Lexroom

Lexroom is an AI research and drafting platform for legal professionals in continental Europe, sold in Italy, Spain and Germany and operating entirely in the local language. Legal research is its core: questions are asked in plain Italian, and every statement in the answer is linked back to the original source, which the user can open, verify and download. The corpus behind it is curated rather than scraped, built from institutional legal sources organised into more than fifteen subject modules, each selected by legal institute and validated by partner jurists, with customers buying access to the modules they need. Alongside research sit document analysis, which summarises filings and contracts and flags problem clauses, and drafting, which produces documents from the firm's own templates or Lexroom's, working inside Microsoft Word through an add-in. A private library lets a customer upload their own filings, doctrine and internal policies to personalise output. The platform is sold to law firms, individual advocates, notaries, accountants, labour consultants, in-house teams and public administration. Processing runs on servers exclusively in the European Union with the principal server in the Netherlands, and Lexroom names Google and OpenAI as the third-party AI providers behind the service. Named customers include Satispay, Fastweb, Italgas, Mediolanum, CRIF, Withers and the law firms LCA and Gatti Pavesi. Lexroom is operated by Lexroom S.r.l., based in Milan.

Vendor siteMilan, Italy
Last verifiedSeptember 2, 2026

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

The models are the engine of what the buyer uses, but there is a real content product underneath them. Lexroom's Libreria Lexroom is a curated collection of institutional legal sources organised into more than fifteen subject modules, each selected by legal institute and validated by partner jurists, and the commercial unit is access to those modules: the published entry plan buys one Lexroom module for one user. A curated legal database is a product that functions without any model, and it is what traditional Italian banche dati sell. The vendor also states plainly that it does not build its own large language model but uses third-party AI. That places this at B rather than A: the AI is the mechanism the buyer pays for, layered on a document collection that would still exist without it. Verified 2 September 2026.

Source: Vendor Published
BB on Citation Accuracy and Hallucination DisclosureGrounding is real and documented, with linked primary sources and a described retrieval method, short of published accuracy figures an outsider can test.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Grounding is real, documented and central to the product. The research page states that every answer is anchored to updated sources that are verifiable and downloadable in one click, and that every statement is linked to the original source so the reader can open it, verify it and cite it. The corpus construction is described rather than asserted: thousands of legislative and case law sources, selected by legal institute, validated by partner jurists, across more than fifteen subject modules built and verified one at a time. The privacy policy adds that Lexroom always makes available the sources that justify the reasoning precisely to let the customer check it. What is entirely absent is measurement. No accuracy figure, test set, benchmark or published evaluation exists on any surface. Set against that gap, the marketing makes an absolute claim in two places, that there are zero hallucinations and zero risks, and on the research page that sources can be consulted without risk of hallucination. An unmeasured absolute claim of this kind is the strongest assertion in the pull with the least evidence behind it, and it is the reason this is not an A. Verified 2 September 2026.

Source: Vendor Published
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

The human review commitment is written down and framed against a legal test rather than as marketing. The privacy policy addresses automated decision-making under the GDPR directly, stating that outputs are always submitted to a human operator who must review them before use, and that they therefore do not constitute automated decisions in the strict sense. The product supports that with a real review surface: sources sit behind every statement so a reader can verify before relying, the research page frames the point as the user deciding rather than an algorithm, and the Word add-in proposes modifications inside the document rather than applying them. What is not published is the boundary. Nothing states what any step completes without a human, what the system does when it is uncertain, or what happens after it is wrong. Verified 2 September 2026.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Named customers are numerous and span sectors: Satispay, Fastweb, Italgas, Mediolanum, CRIF, WST, MDV and Generali on the corporate side, and the law firms Withers, LCA and Gatti Pavesi. Four individuals speak on the record with name, role and employer, including Maddalena Malzanni, Legal Counsel Lead at Qonto, and Ferdinando de Martinis, Associate at Gitti and Partners, with dedicated customer story pages for Qonto, Jet HR and Credem Banca. Figures are published but they sit apart from the customers: 40 per cent time saved on repetitive tasks, 2.5 times more documents drafted, and more than 15,000 legal professionals using the platform. Those are aggregate claims with no method, no basis and no attribution to any named firm, and nothing is dated, so the record has named customers and separately has figures rather than figures for named customers. The individual customer stories were not opened this pass. Verified 2 September 2026.

