Legora vs Noxtua: how they compare in 2026
Legora and Noxtua are both general legal assistants for law firms and in house teams, built on opposite bets. Legora is a collaborative workspace from Stockholm that reaches into the systems a firm already runs. Noxtua is a European sovereign legal AI from Berlin that keeps its hosting and its legal content inside Europe. Noxtua is stronger on confidentiality and on where the data sits. It cites the German professional secrecy provisions by section and encrypts each project under its own key. It names its hosting providers and licenses its law from national publishers such as C.H.Beck and MANZ. Legora is stronger on paperwork a buyer can read and on reach. It publishes its general terms with liability caps, its data processing agreement and a security annex. It connects to iManage, SharePoint, Box, Word and Outlook, and its answers now reach ChatGPT Enterprise. Noxtua publishes no customer terms at all. Both state on their security pages that client data does not train their models. Neither publishes a price or an accuracy rate for its answers.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the product. The workspace is AI native rather than a document system with a model attached, and every surface the vendor sells, review, drafting, research and workflows, is a generative capability. Remove the models and nothing remains to sell.
The AI is the product, built down to the infrastructure. The vendor says it is built as a complete system controlling infrastructure, model, data and interface, running proprietary models trained on licensed legal data rather than calling third party foundation models. It also publishes its own legal embedding model, Noxtua Voyage Embed, built with Voyage AI and dejure.org. Remove the models and nothing remains.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is documented in vendor material, short of any figure an outsider can test. Review output links each cell to its source. On 14 Sep 2026 the vendor published how its rebuilt research layer works: an ontology of the law that maps how authorities rank and relate, including amendments, holdings against dissents and temporal validity, and an AI native citator whose standard is set and audited by a team of former publisher attorney editors, built on technology from its Qura and Wexler acquisitions. The vendor also states it has cataloged more than 50 distinct ways AI fails at legal research, without publishing the list. The research layer is in limited beta, with general availability planned for the fourth quarter of 2026. Not located: a published accuracy measurement, an evaluation framework or a hallucination rate, which is what separates this from an A.
Grounding is real and documented, with published comparative measurement for one component but no accuracy figures for the product itself. The retrieval method is described in detail. The agent analyzes a query, develops a solution plan and researches systematically across licensed publisher content, and version 5 generates a knowledge graph for each query that surfaces relevant sources and maps how they connect. Output carries source references into a licensed corpus a reader can open. The vendor publishes measured figures for its own retrieval model: Noxtua Voyage Embed outperforms a named OpenAI embedding model on legal text benchmarks, with 1.7 times better search accuracy and 2.2 times better ranking quality at a third of the dimensionality. That measures retrieval, not answer accuracy. Not located: an accuracy or hallucination rate for generated output, a test set for it, or any abstention behavior.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Human oversight is asserted as a governing principle in vendor material and is covered in the abstract by an ISO 42001 certification of the AI management system. What is not published is the mechanism: where the review point sits, what an agentic workflow does on its own, at what threshold it stops, and what a supervising lawyer must approve. Oversight appears as a stated principle rather than a described control.
Autonomy is claimed and oversight is asserted without a mechanism. The vendor describes agentic AI that independently develops a solution plan and executes systematic research, and states results are traceable at every stage, which is transparency of process rather than a control structure. Searched the site, the three product pages, the security page and the press releases and located no description of what the system does on its own versus what a lawyer must approve, no review surface, no threshold at which the agent stops, and no statement of what happens after an output is wrong. Traceability shows a reader what happened; it does not establish who decides.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Named customers appear in vendor material, including a published Grant Thornton UK forensic investigations story, and the vendor states more than 1,000 customers across 50 plus markets. Additional named users including Cleary Gottlieb, Goodwin, Linklaters, White and Case, Dentons and Barclays appear in vendor recruiting material. Not located: dated outcome figures with a method a reader could assess, which is what separates this from an A.
