LawToolBox vs LawX: how they compare in 2026
LawToolBox and LawX are not usually weighed against each other, because they are built for two different legal systems. LawToolBox calculates court deadlines for US and Canadian courts inside Microsoft 365, and LawX runs German notarial offices from matter opening to invoice; on one grid they tie. Each sits in the top two bands on nine of fifteen axes, identical on eight. The tie holds because both publish full prices and integrate deeply with the systems their users already run. It splits on where each puts its weight. LawToolBox writes its limits into its agreement: output is legal information, not advice, a licensed attorney must review every deadline, and the firm must keep a second, independent deadline system. It also names Microsoft Azure OpenAI, running in the customer's own tenant, as its model provider. LawX names no model provider, but its AI runs through the whole notarial workflow, and it signs professional confidentiality undertakings once it handles mandate data. Neither holds a security certification of its own.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The AI is real, it is the vendor's own, and it sits on top of a product that predates it by a quarter of a century. The core is a rules-based deadline engine: enter a trigger date and the platform calculates the dependent deadlines from rule sets the vendor's own attorneys build and maintain, covering thousands of state and federal courts, under a patent the company filed for online deadline management in 1998. No model is involved in that. LawToolBox AI is a separately licensed add-on that requires Azure OpenAI to be enabled in the customer's own Microsoft tenant, and what it adds is a way in: reading an email, an attachment or a handwritten court order, pulling the dates out, mapping them to the civil rules behind them and summarising documents. Useful, and removable without touching what the firm bought. A buyer should read the AI as an intake layer on a deterministic calculator, not as the calculator. Verified 20 September 2026.
The machine learning is a real layer across a conventional system rather than the thing being sold underneath it. What the buyer licenses is a practice operating system: matter creation, deed preparation, execution and XNP export, invoicing, a dashboard with task prioritisation, structured case file export, and interfaces to the commercial register and Microsoft 365. Strip the models out and a working notarial practice management system remains. The AI layer is genuine and specific rather than decorative, covering AI-based checking of incomplete entries, context-sensitive wording suggestions, a land register assistant that reads extracts, communication assistance, automated execution preparation, intelligent matter suggestions and adaptive template use, and the company brands the whole product as an AI-supported operating system. That branding is not what the band measures. Checked 4 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Nothing is measured, and the vendor is unusually blunt about why that matters. The agreement warns that the deadline charts and forms the product generates may be out of date or built for a different state or jurisdiction, may not match local court rules, and carries an express disclaimer of any warranty that the information is correct, complete or current. The AI ethics page says plainly that AI hallucinates and makes mistakes and that a licensed person must review everything it produces. Against that, the pricing FAQ says a dedicated team of attorneys monitors court rules daily so deadlines are always up to date and accurate, which is the opposite claim in the opposite register; both are on the estate and a buyer should notice the gap. What grounding exists is structural rather than published: deadlines derive from named rule sets listed in a public catalogue, and the AI maps extracted dates to the rules behind them. No error rate, sample or test of the extraction is published. Verified 20 September 2026.
Accuracy is asserted without measurement and hallucination is not addressed anywhere. The published claims are outcome claims: automated checks mean matters run reliably from the outset, error sources are minimised, excellence becomes the standard rather than the exception. None carries a figure, a test set, a method or a date. What does exist is structural grounding rather than described grounding: outputs are built from the firm's own templates and from data read out of the commercial register and the land register through named interfaces, so a drafted deed starts from official register content and a stored precedent rather than from model recall. That is a real architectural constraint and it is why this does not sit at the floor. Nothing published describes what happens when the model is wrong, no accuracy evaluation is linked, and the words hallucination and error rate appear nowhere on any surface read.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
The constraint is categorical, it is the vendor's own, and it is in the contract rather than the marketing. The agreement states that the application is intended to be used in conjunction with other deadline reminder and calendaring systems, and conditions use of its reminders on the firm representing that it has at least one other independent method of calculating and being reminded of its deadlines; the firm also agrees to verify the algorithms independently against the needs of the matter. The vendor says that condition is priced in. Around it sits a described review structure: extracted deadlines are presented in Outlook for the user to check and edit before they go anywhere, the privacy policy states that no calendar event is ever added without the registered user's prior consent, and the agreement requires a licensed attorney competent to manage the case to review and modify all deadlines and pleadings. What the system does alone, what it may not be relied on for, where a person checks it and how a matter returns to human judgement are all published. Verified 20 September 2026.
A written commitment that the professional approves, with a review point visible in the product. The automation section of the pricing page is headed with the principle directly: Sie geben frei, you release it. The product illustration carries the same shape, showing the assistant proposing a matter update and then asking the user to confirm it is correct before applying it, so the approval step is a described interaction rather than an aspiration. The positioning reinforces it, with routine processes running in the background so the professional concentrates on the legal substance and has more time for substantive review. What is absent is the rest of the control structure: no threshold is published at which the system defers or escalates, nothing states which steps run unattended against which require approval, and nothing addresses what happens after an error reaches a deed or an execution filing.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
There is customer material, and none of it is about the AI. The case studies index carries nine items dated between 2015 and 2021, every one of them written by a platform or a publication rather than the vendor: Microsoft Azure and Microsoft Office customer stories, a Microsoft Teams story for legal departments, a LexisNexis case study on LawToolBox with Time Matters at the Los Angeles Unified School District, and a LegalTalk Network episode on rules-based docketing. The most recent predates the AI features by two years. A separate customer story on Microsoft's partner site names an attorney at Marrache Law. The vendor's own testimonials carry first names and job titles only, three of them paralegals, with no firm named and no figures. Awards are from 2018. So a buyer can see that the deadline platform has been deployed and written about for a decade, and cannot see a single account of the AI in production. Verified 20 September 2026.
