LEGALFLY vs Noxtua: how they compare in 2026

LEGALFLY profileNoxtua profile
Last verifiedSeptember 3, 2026

LEGALFLY and Noxtua are the two European legal AI platforms in this index, one from Ghent and one from Berlin, and both sell sovereignty as the proposition. Noxtua sits in the top two bands on ten of fifteen axes, LEGALFLY on nine. Noxtua owns its stack. It runs proprietary models trained in house on legal data licensed from national publishers, named individually as C.H.Beck for Germany, Poland, the Czech Republic and Slovakia, MANZ for Austria, Ciela for Bulgaria and Blendow for Sweden, on European infrastructure it identifies to the facility including Deutsche Telekom's Industrial AI Cloud in Munich, and it states compliance with the German professional secrecy provisions at section 43e BRAO and section 203 StGB. LEGALFLY answers on architecture rather than ownership: documents are anonymised before analysis begins, and that component can run inside the customer's own environment so identifiable data never crosses to the tenant, one of three deployment models published with the differences spelled out.

At a glance

Category
LEGALFLYGeneral Legal Assistants
NoxtuaGeneral Legal Assistants
Founded
LEGALFLY2023
Noxtua2017
Headquarters
LEGALFLYGhent, Belgium
NoxtuaBerlin, Germany
Last verified
LEGALFLYAug 29, 2026
NoxtuaAug 29, 2026

All 15 axes, side by side

The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

LEGALFLY
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.

The models are the product. Every surface sold is a generative or machine learning capability: research agents, contracting agents, compliance agents and a studio for building custom agents. The anonymisation layer that differentiates the product is itself a fine tuned model rather than a rules engine. Remove the models and nothing remains.

Noxtua
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.

The artificial intelligence is the product, and further down the stack than any other record on this index. The vendor states it is built as a complete system with control over infrastructure, model, data and interface, running proprietary models trained on licensed legal data rather than calling third party foundation models. It also publishes its own legal embedding model, Noxtua Voyage Embed, built with Voyage AI and dejure.org. Remove the models and nothing remains.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

LEGALFLY
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Accuracy is asserted and the grounding behind it is not documented. Vendor material states that answers are grounded in verified case law and legislation across more than 130 jurisdictions and that anonymisation preserves full legal and contextual accuracy of every review, which is an accuracy claim with nothing behind it. Searched the site, the six product pages, the Knowledge platform page, the security page and the resources index on 29 Aug 2026 and located no description of the retrieval method, no statement of how output links back to primary sources a reader can open, no accuracy figure, no hallucination rate and no evaluation. Two jurisdiction counts appear on the same home page, 110 plus in one place and 130 plus in another, which is the kind of inconsistency that matters on an accuracy axis.

Noxtua
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Grounding is real and documented, with published comparative measurement on one component, short of accuracy figures for the product itself. The retrieval method is described in unusual detail: the agent analyses a query, develops a solution plan, and researches systematically across licensed publisher content, with version 5 generating a knowledge graph per query that surfaces relevant sources and maps how they connect. Output carries verifiable source references into a licensed corpus a reader can open. Uniquely on this index the vendor publishes measured figures for its own retrieval model, stating Noxtua Voyage Embed outperforms a named OpenAI embedding model on legal text benchmarks with 1.7 times better search accuracy and 2.2 times better ranking quality at three times lower dimensionality. That is retrieval quality rather than answer accuracy. Not located as of 29 Aug 2026: an accuracy or hallucination rate for generated output, a test set for it, or any abstention behaviour.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

LEGALFLY
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

A real published commitment with described control surfaces, short of the full structure. Agent Studio documentation states that workflows trigger automatically from email, Slack, Teams or manually, that conditional logic routes work and handles follow ups, that the system escalates when needed, and that approval steps keep legal in control without bottlenecking every decision. That is an oversight mechanism described at the point where an agent acts, and the escalation and approval language is more specific than most of this market publishes. Not located as of 29 Aug 2026: the threshold at which an agent escalates rather than proceeds, who configures it, and what the vendor commits to when an agent is wrong.

Noxtua
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.

Autonomy is claimed and oversight is asserted without a mechanism. The vendor describes agentic AI that independently develops a solution plan and executes systematic research, and states results are traceable at every stage, which is transparency of process rather than a control structure. Searched the site, the three product pages, the security page and the press releases on 29 Aug 2026 and located no description of what the system does on its own versus what a lawyer must approve, no review surface, no threshold at which the agent stops, and no statement of what happens after an output is wrong. Traceability shows a reader what happened; it does not establish who decides.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

LEGALFLY
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Real deployment evidence with substance, short of measurement. Three named customer stories are published, ECS on streamlining legal review across departments, PIF Group on speed, consistency and quality, and Wealins of Foyer Group on broader market coverage and reduced external legal spend, alongside a customer logo wall and named enterprise references reported in funding coverage including Slaughter and May and Allianz. Not located as of 29 Aug 2026: figures for what changed at any named customer, dates, or a method a reader could assess. The reduced external legal spend claim carries no number.