Source: Vendor Published
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

This record meets the limb almost every other vendor in this pull fails. Professional secrecy is addressed directly and repeatedly, not merely implied: the security page commits to confidentiality in compliance with privacy law and with segreto professionale, the privacy policy states that beyond privacy Lexroom protects professional secrecy and confidential information generally, and there is an operational control attached to it, since efficiency monitoring data is visible to Lexroom staff only in anonymised form specifically so that confidentiality and professional secrecy are not compromised. Segregation is documented at tenant level: each customer has a dedicated and exclusive virtual space, private library contents are not shared with other customers, and the privacy policy states it is physically impossible for one customer to reach another's. Retention and deletion are stated precisely, and the position on third-party providers is explicit, with Google and OpenAI named and contractually excluded from training on customer prompts. What holds this at B is the vendor's own reservation, examined on the training signal: Lexroom may use prompts for its own benchmarking and fine tuning after stripping personal and confidential data. Matter-level walls inside a single firm are also not addressed, which matters because law firms are a named buyer. Verified 2 September 2026.

Source: Vendor Published
BB on UPL and Professional Responsibility PostureA real position is published on advice versus tooling, short of full treatment: commonly a disclaimer without the supervision and competence dimension, or silence on jurisdiction limits.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

The supervision dimension is published and unusually concrete. The privacy policy states that outputs are always submitted to a human operator who must review them before use, and the research page frames the product as amplifying professional judgement rather than replacing it, with the user rather than an algorithm deciding. Coverage is bounded, since the platform is stated throughout as available in Italy, Spain and Germany only, which tells a professional where it does and does not reach. Two things are missing. No statement that output is not legal advice was located on any surface, which is a notable gap for a research product, and there is no published terms of service anywhere on the site in which such a statement would normally sit. And no bar or professional guidance is engaged: neither Italian Consiglio Nazionale Forense material nor any equivalent in Spain or Germany is named. Verified 2 September 2026.

Source: Vendor Published
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

What exists is compliance positioning rather than governance. The security FAQ states that Lexroom is fully compliant with the GDPR and the new European AI Act, and the privacy policy contains a reasoned analysis of automated processing under Article 22, concluding that outputs are not decisions in the strict sense because a human must review them. A Data Protection Officer is named in full, with chambers, tax code and certified email address, which is more accountability disclosure than any other record in this pull, though the role covers data protection rather than model behaviour. Absent is everything the higher bands ask for: no governance framework, no owner of model behaviour, no account of what is tested before release, no certification such as ISO 42001, and nothing whatsoever published about uneven output across matter types, parties or populations. Checked the home page, research, security and privacy pages on 2 September 2026. Verified 2 September 2026.

Source: Vendor Published
AA on AI Safety and Data StewardshipRetention, deletion, access control, subprocessors and incident practice are all published, current, and specific enough to hold the vendor to.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

All five elements are published and specific to the day. Retention: private library files are deleted within 30 days of the end of the relationship, with backup copies on Google Cloud disposed of within a maximum of 180 days; prompts are kept for the duration of the relationship; customer registry and billing data for ten years under Italian accounting law. Deletion follows the same clock and data subject requests are answered within 30 days. Access control: data access is limited to a small number of technical staff holding special authorisations, with all access and downloads monitored, alongside an enforced password policy, encrypted stored passwords and single sign-on over SAML and OAuth 2.0. Subprocessors: Google and OpenAI are named as the AI providers, with categories of other recipients listed and a software bill of materials available on request. Incident practice: a formalised emergency procedure, notification to the customer as soon as possible, and communication by certified email or another secure channel agreed with the customer. Encryption is AES-256 at rest with a bring your own key option, daily vulnerability scanning is in place, and external penetration tests are run with summaries available on request. Verified 2 September 2026.

Source: Vendor Published
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Nothing published states who bears the loss when the output is wrong. No terms of service, master agreement or customer contract appears anywhere on the site: the footer offers only a privacy policy and a cookie policy, and the data processing agreement is described in the privacy policy as signed at the point of contract activation rather than published. No indemnity, no liability cap, no warranty and no carve-out is stated on any surface. Two liability-adjacent facts are published and are recorded because they are real. Lexroom states that it holds cyber risk insurance with a carrier rated double A by Standard and Poor's, with a copy of the certificate available on request, and that a service level agreement is attached to the corporate plan contract. Neither tells a buyer what recourse it has against Lexroom for a bad answer; the insurance protects the vendor's own balance sheet. Checked the home page, research page, security page, privacy policy and site footer on 2 September 2026. Verified 2 September 2026.