Logos stand in for evidence on the surfaces read. Roughly seventeen unlabelled marks appear on the home and pricing pages under a heading describing experienced practitioners accompanying the product, with no indication of which are customers, which are advisers and which are media. The claim that the product is proven in notarial practice is made without a named office behind it. One genuinely third-party marker is published and is worth recording: LawX appears on the Federal Chamber of Notaries listing of software houses for IT use in the notarial office, which is a professional body's register rather than a vendor claim, and the company states it maintains an exchange with the chamber and regional chambers and contributes to specialist committees. No named customer, no figure, no matter volume and no date appears on any surface read. A dedicated customer page exists in the navigation and was not opened in this pass; it is the cheapest available upgrade on this record.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive commitments, one of them a warning the vendor did not have to publish. The agreement limits use of Confidential Information to performing the vendor's obligations, and its anonymous aggregation clause states that no client file information is ever available or accessed. The privacy policy says matter data sits in dedicated databases on dedicated servers and that personal information there is never shared with third parties, that every employee signs a confidentiality undertaking and passes a background check, and that a firm administrator controls who reaches which matter, can grant read-only access and can withdraw a departing user from every matter. The AI adds a strong position: processing happens inside the customer's own Microsoft container and no result is stored by the vendor. Two things hold it here. The agreement states that emails sent by the application are not encrypted and asks the firm to weigh what that means for privileged material it chooses to store in reminders. And privilege is addressed in that warning rather than in any commitment. Verified 20 September 2026.
The professional secrecy limb is met directly and in the German idiom, which is what this axis exists to find. The security page commits to concluding professional confidentiality undertakings as soon as mandate data is processed, which is the obligation that carries the notary's and lawyer's duty of secrecy onto the vendor's staff rather than a generic confidentiality clause. Processing is described as compliant with both data protection law and professional law throughout. Segregation is documented at feature level with role-based rights management and logging of access, alongside client structure and multi-location capability. Residency is specific, with accounts hosted in German data centres. Encryption is stated at TLS 1.2 or higher in transit and AES-256 at rest. Three limbs are missing entirely and hold this at B: nothing anywhere states whether customer or mandate data is used to train models, no retention or deletion position for mandate data exists, and no model provider is identified, so what any underlying provider may retain is unstated. The published privacy policy covers website use and the pre-contractual sales process only, and expressly defers processing under the customer relationship to a contract that is not published.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
The clearest treatment of the advice line on this index, and it sits in the agreement. A section headed Duty to Consult a Licensed Attorney states that what the product generates is legal information of the kind found in a legal publication or a retail legal form, that the user is not receiving legal advice, that the material is general in nature and may not fit the user's circumstances, and that the output must be verified by an attorney licensed to practise in the applicable state or venue. It goes on to require that a licensed attorney competent to manage the cases loaded onto the platform review and modify as necessary all deadlines and pleadings, and describes the product as generating a first draft and saving time rather than supplying judgement. Competence, supervision and jurisdiction are each named. The AI ethics page adds the same point for the machine: a person licensed to practise must review all AI-generated work, the way they would review a paralegal's. Verified 20 September 2026.
A real published position on professional responsibility, short of the full treatment. Compliance with professional law is stated as a design principle rather than a footnote, with the security page headed on the point and data processing described as compliant with both the GDPR and professional law. The company publishes an active relationship with the profession's regulator, stating that it maintains a close exchange with the Federal Chamber of Notaries and regional notary chambers and contributes expertise to specialist committees, and it links the chamber's own register of notarial software. The professional's role is addressed rather than assumed: routine processes run in the background so the professional concentrates on the legal substance, and the approval principle places the release decision with the office. What is missing from the top band is an express statement of what the output is and is not. Nothing says the product does not give legal advice, nothing addresses the boundary between a prepared draft and a professional's own judgement, and no jurisdiction limit is stated, although the whole product is built around German notarial and court procedure.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A stated commitment with nothing behind it that a buyer could audit. The vendor says it is committed to responsible AI and publishes a Responsible AI Guarantee: results are generated through Microsoft Azure AI and Copilot, which by design do not train on customer data; the vendor does not and cannot store AI-generated results; nothing goes into a Microsoft or LawToolBox model. Its ethics page also addresses bias, though as a duty it places on the reader, telling attorneys they are obliged to understand any bias embedded in AI results and the data set behind them, and noting in its own case that the data set is always defined by the end user, who points the AI at a specific file or URL or at files in their own tenant. That is an architecture argument rather than a governance one. No owner inside the company is named, nothing is published about what is tested before a change ships, and no finding about uneven output has been disclosed. Verified 20 September 2026.