Noxtua
CC on Operational and Outcome EvidenceCustomer logos and unattributed testimonials stand in for evidence, or results are quoted with no basis stated.

Customer logos and an unattributed selected clients strip stand in for evidence. A customer stories page exists in the navigation, and a named endorsement appears from Dr Markus Kaulartz, partner at CMS, though CMS is also a co-initiator and investor rather than an arm's length customer, which is disclosed on the page and weakens it as independent evidence. Corpus scale figures are published, 130 million plus searchable documents and 8.5 million plus court decisions, but those describe the database rather than a deployment. Searched the site, the customer stories entry point and the press centre on 29 Aug 2026 and located no named deployment with figures, dates and an assessable method.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

LEGALFLY
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Substantive published commitments built around an unusual architectural claim, short of the full picture. The vendor states that documents are anonymised before analysis begins, that in the on premise configuration sensitive data never leaves the customer environment in identifiable form, that environments are isolated per client, and that the customer retains data ownership throughout. Anonymisation is configurable, with adjustable levels and term whitelisting. Segregation is documented at the level this buyer segment requires under the amended band, through per client environment isolation and single tenant deployment. Two gaps hold it off an A. Attorney client privilege and work product handling is not addressed directly in located material. No training prohibition on customer content was located on the public pages as of 29 Aug 2026, which for a vendor whose entire pitch is data protection is a conspicuous absence rather than a small one.

Noxtua
AA on Privilege and Confidentiality PostureWritten commitments a buyer can read before signing: no training on client data, segregation documented at the level the buyer segment requires (matter level walls for a firm, tenant level separation for an in house team), privilege and work product handling addressed directly, retention and deletion stated, and the position on third party model providers made explicit.

The most complete confidentiality posture on the index so far, and the only one that engages the professional secrecy question in statute. The vendor states compliance with Section 43e BRAO and Section 203 StGB, the German provisions governing what a lawyer bound by professional secrecy may use, and states this permits use by confidentiality bound professionals without requiring anonymisation. Training is addressed directly and in the negative: inputs and outputs are never used to train the AI and never shared with third parties. Segregation is documented at the level this segment requires under the amended band, with every project encrypted in transit and at rest under its own cryptographic key, strictly controlled access, and every action logged. The vendor further states it has no persistent access to plaintext data. Certification covers AI governance as well as security. Short of a full A only in that the underlying customer agreement is not published, so these commitments were read from the security page rather than a contract.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

LEGALFLY
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

The audience is unambiguous, in house legal and business teams at enterprises, and the vendor is explicit that it is built for that rather than for law firm workflows. But the product is sold to non lawyers by design, with dedicated solution pages for HR, procurement, sales, claims and compliance, and a product called Discovery that delivers legal research and advice. Searched the site, the solution pages, the published terms and conditions and the resources index on 29 Aug 2026 and located no position on the advice line, no treatment of competence or supervision duties, and no statement of jurisdiction limits. Selling a legal advice surface to procurement and sales teams is the configuration where a published position matters most, and none was located.

Noxtua
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

A real position is published and it is grounded in named law rather than a disclaimer. The vendor addresses the professional rules that govern whether a lawyer may use the tool at all, citing Section 43e BRAO and Section 203 StGB and alignment with the EU AI Act, and states the audience precisely across law firms, in house teams, auditors and tax advisers, courts and public authorities. Jurisdiction limits are handled structurally rather than in prose: the product ships as jurisdiction specific editions and the site requires a jurisdiction selection before granting access, which is a real published boundary. Short of an A because competence and supervision duties are not addressed, and because the position is framed around the vendor's own permissibility rather than around what the lawyer remains responsible for.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

LEGALFLY
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

Responsible AI is claimed without a mechanism. The vendor describes itself in published material as setting the global standard for responsible legal AI and states that controls are continuously audited against international standards, and it publishes governed execution and guardrails as product concepts. Searched the site, the security page, the platform pages and the resources index on 29 Aug 2026 and located no named internal owner of model governance, no pre release testing regime for model behaviour, no ISO 42001 or equivalent AI management certification, and nothing on uneven output across matter types, parties or populations. The security governance is real and is a different subject.

Noxtua
BB on AI Governance and Bias DisclosureA published governance framework with real substance, short of testing results or a named owner.

