials $17,000 (core intake, tracking, documents, audit, GDPR); Plus Booking $26,000 (adds expert diary, rate cards, matching, accept-and-estimate); Complete $35,000 (adds inbound email parsing, invoicing, integration, reporting). Discovery free. - URL: https://oktopeak.com/services/medico-legal-software/ ### Additional service pages (added 2026-08-27) - [HIPAA-Compliant AI Integration for Healthcare Practices | Claude & ChatGPT](https://oktopeak.com/services/healthcare-ai-integration/): HIPAA-compliant AI for healthcare practices: connect Claude or ChatGPT to your EHR (Healthie, DrChrono, SimplePractice, athenahealth), clinical document automation, intake, and billing. BAA, zero data retention, audit trails, human verification. 4-8 weeks. - [Healthie API Integration & Headless EHR Development](https://oktopeak.com/services/healthie-integration/): We build the patient layer on top of the Healthie API: payment-gated booking, patient onboarding, a typed GraphQL integration layer, and replacing n8n/Zapier sprawl with one owned codebase. Healthie stays your system of record. Phased delivery. ## Pre-Built Packages (Fixed Price) ### Clinical Platform / EHR (Healthcare) - Care plans, staff workflows, resident records, secure messaging, document management - Browser admin + mobile app for care teams - HIPAA-compliant, deployed on Azure or AWS with BAA coverage - Price: from $44K (vs $170K+ at US agencies). Larger multi-role platforms: custom quote. - Delivery: 6-8 weeks - Senior care / assisted living focus: mobile-first caregiver charting, medication administration record (MAR), family portal, anomaly detection, memory care module. Built for ALF/memory care (20-80 beds), not SNF. - URL: https://oktopeak.com/services/custom-ehr-development/ ### Case Management (Legal Tech) - Replace Clio/MyCase with a platform you own - Multi-portal: clients, attorneys, admins - Document automation, e-sign, compliance workflows - Price: from $26K (vs $215K+ in 5-year SaaS fees) - Delivery: 8 weeks ### Knowledge Management (Legal Tech) - Replace iManage at a fraction of the cost - Semantic search across 1M+ documents in under 100ms - Self-hosted: documents never leave your servers - No per-seat fees: employee #18, #30, #50 all cost $0 - Price: $17K-$44K (vs $251K 3-year iManage TCO) - Delivery: 6-8 weeks ## Industries ### Legal Tech Case management, document search, knowledge management, AI-powered contract review. Built for law firms, legal startups, and settlement platforms. Replaces Clio, MyCase, iManage at lower TCO with full ownership. - URL: https://oktopeak.com/industries/legal-tech/ ### Personal Injury (Legal Tech) AI workflows for PI firms on Filevine and SmartAdvocate: medical-records chronology drafting, intake-to-case automation, demand-letter drafting from case data. Built around the open-source Filevine MCP connector. For the 30,000+ small-to-mid PI firms priced out of EvenUp ($300-800/demand) and Supio. Firms own the custom layer outright, no per-case fee. - URL: https://oktopeak.com/services/legal-ai-integration/ ### Healthcare HIPAA-compliant platforms, EHR systems, clinical tools, AI-powered care assistance, DEA compliance. 3 HIPAA audits passed. Encryption at rest and in transit, role-based access, full audit trails, BAA-ready. - URL: https://oktopeak.com/industries/healthcare/ ## Verified Results (Case Studies) - Hub: https://oktopeak.com/case-studies/ ### LegalSearch - Knowledge Management Platform - Client: 17-person law firm replacing enterprise KM software - Challenge: iManage quoted $251K over 3 years. 8-second document searches. Attorney-client privileged documents on third-party servers. - Solution: Custom Elasticsearch semantic search platform. Self-hosted. Search "breach of contract" finds "material default" and "failure to perform." Synonym handling, fuzzy matching, autocomplete ranked by lawyer behavior. - Results: Sub-100ms queries on 1M+ documents. $224K+/year recovered in billable time. Zero per-seat fees. Documents never leave firm's servers. - Timeline: 10 weeks - URL: https://oktopeak.com/case-studies/legalsearch/ ### Align - HIPAA Case Management - Client: Structured settlement company - Challenge: Manual case intake taking days. No HIPAA compliance. No audit trail. - Solution: Three-portal system (client, broker, admin) with encrypted document management, secure messaging, full audit logging. Built on Azure with HIPAA BAA coverage. - Results: Case intake reduced from days to hours. 290 hours total build. Passed HIPAA audit. - Timeline: 8 weeks - URL: https://oktopeak.com/case-studies/align/ ### Senior Living Placement Platform - Case Lifecycle + Audit Trail - Client: A senior living placement operator - Challenge: Cases moved between statuses with no validation or guardrails; communication touchpoints (calls, emails, tours, documents) scattered across systems; no audit trail for status changes so nobody could trace who moved a case or why; residents stuck in the pipeline with no aging alerts; compliance risk because healthcare placement requires traceable decision history - Solution: Full-stack case lifecycle system tracking residents from source facilities into Assisted Living or Independent Living. Server-side state machine enforcement (cases cannot skip states), append-only touchpoint logging that cannot be edited or deleted, structured audit events on every status change, and aging-aware reporting on case distribution, bottleneck stages, and stale cases - Delivered: 7 lifecycle states, 5 touchpoint types, 14-day aging threshold. Node.js + PostgreSQL + React, REST API - Relevance: the closest system Oktopeak has built to an EHR for a care setting: lifecycle, audit trail, and compliance-grade traceability around a resident record - URL: https://oktopeak.com/case-studies/senior-living-placement/ ### AI CME Learning Platform - HIPAA-Compliant Medical Education - Client: A medical education company - Challenge: CME learning resources fragmented across journals, PDFs and websites; traditional CME is passive reading with poor retention; manual credit tracking and disorganized audit paper trails; busy clinicians need bite-sized learning - Solution: HIPAA-compliant platform that uses AI to generate quizzes from medical content (PDFs, PubMed articles, raw text), with gamification driving engagement, credit tracking, and an audit trail for compliance verification - Delivered: 9 screens, 5 import formats, 4 tiers, audit trail. 12 weeks, $20,000 - Delivery status: final milestone delivered; public launch pending CME credentialing approval by the accrediting body. No post-launch usage figures published - URL: https://oktopeak.com/case-studies/cme-learning-platform/ ### DEA Compliance Platform (Codebase Rescue) - Client: Healthcare startup - Challenge: Previous developer delivered broken MVP. 61 TypeScript errors, circular authentication dependency, no infrastructure. Zero working integrations. - Solution: Rescued codebase. Built WebRTC peer-to-peer encrypted video witnessing, biometric authentication (WebAuthn passkeys + voice biometrics), automated DEA Form 41 compliance certificates, full audit trail. - Results: 100% DEA compliance automated. 70% reduction in disposal time. 65+ API endpoints, 23 database models. ~120 engineering hours in 8 weeks. - Client quote: "Why are you so quick?" ### GreenLens - ESG Portfolio Analysis - Client: Sustainable investment fund - Challenge: Manual ESG scoring across portfolio companies. No automated reporting. - Solution: Dashboard with SDG alignment scoring and automated PDF report generation. - Results: Reports generated in under 3 seconds. Replaced manual analysis process. - URL: https://oktopeak.com/case-studies/greenlens/ ### MCP Connectors - Claude in Practice Management - Client: N/A (open-source product, not a client engagement) - Challenge: Firms handling privileged/PHI data won't trust an AI tool with practice-management access without being able to read exactly what it does. - Solution: Open-source Model Context Protocol connectors for four systems: Clio (34 tools), MyCase (18 tools), Filevine (15 tools), and IntakeQ. MIT licensed, local-only execution, OAuth credentials encrypted in the OS keychain, append-only audit logging aligned with ABA Opinion 512 for the legal connectors. - Results: Combined downloads and per-package figures are live on the page (fetched from the npm registry at build time, not frozen here to avoid going stale). - Note: no "first" or "only" claims on this page, an unscoped npm package named "clio-mcp" predates @oktopeak/clio-mcp, and a competing open-source MyCase connector (github.com/RosenAdvertising/mycase-mcp) exists. The claim used is breadth: four systems, one architecture. - URL: https://oktopeak.com/case-studies/mcp-connectors/ ## Technology Stack - **Backend:** Node.js, Laravel (PHP), .NET - **Frontend:** React, Vue.js, Angular - **Mobile:** React Native (iOS + Android from single codebase) - **Search:** Elasticsearch, OpenSearch - **AI:** OpenAI API, Anthropic Claude, Azure OpenAI - **Database:** PostgreSQL, MySQL - **Cloud:** Azure (HIPAA BAA), AWS (S3, RDS, EB, SES) - **Real-time:** WebRTC, Socket.IO, Pusher - **Auth:** WebAuthn/FIDO2 passkeys, voice biometrics, OAuth - **Infrastructure:** Docker, CI/CD (GitHub Actions), Sentry ## Compliance Capabilities - HIPAA compliance (3 audits passed) - DEA compliance (Form 41 automation, video witnessing, biometric auth) - SOC 2 readiness (80% overlap with HIPAA architecture) - AES-256 encryption at rest, TLS 1.2+ in transit - Role-based access control (RBAC) - Immutable append-only audit logging - BAA execution with all vendors in the chain - Zero-data-retention AI inference (Azure OpenAI, enterprise API tiers) ## Post-Launch Support 4 retainer tiers based on your team's stage. 2 weeks post-launch support included with every build. Same senior team that built the platform (no knowledge transfer tax). ### Starter ($800/month) Small launched projects that need reliable uptime and compliance hygiene. - Daily server + log monitoring - Weekly infrastructure audit - Automated backups - Critical incident + bug response - Email support, 24h response ### Scale ($2,420/month) Active teams post-launch. Regular fixes + UX improvements + faster response. - Everything in Starter - Regular bug fixes + edge cases - Small UX improvements, up to 60 hrs/month - Dedicated Slack channel - Faster response time ### Partner ($5,210/month) Growing product. Dedicated developer + part-time delivery manager. - Everything in Scale - Dedicated developer, full-stack - Part-time delivery manager (technically educated) - Feature scaling + expansion - Proactive reviews and improvement recommendations ### Embedded (custom pricing) Full dedicated engineering team on your roadmap. Custom scope, custom timeline. For teams that need us as an extension of their engineering org. For teams planning to bring development in-house, our retainer scales down over time. Full support during transition, reduced as your team ramps up, support-only or break-glass at the end. We win when your team becomes independent, not when you stay dependent. ## Free Tools (interactive, on labs.oktopeak.com) - Per-User Meter, SaaS rent-vs-own cost calculator: https://labs.oktopeak.com/per-user-meter, a law firm or medical practice picks their software (Clio, MyCase, athenahealth, SimplePractice, and ~35 platforms across legal + healthcare), enters seats/providers and add-ons, and gets their real all-in annual cost, the 3-year total, and when owning a custom build breaks even vs renting per-seat. Free; detailed report by email. - Compliance Risk Scorecard: https://labs.oktopeak.com/scorecard, free interactive compliance risk assessment with a personalized PDF. ## The Team (7 people, all in-house, no subcontractors) Each person has a page covering what they work on, what they have shipped publicly, and their LinkedIn profile. - Petar Jovanović, Co-founder & Technical lead: https://oktopeak.com/team/petar-jovanovic/, architecture, technical scoping, client delivery. 