Customer logos and an unattributed selected clients strip stand in for evidence. A customer stories page exists in the navigation, and a named endorsement appears from Dr Markus Kaulartz, partner at CMS, though CMS is also a co-initiator and investor rather than an arm's length customer, which is disclosed on the page and weakens it as independent evidence. Corpus scale figures are published, 130 million plus searchable documents and 8.5 million plus court decisions, but those describe the database rather than a deployment. Searched the site, the customer stories entry point and the press center and located no named deployment with figures, dates and an assessable method.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive published commitments sit in openly published contract documents rather than only on a trust page. They are general terms and conditions in EU and US versions, a data processing agreement, and a security measures annex covering least privilege access, personnel confidentiality obligations, authorization controls and retention on customer instruction. The security page states the vendor will not use customer data to train or fine tune models. Two gaps remain. Attorney client privilege and work product handling is not addressed directly in located material, and matter level segregation between users is not documented.
The confidentiality posture is complete and engages the professional secrecy question in statute. The vendor states compliance with Section 43e BRAO and Section 203 StGB, the German provisions on what a lawyer bound by professional secrecy may use, and says this permits use by confidentiality bound professionals without anonymization. Training is addressed directly: inputs and outputs are never used to train the AI and never shared with third parties. Separation is documented: every project is encrypted in transit and at rest under its own cryptographic key, access is strictly controlled, and every action is logged. The vendor also says it has no persistent access to plaintext data. Certification covers AI governance as well as security. The customer agreement itself is not published, so these commitments were read from the security page rather than a contract.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
The intended audience is unambiguously lawyers, firms and in house teams, and vendor material describes the product as working with lawyers rather than replacing them. Searched the vendor site, the published acceptable use policy, the general terms and the blog on 29 Aug 2026 and located no published position on the advice line, no treatment of competence and supervision duties, and no statement of jurisdiction limits.
A real position is published and it is grounded in named law rather than a disclaimer. The vendor addresses the professional rules that govern whether a lawyer may use the tool at all, citing Section 43e BRAO and Section 203 StGB and alignment with the EU AI Act, and states the audience precisely across law firms, in house teams, auditors and tax advisers, courts and public authorities. Jurisdiction limits are handled structurally rather than in prose: the product ships as jurisdiction specific editions and the site requires a jurisdiction selection before granting access, which is a real published boundary. Competence and supervision duties are not addressed, and the position is framed around the vendor's own permissibility rather than around what the lawyer remains responsible for.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Legora holds an ISO 42001 certification covering its AI management system, independently audited with ongoing surveillance. It publishes what the certification covers: how AI is designed, deployed, supervised and monitored, with human oversight and structured governance named as the operating principles. That is a published governance framework with real substance and independent validation. Not located: a named internal owner of AI governance, published testing results on model behavior before release, or any disclosure about uneven output across matter types, parties or populations.
A published governance framework with real substance and independent validation, short of testing results or a named owner. ISO 42001 certification covers the AI management system specifically and is stated alongside ISO 27001, 27017, 27018 and 9001, BSI C5 and TISAX, with the vendor stating controls are independently and regularly audited and publishing a trust center for the full current list. Alignment with the EU AI Act is stated. That is a governance regime for AI rather than a principles page, and it is externally audited. Not located: a named internal owner of model governance, published pre release testing results for model behavior, or any disclosure about uneven output across matter types, parties or populations.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
The published security measures annex covers access on a least privilege and role based model, centrally stored logs traceable to unique usernames with security logs retained at least 12 months, data integrity signing, personnel background checks and confidentiality agreements, and retention set by customer instruction. The published data processing agreement commits the vendor to assist with the customer's own breach notification obligations, so incident practice is addressed. ISO 27001:2022 is audited yearly. Not located: a current named subprocessor list, which is the remaining element of the A bar.
Substantive published policy covering most of the ground. Per project encryption in transit and at rest with a distinct cryptographic key per project, strictly controlled access, full action logging, a stated position that the vendor has no persistent access to plaintext data, regular security reviews and risk assessments, and a Vanta backed trust center at a stable URL. Infrastructure providers are named individually with their own certifications, which is effectively a partial subprocessor disclosure at the hosting layer. Not located: a stated retention period or deletion control for documents and prompts, a full subprocessor list, and an incident or breach notification practice.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
A real published position. General terms and conditions are published openly in EU and US versions. They carry numbered liability clauses, aggregate caps that apply across the subscriber and its affiliates, a separate cap of 100,000 Euro on beta features, and a carve out concept the terms call an Enhanced Claim. A buyer can read the allocation of loss before entering a sales process. Not located: indemnity scope for third party claims arising from output, any warranty on output, and any insurance position.