A published governance framework with real substance and independent validation, short of testing results or a named owner. ISO 42001 certification covers the AI management system specifically and is stated alongside ISO 27001, 27017, 27018 and 9001, BSI C5 and TISAX, with the vendor stating controls are independently and regularly audited and publishing a trust center for the full current list. Alignment with the EU AI Act is stated. That is a governance regime for AI rather than a principles page, and it is externally audited. Not located as of 29 Aug 2026: a named internal owner of model governance, published pre release testing results for model behaviour, or any disclosure about uneven output across matter types, parties or populations.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

LEGALFLY
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

Substantive published policy covering most of the ground. Encryption at rest and in transit, per client environment isolation, attribute based access control, multi factor authentication and session governance, SSO across Okta, Azure AD and Google Workspace with SAML 2.0, OIDC and OAuth, annual independent penetration testing, and a trust center published at a stable URL. The anonymisation layer is a genuine data minimisation control rather than a policy statement. Not located as of 29 Aug 2026: a stated retention period or deletion control for documents and prompts, a named subprocessor list, and an incident or breach notification practice. Retention is the notable one, since it is the question this axis asks first.

Noxtua
BB on AI Safety and Data StewardshipSubstantive published policy covering most of the ground, short of the full set: commonly no named subprocessor list or no stated incident practice.

Substantive published policy covering most of the ground. Per project encryption in transit and at rest with a distinct cryptographic key per project, strictly controlled access, full action logging, a stated position that the vendor has no persistent access to plaintext data, regular security reviews and risk assessments, and a Vanta backed trust center at a stable URL. Infrastructure providers are named individually with their own certifications, which is effectively a partial subprocessor disclosure at the hosting layer. Not located as of 29 Aug 2026: a stated retention period or deletion control for documents and prompts, a full subprocessor list, and an incident or breach notification practice.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

LEGALFLY
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

Liability is addressed through published terms and conditions a buyer can read before signing, which puts this above a pure absence, but what was located is the standard shape rather than a position on AI output. Searched the published terms and conditions, the privacy policy, the security page and the trust center on 29 Aug 2026 and located no indemnity running to the customer for third party claims arising from output, no warranty on output, no stated liability cap and no insurance position. For a vendor selling into banking, insurance and regulated manufacturing, the absence of a published position on who bears the loss is a live buyer question.

Noxtua
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

Searched the site, the security page, the imprint, the data privacy statement, the FAQ and the trust center entry point on 29 Aug 2026. No published indemnity, liability cap, carve out, warranty on output or insurance position was located, and no customer terms or general conditions are published at all. Access to the product itself runs through a jurisdiction gated request form, so the agreement is reached through a sales process. Notable given how much else this vendor publishes: the compliance posture is documented in statutory detail while the allocation of loss when output is wrong is not addressed anywhere public.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

LEGALFLY
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Real integrations, named and documented at feature level, short of implementer depth. Microsoft Word and Outlook add ins each have their own product page, workflows trigger from email, Slack or Teams, Multi Review reads across data rooms directly from the customer's document system, and a dedicated integrations page describes the product as embedded across existing enterprise systems. Orientation is toward enterprise business systems rather than legal specific document management, which fits an in house buyer. Not located as of 29 Aug 2026: named document management connectors such as iManage or NetDocuments, and per integration documentation of what moves in which direction and what an administrator configures.

Noxtua
CC on Practice Systems Integration DepthIntegrations are listed as logos or marked as coming, with no documentation an implementer could use.

Integrations are named without documentation an implementer could use. A Microsoft Word integration is stated on the drafting product page, with work possible either in Noxtua directly or in Word. Searched the site, the three product pages, the security page and the FAQ on 29 Aug 2026 and located no other integration: no document management connector such as iManage or NetDocuments, no Outlook, no contract lifecycle or matter management, and no integrations page at all. Nothing describes what the Word integration moves, in which direction, or what an administrator configures.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

LEGALFLY
AA on Deployment Model and Data ResidencyDeployment options and data residency are published, including the regions available, what changes between tiers, and where processing happens as distinct from where data is stored.

The strongest deployment disclosure in the index so far, and the first A on this axis. Three models are published with the differences between them spelled out: fully managed SaaS; single tenant, a dedicated isolated instance deployed in the customer's preferred Azure region, fully managed and completely segregated from other customers; and single tenant plus on premise anonymisation, where the anonymisation component runs inside the customer environment and only anonymised data crosses to the dedicated tenant over private encrypted connections. Residency is stated as customer selected Azure region, and the architecture separates where identifiable data is processed from where the tenant sits, which is precisely the processing versus storage distinction this axis asks for. The public FAQ adds private cloud, hybrid and full on premise. Short of naming the specific regions available.