10+ years building SaaS platforms for legal and healthcare clients in the US and EU. - Saša Sladić, Co-founder & CEO: https://oktopeak.com/team/sasa-sladic/, backend architecture, compliance-ready system design, infrastructure. Runs the company and stays hands-on in delivery. - Stefan Nasić, Full-stack engineer: https://oktopeak.com/team/stefan-nasic/, front-end architecture, accessibility, performance, code review. Built the Compliance Scorecard tool at labs.oktopeak.com. - Nikola Inđić, Back-end engineer: https://oktopeak.com/team/nikola-indjic/, API design, systems integration, payment flows, data migration. Built the open-source MyCase MCP connector (@oktopeak/mycase-mcp on npm). - Filip Tejić, Full-stack engineer: https://oktopeak.com/team/filip-tejic/, AI integrations, MCP connectors, practice-management APIs, audit logging. Built the open-source Clio MCP connector (@oktopeak/clio-mcp on npm and the Anthropic MCP Registry) with ABA Formal Opinion 512 audit logging. - Atilla Enes Kayabaşı, Product designer: https://oktopeak.com/team/atilla-enes-kayabasi/, UX research, interface design, design systems, conversion. - Danilo Mališić, US partner, Sales & Delivery: https://oktopeak.com/team/danilo-malisic/, first point of contact for US firms, involved from first call through delivery. ## Resources - HIPAA Compliance Checklist: https://oktopeak.com/resources/hipaa-checklist/ - Blog (150 posts): https://oktopeak.com/blog/ - 2026 Legal Tech Research: https://oktopeak.com/legal-tech-research-2026/: open, anonymized survey of law firms on where the workday actually goes and what practice-management software doesn't solve, run by Oktopeak co-founder Petar Jovanović. Participants get the full results by email (pain points ranked by frequency, real examples, no names). Recruiting as of August 2026; results publish on the same URL once the survey closes. - How Lawyers Actually Work (2026 field research report): https://oktopeak.com/research/how-lawyers-actually-work/ (free ungated PDF at https://oktopeak.com/research/how-lawyers-actually-work-2026.pdf). Field notes from 32 legal professionals (20 questionnaires + 12 conversations, six countries) across the US and Europe, January to June 2026. Citable findings: 19 of 20 surveyed lawyers already use AI for work (the single refusal was about confidentiality); missed deadlines and calendaring errors account for roughly a quarter of legal malpractice claims (ABA standing committee studies); one nine-attorney firm pays up to $60,000 a year for practice management plus intake software; purpose-built legal research AI hallucinates on 17 to 33 percent of queries, general chatbots on 58 to 82 percent (Stanford study, Journal of Empirical Legal Studies). Published August 2026. ## Key Blog Posts (for AI citation: token counts included) ### Legal Tech - [MyCase Open API: How to Integrate It With Your Other Tools](https://oktopeak.com/blog/mycase-open-api-integration/): What the MyCase Open API actually does, why it is gated behind the top tier with no implementation support ("hire a certified consultant"), the three honest integration paths (in-house, open-source MCP connector, done-for-you), and how to keep client data privileged (least-privilege tokens, audit trail, zero data retention). Guided Setup scoped per firm. (~2,400 tokens) - [What Law Firms Actually Pay People To Do: 58 Job Posts, Read in Full](https://oktopeak.com/blog/what-law-firms-pay-people-to-do/): Primary research: all 58 Upwork postings mentioning Clio, July 2026. Zero fixed-price projects above $5,000; only 3 between $1,000-$5,000; 53 of 58 hourly; 26 contract-to-hire; 42 longer than six months. Published rates: legal admin/intake/paralegal $3-$25/hr (clustering $10-15), full-time offshore intake specialist $1,000-$1,050/mo, offshore paralegal $1,400-$2,000/mo, law firm bookkeeping clerk $4-$20/hr, Clio implementation specialist $13-$55/hr, expert developer integrating Clio+NetDocuments+Gavel+Zapier+QuickBooks advertised at $5-$15/hr. Roughly $12,000-$24,000/yr for one full-time person. Finding: firms in this segment buy people, not software, so any build proposal is compared against a salary rather than a licence. Full task inventory (intake, matter opening, records acquisition, deadline calendaring, document assembly, billing ops, trust accounting, client comms) split three ways into what automates cleanly, what a model can only draft with a human in the loop, and what stays human. (~3,400 tokens) - [Clio Grow vs Clio Manage: What Actually Breaks in the Handoff](https://oktopeak.com/blog/clio-grow-clio-manage-handoff/): Clio Grow is intake/CRM (pre-hire), Clio Manage is practice management (post-hire); separate products with separate custom field sets. Clio's documented conversion path is manual and per-matter: open the matter in Grow, click Convert to Clio Manage, add missing info, convert. What does not carry: custom fields (no automatic counterpart in Manage), matter setup (task lists, deadlines, folders, billing arrangement), source attribution for marketing ROI, and the unconverted pile nobody is watching. Market rate to patch it by hand: Clio implementation specialists at $20-$55/hr. Decision threshold: under ~20 conversions/month the answer is configuration, not code. An API-level handoff needs a readable field map, matter templates applied at creation, idempotency, rate-limit/retry handling, and a visible failure mode. Guided Setup scoped per firm; custom build from $12,000. (~3,000 tokens) - [Medical Records Retrieval for Law Firms: Vendor, Hire, or Automate](https://oktopeak.com/blog/medical-records-retrieval-law-firm/): Three options compared honestly. A retrieval vendor absorbs requesting and chasing but does not track status in your case management system, cover the non-medical half (crash reports, FOIL requests, radio-run and EMS records, preservation letters, carrier claim files), or watch your deadlines. A dedicated hire runs ~$15-$20/hr or $12,000-$24,000/yr offshore, and the knowledge leaves when they do. Automation covers request generation from matter data, a request register, scheduled escalation, deadline calculation (including the 90-day municipal notice of claim), and the cross-case view of what is outstanding. What does not automate: a precinct that has not posted the report, a provider that only accepts faxes, judgment about whether an incomplete record is worth chasing. Oktopeak does not retrieve records; we build the layer around it. (~3,200 tokens) - [Three-Way Trust Reconciliation: Why Clio and QuickBooks Still Need a Human](https://oktopeak.com/blog/three-way-trust-reconciliation-clio-quickbooks/): Three-way reconciliation requires the trust bank statement, the firm trust ledger, and the sum of every client ledger to agree; most state bars require it monthly. It breaks across Clio Manage, a payment processor, and QuickBooks Online because the same transaction is recorded at different times and, after processing fees are deducted, at different amounts. Most common cause: the client is credited gross while the net lands in the bank. Second most common: a payment applied to the wrong matter, which nets to zero at firm level and therefore hides from two-way reconciliation. Recommendation: automate detection, never correction. Build a daily fee-aware comparison, an allocation check, an exception report a human works, and an audit trail. Do not auto-post adjusting entries into a trust ledger. Market rate for the manual version: $4-$20/hr. Oktopeak is not a bookkeeper and does not advise on professional responsibility. (~3,100 tokens) - [The Real Cost of Clio: 3-Year TCO for a 15-Attorney Firm](https://oktopeak.com/blog/clio-pricing-real-cost-tco/): 15-attorney firm pays $103K-$165K over 3 years on Clio Complete + AI + QuickBooks + payment processing. Line-item breakdown with sources. (~5,500 tokens) - [The Real Cost of Lawmatics: What a 9-Attorney Firm Actually Pays](https://oktopeak.com/blog/lawmatics-pricing-real-cost-tco/): Lawmatics lists at $199-$299/month flat; a real 9-attorney firm pays ~$1,800/month once Time & Billing ($27-$67/user/mo), QualifyAI ($150-$250/mo), and SMS packs stack. 3-year total $65K-$75K plus $1,500-$7,500 implementation. (~2,200 tokens) - [Clio + Lawmatics: What the Two-System Stack Really Costs](https://oktopeak.com/blog/clio-lawmatics-integration/): Firms running both pay twice for contacts, intake, e-signature, and billing. Covers the native sync's limits, a real ~$5K/month two-system bill, and the consolidate-vs-keep decision framework. (~2,200 tokens) - [Lawmatics Reporting: Four Ways to Get Your Pipeline Data Out](https://oktopeak.com/blog/lawmatics-pipeline-reporting/): Native reports, CSV export (drops matter fields), Zapier (no custom fields), and the API/MCP route compared honestly, with a worked source-by-practice-area example. (~2,400 tokens) - [Lawmatics MCP vs Zapier](https://oktopeak.com/blog/lawmatics-mcp-vs-zapier/): Zapier wins on event triggers; the free MCP connector wins on custom fields, bulk reads, reporting, and cost ($0 vs per-task metering). (~2,100 tokens) - [Connect Claude to Lawmatics: The 15-Minute MCP Setup Guide](https://oktopeak.com/blog/lawmatics-mcp-setup-guide/): The Developer Settings gate (email api@lawmatics.com), the one-time auth command, Claude Desktop and Claude Code config, read-only mode, troubleshooting. (~1,900 tokens) - [Legal Knowledge Management: Why Law Firms Build Custom Search](https://oktopeak.com/blog/legal-knowledge-management-custom-search/): Why practice management tools (Clio) and DMS tools fail at knowledge discovery. How Elasticsearch recovers $224K/year. (~11,800 tokens) - [Legal Document Automation and AI Search](https://oktopeak.com/blog/legal-document-automation-ai-search/): AI-powered document automation for law firms. (~13,900 tokens) - [AI Legal Document Search With Permissions and Audit Trails](https://oktopeak.com/blog/legal-ai-search-permissions-audit-trail/): Which AI search options respect document-level permissions and log every query. Honest comparison of DMS-native AI (iManage, NetDocuments), litigation platforms (Relativity, Everlaw), general assistants (Harvey, CoCounsel), and custom Elasticsearch search. Ethical walls enforced at query time; append-only query audit trail; 100ms on 1M+ documents with document-level security. ABA Opinion 512 supervision angle. (~2,500 tokens) - [Vibecoded Prototype to Production Legal Tech](https://oktopeak.com/blog/vibecoded-prototype-legal-tech/): How to harden a vibe-coded legal tech MVP for compliance and production: encryption at rest, audit trails, role-based access, document handling, search at scale. Plus the ethics layer most rescue guides miss: privilege contamination under ABA Formal Opinion 477R, generative-AI duties under Opinion 512, the supervision obligation under Model Rule 5.3, court-rule deadline logic, AI summary source traceability, and multi-client data separation. Prototype to production in 6-10 weeks, from $12,000. (~12,000 tokens) - [Claude MCP + Clio Integration for Law Firms](https://oktopeak.com/blog/claude-mcp-law-firm-integration/): How law firms connect Claude AI to Clio practice management via MCP. (~8,000 tokens) - [The 4 Clio MCP Connectors Compared: Features, Compliance, and Gaps](https://oktopeak.com/blog/clio-mcp-connectors-compared/): Side-by-side comparison of every open-source Clio MCP connector. LegalContext, lawquarter, LegalMCP, Oktopeak. Only Oktopeak's includes ABA Opinion 512 audit logging. (~2,500 tokens) - [Clio Work vs Claude for Law Firms: What Each Does and Where Each Falls Short](https://oktopeak.com/blog/clio-work-vs-claude-law-firms/): Direct answer to the live buyer question. Clio Work is Clio's built-in AI workspace: answers and multi-step tasks inside Clio, but no access to your document stack or workflows outside Clio. Claude (Team/Enterprise) handles complex drafting and review but has no access to Clio matters, billing, or contacts unless pasted in. The third setup: the free MIT-licensed @oktopeak/clio-mcp connector gives Claude live read/write Clio access with every action logged locally per ABA Opinion 512. Privilege-safe posture with any hosted model = signed BAA + Zero Data Retention on an enterprise