No published indemnity, liability cap, carve out, warranty on output or insurance position is published, and no customer terms or general conditions are published at all. Access to the product itself runs through a jurisdiction gated request form, so the agreement is reached through a sales process. Notable given how much else this vendor publishes: the compliance posture is documented in statutory detail while the allocation of loss when output is wrong is not addressed anywhere public.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Real and named integrations: an iManage technology partnership working through iManage APIs with an announced expansion, SharePoint, Box, a Microsoft Word add in for drafting and redlining, Outlook, EDGAR, and import from virtual data rooms and contract lifecycle systems. On 17 Sep 2026 the vendor released a plugin for ChatGPT Enterprise that brings its grounded answers into the ChatGPT interface. The vendor is explicit that it integrates with document management systems rather than replacing them. Not located: implementer level documentation describing what each integration moves, in which direction, and what an administrator must configure, which is what the A bar asks for.
Integrations are named without documentation an implementer could use. A Microsoft Word integration is stated on the drafting product page, with work possible either in Noxtua directly or in Word. Searched the site, the three product pages, the security page and the FAQ and located no other integration: no document management connector such as iManage or NetDocuments, no Outlook, no contract lifecycle or matter management, and no integrations page at all. Nothing describes what the Word integration moves, in which direction, or what an administrator configures.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
The claim is made and the detail is not published. Vendor material states flexible storage options matched to data sensitivity, and separate EU and US contract documents indicate region specific arrangements, with the technical team in Sweden operating under GDPR. Searched the vendor site, the security pages and the published legal documents on 29 Aug 2026 and located no list of available regions, no tenancy model, and no statement of where processing happens as distinct from where data is stored.
Where the software runs and where the data sits is published in concrete detail, because it is the product's whole proposition. Hosting providers are named with their certifications and roles. IONOS is a BSI C5 certified critical infrastructure provider operating the Bundescloud. Deutsche Telekom's Industrial AI Cloud is the AI Factory in Munich behind the Deutschland Stack for regulated sectors including the judiciary. T Cloud Public is BSI C5 certified for critical infrastructures, and T Cloud Public in Switzerland is BSI C5 certified and FINMA compliant, offering Swiss data sovereignty. The vendor says data stays in Europe on infrastructure run by European providers independent of US cloud providers and shielded from the US CLOUD Act, which addresses the jurisdiction of processing and not only where data is stored. What changes between deployment options is not stated.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Three current independent certifications are held: ISO 27001:2022 audited yearly, SOC 2 Type II, and ISO 42001 for AI management. A public trust center at security.legora.com carries a resources section and a data flow diagram. Security whitepapers and a security measures annex are published openly with no gate at all, so no request is needed to read the annex. The certifying auditor is not named in located material.
The certification set is broad, and a trust center is reachable without a sales call. Named and current: BSI C5, TISAX, ISO 42001, ISO 27001, ISO 27018, ISO 27017 and ISO 9001, with the vendor saying controls are independently and regularly audited. The trust center is a Vanta portal at a stable URL with the full current certification list and policies, a self serve route. BSI C5 and TISAX matter here: they are the German federal cloud computing criteria and the automotive industry information security assessment. No coverage period, report date or named auditor is published on the public pages.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
Vendor material refers to how it implements, supervises and evolves AI without identifying what sits underneath. The vendor site, the trust center, the published general terms, the data processing agreement and the security measures annex were searched. No named model provider, subprocessor list or commitment to notify customers when the supply chain changes is published. Third party sources describe a multi model approach running on Microsoft Azure, but that is not the vendor's own material.