Noxtua
AA on Deployment Model and Data ResidencyDeployment options and data residency are published, including the regions available, what changes between tiers, and where processing happens as distinct from where data is stored.

Where the software runs and where the data sits is published in more concrete detail than by any other vendor on this index, because it is the product's entire proposition. Hosting providers are named individually with their certifications and their roles: IONOS as a BSI C5 certified critical infrastructure provider operating the Bundescloud; Deutsche Telekom's Industrial AI Cloud, the AI Factory in Munich underpinning the Deutschland Stack for regulated sectors including the judiciary; T Cloud Public, BSI C5 certified for critical infrastructures; and T Cloud Public in Switzerland, BSI C5 certified and FINMA compliant, offering Swiss data sovereignty. The vendor states data stays in Europe on infrastructure operated by European providers independent of US cloud providers and shielded from the US CLOUD Act, which addresses jurisdiction of processing and not merely geography of storage. Short only of a per tier statement of what changes between deployment options.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

LEGALFLY
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Certification is real and stated with an open access route, short of accessible evidence. ISO 27001 and SOC 2 Type II are both stated as certified, annual independent penetration testing is stated, compliance frameworks across the EU, UK and Middle East are named, and a trust center is published at a stable URL, which under the three tier test is materially better than absent. What was not located as of 29 Aug 2026 is any coverage period, audit scope, report date or named auditor. Worth flagging one noun problem: the security page opens by saying the compliance framework is aligned with ISO 27001, SOC 2 Type II and GDPR, and a later section says certified. Alignment and certification are different claims, and the page makes both about the same standards.

Noxtua
AA on Security Certifications and Trust CenterCurrent independent attestation with named scope, reachable without a sales call: a trust center carrying reports, dates and the standards actually covered.

The broadest certification set on the index, with a trust center reachable without a sales call. Named and current: BSI C5, TISAX, ISO 42001, ISO 27001, ISO 27018, ISO 27017 and ISO 9001, with the vendor stating controls are independently and regularly audited and describing itself as the most comprehensively certified legal AI in Europe. The trust center is a Vanta hosted portal at a stable URL carrying the full current certification list and policies, which is a self serve route rather than a sales conversation. BSI C5 and TISAX are meaningful here rather than decorative, being the German federal cloud computing criteria and the automotive industry information security assessment. Short of the very top only because no coverage period, report date or named auditor was located on the public pages as of 29 Aug 2026.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

LEGALFLY
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

The vendor refers to model selection without identifying what sits underneath. The architecture is disclosed at a structural level and it is a real disclosure: the platform is LLM agnostic and selects the best foundation model for each legal scenario, and a fine tuned anonymisation model runs ahead of any external model call. That tells a buyer how the supply chain is shaped. What it does not tell them is which providers are in it. Searched the site, the security page, the anonymisation platform page, the trust center entry point and the published legal pages on 29 Aug 2026 and located no named model provider, no subprocessor list, no statement of where models run, and no commitment to notify customers when the selection changes.

Noxtua
AA on Model Supply Chain DisclosureThe models underneath are named, their providers identified, where they run is stated, and the vendor commits to notifying customers when any of that changes.

The clearest supply chain answer on the index, because the vendor owns the chain. Models are proprietary and trained in house on licensed legal data rather than sourced from a third party foundation model provider, which is stated plainly and is the point of the sovereignty positioning. Where models run is named to the specific provider and facility, IONOS and Deutsche Telekom's Industrial AI Cloud in Munich among them. One named external component is disclosed with its partner: the retrieval model Noxtua Voyage Embed, built with Voyage AI and dejure.org, with the model identifier published. A customer therefore inherits a dependency chain that is both short and named. Not located: a commitment to notify customers when the model or its hosting changes.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

LEGALFLY
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Searched the site, the navigation, the product pages, the industry and solution pages and the published terms on 29 Aug 2026. There is no pricing page anywhere on the property, no published rate, no stated unit of charge, no tier structure and no seat minimum. The only commercial entry point on every page is a demo booking, which is sales gated and earns no credit. Note that three deployment models are published in detail with no indication of what any of them costs or how they differ commercially.

Noxtua
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Searched the site, the navigation, the three product pages, the jurisdictions page and the FAQ on 29 Aug 2026. No pricing page exists, no rate is published, no unit of charge is stated and no tier structure appears. The only commercial entry point is a Get Access request that first requires selecting a jurisdiction, so a buyer cannot reach a figure or even a product edition without entering a sales process. Third party pricing figures were not located either.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

LEGALFLY
AA on Firm and Practice CoverageWho the product serves is documented precisely: firm segments, in house and government use, and the practice areas actually supported, with the limits stated.

