Lexroom
Lexroom is an AI research and drafting platform for legal professionals in continental Europe, sold in Italy, Spain and Germany and operating entirely in the local language. Legal research is its core: questions are asked in plain Italian, and every statement in the answer is linked back to the original source, which the user can open, verify and download. The corpus behind it is curated rather than scraped, built from institutional legal sources organised into more than fifteen subject modules, each selected by legal institute and validated by partner jurists, with customers buying access to the modules they need. Alongside research sit document analysis, which summarises filings and contracts and flags problem clauses, and drafting, which produces documents from the firm's own templates or Lexroom's, working inside Microsoft Word through an add-in. A private library lets a customer upload their own filings, doctrine and internal policies to personalise output. The platform is sold to law firms, individual advocates, notaries, accountants, labour consultants, in-house teams and public administration. Processing runs on servers exclusively in the European Union with the principal server in the Netherlands, and Lexroom names Google and OpenAI as the third-party AI providers behind the service. Named customers include Satispay, Fastweb, Italgas, Mediolanum, CRIF, Withers and the law firms LCA and Gatti Pavesi. Lexroom is operated by Lexroom S.r.l., based in Milan.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the engine of what the buyer uses, but there is a real content product underneath them. Lexroom's Libreria Lexroom is a curated collection of institutional legal sources organised into more than fifteen subject modules, each selected by legal institute and validated by partner jurists, and the commercial unit is access to those modules: the published entry plan buys one Lexroom module for one user. A curated legal database is a product that functions without any model, and it is what traditional Italian banche dati sell. The vendor also states plainly that it does not build its own large language model but uses third-party AI. That places this at B rather than A: the AI is the mechanism the buyer pays for, layered on a document collection that would still exist without it. Verified 2 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is real, documented and central to the product. The research page states that every answer is anchored to updated sources that are verifiable and downloadable in one click, and that every statement is linked to the original source so the reader can open it, verify it and cite it. The corpus construction is described rather than asserted: thousands of legislative and case law sources, selected by legal institute, validated by partner jurists, across more than fifteen subject modules built and verified one at a time. The privacy policy adds that Lexroom always makes available the sources that justify the reasoning precisely to let the customer check it. What is entirely absent is measurement. No accuracy figure, test set, benchmark or published evaluation exists on any surface. Set against that gap, the marketing makes an absolute claim in two places, that there are zero hallucinations and zero risks, and on the research page that sources can be consulted without risk of hallucination. An unmeasured absolute claim of this kind is the strongest assertion in the pull with the least evidence behind it, and it is the reason this is not an A. Verified 2 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
The human review commitment is written down and framed against a legal test rather than as marketing. The privacy policy addresses automated decision-making under the GDPR directly, stating that outputs are always submitted to a human operator who must review them before use, and that they therefore do not constitute automated decisions in the strict sense. The product supports that with a real review surface: sources sit behind every statement so a reader can verify before relying, the research page frames the point as the user deciding rather than an algorithm, and the Word add-in proposes modifications inside the document rather than applying them. What is not published is the boundary. Nothing states what any step completes without a human, what the system does when it is uncertain, or what happens after it is wrong. Verified 2 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Named customers are numerous and span sectors: Satispay, Fastweb, Italgas, Mediolanum, CRIF, WST, MDV and Generali on the corporate side, and the law firms Withers, LCA and Gatti Pavesi. Four individuals speak on the record with name, role and employer, including Maddalena Malzanni, Legal Counsel Lead at Qonto, and Ferdinando de Martinis, Associate at Gitti and Partners, with dedicated customer story pages for Qonto, Jet HR and Credem Banca. Figures are published but they sit apart from the customers: 40 per cent time saved on repetitive tasks, 2.5 times more documents drafted, and more than 15,000 legal professionals using the platform. Those are aggregate claims with no method, no basis and no attribution to any named firm, and nothing is dated, so the record has named customers and separately has figures rather than figures for named customers. The individual customer stories were not opened this pass. Verified 2 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
This record meets the limb almost every other vendor in this pull fails. Professional secrecy is addressed directly and repeatedly, not merely implied: the security page commits to confidentiality in compliance with privacy law and with segreto professionale, the privacy policy states that beyond privacy Lexroom protects professional secrecy and confidential information generally, and there is an operational control attached to it, since efficiency monitoring data is visible to Lexroom staff only in anonymised form specifically so that confidentiality and professional secrecy are not compromised. Segregation is documented at tenant level: each customer has a dedicated and exclusive virtual space, private library contents are not shared with other customers, and the privacy policy states it is physically impossible for one customer to reach another's. Retention and deletion are stated precisely, and the position on third-party providers is explicit, with Google and OpenAI named and contractually excluded from training on customer prompts. What holds this at B is the vendor's own reservation, examined on the training signal: Lexroom may use prompts for its own benchmarking and fine tuning after stripping personal and confidential data. Matter-level walls inside a single firm are also not addressed, which matters because law firms are a named buyer. Verified 2 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