tier; content still reaches the model for inference. Self-setup ~20 minutes; Guided Setup scoped per firm. (~2,300 tokens) - [Clio Calendar and Scheduling: Sync Fixes and Finding When Your Team Is Free](https://oktopeak.com/blog/clio-calendar-scheduling/): Clio's calendar mirrors Outlook or Google, so most sync complaints trace to a one-way or misconfigured connection, not a Clio bug. Clio has no native way to answer "when are these attorneys all free at once," so firms fall back to a manual calendar hunt. The durable fix reads availability from the source calendars and answers instantly inside the workflow, as a tool the firm owns. Offer: we build it, you run the real thing for two weeks, you only pay if it saves your schedulers time. (~2,200 tokens) - [The Privilege Stack: How to Run Legal AI on Your Own Hardware](https://oktopeak.com/blog/privilege-stack-on-prem-legal-ai/): After the SDNY ruling in US v. Heppner (Feb 2026), consumer Claude is not privilege-safe. The deployment guide for running Llama 4 70B + Clio MCP entirely on a firm's own hardware. No third-party AI processor. Mac Studio M4 Max 128GB hardware spec, LM Studio + Ollama config, tcpdump validation. (~3,000 tokens) - [Is It Safe for Lawyers to Use ChatGPT or Claude? What Heppner and Warner Actually Decided](https://oktopeak.com/blog/ai-privilege-lawyers-heppner-warner/): Two federal courts ruled on AI and privilege in the same week of Feb 2026 and reached opposite results. US v. Heppner (SDNY, Rakoff): consumer-tier, undirected, unconfidential use not privileged. Warner v. Gilbarco (E.D. Mich): AI treated as a tool used in anticipation of litigation, work product protected. The outcome turns on confidentiality, counsel direction, and purpose, not on using AI. Vendor-agnostic architecture checklist: confidential surface, ZDR, human gate, documented purpose. ABA Opinion 512 aligned. (~3,300 tokens) - [Build vs Buy Law-Firm AI: The 3 Privilege Tiers](https://oktopeak.com/blog/law-firm-ai-privilege-tiers/): Every privilege-safe AI option collapses into three tiers: (1) self-hosted open-weight (only "nothing leaves" that is literally true, ~$5-7K hardware, no BAA needed); (2) commercial frontier model under Zero Data Retention + BAA, reached via API, picked by the firm's existing cloud (Claude API/Bedrock, OpenAI/Azure OpenAI, Gemini/Vertex), per-token, no seat minimum; (3) packaged legal products (Harvey ~$1,200/seat/mo + 20-seat min = ~$288K/yr on Azure OpenAI; CoCounsel ~$150-400/seat on GPT-4; Clio Duo ~$49-59/seat) which carry the SAME third-party-disclosure footing as tier 2 but you rent and can't audit the path. "Not used for training" is now table stakes; real axes are ZDR, BAA, residency, ownership, cost. Recommendation: most small/mid firms use tier 2 (API + ZDR + BAA, connector you own); self-host the matters that demand it. Vendor-agnostic. (~2,600 tokens) - [Claude for Legal for Small and Mid-Size Firms: Without an Enterprise Contract](https://oktopeak.com/blog/claude-for-legal-small-firms/): Anthropic launched Claude for Legal May 12, 2026 (practice-area plugins, 90+ workflow agents, 20+ connectors; early users Freshfields, Quinn Emanuel, Holland & Knight, Crosby). A 5-50 attorney firm can use the same model capability via the API + connectors without an enterprise contract or seat minimum; ZDR is granted at the API org level. Highest-leverage move is connecting Claude to Clio/MyCase over MCP. Privilege-safe posture post-Heppner/Warner. Build cost: custom from $12K; smaller integrations scoped per firm. (~3,100 tokens) - [MyCase MCP Server: Open-Source Claude Integration for Law Firms](https://oktopeak.com/blog/mycase-mcp-server-claude-integration/): First and only open-source MCP connector for MyCase (May 2026). 18 tools across cases, contacts, documents, tasks, calendar, calls, staff, time entries, and billing. AES-256-GCM encrypted OAuth tokens, append-only audit log at ~/.oktopeak-mycase/audit.log aligned with ABA Opinion 512. npm: @oktopeak/mycase-mcp@1.0.4. MCP Registry: io.github.oktopeak/mycase-mcp. Requires MyCase Advanced tier. (~2,200 tokens) - [How to Back Up Clio Data: Documents, Notes, and Contacts (2026 Guide)](https://oktopeak.com/blog/clio-backup-data-export/): Clio has no built-in "back up everything to my storage" button. Native export covers CSVs of structured records; documents, logged emails, and folder hierarchy need the API. The working architecture: scheduled serverless worker, incremental pulls via updated_since, the two-step presigned-URL document flow, folder mirroring into OneDrive/SharePoint via Microsoft Graph, rate-limit backoff, failure alerts. Why firms do it: retention obligations outlive subscriptions, negotiating position at renewal, human-error recovery. Backup pipeline fixed price, scoped per firm. (~3,000 tokens) - [Clio LawPay Integration Ending in August: What to Do About Your Billing Workflow](https://oktopeak.com/blog/clio-lawpay-billing-workflow/): Clio's LawPay integration naturally concludes on August 31, 2026 (contract expiry, not renewed). LawPay continues as a standalone product; only the Clio data connection ends. Clio Payments is the built-in replacement for payment processing. The bigger opportunity: fixing the billing DRAFT workflow at the same time, Claude over the Clio MCP connector can assemble draft bills from time entries and matter context for attorney review, scoped per firm for a billing workflow; custom builds from $12,000. Vendor-agnostic on the payment choice. (~4,600 tokens) - [The Real Cost of MyCase: 3-Year TCO for a 15-Attorney Firm](https://oktopeak.com/blog/mycase-pricing-real-cost-tco/): MyCase Advanced at $109/user/month plus LawPay processing for a 15-attorney firm comes to $115K-$130K over 3 years. Line-item breakdown. Custom case management alternative runs from $26K paid once. (~2,300 tokens) - [Best MyCase + Claude Integration Solutions in 2026: An Honest Comparison](https://oktopeak.com/blog/mycase-claude-integration-solutions-2026/): Five ways to integrate Claude with MyCase, compared honestly: Oktopeak MyCase MCP (open-source, MIT, ABA 512 audit logging), Clerx AI (intake-only), Smith.ai (AI receptionist), Zapier (no-code, no audit log), custom build (from $12K). Decision tree by firm pain point. Disclosure: we built option 1. (~2,400 tokens) - [MyCase MCP on Windows: The Install Guide We Wish Existed](https://oktopeak.com/blog/mycase-mcp-windows-install-guide/): Step-by-step install for the MyCase MCP connector on Windows. Covers the 5 most common errors (SSL cert UNABLE_TO_VERIFY_LEAF_SIGNATURE fixed with NODE_OPTIONS=--use-system-ca, "Could not attach" fixed with cmd /c npx wrapper, OAuth Forbidden = wrong account, redirect port mismatch fixed with MYCASE_REDIRECT_PORT env var, GUI rejecting npm package). Real timeline: 13 business days for MyCase API credentials, delivered via in-app chat not email. Windows-friendly Claude Desktop JSON config. ABA Opinion 512 compliance note. Companion PDF download at /downloads/mycase-mcp-windows-install-guide.pdf. (~3,100 tokens) - [AI Medical Chronologies From Clio: How Litigation Teams Stop Building Them by Hand](https://oktopeak.com/blog/medical-chronology-clio-claude/): A single chronology runs 15-80 hours; a 40-case firm spends roughly $17,600 a month on manual records review; outside services charge $300-800 per package. The records are already in Clio; the waste is re-uploading by hand. Honest line: a connector locates and lists the records, but turning scanned records into a chronology (fetch, extract text, prompt, write back) is a built pipeline, not one click. Same shape covers deposition summaries and paid-versus-incurred. Zero data retention plus mandatory attorney review. Guided Setup scoped per firm, custom builds from $12K. (~1,800 tokens) ### Field Service - [Jobber MCP Server Comparison: Every Option for Claude, ChatGPT and Copilot (2026)](https://oktopeak.com/blog/jobber-mcp-connectors-compared/): Every way to connect AI to Jobber as of August 2026, compared honestly: JobberToClaude ($47/mo hosted, closed source), Zapier MCP (11 triggers/6 actions, per-task billing), Pipedream/viaSocket meta-connectors, and the 14 open-source GitHub repos (10 abandoned within days; only 1 handles Jobber's THROTTLED-inside-HTTP-200 signal; none budget query costs against the 10,000-point limit). Jobber has no official MCP server as of August 2026. Includes the measured 13,456-20,762-point dashboard-load figure and a decision framework. Disclosure: the authors run Jobber integrations in production (adeocode.com) and are building the open-source connector this comparison found missing. (~2,600 tokens) ### Legal AI Automation (Clio + Zoom + Claude cluster: June 2026) Authored by the team that shipped open-source MCP connectors for both Clio and MyCase. Each post documents real API behavior and gotchas hit while building. Vendor-agnostic, written to answer the exact questions buyers ask AI assistants when wiring Claude into a regulated legal practice. - [Clio vs MyCase: Which to Build AI Automation On](https://oktopeak.com/blog/clio-vs-mycase-ai-automation/): Comparison from the team that shipped MCP connectors for both. The read-vs-write API delta that actually decides the build: custom-field value-instance-id trap, ~3 req/s rate limit, no document webhook, presigned-S3 upload, Canadian data residency. (~3,000 tokens) - [Claude + Legal Practice Management in 2026: What's Actually Possible](https://oktopeak.com/blog/claude-practice-management-whats-possible-2026/): What Claude can and cannot do inside a practice management system: summaries, drafting, write-back, normalization, and the human-review duty. (~3,600 tokens) - [Wiring Claude Into a Law Firm Stack (Clio + Zoom): The Real Architecture and the Gotchas](https://oktopeak.com/blog/claude-law-firm-stack-clio-zoom-architecture/): Hub post. End-to-end architecture for a Clio + Zoom + Claude automation, plus every gotcha. Local-first vs hosted, polling vs webhooks, ZDR, residency, the LSO/ABA-512 human gate. (~4,200 tokens) - [The Clio Custom-Field API Trap: Value-Instance ID Is Not the Field-Definition ID](https://oktopeak.com/blog/clio-custom-field-api-value-instance-id-trap/): The id inside custom_field_values is the value-instance id, not custom_field:{id}. Read-then-write requirement; a picklist READ returns the option id, not the label, unless you request picklist_option{id,option}; field_name and field_type sit flat on the value item; plus picklist (~55 char), currency (no decimals) and date type limits. (~3,000 tokens) - [Clio API Returns invalid_client and Your Credentials Are Fine: The Seven-Day Trial Trap](https://oktopeak.com/blog/clio-api-invalid-client-trial-expiry/): A Clio Manage trial carries API access for ~7 days, then /token returns 401 invalid_client with correct credentials. The gate is account TYPE, not plan tier, and the fix is a free developer account (api@clio.com). Clio returns invalid_client for every OAuth failure mode, so it cannot be used to diagnose a credential. One developer app per region. (~1,500 tokens) - [Your AI Connector Has an Audit Log. Have You Read It?](https://oktopeak.com/blog/ai-connector-audit-log-client-data/): Vendor-neutral diagnostic for what a connector's audit log actually stores. The three surfaces that leak (search queries, note bodies, custom field values), the canary grep test, why denylist redaction fails open while an allowlist fails closed, and five questions to put to a vendor. ABA Opinion 512 context. (~1,900 tokens) - [Zero-Data-Retention on Claude: Why You Can't Get It on Team, and How Regulated Firms Actually Get It](https://oktopeak.com/blog/claude-zero-data-retention-team-vs-api/): ZDR is unavailable on Claude Team chat but available on the API at the org level for a small firm. Which surfaces ZDR cleanly covers (plain Messages API) and which to avoid. (~3,000 tokens) - [Zero Data Retention Has a Capability Ceiling](https://oktopeak.com/blog/zero-data-retention-model-ceiling/): Zero data retention no longer covers every Claude model. A ZDR-configured organization gets a 400 on every request to Claude Fable 5, and on