Who the product serves is documented precisely and the boundary is stated rather than implied. Five industries carry dedicated pages, banking, insurance, transportation and mobility, technology and professional services, and six functions carry their own, legal, claims, compliance, HR, procurement and sales, which is unusually explicit about reaching beyond the legal department. The vendor states plainly that it is built for enterprise legal and business teams rather than law firm productivity workflows, which is a published limit on who it is not for. Jurisdictional coverage is quantified, though inconsistently at 110 plus in one place and 130 plus in another. Named enterprise references span the segments claimed.

Noxtua
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Segment coverage is described with substance and with an unusual axis of precision. Four segments carry their own published sections: in house legal teams, law firms, auditors and tax advisers, and courts and public authorities, the last being the first explicit judiciary and public administration positioning on this index. Jurisdictional coverage is stated concretely as named editions per country rather than as a count, spanning Germany, Austria, Switzerland, Poland, Czech Republic, Slovakia, Bulgaria and Sweden, each tied to its national legal publisher. Short of an A because practice areas supported are not enumerated beyond a general research, analysis and drafting framing, and because what is not supported is nowhere stated.

The 12 legal signals, side by side

Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

LEGALFLY
Terms silent

Searched the security page, the anonymisation platform page, the published terms and conditions, the privacy policy and the home page on 29 Aug 2026. No located term or policy states whether customer content may be used to train models, either way. The vendor's published position is architectural rather than contractual on this point: documents are anonymised before analysis and, in the on premise configuration, sensitive data never leaves the customer environment in identifiable form. That reduces what a model could receive but is not a statement about training. Under the rule that a value is never inferred from the absence of a contradiction, this records as silent. Conspicuous for a vendor whose entire positioning is data protection.

Noxtua
Never, in policy only

The security page states directly that inputs and the product's outputs are never used to train the AI and are never shared with third parties, and separately that the vendor has no persistent access to plaintext data. The commitment as located sits on a public security page rather than in a customer agreement, and no customer terms are published on this property, so it records at the policy level. Worth noting the training relationship runs the other way as well and is disclosed: the vendor states it trains its proprietary models on legal data licensed from publishers, which is publisher content rather than customer content.

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

LEGALFLY
Not addressed

Searched the security page, the platform pages, the published terms and conditions, the privacy policy and the trust center entry point on 29 Aug 2026. No public material states how long documents, prompts or outputs are retained, whether the customer controls the window, or whether deletion is available. The vendor states that customers maintain data ownership throughout and that environments are isolated per client, neither of which answers the retention question. First vendor on this index to record an absence rather than a period here.

Noxtua
Not addressed

Searched the security page, the data privacy statement, the FAQ, the imprint and the trust center entry point on 29 Aug 2026. No public material states how long inputs, outputs or uploaded documents are retained, whether the customer controls the window, or whether deletion is available. The vendor does publish related architecture, per project encryption under a distinct key and a statement that it holds no persistent access to plaintext data, but neither answers the retention question. Second vendor on this index to record an absence rather than a period.

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

LEGALFLY
Own model, documented

The product maintains its own documented permission model rather than inheriting one from a document management system. Published controls are attribute based access control, multi factor authentication and session governance, configurable to the customer's own standards, with SSO through Okta, Azure AD or Google Workspace enforcing the customer's access policies. Environments are isolated per client, and single tenant deployment segregates a customer completely from others. What is not documented is segregation between users or matters inside a customer, and no document management integration was located whose permissions retrieval could enforce at query time.

Noxtua
Own model, documented

The product maintains its own documented segregation model rather than inheriting one from a document management system. Every project is encrypted in transit and at rest under its own cryptographic key, access is strictly controlled and every action is logged, and the vendor states it has no persistent access to plaintext data. Per project cryptographic separation is a stronger mechanism than most and it is documented, but it is the vendor's own model, which the firm must keep aligned with its walls. No document management integration was located whose permissions retrieval could enforce at query time, and no material addresses conflicts or ethical walls as such.

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

LEGALFLY
Not addressed

Searched the published terms and conditions, the privacy policy, the security page and the trust center entry point on 29 Aug 2026. No clause addressing government or law enforcement requests for customer data was located, and no transparency report was located. Worth noting for a future reader that the on premise anonymisation configuration materially changes what a vendor could produce in response to such a request, since identifiable data never reaches it, but the vendor does not make that argument in published material and it is not recorded as a value here.

Noxtua
Not addressed

Searched the security page, the data privacy statement, the imprint, the FAQ and the trust center entry point on 29 Aug 2026. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. The vendor does address the adjacent question of foreign jurisdiction directly, stating data stays in Europe shielded from the US CLOUD Act on infrastructure operated by European providers, which speaks to which state could compel production rather than to whether the customer would be told.