The supervision dimension is published and unusually concrete. The privacy policy states that outputs are always submitted to a human operator who must review them before use, and the research page frames the product as amplifying professional judgement rather than replacing it, with the user rather than an algorithm deciding. Coverage is bounded, since the platform is stated throughout as available in Italy, Spain and Germany only, which tells a professional where it does and does not reach. Two things are missing. No statement that output is not legal advice was located on any surface, which is a notable gap for a research product, and there is no published terms of service anywhere on the site in which such a statement would normally sit. And no bar or professional guidance is engaged: neither Italian Consiglio Nazionale Forense material nor any equivalent in Spain or Germany is named. Verified 2 September 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
What exists is compliance positioning rather than governance. The security FAQ states that Lexroom is fully compliant with the GDPR and the new European AI Act, and the privacy policy contains a reasoned analysis of automated processing under Article 22, concluding that outputs are not decisions in the strict sense because a human must review them. A Data Protection Officer is named in full, with chambers, tax code and certified email address, which is more accountability disclosure than any other record in this pull, though the role covers data protection rather than model behaviour. Absent is everything the higher bands ask for: no governance framework, no owner of model behaviour, no account of what is tested before release, no certification such as ISO 42001, and nothing whatsoever published about uneven output across matter types, parties or populations. Checked the home page, research, security and privacy pages on 2 September 2026. Verified 2 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
All five elements are published and specific to the day. Retention: private library files are deleted within 30 days of the end of the relationship, with backup copies on Google Cloud disposed of within a maximum of 180 days; prompts are kept for the duration of the relationship; customer registry and billing data for ten years under Italian accounting law. Deletion follows the same clock and data subject requests are answered within 30 days. Access control: data access is limited to a small number of technical staff holding special authorisations, with all access and downloads monitored, alongside an enforced password policy, encrypted stored passwords and single sign-on over SAML and OAuth 2.0. Subprocessors: Google and OpenAI are named as the AI providers, with categories of other recipients listed and a software bill of materials available on request. Incident practice: a formalised emergency procedure, notification to the customer as soon as possible, and communication by certified email or another secure channel agreed with the customer. Encryption is AES-256 at rest with a bring your own key option, daily vulnerability scanning is in place, and external penetration tests are run with summaries available on request. Verified 2 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Nothing published states who bears the loss when the output is wrong. No terms of service, master agreement or customer contract appears anywhere on the site: the footer offers only a privacy policy and a cookie policy, and the data processing agreement is described in the privacy policy as signed at the point of contract activation rather than published. No indemnity, no liability cap, no warranty and no carve-out is stated on any surface. Two liability-adjacent facts are published and are recorded because they are real. Lexroom states that it holds cyber risk insurance with a carrier rated double A by Standard and Poor's, with a copy of the certificate available on request, and that a service level agreement is attached to the corporate plan contract. Neither tells a buyer what recourse it has against Lexroom for a bad answer; the insurance protects the vendor's own balance sheet. Checked the home page, research page, security page, privacy policy and site footer on 2 September 2026. Verified 2 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
The surface is narrow and what exists is described with real precision. The Microsoft Word add-in is documented as to data flow rather than merely named: the privacy policy states that the add-in involves no additional data processing and that prompts formulated through it are directed straight to Lexroom without retention by or access from Microsoft or any other intermediary. That is a clearer statement of what moves and where it goes than most vendors in this pull manage for any integration. Single sign-on is specified by protocol, compatible with Google and Microsoft accounts and with SAML and OAuth 2.0. Beyond those two there is nothing. No document management, practice management, email or e-filing integration is named, no API or developer documentation was located, and no integrations page exists. Real integrations documented, but too few of them and no implementer material, which is the B band. Verified 2 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Residency is published with a named country and processing is separated from storage. The security page states that all data are processed on servers located exclusively in the European Union and that the principal server is in the Netherlands, with backup redundancy across several EU data centres as protection against extreme weather events. The privacy policy adds the storage half, that Lexroom keeps data long term on servers within the European Union, and discloses the one exception precisely rather than burying it: limited transits to the United States for website hosting only, covered by both EU standard contractual clauses and the Data Privacy Framework. The tenancy model is stated, with each customer given a dedicated and exclusive virtual space, and a bring your own key option is offered for encryption. Lexroom also states it operates no physical data centre of its own and relies on cloud services listed in the Italian national cybersecurity agency's digital infrastructure catalogue. The limitation a buyer outside Europe should weigh is that there is one region and no non-EU option, which is a disclosed restriction rather than a gap in disclosure. Verified 2 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Certification is real, stated, and named to the version, which is more precise than most: Lexroom is certified to ISO 27001:2022. External penetration testing is stated with auditors described as external and a summary report available on request, daily vulnerability scanning is described with findings classified and prioritised, and a software bill of materials and a cyber insurance certificate