No governance position is published for the product. There is no responsible AI statement, no governance framework, no named owner accountable for model behaviour, no evaluation or testing regime for output quality, no published results and nothing at all on bias. Two published items sit close to the subject and neither answers it. The privacy policy states that no automated decision-making or profiling within the meaning of Article 22 GDPR takes place, but scopes that expressly to operation of the website and to contract initiation and performance rather than to the product's processing of mandate data. And the EU AI Act appears only through a partner's training offering, which sells firms a course on meeting AI Act compliance requirements, so it is a service sold alongside the product rather than a statement of the vendor's own governance. A data protection officer is named, which is a data protection role and not an AI one. Searched the home page, product, pricing, security and privacy pages on 4 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Access and handling are described in real detail; the ends of the data's life are where it thins. Published: matter data in dedicated databases on dedicated servers, https in transit, passwords stored as PBKDF2 hashes with the iteration count and key sizes given, single sign-on through OpenID, firm administrators controlling per-matter access with read-only options and full revocation when someone leaves, OAuth tokens for integrators that a Microsoft global administrator can revoke from their own Azure portal, background checks and confidentiality undertakings for every employee, and server request logging kept inside the company. For the AI specifically, nothing is retained because processing stays in the customer's Microsoft container. The gaps: no subprocessor list, no incident response or breach notification practice, no encryption-at-rest statement, and a retention position that runs the other way, since a subscriber's data is not deleted until all statutes of limitation have expired. Verified 20 September 2026.
Substantive published policy across most of the ground, with the matter-data half missing. What is published is specific: hosting of customer accounts in ISO 27001 certified German data centres holding a BSI C5 attestation, TLS 1.2 or higher in transit and AES-256 at rest, role-based rights management with logging of access, access control and login logs, and regular audits and tests described as an ongoing process rather than an event. Governance of personal data is properly staffed, with a named data protection officer and a stated supervisory authority. The privacy policy publishes a full named processor list for the website and sales process, covering Framer, Microsoft Deutschland, Attio, Intercom, Mailchimp, Luma, Typeform, Posthog, Google Ireland, Calendly and TeamViewer, with third-country transfers addressed under the Data Privacy Framework and Article 46 safeguards and an unusually frank statement of the residual FISA risk. What is absent is everything covering mandate data after processing: no retention period, no deletion commitment, no incident or breach notification practice, and no processor named for the AI itself. The privacy policy states in terms that it covers website use and pre-contractual measures, with the customer relationship governed by a contract that is not published.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Published, specific, and pointed entirely away from the vendor. The agreement sells the product as is with all warranties disclaimed, invokes the economic loss doctrine, and carries an exculpatory clause in which the user releases the vendor from all liability for negligence, including negligent misrepresentation. The sole and exclusive remedy for any claim of harm or economic loss, however framed, is a refund: the amount paid for the specific matter where the firm pays per matter, or no more than six months of that user's fees. The vendor ties this back to the firm's own non-delegable duty to have every deadline reviewed by an attorney. Alongside it sits a real service level agreement with a 99.9 per cent monthly uptime target and credits of 10 or 25 per cent of that month's fees, claimable within 30 days and capped at the month's fees. That answers downtime. Nothing answers a deadline calculated wrong. Verified 20 September 2026.
Nothing is published on who bears the loss when the system is wrong. There are no general terms and conditions, no customer agreement, no master subscription terms and no service level document anywhere on the site. The navigation carries Product, Solutions, Customers, Pricing, Security and a company menu; the footer carries an imprint, a privacy policy, careers and support. The imprint is the disclosure German law requires of any commercial website and says nothing about the contract. No indemnity, no liability cap, no warranty, no uptime commitment and no insurance position was located, and the privacy policy is the only legal instrument published, expressly scoped to the website and the sales process. A buyer evaluating a system that prepares deeds and executes filings has nothing to read on allocation of loss before entering a sales conversation. Searched the home page, product, solutions, pricing, security, privacy and imprint links and the full footer on 4 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
This is the deepest integration estate in the pull, and it is documented rather than listed. Sixteen named systems each have their own page, split into direct integrations with Actionstep, Caret, LEAP, MyCase, Neos, PracticePanther, Rocket Matter and Smokeball, and Microsoft 365 integrations with Centerbase, ECFX, Filevine, iManage, InfoTrack, NetDocuments, PCLaw and Time Matters, ProfitSolv, Soluno, SurePoint and TagMyFav. What moves is stated: deadlines sync to Outlook, Google and Apple calendars and to case management platforms through published APIs; each matter provisions its own Microsoft group, calendar, Teams space, SharePoint folder structure and OneNote; a document management system can be connected to deadlines or Microsoft itself used as one. Configuration is described in the subscription terms, from administrator rights and application permissions to Outlook rules and calendar filters, and the connector surcharge is published at four dollars per user. Third-party integrators authenticate with their own OAuth tokens. Verified 20 September 2026.