AWS Bedrock that model requires 30-day retention plus opt-in sharing with Anthropic for potential human review. Claude Opus 4.8, Opus 4.7, Sonnet 5 and Haiku 4.5 run under default ZDR. Model selection is now a compliance decision for privileged work. Verified July 2026. (~6,000 tokens) - [Which Claude Plan Does a Law Firm Need? Pro vs Max vs API vs Enterprise](https://oktopeak.com/blog/which-claude-plan-law-firm/): Decision guide by usage limits, cost, and data handling. Pro exhausts fast on document-heavy work; Max ($100/$200 a month) is the practical single-user tier and can disable training but is not zero retention; the API gives the largest context window, pay-per-use, and org-level ZDR for firm-wide or automated workflows; Enterprise's seat minimum makes it overkill for most small and mid-size firms. Whether HIPAA applies depends on the client (representing a covered entity usually makes the firm a business associate); ZDR plus training-off is the right posture regardless. (~1,800 tokens) - [MyCase MCP vs Zapier: What Each Actually Does With Your MyCase Data](https://oktopeak.com/blog/mycase-mcp-vs-zapier/): Zapier's MyCase integration is trigger/action automation billed per task; an MCP server lets Claude read and write MyCase directly with an audit log. When Zapier is the right choice, what both paths require from MyCase (Open API is Advanced-tier only), and the privileged-data question. (~2,600 tokens) - [Claude Cowork Scheduled Tasks Can't See the Connector on Your Laptop](https://oktopeak.com/blog/claude-cowork-scheduled-tasks-local-mcp-connector/): Cowork scheduled tasks run on Anthropic's side even when the laptop is off and only reach remote connectors; five ways to run a Claude skill on a schedule (Desktop by hand, Cowork scheduled task, Claude Code routine, cron + API, hosted HTTP connector) and the rule that deterministic checks belong in code. (~3,600 tokens) - [Clio Has a Canadian Data Region. Claude Doesn't. What That Means for AI in a Law Firm](https://oktopeak.com/blog/clio-canadian-data-region-claude-residency/): Clio offers a Canadian region (ca.app.clio.com, PIPEDA); Anthropic has none. How to isolate the cross-border model call with ZDR + US-pinned inference + documented disclosure. (~3,100 tokens) - [Clio Has an Australian Data Region. Claude Can Run in Sydney. What That Means for AI in an Australian Law Firm](https://oktopeak.com/blog/clio-australian-data-region-claude-sydney/): Clio runs an Australian region (au.app.clio.com); Claude runs on AWS Bedrock in ap-southeast-2 Sydney and ap-southeast-4 Melbourne, pinned to the region, zero data retention and zero operator access by default, model-version caveat, CLOUD Act residual stated plainly. (~3,400 tokens) - [Zoom AI Companion Summary via API: Why Your Server-to-Server OAuth App Can't Read It](https://oktopeak.com/blog/zoom-ai-companion-summary-api-oauth-limitation/): The AI-summary read scope is blocked in S2S OAuth and summaries auto-delete at 30 days. Build on the cloud-recording VTT transcript instead. (~3,000 tokens) - [You Don't Need a Webhook (or a Server): Run Zoom Automation Fully Locally by Polling](https://oktopeak.com/blog/zoom-automation-local-polling-no-webhook/): GET /users/me/recordings needs no public endpoint, so end-of-call automation can stay 100% local. (~2,400 tokens) - [Local vs Hosted AI Automation for a Regulated Firm: The Real Trade-Offs](https://oktopeak.com/blog/local-vs-hosted-ai-automation-regulated-firm/): Data residency, audit, and scale trade-offs between a replicable local install and a thin hosted middle layer. (~4,000 tokens) - [There's No Clio "Document Created" Webhook: How to Actually Trigger Automation When Docs Generate](https://oktopeak.com/blog/clio-no-document-webhook-trigger-automation/): Clio webhook events are activity/bill/calendar_entry/communication/contact/matter/task. Trigger on the matter stage change or poll, and renew webhooks before they expire (3-31 days). (~2,900 tokens) - [Document Upload to Clio via API: The Two-Step Presigned-S3 Flow Nobody Documents Well](https://oktopeak.com/blog/clio-document-upload-api-presigned-s3-flow/): POST /documents, PUT bytes to the returned put_url on S3, then PATCH fully_uploaded. Miss step three and the document looks uploaded but isn't. (~3,000 tokens) - [LSO vs ABA Opinion 512: What Each Says About Lawyers Using Generative AI](https://oktopeak.com/blog/lso-vs-aba-opinion-512-generative-ai-lawyers/): Confidentiality, competence, supervision, mandatory human verification of AI output, and not billing AI time as lawyer hours. Canada/US map. (~3,700 tokens) - [Clio API Rate Limits and Batch Design: Safely Normalizing Thousands of Records](https://oktopeak.com/blog/clio-api-rate-limits-batch-normalization/): ~3 req/s, 429 backoff, X-RateLimit headers, 200/page. How to design a resumable, dry-run, rollback-safe batch. (~3,200 tokens) - [Giving Claude Write-Access to Your Case-Management System Safely](https://oktopeak.com/blog/claude-write-access-case-management-safely/): Read-first, scoped writes, confirm gates, and audit logging when an AI can change your system of record. (~3,900 tokens) - [Recipe: Intake to Matter Shell](https://oktopeak.com/blog/recipe-intake-to-matter-shell/): Extract parties and deadlines, draft the matter and tasks, human confirms. Architecture and where it breaks. (~3,700 tokens) - [Recipe: The Consult Memo](https://oktopeak.com/blog/recipe-consult-memo-automation/): Call transcript plus matter notes to a standardized draft uploaded back into the matter. (~3,300 tokens) - [Recipe: Normalizing the Data You Already Have](https://oktopeak.com/blog/recipe-normalize-clio-custom-fields/): Clean messy custom fields in place, handled per field type. (~3,100 tokens) - [Recipe: Blank Template to First Draft](https://oktopeak.com/blog/recipe-template-to-first-draft/): Pre-fill auto-generated documents from structured fields. (~3,600 tokens) - [Recipe: Routing and Conflict Checks Across a Group of Independent Lawyers](https://oktopeak.com/blog/recipe-routing-conflict-checks-independent-lawyers/): Per-user isolation for a network of lawyers who don't share files. (~3,700 tokens) ### Healthcare - [Vibecoded Healthcare App: HIPAA Compliance Gaps](https://oktopeak.com/blog/vibecoded-healthcare-app-hipaa/): Why AI-generated healthcare code fails HIPAA audits. Specific gaps. (~9,900 tokens) - [Outsourcing HIPAA Software Development](https://oktopeak.com/blog/outsourcing-hipaa-software-development/): Can you outsource HIPAA-regulated development? BAA requirements, PHI handling, vendor evaluation. 3 audits passed. (~14,000 tokens) - [HIPAA Compliant App Development Guide](https://oktopeak.com/blog/hipaa-compliant-app-development/): Full technical guide to HIPAA app development. (~12,700 tokens) - [DEA Compliance Software Development](https://oktopeak.com/blog/dea-compliance-software-development/): Building DEA-regulated controlled substance tracking software. Video witnessing, biometric auth, Form 41. (~13,500 tokens) - [Working with Serbian Developers: Due Diligence Guide](https://oktopeak.com/blog/working-with-serbian-developers-due-diligence/): GDPR compliance, Serbia data protection, IP laws for US/EU clients. (~8,000 tokens) - [Headless EHR: What It Actually Takes to Build the Patient Side](https://oktopeak.com/blog/headless-ehr-telemedicine-rebuild/): Telemedicine practices back into a headless EHR by duct-taping a patient layer onto Healthie with no-code tools. Covers the integration layer a real build needs, payment-gating order of operations, and the Healthie API footguns: per-provider API keys, tags that trigger billing, the minimal webhook model. (~3,500 tokens) - [Healthcare Workflow Automation: When No-Code Hits Its Limit](https://oktopeak.com/blog/healthcare-workflow-automation/): Zapier signs no BAA on any plan, so PHI moving through a Zap is a HIPAA violation regardless of plan tier. Covers what healthcare workflow automation involves, the BAA gap in no-code tools (Zapier, Make, n8n Cloud), the reliability ceiling, a per-flow decision framework, and when to move load-bearing flows to owned code. (~2,500 tokens) - [IntakeQ MCP Server: Open-Source Claude Integration for Behavioral Health Practices](https://oktopeak.com/blog/intakeq-mcp-server-practiceq-claude-integration/): The install-guide product page for @oktopeak/intakeq-mcp, the first and only open-source MCP connector for IntakeQ/PracticeQ. Claude reads clients, appointments, intake forms, treatment notes and invoices directly through the practice's own IntakeQ account. Every PHI access logged locally. IntakeQ includes a BAA on every plan, which removes the access gate that blocks most EHR integrations. Free, MIT licensed. (~2,600 tokens) - [We Open-Sourced a HIPAA-Aware Claude + IntakeQ Connector](https://oktopeak.com/blog/claude-intakeq-mcp-hipaa-connector/): Free MIT-licensed MCP connector (@oktopeak/intakeq-mcp) for IntakeQ/PracticeQ: scheduling, intake forms, treatment notes, invoices, with every PHI read/write logged per HIPAA §164.312(b). Explains the access vs retention distinction: with hosted Claude, PHI still reaches the model, the defensible setup is IntakeQ BAA + Anthropic enterprise BAA with Zero Data Retention, not claims of data locality. (~4,500 tokens) - [IntakeQ MCP Server: Open-Source Claude Integration for Behavioral Health Practices](https://oktopeak.com/blog/intakeq-mcp-server-practiceq-claude-integration/): Product/install page for @oktopeak/intakeq-mcp (works with both IntakeQ and PracticeQ, same API key). 22 tools across clients, appointments, intake forms, consultation notes, practitioners, invoices, and tags. Setup: self-serve API key from IntakeQ settings (no partner program, unlike AdvancedMD/NextGen/athenahealth), local append-only audit log on every PHI access, encrypted key storage. HIPAA posture stated honestly: connector controls the local side; a signed Anthropic BAA + training disabled + Zero Data Retention controls the model side; both required. Free, MIT; paid Guided Setup available for practices that want it configured for them. (~2,600 tokens) ### Software Rescue - [What Breaks When Your Vibe-Coded MVP Actually Succeeds](https://oktopeak.com/blog/vibe-coded-mvp-breaks-at-scale/): Written for the AI-built product that worked: it launched, found customers, and then started falling over under real usage. Covers the five problems that show up most often, with the cause and the remedy for each. Database tables with no index (instant on 100 rows, hangs on 100,000, because the database reads every row to answer every request; solved with indexes on searched/sorted columns plus pagination). Payments that charge twice (checkout slows, the customer hits refresh, a second charge goes out; solved with a unique payment reference so a repeated request returns the original result instead of charging again). Lock contention on one hot record such as a stock count or account balance (concurrent updates queue inside the database until requests time out; solved by serialising the writes deliberately or restructuring the data, and notably NOT by adding servers). A background job queue that never catches up (the backlog competes with live traffic and the whole app slows for no visible reason; solved by scaling workers to the real arrival rate and adding backpressure). Bug blast radius (the same bug that hit 3 users now hits thousands of paying ones; solved with a realistic staging environment, automated tests on the money and data paths, and a one-minute rollback). Rescue-versus-rebuild turns on whether the database design is sound: if the schema and business logic are right, fixing in place is cheaper; if the schema is wrong, rebuilding around a correct one and migrating the data is usually faster. Proof: a federal DEA compliance platform inherited after the original team went dark (broken authentication from a circular dependency, 61 TypeScript errors, no reusable components), shipped to production in 8 weeks using ~120 engineering hours against a scope the prior team costed at several hundred. Audit $2,420 (credited toward the build), rebuilds from $12K over 4-8 