The vendor owns the supply chain and says so. Models are proprietary and trained in house on licensed legal data rather than sourced from a third party foundation model provider, which is the point of the sovereignty positioning. Where the models run is named down to the provider and facility, including IONOS and Deutsche Telekom's Industrial AI Cloud in Munich. One external component is disclosed with its partner: the retrieval model Noxtua Voyage Embed, built with Voyage AI and dejure.org, with its model identifier published. A customer inherits a dependency chain that is short and named. Not located: a commitment to notify customers when the model or its hosting changes.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing page, published rate, stated unit of charge or published tier structure is published. The only commercial entry point is a demo request. Several independent third party pricing analyses say the same, and one reports a consumption based tier that is not published on the vendor site. Third party estimates per seat are not published by the vendor. The vendor does publish its general terms openly, which is transparency of terms rather than of price and is covered under AI Liability and Recourse.
No pricing page exists, no rate is published, no unit of charge is stated and no tier structure appears. The only commercial entry point is a Get Access request that first requires selecting a jurisdiction, so a buyer cannot reach a figure or even a product edition without entering a sales process. Third party pricing figures are not published either.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segment coverage is described with substance: large law firms, in house legal departments, and professional services including a published forensic investigations customer story, spanning more than 1,000 customers across 50 plus markets with multi jurisdiction and cross border work as a stated strength. Practice coverage spans review and diligence, research, drafting and investigations. Not located: any statement of the boundaries, meaning which firm sizes or practice areas the product is not built for.
Segment coverage is described with substance and precision. Four segments have their own published sections: in house legal teams, law firms, auditors and tax advisers, and courts and public authorities, the last an explicit positioning for the judiciary and public administration. Jurisdictional coverage is stated as named editions for each country, spanning Germany, Austria, Switzerland, Poland, Czech Republic, Slovakia, Bulgaria and Sweden, each tied to its national legal publisher. Practice areas are not listed beyond a general research, analysis and drafting framing, and nothing says what is not supported.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
The vendor home page and security page both state that customer data is not used to train or fine tune any AI models. The vendor publishes its general terms and conditions and its data processing agreement openly, and a training prohibition was searched for in those documents on 29 Aug 2026 and not located, so the commitment as recorded rests on the security and marketing pages rather than on a located contract term. The full agreement text was not read end to end.
The security page states directly that inputs and the product's outputs are never used to train the AI and are never shared with third parties, and separately that the vendor has no persistent access to plaintext data. The commitment as located sits on a public security page rather than in a customer agreement, and no customer terms are published on this property, so it is a policy statement rather than a contract term.
The training relationship running the other way is disclosed as well: the vendor states it trains its proprietary models on legal data licensed from publishers, which is publisher content rather than customer content.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Section 17 of the published security measures annex, dated 31 Jan 2025, states that during the term of the data processing agreement, personal data is subject to the retention requirements the subscriber instructs from time to time. After termination or expiry, clause 11 of that agreement governs. Retention is therefore set by the customer, and the commitment sits in a contract document rather than a policy page, which makes it enforceable.
No retention period is published and no zero retention setting was located as of 29 Aug 2026. The same document states that subscriber environments are logically separated at all times and that full production backups are taken every four hours.
The security page, the data privacy statement, the FAQ, the imprint and the trust center entry point were searched on 29 Aug 2026. Nothing public says how long inputs, outputs or uploaded documents are kept, whether the customer controls the window, or whether deletion is available. The vendor does publish related architecture, encryption for each project under a distinct key and a statement that it has no persistent access to plaintext data, but neither answers the retention question.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Searched the vendor site, the iManage partnership announcement, the security page, the published security measures annex and the trust center on 29 Aug 2026. No vendor material was located addressing whether retrieval enforces document management system permissions at query time per user, or how ethical walls and matter level segregation are handled. The security annex documents least privilege access for vendor personnel, which is a different question. A partner case study describes per query authentication, which is not vendor material.
The product keeps its own documented separation model rather than inheriting one from a document management system. Every project is encrypted in transit and at rest under its own cryptographic key, access is strictly controlled, every action is logged, and the vendor says it has no persistent access to plaintext data. Cryptographic separation by project is a strong, documented mechanism, but it is the vendor's own model, which the firm must keep aligned with its walls.