The integrations are named, specific to the jurisdiction's actual infrastructure, and described in terms of what moves. Into the office: Microsoft 365 with Outlook and Word named, with drafts and letters prepared directly in Word, and email integration that assigns incoming mail automatically to the correct matter. Into the official systems that notarial work runs on: a commercial register interface, a land register assistant that reads extracts intelligently, and export to XNP, the electronic notarial filing standard, including into the deposit register for escrow. Outward: structured export of case files, so a customer can leave with its data. Through named partners: a DATEV interface for accounting and e-invoicing, transparency register extracts and sanctions screening in the anti-money-laundering workflow, and escrow account opening with transactions flowing back into the LawX file. Onboarding covers data migration explicitly, and the product is documented as able to run in parallel with an incumbent system rather than requiring replacement, which is the practical question an implementer asks first.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The tenancy story is stated clearly and in two halves that a buyer needs to hold together. On one side, every plan carries the promise to keep data in the customer's own tenant, and that is literally true for the Microsoft artefacts the product creates, the matter groups, calendars, Teams spaces, SharePoint folders and documents, and for the AI, which runs on the customer's own Azure OpenAI inside their Microsoft container and returns nothing to the vendor. On the other, the privacy policy states that matter and personal information submitted to LawToolBox is stored in dedicated SQL databases on dedicated LawToolBox servers, which is a separate estate under the vendor's control. No region is published for those servers, no residency option is offered, no single-tenant or on-premises alternative is described, and nothing addresses where a customer outside the United States would sit. Verified 20 September 2026.
Residency is published precisely and tenancy is not addressed. The security page states that the customer's account is hosted in ISO 27001 certified data centres in Germany holding a BSI C5 attestation, and describes the arrangement as compliant with both data protection law and professional law. That is a specific country, a named certification regime for the facility and a named German federal attestation standard, which is a good deal more than a region label. What is absent is the tenancy limb and the processing limb. Nothing states whether the platform is single or multi-tenant, no dedicated or private option appears at the single published price tier, and nothing distinguishes where mandate data is stored from where model inference happens, which matters because no model provider is identified anywhere. Multi-location capability is published but describes the customer's own offices rather than the deployment model.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
No independent attestation was located and none is claimed. There is no security page and no trust centre in the navigation or the footer, no SOC 2, ISO or penetration test reference in the agreement, the privacy policy or any product page, and no report offered on request. What appears instead is the phrase Enterprise Security listed as a feature included in every plan, with nothing behind it, and a detailed self-description of security measures in the privacy policy which is a statement of practice rather than an audit. The vendor does lean on Microsoft's posture, noting that AI processing happens behind Microsoft's enterprise-grade security inside the customer's own tenant; that is the host's assurance, not the vendor's. The absence is recorded rather than inferred: the navigation and footer were run to the bottom and one search for an attestation returned nothing from the estate. Verified 20 September 2026.
LawX holds no independent attestation of its own and says so plainly, which is honest and does not change what is located. The security page states that its processes and systems are oriented to ISO 27001 standards and that certification is currently in preparation. An orientation is a self-assessment: no certifying body, no scope, no observation period and no date, and nothing a buyer can check against a register without asking. The ISO 27001 certification and the BSI C5 attestation named on the same page belong to the data centres hosting the accounts, not to LawX, and the page is careful about that distinction, so they credit to the host and are recorded on the deployment axis instead. Regular audits and tests are described without naming an auditor, a standard or a cadence. There is no trust centre, no report is offered at any access tier including on request, and no penetration testing is mentioned. Checked home page, security page, pricing page, privacy policy and footer on 4 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The provider is named without hedging and the architecture is the disclosure. All AI features run on Microsoft Azure OpenAI, and the vendor states that the processing happens inside each customer's own Microsoft 365 cloud, interpreting only data that user can already reach, with prompts and responses never used to train models that benefit other legal professionals. Activating the feature requires Azure OpenAI to be enabled in the customer's own tenant, and a firm can bring its own Azure OpenAI licence and run its own prompts against its own documents or a URL. That answers whose models, where they run and on whose account more completely than most records in this index manage. What is not published is the rest: no model or version is identified, nothing states which Azure region serves the deployment, and nothing commits to telling customers if the underlying model changes beneath a prompt library they have built. Verified 20 September 2026.
Nothing is published about the model supply chain a customer inherits. No model is named, no model provider is identified, no location is given for inference, and no commitment to notify customers when any of it changes was located. The one detailed processor list the company publishes, in the privacy policy, covers the website and the sales process and names Framer, Microsoft Deutschland, Attio, Intercom, Mailchimp, Luma, Typeform, Posthog, Google Ireland, Calendly and TeamViewer; none of those is presented as processing mandate data and the list is expressly scoped away from the customer relationship. So a buyer can establish in detail who handles a demo request and nothing at all about what reads a deed. The gap is conspicuous on a product whose security page otherwise engages professional secrecy directly. Searched the home page, product, pricing, security and privacy pages on 4 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
A buyer can work out the bill without speaking to anyone. Rates are published for every firm-size band in both cadences: billed yearly, $35 per user per month at 2 to 9 users, $33 at 10 to 19, $23 at 20 to 79 and $19 at 80 or more; billed monthly, $42, $40, $30 and $22. The unit is stated as a licence for every Microsoft 365 licensed mailbox in the firm or department, the commitment is a minimum of one year, and cancellation carries no refund for the current term. What implementation adds is published too: four dollars per user to activate the NetDocuments, iManage, ECFX or InfoTrack connectors, additional training and consulting at $225 an hour, up to 20 published rule sets included for firms of 20 or more with further jurisdictions quoted on request, and onboarding quoted separately. One figure is withheld, and it is the one this index cares about most: LawToolBox AI is described only as an additional fee. Verified 20 September 2026.