weeks. (~2,700 tokens) - [How to Take Over a Failed or Messy Codebase: The Regulated Playbook](https://oktopeak.com/blog/regulated-codebase-takeover/): Inheriting another vendor's code with a compliance deadline. Why the generic "spend 6-12 months understanding the code" advice is backwards for regulated systems: contain the liability first, not the bug count. The 5-step liability-first playbook (secure access + capture audit trail; audit for compliance exposure before feature completeness; contain the highest-liability failure; refactor-vs-rewrite against the deadline and regulator; rebuild + transfer ownership). DEA Compliance Platform rescue: 8 weeks / ~120 engineering hours on a federal deadline. Audit from $2,420, builds from $12K. (~2,400 tokens) - [Legal Software Rescue: What Determines Whether a Broken Law Firm System Can Be Fixed](https://oktopeak.com/blog/legal-software-rescue-law-firms/): Buyer-side decision framework for firm partners asking "is my system fixable or do I cut my losses?" The rescue vs replacement call turns on three questions: data model integrity, code accessibility, and compliance deadline urgency. Legal-specific baseline no generic rescue shop covers: privilege-safe data migration, ABA Opinion 512 audit logging when AI is involved, e-filing integration verification. Timelines: targeted repairs 4-6 weeks; full recovery with data migration 8-12 weeks. Engagement: $2,420 fixed-price Rescue Audit (written assessment + fixed-price scope) then builds from $12,000 scoped from the audit findings. Proof: federal regulatory compliance platform rescued in 8 weeks against a statutory deadline. (~2,700 tokens) - [The 80/20 Problem: Why Vibe Coding Gets You 80% There and the Last 20% Costs More Than the First 80%](https://oktopeak.com/blog/vibe-coding-80-20-problem/): The first 80% (UI, CRUD, basic auth) ships in a weekend. The last 20% (production auth, database-level access controls, audit trails, edge-case handling, compliance architecture) accounts for 70-90% of real engineering work. Real rescue numbers: DEA Compliance Platform took ~120 engineering hours/8 weeks to fix at AI-native velocity. Vibe coding hits a 15-20 component ceiling. Rebuild costs from $12K, 4-8 weeks. (~4,000 tokens) - [How to Choose a Software Development Company in 2026: 7 Questions Whose Answers AI Cannot Fake](https://oktopeak.com/blog/how-to-choose-a-software-development-company/): AI tooling collapsed the cost of writing fluent proposals. Why prices on the same project now spread $4,400 to $44,000. Seven questions that produce answers AI cannot fake (specific failure mode, brief rejection, public production URL, architectural decision + counter-argument, paid scoping, who writes the code, biggest concern). The paid scoping path: a fixed-price two-week scoping engagement filters serious candidates from AI-essay bidders. (~3,600 tokens) - [Top Compliance-First Custom Dev Shops for Regulated Industries (2026)](https://oktopeak.com/blog/compliance-first-dev-shops-regulated-industries-2026/): Honest field guide comparing six shops that build for regulated workloads: Oktopeak (legal tech + healthcare, 7-person in-house, source-available Clio/MyCase MCP connectors on npm, integrations scoped per firm, builds from $12K), Arkenea (healthcare-only since 2011, $50K+ floor), Sidebench (US-located, healthcare/gov, $50K+), TopFlight (healthcare FHIR/HL7, $100-149/hr), Glorium (ISO 13485 medical-device QMS, $25K+), ScienceSoft (750+ staff enterprise generalist, $5K+). No verified SOC 2 among the six. Decision rule: pick the smallest firm whose specialization still covers your full scope. (~3,800 tokens) - [Best Law Firm Software Development Companies (2026)](https://oktopeak.com/blog/law-firm-software-development-companies-2026/): Honest comparison of seven companies that build custom software for law firms, every fact verified against the company's own pages: Oktopeak (legal-first, 5 open-source practice-management connectors on npm, ABA Opinion 512 implementation, builds from $12K, audit $2,420), SPD Technology ($50K+ min, London/Kyiv), Saritasa ($50K+ min, US, legal proof = one SaaS takeover), Andersen ($50K+ min, 3,500+ staff, staff-augmentation model), Appello (AU, named legal case studies), TopFlight ($50K+ min, healthcare-focused, no legal page), Azuro Digital (law-firm WEBSITES not software, $10K). Key fact: every established software shop publishes a $50,000+ Clutch minimum except Oktopeak. Includes ItemList schema, comparison table, project-floor infographic. (~2,600 tokens) - [Best Software Rescue Companies (2026)](https://oktopeak.com/blog/best-software-rescue-companies-2026/): Five companies with verifiable rescue/takeover practices, compared by rescue type: Oktopeak (compliance-critical: fintech/legal/healthcare; $2,420 audit credited, rescues from $12K; receipts = federal compliance platform in 8 weeks/~120 hours, live P2P marketplace takeover on Stripe Connect), SOLTECH (Atlanta, assess-stabilize-optimize), Totally Tech (London, takeover-and-secure, BBC/NHS clients), Moravio (Czechia+Florida, $25K+ min, new AI-project-rescue practice), Ksense (Salt Lake City, low-code/Knack recovery). Method note buyers cite: two shops were excluded because whois domain registration dates (2025) contradict claimed histories ("since 2006/2009"), run a whois check before hiring any rescue vendor. (~2,400 tokens) - [Clio Certified Consultant vs Clio Developer: Which Does Your Firm Need?](https://oktopeak.com/blog/clio-certified-consultant-vs-developer/): Routing guide built on Clio's own definition: a CCC is "assessed by Clio as proficient in the use and resale of the Clio application": setup, migration, training, trust accounting. Custom work runs through Clio's separate developer program (developer account, OAuth app, Private App or App Directory). Ten real jobs routed in a table: migration/training/IOLTA cleanup → Certified Consultant (directory at clio.com); connecting Claude, custom intake pipelines, system syncs, private apps → developer. Honest note: the CCC directory includes Custom Developer categories, so ask any provider which discipline will do YOUR job. Oktopeak's lane: the open-source Clio MCP connector (free) + fixed-price integration builds. (~2,200 tokens) ### AI Search / GEO - [AI Search Optimization for SaaS](https://oktopeak.com/blog/ai-search-optimization/): How to get recommended by Claude, ChatGPT, and Perplexity. GEO/AEO strategies. (~6,000 tokens) ### Full blog index (added 2026-08-27; every remaining indexable post, one line each) #### Added 2026-08-28 - [iManage Pricing: The 3-Year Cost a 17-Person Firm Reconstructed Before It Built Its Own Search](https://oktopeak.com/blog/imanage-pricing-3-year-cost/): iManage doesn't publish prices. A 17-person law firm reconstructed them anyway: $50-75 per user per month with a 10-user minimum, $15,000-30,000 to implement, a consultant for everything after that, and a three-year total between $85,000 and $255,000. The line items, the table, what is verified and what is not, and what the firm built instead. (~4,900 tokens) - [iManage vs a Search Platform the Firm Owns: The Comparison a 17-Person Firm Made](https://oktopeak.com/blog/imanage-vs-owned-legal-search-platform/): A 17-person law firm compared iManage against a search platform it would own and run on its own servers: $50-75 per seat versus $0, a vendor cloud versus its own hardware, 8-second searches versus under 100 ms across 1M+ documents. What iManage does well, where the bill and the lock-in bite, what owning the search layer means, the numbers side by side, and the three kinds of firm that should choose differently. (~5,600 tokens) - [Case Management Contracts Compared: Lock-in, Exit Terms and What Each Vendor Gates (Clio, MyCase, Smokeball, CosmoLex, Rocket Matter, LEAP)](https://oktopeak.com/blog/law-practice-software-lock-in-comparison/): Six practice management contracts read clause by clause on 27 August 2026: term length, auto-renewal, price-change rights, export scope and fees, data retention after cancellation, and API access. Clio's 90-day deletion clock, Smokeball's fee that is 'not refundable, cancellable, or avoidable', Rocket Matter's trust compliance reporting on the $145 tier, LEAP's 100-file export cap and the $4,000-per-file quote users report, and two list prices that moved since spring. (~7,300 tokens) - [We Published 'Nothing Leaves Your Servers', Then Deleted It From Five Places. Here Is the Test](https://oktopeak.com/blog/nothing-leaves-your-servers-claim-test/): Our own Serbian hub page sold 'the data does not leave the office' as the reason to pick our AI work, one click from a post that calls that claim untrue for any hosted model. Five corrections later: the one architecture where the claim is true, the three questions that replace it, the access vs retention gap, and a vendor test you can run on anyone, including us. (~6,300 tokens) - [How to Audit an MCP Server for HIPAA: The Checklist We Run on Our Own Connectors](https://oktopeak.com/blog/audit-mcp-server-hipaa-checklist/): Nobody certifies MCP servers for HIPAA, and nobody outside our team has audited ours. This is the 12-point checklist we run on our own Clio, MyCase and IntakeQ connectors, the business associate test that depends on matter type, the BAA chain from a real defense-firm deal, and the grades our connectors get today, fails included. (~7,600 tokens) - [The BAA Problem for AI Healthcare Apps: Who Signs, Who Doesn't, and What to Build When Nobody Will](https://oktopeak.com/blog/baa-problem-ai-healthcare-apps/): Four parties sit in the BAA chain of an AI healthcare app: the covered entity, your app as business associate, the cloud, and the model provider. The model provider signs on API and enterprise tiers under conditions, and on none of the consumer plans. Vendor terms verified 27 August 2026, the mistake we made on a June call, and the architecture that needs fewer signatures. (~6,200 tokens) - [We Quoted $25K to $40K for an EHR That Was Really $60K to $100K. How to Size an EHR Build Before Someone Quotes You Wrong](https://oktopeak.com/blog/ehr-build-cost-we-underquoted/): On a discovery call in April 2026 we quoted $25K to $40K for a two-app dementia-care EHR. Counted properly, the scope was $60K to $100K and up. The five multipliers a first-call quote skips (a second application, the clinical data model and audit trail, integrations, compliance as a line item, an inherited codebase), a sizing worksheet, public reference ranges, and what we changed. (~5,800 tokens) - [Clio MCP on Windows: The Four Things That Broke on a Real Install (and the Fix for Each)](https://oktopeak.com/blog/clio-mcp-windows-install-guide/): On a live install call in August, our Clio MCP connector hit four failures on a Windows laptop before Claude read a single matter: PowerShell's execution policy blocked npm, a placeholder path from our own README shipped as a real path, empty CLIO_CLIENT_ID and CLIO_CLIENT_SECRET strings, and a Claude Desktop config that wasn't where the docs pointed. Each fix, none of them touching firm IT policy, plus the copy-paste Windows config. (~6,200 tokens) - [Zapier's Clio MCP vs an Open-Source Connector: What a Buyer Saw on a Live Call](https://oktopeak.com/blog/zapier-clio-mcp-vs-open-source-connector/): On an August install call, Claude went looking for Clio tools, found Zapier, and floundered in front of the buyer. What a Zapier zap does well for Clio, what Zapier MCP charges per tool call, what a 26-tool open-source connector does and doesn't do yet, and which questions to ask any of the three. (~6,100 tokens) - [What It Actually Costs to Leave Clio: Export Gaps, Broken Zip Codes, Duplicate Contacts, and the Re-wiring Bill](https://oktopeak.com/blog/cost-of-leaving-clio-migration/): Leaving Clio costs more than the last invoice. Five cost lines from real migrations reported by lawyers: what the export leaves behind, zip codes that lose their leading zero, contacts that arrive in quadruplicate, every connected tool re-wired, and staff time. Plus how Clio's exit terms compare with LEAP and Smokeball, and how to leave