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

LEGALFLY
Jurisdictions only

Coverage is described by jurisdiction with no identification of the underlying corpus. Vendor material states that answers are grounded in verified case law and legislation across more than 130 jurisdictions, with a separate home page figure of more than 110 jurisdictions for global translation and jurisdiction coverage. Neither number is accompanied by a named source or publisher, a licence or public domain basis, or an update cadence. A Knowledge platform page describes verified legal knowledge without saying where it comes from.

Noxtua
Sources named and licensed

The strongest corpus disclosure on the index so far and the first to state a licence basis. Sources are named individually as national legal publishers and tied to the jurisdiction each serves: C.H.Beck for Germany, Poland, Czech Republic and Slovakia, MANZ for Austria, Ciela for Bulgaria and Blendow for Sweden, plus a Swiss edition, with dejure.org named in the retrieval model partnership. The rights basis is stated as exclusive publisher partnerships, described as the first Europe licence of its kind. Scale is quantified at more than 130 million searchable documents and more than 8.5 million court decisions. Short of the top value only because no update cadence or lag for the corpus was located as of 29 Aug 2026.

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

LEGALFLY
Not addressed

Searched the site, the Discovery product page, the Knowledge platform page and the resources index on 29 Aug 2026. No material was located addressing whether authority returned by the product carries a treatment signal, whether subsequent history is checked, or whether any commercial citator is licensed. The vendor describes case law as verified without stating what verification means or when it was performed.

Noxtua
Not addressed

Searched the site, the three product pages, the jurisdictions page and the press releases on 29 Aug 2026. No material was located addressing whether authority returned carries a treatment signal or whether subsequent history is checked. The Understanding product is described as assessing the validity of clauses, which is contract clause analysis rather than the standing of cited authority, and was not treated as evidence here. Noted for context: continental civil law jurisdictions do not use citators in the Anglo American sense, so this signal reads differently for a vendor selling into Germany, Austria and Switzerland than for a US product.

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

LEGALFLY
Not addressed

Searched the site, the six product pages, the Agent Studio page and the resources index on 29 Aug 2026. No published material describes what the product does when it cannot ground an answer, and no explicit no answer path or confidence signal was located. Agent Studio documents escalation when needed as a workflow routing behaviour, which is about handing a task to a person rather than about the system declining to answer, and was not treated as evidence for this signal.

Noxtua
Not addressed

Searched the site, the three product pages, the security page and the press releases on 29 Aug 2026. No published material describes what the product does when it cannot ground an answer, and no explicit no answer path or confidence signal exposed to the user was located. The vendor publishes that results are traceable at every stage and that version 5 surfaces a knowledge graph of the sources behind an answer, which lets a reader inspect the basis of an answer that was given rather than telling them when the system found nothing.

Fabricated Citation Record

Does a public court record exist involving output from this product?

LEGALFLY
None located

No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance, and it is bounded by what that database covers, which is weighted toward US and other common law filings while this vendor sells primarily into European enterprises.

Noxtua
None located

No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. The bound is worth stating plainly for this vendor: that database is weighted toward US and other common law filings, and this product sells into German speaking and central European jurisdictions whose decisions are less comprehensively covered by it.

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

LEGALFLY
Not addressed

Searched the site, the security page, the solution pages and the resources index on 29 Aug 2026. No engagement with any named ethics opinion or bar guidance was located. The vendor publishes compliance material aligned to information security and data protection standards across the EU, UK and Middle East, which addresses its own regulatory posture rather than the professional responsibility obligations its buyers are bound by. Noted for a future reader: this vendor sells primarily into European enterprises, where the applicable guidance is issued by national bars and law societies rather than the ABA, and none of those was engaged either.

Noxtua
Named guidance addressed

Public materials engage with named professional obligations by statutory citation rather than in general terms: Section 43e of the German Federal Code for Lawyers and Section 203 of the German Criminal Code, the provisions governing what a lawyer bound by professional secrecy may use, plus stated alignment with the EU AI Act. The vendor states this permits use by confidentiality bound professionals without requiring anonymisation, which is a specific claim about the rules its buyers are bound by. Short of the mapped by jurisdiction value because the engagement is with German law only, despite the product shipping in eight national editions, and no equivalent Austrian, Swiss, Polish, Czech, Slovak, Bulgarian or Swedish provision was addressed in located material.