One published figure, one unit, one term, and the whole feature set itemised against it. The price is 159 euro per licence per month on annual payment, presented as a single tier with no packaging to decode and no enterprise band withheld. What the licence includes is listed in detail rather than gestured at, across five groups: core processes covering matter creation with register data capture, deed preparation and drafting, execution and XNP export, invoicing, dashboard and task prioritisation and structured case file export; communication and documents covering email integration with automatic assignment, AI communication assistance, file and party management, the commercial register interface and the land register assistant; security and compliance; technical integration covering Microsoft 365; and automation and AI. Implementation is addressed rather than left open, with onboarding, data migration and customer service published as included in the licence under LawX Care. The only thing a buyer cannot do is purchase without contact, since every route resolves to booking a demo, which the band does not require.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Who this is for is documented segment by segment, and so is what it does not cover. Four buyer pages sit in the navigation: law firms, corporate legal departments, enterprise firms, and government and agencies, and the pricing bands run from two users to eighty and above, so a solo practice and an enterprise deployment can each see themselves. Practice coverage is stated rather than claimed: thousands of state and federal courts across the United States and Canada, with bankruptcy, patent, family law, probate, estate and administrative rules named, and a published rule set catalogue a buyer can read before subscribing. The limits are stated in the agreement itself, which is rarer: a subscription includes up to 20 published rule sets for firms with 20 or more licensed users, rule sets outside the catalogue are quoted on request, and those marked private preview are excluded unless agreed. Custom rule sets are built on request at extra cost. Verified 20 September 2026.
Coverage is described with substance in two dimensions and the boundary is soft. Two buyer segments are named and their relationship is stated honestly rather than blurred: the product is proven in notarial practice and is now being offered to law firms, with a separate landing page for firms offering early access and introductory terms, which tells a buyer plainly which segment is mature. Within the office, three roles are addressed separately with their own material, covering the professionals themselves, staff, and IT specialists. Practice coverage is evidenced concretely through the workflows rather than claimed, spanning property purchase deeds, land register and commercial register work, execution and deposit, escrow accounts and anti-money-laundering checks, which is the substance of German notarial practice. What is missing is the edge: no firm size is addressed, no matter volume is stated, in-house and government use are not mentioned, and nothing says which areas of practice fall outside the system. The solutions and customer pages were not opened in this pass.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
Never, stated as a guarantee on a policy page, with a contract that stops short of saying it. The AI ethics page carries a Responsible AI Guarantee: results are generated through Microsoft Azure AI and Copilot, which by design do not train on customer data, the vendor does not and cannot store any AI-generated result because processing stays inside the customer's own Microsoft container, and none of the customer's data is ever used to train a Microsoft or LawToolBox model.
The agreement never uses the word training. What it does is narrower and still useful: the customer grants a right to use Confidential Information for the sole purpose of performing the vendor's obligations, and a separate clause permits aggregate anonymized reports on system usage and content trends with five named safeguards, including that no personally identifiable information is extracted and no client file information is ever available or accessed.
No agreement is published. LawX publishes no general terms and conditions, no customer agreement and no data processing agreement; the footer carries an imprint and a privacy policy and nothing else. The privacy policy states at its opening that it covers use of the website and the initiation of a contract, and that further processing under the customer relationship is explained when the contract is concluded, so it never reaches mandate data.
Nothing on the security page, the product page or the pricing page states whether client or mandate content is used to train or improve models. The absence sits against a security page that does engage professional secrecy directly, which makes it a gap in an otherwise deliberate disclosure rather than general silence. Searched the home page, product, pricing, security, privacy and imprint on 4 September 2026.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
For the AI the window is zero, and the vendor explains why rather than asserting it. Prompts and results stay inside the customer's own Microsoft container: the feature runs on Azure OpenAI in the customer's tenant, interprets only data that user can already reach, and the vendor says it does not and cannot store any AI-generated result. That is a definite position, not a vague one. Matter data is the opposite case and a buyer should read the two together.
The privacy policy states that a subscriber's account can be disabled but the data will not be deleted until all possible statutes of limitation have expired and all potential claims against the vendor are released; only trial accounts can ask for deletion outright. So nothing the machine produces is kept, and what the firm typed into the platform is kept for a period measured in years and defined by litigation risk rather than by a retention schedule.
No located public material states how long mandate data, prompts or generated drafts are retained. The privacy policy does publish retention periods in detail, but only for the categories it governs: server log files deleted after at most seven days, contact data held while the sales process is active, applicant data deleted after six months or two years in a talent pool, and commercial and tax retention obligations of two to ten years with limitation periods running to thirty.
All of that concerns website visitors and prospects. For the product itself the policy defers expressly to the customer contract, which is not published, and no deletion commitment or end-of-subscription position appears anywhere. The one adjacent product feature is a structured export of case files, which addresses getting data out rather than how long it stays.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Segregation is described at the level this product works at, which is the matter. Every firm gets a firm administrator who controls user permissions matter by matter, can limit a user's access to a shared case to read only, and when someone leaves can withdraw their access to every matter they were granted and then remove them from the firm entirely. Matter data sits in dedicated databases on dedicated servers, and each matter provisions its own Microsoft group, calendar, Teams space and SharePoint folder structure, so the wall a firm builds in Microsoft is the wall the product inherits.
Third-party integrators authenticate with their own OAuth tokens, and a Microsoft global administrator can revoke the add-in's token directly from their own Azure portal. What is not addressed is conflicts: nothing describes screening a named user from a matter for ethical rather than administrative reasons.