No document management integration was located whose permissions retrieval could enforce at query time, and nothing addresses conflicts or ethical walls as such.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Searched the published EU and US general terms and conditions, the data processing agreement, the security measures annex and the acceptable use policy on 29 Aug 2026. No clause addressing government or law enforcement requests for customer data was located, and no transparency report was located. This records a search that did not surface the clause rather than a reading of the full agreements end to end.
Searched the security page, the data privacy statement, the imprint, the FAQ and the trust center entry point on 29 Aug 2026. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. The vendor does address the adjacent question of foreign jurisdiction directly, stating data stays in Europe shielded from the US CLOUD Act on infrastructure operated by European providers, which speaks to which state could compel production rather than to whether the customer would be told.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Research coverage is described by jurisdiction, reported at twelve. The vendor announced the acquisition of Qura, a Stockholm legal database covering case law, legislation and regulation, which it is extending to larger markets. The underlying sources are not identified: which publishers or public sources the law comes from, the license or public domain basis for each, and the update lag. Searched the vendor site, newsroom and product pages on 29 Aug 2026.
Sources are named as national legal publishers, each tied to the jurisdiction it serves: C.H.Beck for Germany, Poland, Czech Republic and Slovakia, MANZ for Austria, Ciela for Bulgaria and Blendow for Sweden, plus a Swiss edition, with dejure.org named in the retrieval model partnership. The rights basis is stated as exclusive publisher partnerships. Scale is given as more than 130 million searchable documents and more than 8.5 million court decisions. No update schedule or lag for this content was located as of 29 Aug 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
The vendor published on 14 Sep 2026 that it is building its own AI native citator on an ontology of the law. The ontology captures the hierarchy of authority, how sources relate to each other and temporal validity, so that an amended rule or an overruled case is recognized as such. The standard is set and audited by a team of former publisher attorney editors, and the technology comes from its Qura and Wexler acquisitions.
The method is described, and the check is computed by the vendor rather than licensed from a commercial citator. The citator is in limited beta with general availability planned for the fourth quarter of 2026, so it may not yet be switched on for a given account. No treatment coverage figure or error rate was located as of 24 Sep 2026.
The site, the three product pages, the jurisdictions page and the press releases were searched on 29 Aug 2026. Nothing addresses whether returned authority carries a treatment signal or whether subsequent history is checked. The Understanding product is described as assessing the validity of clauses, which is contract clause analysis rather than the standing of cited authority. Continental civil law jurisdictions do not use citators in the Anglo American sense, so the question reads differently for a vendor selling into Germany, Austria and Switzerland than for a US product.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
Searched the vendor site, blog, newsroom and trust center on 29 Aug 2026. No published material was located describing what the product does when it cannot ground an answer, whether an explicit no answer path exists, or whether any confidence or grounding signal is exposed to the user.
Searched the site, the three product pages, the security page and the press releases on 29 Aug 2026. No published material describes what the product does when it cannot ground an answer, and no explicit no answer path or confidence signal exposed to the user was located. The vendor publishes that results are traceable at every stage and that version 5 surfaces a knowledge graph of the sources behind an answer, which lets a reader inspect the basis of an answer that was given rather than telling them when the system found nothing.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one.
This is a statement about the public record on the date shown and not a clearance, and it is bounded by what that database covers.
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one.
This is a statement about the public record on the date shown and not a clearance. The bound is worth stating plainly for this vendor: that database is weighted toward US and other common law filings, and this product sells into German speaking and central European jurisdictions whose decisions are less comprehensively covered by it.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Searched the vendor site, blog, newsroom and resource pages on 29 Aug 2026. No engagement with any named ethics opinion was located, including ABA Formal Opinion 512 and state or national bar guidance. The vendor publishes substantial governance and certification material, which addresses its own AI management system rather than the professional responsibility obligations its buyers are bound by.
Public materials engage with named professional obligations by statutory citation: Section 43e of the German Federal Code for Lawyers and Section 203 of the German Criminal Code, the provisions on what a lawyer bound by professional secrecy may use, plus stated alignment with the EU AI Act. The vendor says this permits use by confidentiality bound professionals without anonymization, a specific claim about the rules its buyers follow.