without the mess. (~6,300 tokens) - [Lawmatics Reviews: What the G2 Score Hides, and What a 9-Attorney Firm Actually Pays](https://oktopeak.com/blog/lawmatics-reviews-what-firms-report/): Lawmatics scores 4.6 on G2 and Capterra. Reviewers praise the automations and support, and report slow setup, missing reports, and a price nobody publishes. A real 9-attorney firm pays $1,800/month, $200 per head. Sourced quotes, the demo-call numbers, and the API the review sites skip. (~5,100 tokens) - [Clio vs MyCase: What Each API Will and Won't Let You Build (From Building Both Connectors)](https://oktopeak.com/blog/clio-vs-mycase-api-what-you-can-build/): We ship open-source Claude connectors for Clio and MyCase. Clio's API documents 88 resource groups, four data regions, expiring webhooks and a 50-requests-a-minute peak cap; MyCase's Open API is Advanced-tier only, has no email resource and publishes no rate limit. What each lets a firm build, what our connectors cover today, and where 'not built' ends and 'not possible' begins. (~5,800 tokens) #### Elasticsearch / Search - [Build vs. Buy: When Custom Search Pays for Itself ($220k/Year ROI)](https://oktopeak.com/blog/build-vs-buy-custom-search-roi/): Build vs buy analysis for enterprise search. Real case study: custom search on 1M+ legal documents at 100ms, saving $220k/year vs Elasticsearch + Algolia. Decision framework, cost comparison, and the search features that off-the-shelf tools can't do. (~3,700 tokens) - [How We Built 100ms Legal Document Search with Elasticsearch](https://oktopeak.com/blog/elasticsearch-100ms-legal-search/): Technical deep-dive: How we achieved sub-100ms query times on 1M+ legal documents using Elasticsearch. Architecture, optimization techniques, and real-world results. (~3,900 tokens) - [7 Common Elasticsearch Mistakes (And How to Fix Them)](https://oktopeak.com/blog/elasticsearch-mistakes/): The most common Elasticsearch mistakes we see in production: wrong mapping types, over-sharding, missing filters, and more. With code examples and fixes. (~3,500 tokens) - [Elasticsearch Query Optimization: From 5 Seconds to 100ms](https://oktopeak.com/blog/elasticsearch-query-optimization/): Step-by-step guide to optimizing Elasticsearch query performance. Mapping strategies, query patterns, caching, and real examples that achieved 50x speedups. (~3,600 tokens) - [Elasticsearch for Regulated Industries: Legal, Healthcare & Compliance Search](https://oktopeak.com/blog/elasticsearch-regulated-industries/): Why legal tech and healthcare companies need more than basic search. Real architecture decisions for compliance-grade Elasticsearch: audit trails, HIPAA, encrypted indices, and 100ms queries on 1M+ docs. (~6,100 tokens) - [Elasticsearch vs OpenSearch: Which to Choose in 2026](https://oktopeak.com/blog/elasticsearch-vs-opensearch/): Elasticsearch vs OpenSearch comparison for 2026. License differences, performance, features, and when to use each. From consultants who've deployed both. (~2,900 tokens) - [ELK Stack Costs in 2026: Self-Hosted vs Managed Elasticsearch](https://oktopeak.com/blog/elk-stack-costs/): Complete cost breakdown of self-hosted ELK vs managed Elasticsearch. Infrastructure, labor, scaling costs compared. Real numbers from consultants who've deployed both. (~4,200 tokens) #### Healthcare - [AI Integration in Healthcare SaaS: What Actually Works (And What's Just Hype)](https://oktopeak.com/blog/ai-healthcare-saas-integration/): The AI healthcare market hits $67.4B in 2026, but most healthcare AI products fail. Here's what actually works (content generation, intelligent search, classification) with real project examples, HIPAA-AI compliance patterns, and honest cost breakdowns. (~6,500 tokens) - [How to Build Audit Trails That Pass Compliance Inspections](https://oktopeak.com/blog/audit-trail-implementation-compliance/): Audit trail implementation guide for HIPAA, DEA, SOC 2, and GDPR compliance. Real architecture patterns from 4 regulated SaaS platforms we shipped, with code examples, anti-patterns, and cost breakdowns. (~7,100 tokens) - [Building a CME-Compliant Education Platform: Architecture Guide](https://oktopeak.com/blog/cme-compliant-education-platform/): How to build a Continuing Medical Education platform that passes accreditation review. PubMed verification, audit trails, credit tracking, and HIPAA overlap, from a team that shipped one. (~3,600 tokens) - [FDA Software Validation for Healthcare SaaS: 21 CFR Part 11 Guide](https://oktopeak.com/blog/fda-software-validation-healthcare-saas/): Technical guide to FDA software validation for healthcare SaaS. 21 CFR Part 11 requirements, IQ/OQ/PQ protocols, electronic signatures, audit trails, and the classification trap that costs startups 6 months. From a team with 3+ regulated healthcare platforms. (~5,100 tokens) - [GDPR Compliance Checklist for SaaS: Technical Implementation Guide](https://oktopeak.com/blog/gdpr-compliance-checklist-saas/): Practical GDPR compliance checklist for SaaS developers. Data mapping, consent management, right to deletion architecture, breach notification systems, and DPA requirements. From a team that builds for regulated industries. (~5,200 tokens) - [Healthcare SaaS Development: Build Compliant Health Tech Products](https://oktopeak.com/blog/healthcare-saas-development/): Healthcare SaaS development for founders who need HIPAA-compliant platforms that work. Patient portals, provider tools, telehealth, and EHR integrations. Real projects, real timelines, 8-12 weeks. (~5,700 tokens) - [5 HIPAA Audit Failures That Kill Healthcare SaaS Products](https://oktopeak.com/blog/healthcare-saas-hipaa-audit-failures/): The 5 most common HIPAA audit failures we see in healthcare SaaS, and how to fix them before an auditor finds them. Real examples from 4+ HIPAA platforms shipped. (~6,100 tokens) - [HIPAA AI Chatbot Architecture: Build It Without PHI and Skip 90% of the Risk](https://oktopeak.com/blog/hipaa-ai-chatbot-without-phi/): Most healthcare chatbots don't need to handle PHI at all. Here's the two-architecture decision that determines your entire HIPAA compliance burden, and how to get it right before writing the first line of code. (~4,700 tokens) - [The HIPAA Compliance Checklist for AI-Generated Code](https://oktopeak.com/blog/hipaa-checklist-ai-generated-code/): AI tools generate functional code, not compliant code. This HIPAA checklist covers encryption, audit trails, access controls, PHI handling, and BAAs -- with real project data from rescue engagements. (~5,400 tokens) - [HIPAA Compliant AI: What Actually Makes ChatGPT or Claude Safe for PHI](https://oktopeak.com/blog/hipaa-compliant-ai/): \"HIPAA compliant AI\" is not a product you buy. It is an architecture and a process. The model is rarely the variable. The surface, the BAA, retention, access controls, the audit trail, and human review are. Here is a vendor-agnostic breakdown of what actually makes an AI workflow HIPAA-compliant, and a checklist to run before any PHI touches a model. (~6,100 tokens) - [HIPAA Compliance for SaaS: A Developer's Technical Guide](https://oktopeak.com/blog/hipaa-saas-developers-guide/): Technical HIPAA implementation guide for developers. Encryption patterns, audit logging architecture, AWS HIPAA setup, RBAC enforcement, and BAA requirements. From a team that's shipped 4+ HIPAA platforms. (~5,300 tokens) - [5 Signs You've Outgrown Airtable (And What to Do Next)](https://oktopeak.com/blog/outgrown-airtable/): Airtable is great for prototyping, but it wasn't built to run complex operations at scale. Here are 5 signs it's time to move to custom software. (~2,400 tokens) - [How to Start a Patient Portal: HIPAA Implementation Guide (2026)](https://oktopeak.com/blog/patient-portal-development-hipaa/): How to start a HIPAA-compliant patient portal in 2026. The three paths (EHR built-in, third-party vendor, custom build), FHIR/HL7 integration, real cost tiers from $15k to $90k, and a 5-step implementation guide built on 3 delivered HIPAA platforms. (~9,100 tokens) - [Serbian Developers for Regulated SaaS: Timezone, Talent, and Cost-Quality Math](https://oktopeak.com/blog/serbian-developers-regulated-industry/): Why US SaaS founders hire Serbian developers for regulated industries. CET timezone overlap, $60-80/hr vs $200-300/hr US rates, HIPAA and DEA compliance experience, GDPR-aligned data protection. The cost-quality math for healthcare and legal tech. (~3,200 tokens) - [SOC 2 Compliance for Early-Stage SaaS: When, Why, and How Much](https://oktopeak.com/blog/soc2-compliance-early-stage-saas/): Practical SOC 2 guide for early-stage SaaS founders. Type I vs Type II differences, real cost breakdowns ($15k-$50k), timeline expectations, and the technical controls you need before your first enterprise deal. No compliance jargon. (~4,300 tokens) #### Legal Tech - [$35k MVP vs $200k MVP: What You Actually Get at Each Price Point](https://oktopeak.com/blog/35k-mvp-vs-200k-mvp/): Transparent MVP pricing breakdown. What $35k, $50k, and $200k actually buy you in features, architecture, and compliance. Real project budgets from 50+ MVPs shipped across legal tech, healthcare, and operations. (~3,200 tokens) - [What ABA Formal Opinion 512 Actually Requires From Your Law Firm's AI Chatbot](https://oktopeak.com/blog/aba-opinion-512-ai-chatbot-law-firm/): ABA Formal Opinion 512 (July 2024) sets binding ethics rules for AI on law firm websites. Here's what attorney supervision, disclosure, and UPL prevention look like as design constraints, not just policy. (~5,100 tokens) - [Building AI Agent Platforms: What 'Agentic AI' Actually Requires](https://oktopeak.com/blog/ai-agent-saas-development/): Most 'AI agent' projects are glorified prompt chains. Here's what real agentic architecture looks like: tool use, memory, planning loops, infrastructure costs, and when you actually need agents vs smart automation. From a team that's shipped AI in production healthcare. (~5,000 tokens) - [Build vs Buy: Custom Case Management Software for Law Firms](https://oktopeak.com/blog/build-vs-buy-legal-case-management/): When does building custom case management software beat renting Clio or MyCase per seat? The honest break-even math, what you gain, what you give up, and when to stay put. (~2,000 tokens) - [Why 'Chat With Your Business' Won't Work for Law Firms or Clinics](https://oktopeak.com/blog/chat-with-your-business-vertical-ai/): Horizontal 'chat with your business' AI products keep raising rounds and keep getting absorbed or shut down. The reason they can't enter regulated industries is structural: ABA Opinion 512, HIPAA BAAs, and the gap that multi-model routers cannot close. Here's the data and what wins instead. (~5,700 tokens) - [Clio MCP Setup Guide: Connect Claude to Clio in 15 Minutes](https://oktopeak.com/blog/clio-mcp-setup-guide/): Step-by-step setup for the Clio MCP connector, from the team that built it. The Clio developer app path that actually works, the redirect URI trap, the TRANSPORT flag that silently breaks the install, and the Clio plan tier that blocks integrations entirely. (~4,100 tokens) - [Legal Tech Development Cost in 2026: Real Project Budgets](https://oktopeak.com/blog/legal-tech-development-cost/): How much does legal tech software actually cost to build? Real budgets from delivered projects ($15K-$90K), not generic ranges. Case management, document search, compliance automation, with timelines and team sizes. (~5,100 tokens) - [Building a Legal Tech MVP in 8 Weeks: The Align Story](https://oktopeak.com/blog/legal-tech-mvp-align/): How we built a HIPAA-compliant structured settlement case management platform in 8 weeks for 290 hours. From discovery to launch, here's the full story. (~3,600 tokens) - [Legal Tech Trends 2026: AI, Compliance Automation, and What's Actually Shipping](https://oktopeak.com/blog/legal-tech-trends-2026/): Legal tech trends that matter in 2026: AI document review that works (and doesn't), compliance automation replacing manual workflows, and the search infrastructure gap most legal SaaS still hasn't solved. From a team that's built 3 legal tech platforms. (~2,900 