LawX maintains and describes its own permission model rather than inheriting one. The security page publishes role-based rights management with logging of access, under the heading that the system is for authorized people only, and the pricing page repeats it as rights management by role plus access control and login logs. Client structure and multi-location capability are published as product features, which is the mechanism by which a firm with several offices keeps files separated.
So the model is LawX's own, documented at feature level, and the office administers its own roles, which is the alignment burden this value describes. What is not published is how the roles map to a wall in practice, and nothing addresses separation between individual matters within a single office, which is the form the question takes for a notary acting for multiple parties.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Disclosure is provided for and no notice attaches to it. The privacy policy says personal information is not disclosed except as described there, to comply with applicable laws or valid legal process, or to protect the vendor's rights or property, and elsewhere lists sharing with third parties when required by law or in response to legal process or lawful requests from law enforcement or government agencies. Nothing commits to telling the customer a demand has arrived, to waiting before complying, to narrowing what is produced, or to helping the firm seek a protective order, which matters more than usual here because the data in question is a law firm's matter list and deadline chart.
The agreement contains no confidentiality clause of the kind that normally carries a compelled-disclosure notice; its confidentiality language runs the other way, limiting what the vendor may do with the firm's information. No transparency report is published.
The privacy policy addresses compelled disclosure and commits to no notice. Section nine provides that data is passed on where LawX is legally obliged to do so under Article 6(1)(c) GDPR, in particular where required by official requests, court orders and legal proceedings for the pursuit or enforcement of rights, and separately lists public authorities receiving data under statutory provisions. No commitment to inform the customer before or after such a disclosure appears, and no discretion over notice is reserved either.
Two limits on the clause are recorded because they matter here: it governs the personal data the privacy policy covers, being website and sales process data, and the policy expressly defers processing under the customer relationship to an unpublished contract, so nothing published addresses compelled disclosure of mandate data itself. No transparency report was located.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
The corpus is court rules, the jurisdictions are published, and the basis on which the rule sets are built is the vendor's own work. A public rule set catalog lists what a subscriber gets, covering thousands of state and federal courts in the United States and Canada and naming practice areas including bankruptcy, patent, family law, probate, estate and administrative rules; the subscription includes up to 20 published rule sets for firms of 20 or more users, anything outside the catalog is quoted, and custom rule sets are built on request.
The vendor says a dedicated team of attorneys monitors the courts daily for rule changes. The deadline algorithms are asserted as the vendor's own intellectual property under a patent and a copyright, and the agreement forbids reusing them elsewhere. What is not stated is which text each rule set is derived from or on what license, court rules being public.
No located public material identifies a corpus behind the product's output. The product works on the firm's own material and on official register data reached through interfaces, drafting from the office's existing templates and reading land register extracts and commercial register entries. Those registers are named as data sources the product connects to, which is an integration fact rather than an identification of a training or retrieval corpus, and nothing states what any underlying model was trained on, under what license, or with what update cadence.
No database, publisher or legal collection is named on any surface read. Searched the home page, product, pricing, security and privacy pages on 4 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No case-law citator, and a currency mechanism of the vendor's own doing the same job for court rules. The pricing FAQ states that a dedicated team of attorneys monitors daily for changes to court rules, a blog post explains how the rule sets are kept current, and dated posts track specific amendments, such as the California summary judgment rule changes effective 1 January 2025. Release notes are published. That is a treatment signal for procedural rules rather than for authority, and it belongs to the vendor rather than a licensed source.
One contradiction a buyer should carry: the agreement says the opposite in the register that binds, warning that the forms and deadline charts the product generates may be out of date or built for a different jurisdiction and disclaiming any warranty that the information is correct, complete or up to date. Nothing published says how quickly a rule change reaches a live rule set.
Nothing on any located surface addresses whether authority is checked for subsequent history. The product does not retrieve or present case law: it runs the operational lifecycle of a matter, drafting deeds from the office's templates and register data, handling execution and export, and raising invoices. The question does not bite on this product class and the honest value is the absence rather than a penalty. Searched the home page, product, pricing and security pages on 4 September 2026.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
Nothing published describes what the extraction does when it cannot tell. The AI reads an email, an attachment or a handwritten order and proposes deadlines for the user to review, but no confidence signal, threshold or abstention is described, and nothing says what a reviewer sees when the model has found a date it is unsure of, or an order it cannot parse, as distinct from one it has read cleanly. The vendor's answer to uncertainty is structural rather than behavioral, and it is a serious one: the agreement conditions use of the product on the firm keeping a second independent method of calculating deadlines, and the ethics page states that AI hallucinates and makes mistakes and that a licensed person must review everything it produces.
That is recorded on the oversight row. Checked the AI page, the ethics page, the agreement and the privacy policy on 20 September 2026.
No located public material describes what the product does when it cannot ground an output. One published feature sits near the question and answers a different one: AI-based checking of incomplete entries, which flags gaps in the data the office has supplied rather than uncertainty in what the model has produced. That is an input completeness check. Nothing describes an abstention path, a no-answer state, or any confidence or grounding signal surfaced to the professional before they approve.