The engagement covers German law only, although the product ships in eight national editions. No equivalent Austrian, Swiss, Polish, Czech, Slovak, Bulgarian or Swedish provision was addressed in located material.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Vendor material is framed around speed and volume, describing analysis of thousands of documents in minutes and teams moving faster. Searched the vendor site, blog and legal pages on 29 Aug 2026 and located no per matter record of AI assisted work intended for fee purposes, and no published guidance on billing, fee or client disclosure treatment.
The site, the three product pages, the customer stories entry point and the press center were searched on 29 Aug 2026. No guidance on billing, fees or client disclosure was located, and no per matter record of AI assisted work for fee purposes. No time savings or efficiency figures were located either. The vendor's framing is precision, verifiability and permissibility rather than hours saved, so there is no savings claim to weigh against the client's side of the bill.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
The picture is mixed. Openly published with no gate, and forwardable to a client today, are general terms and conditions in EU and US versions, a data processing agreement, a security measures annex and an acceptable use policy. Not located as of 29 Aug 2026: a current subprocessor list, any statement of which model providers see client content, and any consent or notification pack for clients. The trust center carries a resources section that routes document access through a request.
A trust center is published at a stable URL, reachable without a sales conversation, carrying what the vendor describes as the full list of current certifications and policies. The certification set named on the public security page is broad and specific: BSI C5, TISAX, ISO 42001, 27001, 27018, 27017 and 9001. Infrastructure providers are named individually with their own certifications, which covers the hosting layer of the supply chain, and the model layer is proprietary rather than third party, which removes the model provider question a firm would normally have to answer for its client. No formal subprocessor list and no consent or notification material for clients were located as of 29 Aug 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Searched the vendor site, product pages and published legal documents on 29 Aug 2026. Partner material describes citations being preserved when work is exported to Word, and the security annex documents security logging traceable to unique usernames, which is an infrastructure control rather than a record of AI assisted work. No per document record covering model used, sources retrieved and human verification was located.
Several elements of a disclosure record are available and documented. The vendor says every action is logged and agentic research is traceable at every stage, and version 5 generates a knowledge graph for each query that surfaces the sources relied on and maps how they connect, with source references throughout. Sources retrieved and the reasoning path can therefore be recovered. Two elements are missing: no export for each document covering model used, sources retrieved and human verification together was located, and human verification is not recorded as such. The model question is simpler here, since the model is the vendor's own system rather than a changing third party.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- Commercial Transparency
- Third Party Request and Subpoena Notice
- Refusal and Uncertainty Behavior
Which one fits
Choose Legora if
- You want to read the contract before the sales call. Legora publishes its general terms in EU and US versions, a data processing agreement and a security measures annex with no gate. The terms carry numbered liability clauses with aggregate caps and a separate cap on beta features. Noxtua publishes no customer terms or general conditions, so its allocation of loss is reached only through a sales process.
- The AI has to work inside the systems your firm already runs. Legora connects to iManage through a technology partnership, and to SharePoint, Box, Outlook, EDGAR and a Word add in for drafting and redlining. Since 17 September 2026 a plugin also brings its answers into ChatGPT Enterprise. Noxtua names Word and Outlook add ins and no document management connector.
- You want named customers before you shortlist. Legora publishes a Grant Thornton UK forensic investigations story and states more than 1,000 customers across more than 50 markets. Noxtua's named endorsement comes from a partner at CMS, which helped launch the company and invested in it, and its published figures describe the size of its database rather than results from deployments.
Choose Noxtua if
- Your lawyers are bound by German professional secrecy rules. Noxtua cites § 43e BRAO and § 203 StGB, the provisions on what a lawyer bound by secrecy may use, and states that this permits use without anonymization. Each project is encrypted in transit and at rest under its own key, and the vendor states it has no persistent access to plaintext data. Legora does not address privilege or matter level segregation directly.
- The data has to stay in Europe and out of reach of US law. Noxtua names IONOS and Deutsche Telekom as its hosting providers, with their certifications, and states that its Standard model category has no US law provider in its chain. Its Frontier category, added in September 2026, reaches a closed source model in a Google processing environment in an EU data center, which Noxtua says reduces rather than removes US CLOUD Act exposure. Legora publishes no list of regions.