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

LEGALFLY
Savings claims only

Vendor material is framed around speed and cost reduction, including a published customer story headlined on broader market coverage and reduced external legal spend, and product copy promising review and negotiation in minutes rather than hours. Searched the site, the product pages, the customer stories and the resources index on 29 Aug 2026 and located no per matter record of AI assisted work intended for fee purposes, and no published guidance on billing, fee or client disclosure treatment. The buyer here is an in house team rather than a firm billing a client by the hour, so this signal reads differently for this segment.

Noxtua
Not addressed

Searched the site, the three product pages, the customer stories entry point and the press centre on 29 Aug 2026. No published guidance on billing, fee or client disclosure treatment was located, and no per matter record of AI assisted work intended for fee purposes was located. Distinct from the other vendors on this index in that no time savings or efficiency figures were located either: the vendor's published framing is precision, verifiability and permissibility rather than hours saved, so there is no savings claim to weigh against the client's side of the equation.

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

LEGALFLY
Not addressed

Searched the security page, the trust center entry point, the published terms and conditions and the privacy policy on 29 Aug 2026. No subprocessor list was located, no statement of which model providers see customer content was located, and no client facing consent or notification material was located. A trust center exists at a stable URL, which is an access route rather than the artifacts themselves. Worth recording that this vendor's architecture arguably answers the underlying question differently, since the on premise anonymisation option means identifiable client content need not reach a model provider at all, but the disclosure a firm could forward is not published.

Noxtua
Subprocessors listed

A trust center is published at a stable URL, reachable without a sales conversation, carrying what the vendor describes as the full list of current certifications and policies. The certification set named on the public security page is broad and specific: BSI C5, TISAX, ISO 42001, 27001, 27018, 27017 and 9001. Infrastructure providers are named individually with their own certifications, which covers the hosting layer of the supply chain, and the model layer is proprietary rather than third party, which removes the model provider question a firm would normally have to answer for its client. Short of the full disclosure pack because no formal subprocessor list was located and no client facing consent or notification material was located as of 29 Aug 2026.

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

LEGALFLY
Partial record

Some elements of a record are available, short of a document level export. Multi Review is documented as exporting audit ready reports intended for deal teams, regulators or internal stakeholders, and the same review logic is stated to apply across every document so results are comparable. That is an exportable artifact, but it is a review output rather than a record of how AI produced it. Not located as of 29 Aug 2026: any export covering model used, sources retrieved and human verification per document, and the model used is not identifiable in any case since the platform selects different models per task.

Noxtua
Partial record

Several elements of a disclosure record are available and unusually well documented. The vendor states every action is logged, that agentic research is traceable at every stage, and that version 5 generates a knowledge graph per query surfacing the sources relied on and mapping how they connect, with verifiable source references throughout. Sources retrieved and the reasoning path are therefore recoverable. Two elements are missing: no per document export covering model used, sources retrieved and human verification together was located, and human verification is not recorded as such. The model question is simpler here than elsewhere, since the model is the vendor's own proprietary system rather than a rotating third party.

What neither one publishes

The questions both sides leave open

Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.

Axes where neither earns credit
  • Commercial Transparency
Signals neither addresses in public material
  • Prompt and Output Retention
  • Third Party Request and Subpoena Notice
  • Good Law Verification
  • Refusal and Uncertainty Behaviour

Which one fits

Choose LEGALFLY if

  • Sensitive material cannot leave your environment in identifiable form. LEGALFLY publishes three deployment models with the differences spelled out: fully managed SaaS, a single tenant instance in the customer's preferred Azure region fully segregated from other customers, and single tenant with the anonymisation component running on premise so only anonymised data crosses to the dedicated tenant over private encrypted connections.
  • You want data minimisation applied before the model sees anything. LEGALFLY anonymises documents before analysis begins rather than after, with adjustable anonymisation levels and term whitelisting, environments isolated per client, and the customer retaining data ownership throughout.
  • Your requests come from procurement and HR as much as from legal. LEGALFLY publishes dedicated pages for six functions covering legal, claims, compliance, HR, procurement and sales and for five industries, and states plainly that it is built for enterprise legal and business teams rather than for law firm productivity workflows.

Choose Noxtua if

  • You need to know exactly whose law the answer rests on. Noxtua names its sources individually and states the rights basis, licensing content from national legal publishers under exclusive partnerships: C.H.Beck for Germany, Poland, the Czech Republic and Slovakia, MANZ for Austria, Ciela for Bulgaria and Blendow for Sweden, across a corpus it puts at more than 130 million documents and 8.5 million court decisions.
  • Sovereignty has to mean a named facility rather than a region setting. Noxtua runs proprietary models on European infrastructure it identifies by provider, including IONOS and Deutsche Telekom's Industrial AI Cloud in Munich, states that data stays in Europe shielded from the United States CLOUD Act, and publishes BSI C5, TISAX, ISO 42001, ISO 27001, 27017, 27018 and 9001 through a trust centre reachable without a sales call.
  • Your obligation is professional secrecy rather than privilege. Noxtua addresses it in statute, citing section 43e of the German Federal Code for Lawyers and section 203 of the Criminal Code and stating that use by confidentiality bound professionals is permitted without requiring anonymisation, alongside a statement that inputs and outputs are never used to train its AI and never shared with third parties, with each project encrypted under its own key.