The published approval principle places a human at the release point, which is a control on the output rather than a description of the system's own behavior when it is unsure. Searched the home page, product, pricing and security pages on 4 September 2026.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No record was located of this product's output being found fabricated or inaccurate in a proceeding, a regulatory action or a published account. Searches on 20 September 2026 across the vendor's estate, press and directory profiles returned nothing of the kind. The exposure here is not an invented citation: the product calculates dates and extracts them from documents, so the failure that would matter is a missed or miscalculated deadline, which is also the malpractice risk the vendor's own marketing names. Nothing published describes such an incident, and no account of one was found.
The AI Hallucination Cases database maintained by Damien Charlotin was searched on 4 September 2026 on both the product name LawX and the corporate name LawX GmbH. No court order, opinion or disciplinary record naming the product was located. The database covers Germany among its jurisdictions. This records the state of the public record on that date and is not a finding about the product.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Professional responsibility is engaged at length, and not one rule, opinion or bar is named. A dedicated page of 23 February 2024 sets out seven duties it says are emerging as ethics rules on AI are promulgated around the United States: never submitting privileged work product to a model that trains on it, understanding how any third-party AI handles firm data, understanding embedded bias and the data set behind a result, treating generative AI as a higher bar than the semantic search offered by the large research providers, having a licensed lawyer review all AI-generated work as they would a new associate's, disclosing to a court the extent of AI use where a jurisdiction requires it, and addressing AI use and billing in the client engagement agreement.
The agreement adds a duty to consult a licensed attorney in the applicable state or venue. Substantial, and entirely generic: no model rule, no formal opinion, no state bar guidance is cited.
The vendor names the profession's regulator and describes an active relationship with it. The security page states that LawX maintains a close exchange with the Federal Chamber of Notaries and with regional notary chambers, that it contributes expertise to specialist committees, and it links the chamber's own published listing of software houses for IT use in the notarial office, where LawX appears. Compliance with professional law is stated as a design constraint across the security and pricing pages, and professional confidentiality undertakings are committed once mandate data is processed.
What is not published is a mapping: no individual rule, chamber guideline or opinion is cited, and nothing sets out how specific product behaviors meet specific professional obligations, which is what separates this from the top value.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
The fee question is addressed squarely, as advice, with no record behind it. The ethics page tells attorneys to set out in their client agreements whether they will use AI and how they will bill for it, states that they cannot bill an hour for work the AI did in five minutes, allows billing for the time spent drafting and revising prompts, and points to flat or contingent fee arrangements as a way to capture the value instead.
That is more than most vendors say. What does not exist is the record that would let a firm act on it: the vendor states it does not and cannot store any AI-generated result, so nothing marks which deadlines or summaries the machine produced, and no export exists to show a client. The published commercial case is time saved, through an ROI calculator and claims about hours recovered from hand-calculating deadlines, with nothing addressing what a client is told.
No located public material addresses billing or disclosure of AI-assisted work. The product raises invoices as a core function and the pitch is built on efficiency, with routine work automated so the office can handle more matters despite a shortage of qualified staff, but nothing quantifies a saving and nothing addresses what happens to a fee when the work takes less time. The question has a particular shape in this market and is untouched: German notarial fees are fixed by statute rather than billed by the hour, so the compression this signal was written for does not translate directly, and nothing published engages either that point or the position for the law firm segment the company is now entering. No per-matter record of AI-assisted work is described.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A buyer would answer some of a diligence checklist from published material and would have to ask for the rest. What is published, and readable before signing, is the full agreement including the service level terms, the security practices in the privacy policy, and the model provider: Microsoft Azure OpenAI, running inside the customer's own tenant. What is absent is the pack itself. No subprocessor list exists; the privacy policy refers in general terms to other companies employed to provide hosting, network services, IT support and customer service without naming any.
There is no security certification, no penetration test summary, no data processing addendum, no business associate agreement and no stated incident response or breach notification practice, and nothing is offered on request. Checked the agreement, the privacy policy, the full navigation and the footer on 20 September 2026.
No located public material supports a client-side disclosure obligation for the product. A full and current processor list is published in the privacy policy, naming Framer, Microsoft Deutschland, Attio, Intercom, Mailchimp, Luma, Typeform, Posthog, Google Ireland, Calendly and TeamViewer, with Article 28 obligations, third-country transfers addressed under the Data Privacy Framework and Article 46, and a frank statement of residual United States surveillance risk.
That is a genuinely good disclosure and it covers the wrong thing: the policy scopes itself to the website and the pre-contractual sales process, so none of those processors is presented as handling mandate data. No model provider is identified anywhere, no subprocessor register for the product exists, and no data processing agreement or forwardable client-facing pack is published at any access tier.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
The vendor raises court disclosure itself, and leaves the firm to produce the record. Its ethics page tells attorneys that if they use AI to generate any portion of a document filed with a court they may have an obligation to disclose the extent of that use, that some jurisdictions go further and require certification that confidential information was not disseminated, and that some require every section generated with generative AI to be identified to the court.
Raising the duty in that much detail is unusual. Nothing in the product answers it. The vendor states it does not and cannot store any AI-generated result, so no log exists of what the machine produced, nothing distinguishes an extracted deadline from one a paralegal typed once both sit on the matter calendar, and no export or format is offered for a filing. Guidance, then, without an artifact.
Some elements of a record are produced and nothing covers the AI itself. Access logging is published twice, as logging of access under role-based rights management and as access control with login logs, so the office has a trail of who did what. Structured export of case files is a published feature, and export to XNP places documents into the official electronic notarial record, which is a formal filing route rather than an internal report.