- You need to know where the law in the answers comes from. Noxtua licenses its content from national publishers, among them C.H.Beck for Germany, MANZ for Austria, Ciela for Bulgaria and Blendow for Sweden, and states more than 130 million searchable documents. Legora describes its research coverage by jurisdiction, twelve of them, without naming its sources.
In summary
Legora
Legora is a collaborative AI workspace for law firms and in house legal teams, headquartered in Stockholm. Its core surface is Tabular Review, a grid that turns large document sets into structured review with each cell linked to its source. Around it sit a Word add in, agentic workflows, legal research and a portal for sharing work with clients. According to the AI Legal Index, its strength is published paperwork. It holds ISO 27001:2022, SOC 2 Type II and ISO 42001, and publishes its general terms, data processing agreement and security annex openly. Its security page states that customer data is not used to train or fine tune models. It publishes no price, no model provider and no accuracy measurement.
Noxtua
Noxtua is a European sovereign legal AI headquartered in Berlin, sold to law firms, in house teams, auditors and tax advisers, courts and public authorities. It offers Research, Understanding for analysis across document sets, and Drafting with a Word add in. Each national edition runs on licensed publisher content, such as Beck-Noxtua in Germany and MANZ-Noxtua in Austria. According to the AI Legal Index, its case rests on sovereignty and secrecy. Its Standard model category runs on IONOS and Deutsche Telekom infrastructure independent of US cloud providers. It cites the German professional secrecy provisions in § 43e BRAO and § 203 StGB and encrypts each project under its own key. It holds BSI C5, TISAX, ISO 42001 and ISO 27001. It publishes no price and no customer terms.
Questions buyers ask
Legora vs Noxtua: which is better for a law firm?
Neither outright. Legora fits a firm that wants one workspace across review, drafting and research, connected to iManage, SharePoint and Word, with its contract terms published before the sales call. Noxtua fits a firm bound by German or other European professional secrecy rules that needs its data kept on European infrastructure and its law drawn from licensed national publishers. Neither publishes a price, so both end in a sales conversation. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.
Are Legora and Noxtua US companies?
No. Legora was founded in Stockholm in 2023 as Leya and is headquartered there. It sells to US buyers and publishes a US version of its general terms alongside the EU version. Noxtua was founded in Berlin in 2017 as Xayn and is headquartered there. Its whole proposition runs the other way: hosting on IONOS and Deutsche Telekom infrastructure, independent of US cloud providers. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.
Which one is better for legal research?
It depends on the jurisdiction. Noxtua ships national editions on licensed publisher content, such as Beck-Noxtua in Germany and MANZ-Noxtua in Austria, and publishes comparative figures for its retrieval model, though not for its answers. Legora reports research coverage across twelve jurisdictions without naming its sources. In September 2026 it began a limited beta of a rebuilt research layer with its own citator, built with technology from its Qura and Wexler acquisitions. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.
Do Legora and Noxtua train their AI on client data?
Both say no, on their own pages rather than in a published contract term. Legora's home and security pages state that customer data is not used to train or fine tune any model, and its published security annex leaves retention to customer instruction. Noxtua's security page states that inputs and outputs are never used for training or shared with third parties. Since September 2026 it also states zero retention during processing, with conversation history held under client set retention. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.
What do Legora and Noxtua both leave unpublished?
Price, first. Legora's commercial route ends at a demo request and Noxtua's at an access form that asks for a jurisdiction. Neither publishes an accuracy or hallucination rate for generated answers, or what the product does when it cannot ground one. Neither describes where a lawyer must approve an agentic step, addresses a lawyer's competence and supervision duties, or commits to tell a customer about a government request for its data. From the AI Legal Index, based on each vendor's own published materials as of October 8, 2026. No vendor pays for placement.
Both are general legal assistants for law firms and in house teams, and Noxtua sells itself as the European sovereign option. Two points cut across the page. Neither training commitment is a contract term. Both sit on security pages, and Noxtua publishes no customer agreement at all. Noxtua's model picture also moved in September 2026. It describes its models as proprietary, while its new model picker offers open weights models self hosted in a Standard category and an international closed source model in a Frontier category. Legora names no model provider. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.