In summary

LEGALFLY

LEGALFLY is a European legal AI platform for enterprise in house teams, positioned as a legal operating system reaching beyond legal into claims, compliance, HR, procurement and sales, with products for research and advice, contract review, drafting, due diligence across data rooms, regulatory monitoring and custom agent building. The AI Legal Index grades it in the top two bands on nine of fifteen capability axes, with A grades on AI centrality, deployment and data residency and practice coverage. Its signature control is anonymisation applied before analysis begins, with an option to run that component inside the customer's own environment so identifiable data never reaches a model. As of 29 August 2026 the index located no training position, no retention period and no published price.

Source: AI Legal Index, 2026

Noxtua

Noxtua is a European sovereign legal AI for law firms, in house teams, auditors and tax advisers, courts and public authorities, shipping research, matrix analysis across document sets and drafting with a Microsoft Word add in, as jurisdiction specific editions built with national legal publishers. The AI Legal Index grades it in the top two bands on ten of fifteen capability axes, with A grades on AI centrality, model supply chain disclosure, security certifications, deployment and privilege and confidentiality posture. It runs proprietary models on named European infrastructure and states compliance with the German professional secrecy provisions at section 43e BRAO and section 203 StGB. As of 29 August 2026 the index located no published customer terms, no liability position and no pricing.

Source: AI Legal Index, 2026

Questions buyers ask

LEGALFLY vs Noxtua: which is better for a European legal team?

The AI Legal Index places Noxtua in the top two bands on ten of fifteen capability axes and LEGALFLY on nine. Noxtua owns its stack, running proprietary models on named European infrastructure over content licensed from national publishers, and addresses professional secrecy in statute. LEGALFLY answers with architecture, anonymising documents before analysis and offering an on premise anonymisation option. Neither publishes a price.

Where does each one run?

Noxtua names the facilities: proprietary models on IONOS and on Deutsche Telekom's Industrial AI Cloud in Munich, with a Swiss option on T Cloud Public, stating that data stays in Europe on infrastructure independent of United States cloud providers and shielded from the CLOUD Act. LEGALFLY publishes a single tenant instance in the customer's preferred Azure region, and in its third configuration the anonymisation layer runs inside the customer's own environment so identifiable data never reaches the tenant. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

Do either say whether client documents train their models?

Noxtua does. Its security page states that inputs and outputs are never used to train its AI and are never shared with third parties, and it separately discloses that its proprietary models are trained on legal data licensed from publishers rather than on customer content. On LEGALFLY nothing was located either way as of 29 August 2026, so the index records the question as silent, which is conspicuous for a vendor whose positioning is built on data protection. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

Which one names the legal sources behind its research?

Noxtua, in unusual detail. It names the publisher behind each jurisdiction and states the rights basis as exclusive licensing partnerships, shipping as national editions including Beck-Noxtua in Germany, MANZ-Noxtua in Austria and Blendow-Noxtua in Sweden. LEGALFLY states that answers are grounded in verified case law and legislation across its stated jurisdictions without naming a source, publisher, licence basis or update cadence anywhere. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

What do LEGALFLY and Noxtua both leave unpublished?

Neither publishes a price, a tier structure or a unit of charge. Neither publishes an indemnity running to the customer, a warranty on output or an insurance position. Neither states a retention period or a deletion control for documents, prompts or outputs. Neither documents what the product does when it cannot ground an answer. And neither publishes an accuracy or hallucination rate for generated output, although Noxtua does publish comparative figures for its own retrieval model. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 3, 2026. No vendor pays for placement.

Disclosure

One absence on each side deserves naming. LEGALFLY sells data protection as its central proposition, and no statement about whether customer content may be used to train models was located on any public page, so the index records it as silent rather than as a commitment in either direction; its home page also gives two different jurisdiction counts, 110 plus in one place and 130 plus in another. Noxtua publishes no customer terms of any kind, so no indemnity, cap or warranty is readable, and access to the product runs through a jurisdiction gated request form. Its engagement with professional rules is also German law only, despite the product shipping in eight national editions. Both records were verified on 29 August 2026. Neither vendor reviewed this page.

Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.

Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 2, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746