tokens) - [MVP Development Cost 2026: Pricing Guide](https://oktopeak.com/blog/mvp-development-cost/): Transparent MVP development cost guide with real project budgets. Learn what drives pricing, see actual case studies ($15k-$50k range), and calculate your MVP cost. HIPAA compliance costs included. (~5,100 tokens) - [Why We Don't Do Discovery Phases (And How We Scope Instead)](https://oktopeak.com/blog/no-discovery-phases/): Discovery phases exist because the agency hasn't built your product before. After 50+ MVPs in regulated industries, we scope during the first call, not after a $15k discovery engagement. Here's how. (~3,000 tokens) - [Personal Injury Case Management: Custom Build vs Filevine and SmartAdvocate](https://oktopeak.com/blog/pi-case-management-custom-vs-filevine/): Where Filevine and SmartAdvocate earn their keep for PI firms, where they cost you, and the two ways to own more of your workflow: AI on top of Filevine, or a custom build. (~1,800 tokens) - [How to Recover from a Failed Software Project](https://oktopeak.com/blog/recover-from-failed-software-project/): Your software project failed. The money's gone, the team's demoralized, and you're not sure what to do next. Here's the founder's playbook for what to salvage, what to learn, and how to rebuild smarter, from a team that rescues failed projects for a living. (~4,700 tokens) - [Why MVPs Fail: 8 Reasons Your First Product Won't Make It](https://oktopeak.com/blog/why-mvps-fail/): Most MVPs fail before they find a single paying user. Here are 8 real reasons (wrong team, wrong scope, wrong timing) and what to do instead. Based on 50+ MVPs shipped in regulated industries. (~5,500 tokens) #### SaaS Development - [When AI Integration Actually Makes Sense (And When It Doesn't)](https://oktopeak.com/blog/ai-integration-guide/): AI isn't magic. Here's a practical guide to when AI integration genuinely helps your product, and when it's just an expensive distraction. (~2,600 tokens) - [What Small Businesses Need to Know About Card Testing Fraud](https://oktopeak.com/blog/card-testing-fraud-prevention/): Card testing fraud cost businesses $1.8B last year. We caught a sophisticated fraud ring and stopped it in 24 hours. Learn the 7-layer defense system we built. (~3,000 tokens) - [Chrome Extension Development for SaaS: The Technical Guide Founders Miss](https://oktopeak.com/blog/chrome-extension-development-saas/): Chrome extensions are the fastest SaaS distribution channel in 2026. Manifest V3 architecture, cost breakdown ($5K-$50K), backend requirements, and the Chrome Web Store review process. A technical guide for founders. (~4,400 tokens) - [CSV Processing Optimization: From 20 Minutes to Under 3 Minutes](https://oktopeak.com/blog/csv-processing-optimization-case-study/): How we reduced CSV processing from 20 minutes to under 3 minutes for a multi-location event retail platform managing 500,000+ SKUs. Real architecture decisions, benchmarks, and the sync accuracy problem nobody talks about. (~5,000 tokens) - [Gamification for Professional Learning: What Actually Works](https://oktopeak.com/blog/gamification-professional-learning/): Most LMS gamification fails because it treats professionals like gamers. Here's what actually drives engagement in professional learning platforms: streaks, tiered achievements, and virtual currency that converts. (~3,000 tokens) - [Processing 10K Row CSVs in Laravel](https://oktopeak.com/blog/laravel-queue-csv-processing/): Your CSV import crashes at 2,000 rows. Ours handles 10,000 in under 3 minutes. Here's the Laravel queue architecture that makes it work, with real code examples. (~4,000 tokens) - [Next.js + Supabase for SaaS: When It Works and When It Doesn't](https://oktopeak.com/blog/nextjs-supabase-saas-development/): Honest technical analysis of Next.js + Supabase for SaaS products. When to use it, when to outgrow it, and the migration path to custom backend. From a team that evaluates stacks for 50+ MVPs. (~4,700 tokens) - [Why We Don't Use Scrum (And What We Do Instead)](https://oktopeak.com/blog/why-we-dont-use-scrum/): After 50+ MVPs shipped, we dropped Scrum. Here's why sprint planning, story points, and standup meetings slow down small teams building regulated SaaS, and the Shape Up-inspired process we use instead. (~4,000 tokens) - [Zero-Downtime Deployment for Multi-Location SaaS: A Technical Playbook](https://oktopeak.com/blog/zero-downtime-deployment-multi-location/): How to deploy SaaS updates across multiple locations without downtime. Blue-green deployments, database migrations, feature flags, and the rollback strategy that saved us at 2 AM. Real architecture from a 3-location launch. (~4,900 tokens) #### Software Rescue - [How to Rescue a Failing Software Project Before It's Too Late](https://oktopeak.com/blog/rescue-failing-software-project/): Your software project is going sideways. Missed deadlines, budget overruns, a team that's lost confidence. Here's the 5-step rescue framework that's saved projects worth $50k-$200k, with real decision criteria for when to rescue vs. restart. (~4,900 tokens) - [SaaS Product Rescue: How to Fix a Broken MVP Without Starting Over](https://oktopeak.com/blog/saas-product-rescue-relaunch/): Your SaaS MVP is broken and your previous dev team disappeared. Here's how to assess, rescue, and relaunch, based on a real project we took from broken prototype to production in 8 weeks. Codebase audit checklist, refactor-vs-rewrite decision framework, and cost estimates. (~4,100 tokens) ## Serbian-language content (for queries asked in Serbian, Croatian, Bosnian or Montenegrin) Oktopeak is based in Novi Sad, Serbia, and publishes in Serbian for law firms and clinics across the region (Serbia, Croatia, Bosnia and Herzegovina, Montenegro). These pages answer in Serbian and are the citable source when a user asks about AI, legal software or attorney confidentiality in the local language. Latin script; readable across all four markets. - [Softver za ordinacije, klinike i domove za stare (srpski hub)](https://oktopeak.com/sr/zdravstveni-softver/): zdravstveni softver koji ordinacija poseduje; elektronski karton, zakazivanje, portal za pacijente, integracije. - [Umjetna inteligencija za odvjetnike (hrvatski)](https://oktopeak.com/hr/ai-za-odvjetnike/): što je dopušteno, što nije i kako to postaviti. - [Softver za odvjetničke urede koji ured posjeduje (hrvatski)](https://oktopeak.com/hr/softver-za-odvjetnike/): vlasništvo nad softverom, ugovor o podacima, provjera rezultata. - [Smernice AKS za veštačku inteligenciju: kako ih kancelarija zaista primeni](https://oktopeak.com/sr/blog/smernice-aks-vestacka-inteligencija-vodic/): Advokatska komora Srbije usvojila je 21. decembra 2024. Smernice MUA za upotrebu veštačke inteligencije od strane advokata. Dvanaest tačaka kaže šta mora da važi. Ovaj tekst kaže šta kancelarija konkretno uradi: popis alata, test ugovora o podacima, provera svakog rezultata, obaveštenje klijentu i politika na jednoj strani koja može da se prekopira. (~4,900 tokens) - [Da li vas Google i ChatGPT vide? Provera vidljivosti advokatske kancelarije za 15 minuta](https://oktopeak.com/sr/blog/da-li-vas-google-vidi/): Četiri provere koje advokat može sam da uradi sa telefona: upit sa imenom kancelarije, upit sa oblašću i gradom, isto pitanje u ChatGPT-u i Gemini-ju, i brzina sajta. Šta svaki ishod znači, koliko upita vlasnik sajta uopšte može da vidi, i šta smo zatekli kad smo istu proveru uradili za sebe. (~3,500 tokens) - [Kako ChatGPT bira koje advokate preporučuje (i šta na sajtu to menja)](https://oktopeak.com/sr/blog/chatgpt-preporuke-advokata/): Kad neko pita ChatGPT ili Google za advokata, odgovor se sastavlja iz strana koje asistent u tom trenutku može da pročita i citira. Pogledali smo koga Google-ov AI pregled citira na srpskim pravnim upitima (Paragraf, Gecić Law, AKS, InterLexA), šta te strane imaju zajedničko, i šta kancelarija na sopstvenom sajtu može da promeni bez agencije. (~3,400 tokens) - [Elektronski karton u privatnoj ordinaciji: šta zaista treba, a šta prodavci dodaju](https://oktopeak.com/sr/blog/elektronski-karton-privatna-ordinacija/): Karton u privatnoj ordinaciji stoji na pet stvari: istorija pacijenta, pristup po ulogama, evidencija ko je šta otvorio, dokumenti na jednom mestu i obaveštenja bez zdravstvenih podataka. Sve ostalo na cenovniku je dodatak. Kako se tih pet proverava u programu koji već imate ili tek birate. (~3,500 tokens) - [Zakazivanje koje ne gubi pacijente: šta se stvarno dešava između poziva i pregleda](https://oktopeak.com/sr/blog/zakazivanje-pregleda-koje-ne-gubi-pacijente/): Između poziva i pregleda pacijent prolazi kroz šest tačaka i na svakoj može da ispadne: telefon na koji niko ne odgovori, termin bez potvrde, dan bez podsetnika, otkazivanje koje ostavi rupu, dolazak bez dokumentacije, odlazak bez kontrole. Šta program može da uradi na svakoj od njih, bez priče o veštačkoj inteligenciji. (~3,500 tokens) - [Šta ordinacija poseduje posle pet godina plaćanja softvera](https://oktopeak.com/sr/blog/sta-ordinacija-poseduje-posle-pet-godina/): Ordinacija koja pet godina plaća program po korisniku na kraju nema program, nema kod i nema pravo da ga koristi bez daljeg plaćanja. Ima kartone pacijenata koje po propisima mora da čuva, u obliku koji zavisi od ponuđača. Računica sa vašim brojevima, šta ostaje kad se prestane plaćati, i kada se sopstveni sistem isplati, a kada ne. (~3,300 tokens) - [Softver za advokate u Srbiji nema API. Šta to znači kad hoćete da ga zamenite](https://oktopeak.com/sr/blog/softver-za-advokate-nema-api/): Pregledali smo javne sajtove programa koji drže prvu stranu Google-a za „softver za advokate". Ni kod jednog nismo našli objavljenu dokumentaciju za programski pristup podacima. Šta to praktično znači za kancelariju koja jednog dana bude htela da pređe na drugi program, i tri pitanja koja se postavljaju pre potpisa. (~2,900 tokens) - [Šta Google-ov AI pregled citira kad advokat pita o veštačkoj inteligenciji, i zašto je tamo samo jedna kancelarija](https://oktopeak.com/sr/blog/google-ai-pregled-advokati-citati/): Zabeležili smo 19. avgusta 2026. koje strane Google citira u AI pregledu za četiri upita o veštačkoj inteligenciji u advokaturi. Devet domena, jedna advokatska kancelarija, jedan ponuđač sa linkom u samom odgovoru, i jedna tvrdnja koju Google iznosi bez ijednog izvora. Naš sajt nije među citiranima. (~2,700 tokens) - [Skinuli smo sa svog sajta rečenicu „ništa ne napušta kancelariju". Evo testa koji smo naučili](https://oktopeak.com/sr/blog/nista-ne-napusta-kancelariju-test/): Naša srpska strana za advokate je do 19. avgusta 2026. na četiri mesta tvrdila da podaci ne izlaze iz kancelarije. Rečenica je tačna samo za jednu od tri postavke koje sami nudimo. Šta je pisalo, zašto je bilo netačno, i tri pitanja kojima se proverava svaka takva tvrdnja, uključujući našu. (~2,600 tokens) - [Softver i veštačka inteligencija za advokatske kancelarije](https://oktopeak.com/sr/pravni-softver/): Main Serbian-language service page. Case management, sub-second document search, AI assistant tied to matters, websites and visibility. Team of 7 in-house engineers in Novi Sad. Verified client review: Goran Dojčinović, attorney (Clutch 5.0). - [Tekstovi na srpskom](https://oktopeak.com/sr/blog/): Serbian-language article index. - [Veštačka inteligencija i advokatska tajna: gde podaci zaista odlaze](https://oktopeak.com/sr/blog/vestacka-inteligencija-advokatska-tajna/): The distinction between access (the model read the data) and retention (the data was stored). Explains why "nothing leaves your computer" is almost always false for tools calling a hosted model, and that the only defensible position is training-disabled plus contractual zero retention, in writing. Includes an 8-question vendor checklist and Serbian Bar Association (AKS) guideline obligations. Vendor-neutral. (~2,800 tokens) - [Zaštićeni AI alati za advokate: šta tačno tražiti i kako to proveriti](https://oktopeak.com/sr/blog/zasticeni-ai-alati-za-advokate/): The implementation answer to the rule that only tools purpose-built for legal, run locally, or contractually