Source: Operator Verified
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

The surface is narrow and what exists is described with real precision. The Microsoft Word add-in is documented as to data flow rather than merely named: the privacy policy states that the add-in involves no additional data processing and that prompts formulated through it are directed straight to Lexroom without retention by or access from Microsoft or any other intermediary. That is a clearer statement of what moves and where it goes than most vendors in this pull manage for any integration. Single sign-on is specified by protocol, compatible with Google and Microsoft accounts and with SAML and OAuth 2.0. Beyond those two there is nothing. No document management, practice management, email or e-filing integration is named, no API or developer documentation was located, and no integrations page exists. Real integrations documented, but too few of them and no implementer material, which is the B band. Verified 2 September 2026.

Source: Vendor Published
AA on Deployment Model and Data ResidencyDeployment options and data residency are published, including the regions available, what changes between tiers, and where processing happens as distinct from where data is stored.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Residency is published with a named country and processing is separated from storage. The security page states that all data are processed on servers located exclusively in the European Union and that the principal server is in the Netherlands, with backup redundancy across several EU data centres as protection against extreme weather events. The privacy policy adds the storage half, that Lexroom keeps data long term on servers within the European Union, and discloses the one exception precisely rather than burying it: limited transits to the United States for website hosting only, covered by both EU standard contractual clauses and the Data Privacy Framework. The tenancy model is stated, with each customer given a dedicated and exclusive virtual space, and a bring your own key option is offered for encryption. Lexroom also states it operates no physical data centre of its own and relies on cloud services listed in the Italian national cybersecurity agency's digital infrastructure catalogue. The limitation a buyer outside Europe should weigh is that there is one region and no non-EU option, which is a disclosed restriction rather than a gap in disclosure. Verified 2 September 2026.

Source: Vendor Published
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

Certification is real, stated, and named to the version, which is more precise than most: Lexroom is certified to ISO 27001:2022. External penetration testing is stated with auditors described as external and a summary report available on request, daily vulnerability scanning is described with findings classified and prioritised, and a software bill of materials and a cyber insurance certificate are each offered on request. What the top band asks for is missing from the pages read: no auditor is named, no certificate number, issue date or coverage period is published, and no report is downloadable. A trust centre exists at trust.lexroom.ai and is linked from both the footer and the security page, but it was not opened this pass, so its contents and access tier are unestablished and nothing in it is either credited or held against the vendor. That single surface is the one most likely to move this grade. Verified 2 September 2026.

Source: Vendor Published
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

The providers are named and the vendor is candid about the architecture. The privacy policy states plainly that Lexroom does not develop its own large language model but relies on third-party artificial intelligence, and that the service therefore transfers data to sub-suppliers, in particular Google and OpenAI. It adds a real contractual commitment about what those providers may do, namely that customer prompts are expressly excluded from the AI suppliers' training under the terms agreed with them as sub-processors. Where inference runs is addressed at the level of the estate rather than the route, with all processing on EU servers. Two of the four things the top band asks for are absent: no model is named, only the houses they come from, and nothing commits to notifying customers when the supply chain or the models change. Verified 2 September 2026.

Source: Vendor Published
BB on Commercial TransparencyReal pricing is published for part of the range, with enterprise tiers withheld, or the unit and structure are stated without the figure.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

Real pricing is published for the entry point and withheld above it, which is the B band exactly. The site states a starting price of 99 euros per month, excluding VAT and on an annual contract, and sets out precisely what that buys: one Lexroom module, one user, up to 200 documents, the Microsoft Word add-in, and the possibility of tailored training. That is a rate, a unit and a term, and it is the only published figure located in this pull so far. Above the entry plan the page says prices are tailored to requirements, so the enterprise range is a sales conversation. What keeps it off the top band is that nothing states what implementation or the tailored training adds, no module is priced individually even though modules are the unit of purchase, and there is no pricing page as such, the figure appearing in a demo-booking block repeated across the site. Verified 2 September 2026.

Source: Vendor Published
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

The buyer taxonomy is the most complete in this pull. Seven segments each have their own page: law firms, companies and public administration on the organisation side, and advocates, notaries, accountants and labour consultants on the professional side, which covers private practice, in-house and government use explicitly. Jurisdiction is bounded and repeated on every page, with the platform stated as available in Italy, Spain and Germany, so a buyer knows where it does not reach. Subject coverage is counted rather than listed: more than fifteen subject modules are said to exist, each built and verified individually, and modules are the unit a customer buys, but the pages read do not name them. That is what holds this below A, together with the absence of any statement of firm size or of what the product does not support. Verified 2 September 2026.

Source: Vendor Published

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Permitted, in policy only

Public material states that customer content trains, refines or personalises models, with no matching term located in the published agreement. Any de identification, anonymisation or aggregation qualifier is recorded in the summary.