Register-derived content is traceable to the register it came from through the named interfaces. What is absent is the model dimension entirely: nothing states that the system records which outputs were AI-generated, no model is identified against an output, no record of what a professional reviewed or amended before approval is described as exportable, and no disclosure guidance for a court, chamber or supervisory authority was located.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- Security Certifications and Trust Center
- Refusal and Uncertainty Behavior
- Outside Counsel Guideline Readiness
Which one fits
Choose LawToolBox if
- You need court deadlines calculated from the rules. LawToolBox calculates dependent deadlines from a trigger date using rule sets its attorneys maintain for thousands of state and federal courts in the United States and Canada, and syncs them to Outlook, Google or Apple calendars or a case management system.
- You want AI that pulls deadlines from court orders without leaving your tenant. LawToolBox AI runs on Azure OpenAI inside your own Microsoft tenant, reads emails and attachments including handwritten orders, and presents extracted deadlines for review before they reach a calendar.
- You want to price the whole firm in advance. LawToolBox publishes rates for every firm size, from $35 per user a month billed yearly at 2 to 9 users down to $19 at 80 or more, with connector and consulting fees listed, though its AI is an unpriced add on.
Choose LawX if
- You run a German notarial office. LawX creates the matter with register data, prepares deeds from your templates in Word, reads land register extracts, handles execution and XNP export, and raises the invoice, and it appears on the Federal Chamber of Notaries' software register.
- You want AI that suggests and waits for your approval. LawX checks entries for gaps, suggests wording in context and proposes next steps on a matter, under a published principle that the professional releases each step before it takes effect.
- You want one price with setup included. LawX charges 159 euros per license a month on annual payment, a single tier that includes onboarding, data migration and support, and hosts accounts in German data centers holding ISO 27001 and a BSI C5 attestation.
In summary
LawToolBox
LawToolBox, from LawToolBox.com, Inc. of Englewood, Colorado, is court rules deadline calendaring and matter management built inside Microsoft 365. A user enters a trigger date and the platform calculates dependent deadlines from the vendor's rule sets for thousands of US and Canadian courts, syncing them to calendars and case systems, while each matter gets its own Microsoft group, Teams space and SharePoint folders. LawToolBox AI, licensed separately, runs on Azure OpenAI in the customer's tenant to extract deadlines from emails and orders for review. The AI Legal Index grades it in the top two bands on nine of fifteen capability axes, with A grades on oversight, professional responsibility, integration, pricing and coverage. As of 20 September 2026 the index located no security certification or AI price.
LawX
LawX, from LawX GmbH of Berlin, is a practice operating system for German notarial offices and, more recently, law firms, running a matter from opening to invoice: register data capture, deed drafting in Word from the office's templates, land register reading, execution and XNP export, and invoicing. Its AI checks entries, suggests wording and next steps, and prepares execution, with the professional approving each step. The AI Legal Index grades it in the top two bands on nine of fifteen capability axes, with A grades on integration depth and pricing, at 159 euros per license a month. It hosts in German data centers and signs professional confidentiality undertakings. As of 4 September 2026 the index located no customer agreement, named model provider or training position.
Questions buyers ask
Are LawToolBox and LawX the same kind of product?
No. LawToolBox calculates court rules deadlines and manages matters inside Microsoft 365 for US and Canadian courts. LawX is a practice operating system for German notaries and law firms, covering deeds, registers, execution and invoicing. Both sit in the top two bands on nine of fifteen AI Legal Index capability axes, identical on eight, and both publish their prices in full.
Does LawToolBox tell users its deadlines are not legal advice?
Yes, in its agreement. A section headed Duty to Consult a Licensed Attorney states that its output is legal information rather than legal advice and must be verified by an attorney licensed in the relevant state or venue, and requires a competent licensed attorney to review all deadlines and pleadings. The agreement also requires firms to keep a second, independent deadline system. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Which AI model does LawX use?
LawX names no model or model provider, and states nothing about where AI processing runs as distinct from where accounts are hosted, which is in German data centers. Its detailed published processor list covers its website and sales process rather than client matters. LawToolBox names Microsoft Azure OpenAI, running inside the customer's own Microsoft tenant. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
How much do LawToolBox and LawX cost?
LawToolBox publishes per user monthly rates by firm size: $35, $33, $23 and $19 billed yearly, or $42, $40, $30 and $22 billed monthly, for every Microsoft 365 mailbox, with its AI priced separately and not published. LawX charges 159 euros per license a month on annual payment, including onboarding, data migration and support. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
What do LawToolBox and LawX both leave unpublished?
An independent security attestation and any measure of AI accuracy. Neither holds a SOC 2 report or ISO certification of its own, LawX stating that its certification is in preparation. Neither publishes an error rate for AI extraction or drafting, names who is accountable for its AI, or commits to notify customers when authorities demand their data. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Three readings to weigh. LawToolBox's agreement caps its liability at a refund of up to six months of fees and warns that its deadline charts may be out of date, while its pricing page says its rules team keeps deadlines current; both statements are published. LawX publishes no customer agreement, and its privacy policy covers only its website and sales process. LawX states its own ISO 27001 certification is in preparation. LawToolBox was verified on 20 September 2026 and LawX on 4 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.