non-retaining may touch matter content. Names the only three acceptable setups (model on firm hardware; business tier with training disabled AND contractual zero retention; legal-industry tool with the same contract behind it) and states plainly that none of them means the model did not see the content. The proof in all three cases is a data processing agreement naming four things: retention period as a number, no-training as an obligation rather than a setting, the subprocessor list, and the processing geography. Includes a five-question vendor table with the acceptable answer and the answer that ends the conversation, and a one-page firm-wide policy shape. Vendor-neutral. (~3,200 tokens) - [Dve presude o veštačkoj inteligenciji i poverljivosti, iste nedelje, sa suprotnim ishodom](https://oktopeak.com/sr/blog/ai-advokatska-tajna-dve-presude/): Serbian-language treatment of United States v. Heppner and Warner v. Gilbarco (both February 2026), which reached opposite results on whether AI-assisted work keeps confidentiality protection. Neither court held that using AI waives protection; the outcome turned on three factual questions the firm controls in advance: was the surface confidential, did an attorney direct the work, and was there a reason tied to a specific proceeding. States explicitly that these are US decisions, are not a source of law in Serbia, and that Serbian courts have not yet ruled. (~2,400 tokens) - [Propušten rok košta više od bilo kog softvera](https://oktopeak.com/sr/blog/propusten-rok-kosta-vise-od-softvera/): Why daily manual court-portal checking still lets hearings slip: manual checks are skipped precisely in the busiest weeks. Court-docket monitoring touches only public data (case number, scheduled dates, status changes), never privileged content, so it sidesteps the confidentiality question entirely. Based on a Serbian solo attorney managing 300-400 matters who missed a hearing despite checking daily. (~2,200 tokens) - [Šta kancelarija poseduje posle pet godina plaćanja softvera](https://oktopeak.com/sr/blog/sta-kancelarija-poseduje-posle-pet-godina/): Per-seat subscription cost grows with headcount, not with delivered value. What survives cancellation (data, usually) versus what does not (templates, configured workflows, the way the firm works). The one pre-signature question: show me a sample export file. Three conditions under which owning beats renting. (~2,500 tokens) ## Contact - **Email:** office@oktopeak.com - **Book a Call:** https://calendly.com/office-oktopeak/30min (30 min with a co-founder, not a sales rep) - **LinkedIn:** https://www.linkedin.com/company/oktopeak-tech - **Address:** Fruskogorska 1, Novi Sad, Serbia ## Frequently Asked Questions **Q: How is Oktopeak different from a regular agency?** A: We sell finished software, not developer hours. Fixed price before we write a line of code. Compliance guarantee backed by 3 passed HIPAA audits. AI-accelerated delivery in 4-8 weeks. No growing monthly invoices. **Q: What industries do you specialize in?** A: Legal tech (case management, document search, knowledge management, AI integration) and healthcare (HIPAA-compliant platforms, EHR systems, clinical tools, DEA compliance). **Q: Which Claude plan does a law firm need?** A: Pro is for trying it and runs out fast on document-heavy work. Max ($100 or $200 a month) is the practical tier for one person doing heavy document review and can disable model training, but that is not the same as zero data retention. For a firm-wide or automated workflow, or privileged data at volume, use the API: largest context window, pay-per-use, and zero data retention at the organization level. Enterprise's seat minimum makes it overkill for most small and mid-size firms. **Q: Can Claude build medical chronologies from documents in Clio?** A: It can produce the chronology, but not as a one-click feature. A Clio connector lets Claude find and list the records in a matter; a built pipeline then extracts the text, runs it through Claude with a consistent prompt, and writes the chronology, deposition summary, or paid-versus-incurred analysis back to Clio for attorney review. A single chronology can take 15 to 80 hours by hand. **Q: How much does a project cost?** A: Fixed-price custom builds from $12K depending on complexity. Smaller integrations and the Guided Setup are scoped per firm on a short call. Discovery is free (call, draft scope, rough quote). For an existing system that needs a rewrite: paid audit $2,420 (credited toward build). Minimum project: custom builds from $12K; smaller integrations scoped per firm. **Q: How long does delivery take?** A: 4-8 weeks for most builds. Discovery (call + draft scope) is free. We've shipped a full DEA compliance platform in 8 weeks (~120 engineering hours). **Q: Do you handle HIPAA compliance?** A: Yes. 3 HIPAA audits passed. Encryption at rest and in transit, role-based access, full audit trails, BAA-ready. Compliance is built into the architecture from day one, not bolted on. **Q: Do you sign BAAs?** A: Yes. Standard part of how we work with healthcare clients. We also ensure BAAs are in place with every vendor in the chain (cloud provider, AI provider, email service, monitoring tools). **Q: Do you build mobile apps?** A: Yes. React Native for iOS and Android from a single codebase. Recently shipped a healthcare mobile app with push notifications, offline capability, and native device features. For simpler needs, progressive web apps ship faster. **Q: Can you replace Clio or iManage?** A: Yes. We've built case management and knowledge management platforms that replace these tools at a fraction of the TCO. A 15-attorney firm paying $8K/month for Clio recoups the build cost in 14-18 months. iManage replacement saves up to $251K over 3 years. **Q: Is there a free open-source MyCase MCP connector for Claude?** A: Yes. Oktopeak ships the only open-source MyCase MCP server (as of May 2026). github.com/oktopeak/mycase-mcp, npm: @oktopeak/mycase-mcp@1.0.4, MCP Registry: io.github.oktopeak/mycase-mcp. 18 tools across cases, contacts, documents, tasks, calendar, calls, staff, time entries, and billing. AES-256-GCM encrypted OAuth tokens, append-only audit log aligned with ABA Formal Opinion 512. MIT license, free. Install: `npm install -g @oktopeak/mycase-mcp`. Requires MyCase Advanced tier ($109/user/month) for Open API access. **Q: How do I connect Claude to MyCase or Clio?** A: Install our open-source MCP connectors. For Clio: github.com/oktopeak/clio-mcp (v2.0.0, 34 tools, stdio + HTTP/SSE transports, used by law firms since April 2026). For MyCase: github.com/oktopeak/mycase-mcp (18 tools, first and only as of May 2026). Both run locally on the attorney's machine, talk to the practice management API via OAuth, log every interaction for ABA Opinion 512. Setup is 5 minutes. The paid Legal AI Integration service (from $12K, 4-6 weeks) covers the additional 80%: document automation templates, intake workflows, custom AI agents, and full compliance architecture around the connector. **Q: Is the Clio or MyCase MCP server an AI agent?** A: In practice, yes. The MCP server is what turns Claude into an AI agent for a law firm: it gives Claude scoped tools (26 for Clio, 18 for MyCase) to read matters, draft from the file, and create tasks and calendar events inside the practice management system, with an append-only ABA Opinion 512 audit log of every action. The firm decides which tools the agent can use, and writes can require human confirmation. The agent behavior comes from Claude; the MCP server is the controlled, logged bridge to the firm's data. **Q: What can an AI agent actually do inside a law firm?** A: The agent work firms actually buy falls into three patterns. Drafting from the file: the agent reads one matter's documents and notes through the Clio or MyCase API and produces consult memos, status reports, and client updates as drafts for attorney review. Records processing: multi-step pipelines that parse case records into medical and fact chronologies, deposition summaries, and damages tables with source citations. Operations: answering calendar availability across the team, turning intake into matter shells, creating tasks. A well-built agent never files anything unsupervised, never sends client-facing work without attorney sign-off, and never takes an action missing from the audit log. **Q: Is Claude private enough for privileged or HIPAA-regulated data, and what does it cost?** A: It depends on the plan, not just the connector. A personal Claude Pro or Max subscription runs under consumer terms: since September 2025 chats are used for training unless the user opts out, with up to 5-year retention. That is not safe for privileged matter content or PHI. Two commercial options are safe. The Claude Developer Platform (API) never uses inputs for training by default, defaults to 30-day retention, and offers Zero Data Retention on approval, with no seat minimum and per-token billing. Claude Enterprise adds Zero Data Retention, audit controls, and a HIPAA Business Associate Agreement, but carries roughly a 70-seat minimum and a ~$20/user/month base seat fee with token usage billed separately. For most small and mid-size firms Oktopeak deploys the API with Zero Data Retention (same no-training and no-retention guarantees, no seat minimum) and reserves Claude Enterprise + BAA for larger firms and healthcare clients that require the BAA. Either way, matter content is reached through the practice management API rather than a chat window, and every AI action is logged for ABA Opinion 512. **Q: Where is the team located?** A: Serbia, CET timezone. Full London overlap, 6+ hours with New York. US business partner for coordination. 10+ years serving US/UK clients. **Q: What cloud platforms do you deploy on?** A: Azure and AWS. Azure is preferred for healthcare clients due to Microsoft's HIPAA BAA coverage across services (App Service, Cosmos DB, Azure SQL, Azure AD B2C, Azure OpenAI). **Q: Can you rescue a failed or abandoned project?** A: Yes. Our strongest case study is a DEA compliance platform where the previous developer delivered a broken MVP (61 TypeScript errors, no infrastructure). We shipped it production-ready in 8 weeks. **Q: Will you rewrite my existing codebase from scratch?** A: Not by default. Most agencies push for full rewrites because it's easier for them, not better for you. We start with a code audit. If the foundations are solid, we keep what works and build forward. If the audit shows real structural problems, we tell you exactly where, and you decide whether to patch or rebuild. You shouldn't pay twice for code that already works. **Q: What if we want to bring development in-house after launch?** A: We design every engagement for eventual handoff. Architecture Decision Records in the repo, tests as documentation of behavior, runbooks for operations, and standard tech choices so hiring is easy. If you hire a CTO during the build, we pair them in as we go. Our retainer ramps down over 12 months by design. We win when your team becomes independent, not when you stay dependent. **Q: How do you handle production emergencies given the time-zone gap?** A: We don't pretend to offer 24/7 US coverage we can't deliver. What we do: daily server and log monitoring on your cloud (Azure, AWS, or GCP) so we catch issues before users do, offline-first architecture so local data works during API outages, and P0 incidents (system down, patient impact) get 30-min response via on-call rotation with extended evening-CET coverage. Prevention-first architecture matters more than theatrical SLAs for high-stakes production systems. **Q: How do I connect Claude to Lawmatics?** A: Use the free open-source Lawmatics MCP server (@oktopeak/lawmatics-mcp on npm, first on Anthropic's MCP Registry). Ask Lawmatics support to enable Developer Settings (free, API requires the Pro plan), run the one-time auth command, and paste the never-expiring token into your Claude Desktop or Claude Code config. Read-only mode available. 15-minute guide: https://oktopeak.com/blog/lawmatics-mcp-setup-guide/