The quoted line, from the Training section of the privacy policy, states that Lexroom itself may use customer Prompts for its own benchmarking and fine tuning, with the de-identification qualifier that personal data and confidential information are removed first and the work carried out only on principles not traceable to identified or identifiable persons. It names fine tuning expressly, which is what makes this a permission rather than an aggregate-data carve-out. No published agreement exists to test it against: the site publishes only a privacy policy and a cookie policy, and the data processing agreement is signed at contract activation. The marketing says the opposite in three places and a buyer should see both halves. The home page and security page state that documents and data sent to Lexroom are not used for training, a Zero Training Policy badge appears in the footer, and the security FAQ narrows it, saying uploaded documents and user queries are never used to train global language models. The genuinely strong commitment sits one layer out: customer prompts are expressly excluded from the AI suppliers' own training under the terms agreed with Google and OpenAI as sub-processors.

Source: Vendor Publishedpotrà utilizzare i Prompt per lo svolgimento delle proprie attività di banchmarking e/o fine tuningAs of Sep 2, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Disclosed fixed window

A specific retention period is published and the customer cannot change it.

Specific published periods that the customer cannot change. Prompts are kept for the entire duration of the relationship and afterwards only for the time needed to run Lexroom's updates. Private library files, where that optional service is activated, are deleted within 30 days of the end of the relationship, with traces remaining only in Google Cloud backup copies which are disposed of within a maximum of 180 days. Customer registry and billing data are held for ten years as required by Italian accounting law, and navigation data for one year. Two published statements sit against this and a buyer should weigh them: a Zero Data Retention Policy badge appears in the site footer, and the security FAQ says documents are not stored permanently. Neither is false on its own terms, since library files are deleted and backups expire, but prompts persisting for the life of the contract is not zero retention, and no retention setting is offered to the customer.

Source: Vendor Publishedi Prompt vengono conservati per tutta la durata del rapportoAs of Sep 2, 2026Evidence

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Own model, documented

The product maintains its own permission model, documented, requiring the firm to keep it aligned.

Lexroom operates and documents its own separation model at the level of the customer account. The security page states that each customer has a dedicated and exclusive virtual space, that Lexroom does not share customer data to feed public libraries, and that it does not share it with other customers. The privacy policy goes further on the private library, saying each customer can use only its own and that it is physically impossible to reach a third party's, and adds that prompt data remain segregated inside the user's account. Access is administered by Lexroom rather than inherited from a source system, with authorisation limited to a small number of technical staff and all access and downloads monitored. What is not addressed is separation inside a single customer. Law firms are a named buyer segment with their own page, and nothing published describes walls between matters, teams or individual users within one firm's account.

Source: Vendor PublishedOgni cliente dispone di uno spazio virtuale dedicato ed esclusivo per i propri datiAs of Sep 2, 2026Evidence

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Disclosure addressed, notice absent

Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.

The privacy policy addresses disclosure to authorities directly, listing public administrations, supervisory and control authorities and judicial authorities among the categories to which personal data may be communicated, where required by law or by an order of those bodies. It also records that personal data may be used in judicial proceedings to defend Lexroom's own position. Nothing anywhere commits to telling the customer when such a request arrives, and nothing reserves discretion over notice either: the question is simply never reached. Checked the privacy policy, the security page including its governance and continuity section, the research page and the home page on 2 September 2026. The breach notification commitment on the security page, that the customer will be warned as soon as possible and by certified email, addresses security incidents rather than legal process.

Source: Vendor PublishedAutorità giudiziarie (ove richiesto dalla legge o da ordini di detti soggetti)As of Sep 2, 2026Evidence
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Jurisdictions only

Coverage is described by jurisdiction with no identification of the underlying corpus.

Coverage is described by jurisdiction and the corpus itself is not identified. The three markets are stated on every page, Italy, Spain and Germany. The research page describes thousands of legislative and case law sources selected by legal institute and validated by partner jurists across more than fifteen subject modules, and the privacy policy adds that the Lexroom Library is a collection of documents drawn from institutional legal sources, divided by subject, with customers accessing only the modules bought. That identifies the character and the curation method but not a single named source, publisher or database, and no licence or rights basis is stated for any of it. An update cadence is claimed only as sources being current. One inconsistency belongs on the record: the first-party pages say thousands of sources, while Italian trade press in May 2026 reported a company statement of more than six million verified legal sources, a figure that could not be confirmed on any first-party surface.

Source: Vendor PublishedAs of Sep 2, 2026

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

Checked the home page, the legal research feature page, the security page and the privacy policy on 2 September 2026. No public material addresses whether an authority returned by the product is still good law. The nearest claims concern the freshness of the collection rather than the standing of an individual authority: sources are described as updated, official and certified, and the stated purpose of retaining the library is to ensure outputs stay current. Neither speaks to subsequent history, to legislation that has been repealed or amended, or to decisions overtaken by later Cassazione rulings. The question bites on this product because it retrieves legislation and case law directly and presents linked authority as the basis for its answers.

Source: Operator VerifiedAs of Sep 2, 2026

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

Checked the home page, the legal research feature page, the security page and the privacy policy on 2 September 2026. Nothing describes what the product does when it cannot ground an answer. No abstention path is documented and no confidence or grounding indicator is described. The marketing runs the other way, asserting zero hallucinations and zero risks, which is a claim that the situation does not arise rather than an account of what happens when it does. The architectural answer offered instead is verification by the reader: every statement is linked to its source so the user can check it, which places the burden of detecting an unsupported assertion on the lawyer rather than on the system.

Source: Operator VerifiedAs of Sep 2, 2026

Fabricated Citation Record

Does a public court record exist involving output from this product?

None located

No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.

Searched the AI Hallucination Cases database maintained by Damien Charlotin, and Italian and international reporting drawing on it, on 2 September 2026 on the product and corporate name Lexroom and Lexroom S.r.l. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product. One structural caveat: the database is heavily weighted to United States filings and its Italian coverage is thin, so an Italian product is less likely to surface even where an incident occurred. Lexroom itself cites the phenomenon in its own marketing, with company material reported in May 2026 referring to more than 1,300 documented filings containing AI-generated hallucinations.

Source: Operator VerifiedAs of Sep 2, 2026Evidence
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

Checked the home page, the legal research feature page, the security page, the privacy policy and the professional segment pages for advocates and notaries on 2 September 2026. No public material engages with professional or ethics guidance from any of the three markets served, and nothing names the Italian Consiglio Nazionale Forense, the Consiglio Nazionale del Notariato, or any Spanish or German equivalent. Lexroom does engage named instruments, claiming compliance with the GDPR and the European AI Act, and it addresses professional secrecy directly, but both bind the supplier rather than setting out the professional obligations of the lawyers and notaries using the product, which is what this signal records.

Source: Operator VerifiedAs of Sep 2, 2026

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Savings claims only

Public materials claim time savings without addressing billing or disclosure.

Savings are claimed with figures and nothing addresses the bill. The home page publishes a 40 per cent reduction in time spent on repetitive tasks and 2.5 times more documents drafted, and a named customer is quoted saying the platform is not only a saving of time but a saving of money for the company because she has needed outside counsel less often. No published material addresses how AI-assisted work is recorded, billed or disclosed to a client, and no per matter record of AI-assisted work was located. The buyer mix is relevant to how this signal reads here: Lexroom sells to private practice advocates and law firms who do bill clients, so unlike the in-house products in this pull the assumed direction holds, which makes the silence more pointed rather than less.

Source: Vendor PublishedAs of Sep 2, 2026

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Subprocessors listed

A current subprocessor or model provider list is published.

The model providers are named on a public page, which clears the test that infrastructure alone never satisfies this signal: the privacy policy states that Lexroom does not develop its own large language model and transfers data to sub-suppliers, in particular Google and OpenAI, and records that customer prompts are excluded from those suppliers' training under the terms agreed with them. Categories of other recipients are listed, and a software bill of materials is offered on request. It stops short of the top value because the third limb is not published: there is no forwardable client-facing disclosure pack, the data processing agreement is signed at contract activation rather than published, and no consolidated subprocessor register with entities, roles and regions exists. Cloud storage providers are given by category rather than by name, although Google Cloud is identified elsewhere as holding backups.

Source: Vendor PublishedAs of Sep 2, 2026

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Not addressed

No located public material addresses court disclosure or verification certification.

Checked the home page, the legal research feature page, the security page and the privacy policy on 2 September 2026. Nothing addresses court disclosure of AI use or any certification that citations were checked by a person. The product does leave a usable trail for the lawyer's own verification, since every statement is linked to the source that justifies it and search history is retained and retrievable, but nothing is described as an exportable per document record covering which model produced which passage, what was retrieved and who reviewed it. Italian and Spanish courts have not developed the standing-order practice that drives this signal in the United States, so the obligation it tracks is less established in the markets Lexroom serves, but the record here is simply that the question is not addressed.

Source: Operator VerifiedAs of Sep 2, 2026
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 61 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 2, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746