are each offered on request. What the top band asks for is missing from the pages read: no auditor is named, no certificate number, issue date or coverage period is published, and no report is downloadable. A trust centre exists at trust.lexroom.ai and is linked from both the footer and the security page, but it was not opened this pass, so its contents and access tier are unestablished and nothing in it is either credited or held against the vendor. That single surface is the one most likely to move this grade. Verified 2 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The providers are named and the vendor is candid about the architecture. The privacy policy states plainly that Lexroom does not develop its own large language model but relies on third-party artificial intelligence, and that the service therefore transfers data to sub-suppliers, in particular Google and OpenAI. It adds a real contractual commitment about what those providers may do, namely that customer prompts are expressly excluded from the AI suppliers' training under the terms agreed with them as sub-processors. Where inference runs is addressed at the level of the estate rather than the route, with all processing on EU servers. Two of the four things the top band asks for are absent: no model is named, only the houses they come from, and nothing commits to notifying customers when the supply chain or the models change. Verified 2 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Real pricing is published for the entry point and withheld above it, which is the B band exactly. The site states a starting price of 99 euros per month, excluding VAT and on an annual contract, and sets out precisely what that buys: one Lexroom module, one user, up to 200 documents, the Microsoft Word add-in, and the possibility of tailored training. That is a rate, a unit and a term, and it is the only published figure located in this pull so far. Above the entry plan the page says prices are tailored to requirements, so the enterprise range is a sales conversation. What keeps it off the top band is that nothing states what implementation or the tailored training adds, no module is priced individually even though modules are the unit of purchase, and there is no pricing page as such, the figure appearing in a demo-booking block repeated across the site. Verified 2 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
The buyer taxonomy is the most complete in this pull. Seven segments each have their own page: law firms, companies and public administration on the organisation side, and advocates, notaries, accountants and labour consultants on the professional side, which covers private practice, in-house and government use explicitly. Jurisdiction is bounded and repeated on every page, with the platform stated as available in Italy, Spain and Germany, so a buyer knows where it does not reach. Subject coverage is counted rather than listed: more than fifteen subject modules are said to exist, each built and verified individually, and modules are the unit a customer buys, but the pages read do not name them. That is what holds this below A, together with the absence of any statement of firm size or of what the product does not support. Verified 2 September 2026.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
Public material states that customer content trains, refines or personalises models, with no matching term located in the published agreement. Any de identification, anonymisation or aggregation qualifier is recorded in the summary.
The quoted line, from the Training section of the privacy policy, states that Lexroom itself may use customer Prompts for its own benchmarking and fine tuning, with the de-identification qualifier that personal data and confidential information are removed first and the work carried out only on principles not traceable to identified or identifiable persons. It names fine tuning expressly, which is what makes this a permission rather than an aggregate-data carve-out. No published agreement exists to test it against: the site publishes only a privacy policy and a cookie policy, and the data processing agreement is signed at contract activation. The marketing says the opposite in three places and a buyer should see both halves. The home page and security page state that documents and data sent to Lexroom are not used for training, a Zero Training Policy badge appears in the footer, and the security FAQ narrows it, saying uploaded documents and user queries are never used to train global language models. The genuinely strong commitment sits one layer out: customer prompts are expressly excluded from the AI suppliers' own training under the terms agreed with Google and OpenAI as sub-processors.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
A specific retention period is published and the customer cannot change it.
Specific published periods that the customer cannot change. Prompts are kept for the entire duration of the relationship and afterwards only for the time needed to run Lexroom's updates. Private library files, where that optional service is activated, are deleted within 30 days of the end of the relationship, with traces remaining only in Google Cloud backup copies which are disposed of within a maximum of 180 days. Customer registry and billing data are held for ten years as required by Italian accounting law, and navigation data for one year. Two published statements sit against this and a buyer should weigh them: a Zero Data Retention Policy badge appears in the site footer, and the security FAQ says documents are not stored permanently. Neither is false on its own terms, since library files are deleted and backups expire, but prompts persisting for the life of the contract is not zero retention, and no retention setting is offered to the customer.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product maintains its own permission model, documented, requiring the firm to keep it aligned.
Lexroom operates and documents its own separation model at the level of the customer account. The security page states that each customer has a dedicated and exclusive virtual space, that Lexroom does not share customer data to feed public libraries, and that it does not share it with other customers. The privacy policy goes further on the private library, saying each customer can use only its own and that it is physically impossible to reach a third party's, and adds that prompt data remain segregated inside the user's account. Access is administered by Lexroom rather than inherited from a source system, with authorisation limited to a small number of technical staff and all access and downloads monitored. What is not addressed is separation inside a single customer. Law firms are a named buyer segment with their own page, and nothing published describes walls between matters, teams or individual users within one firm's account.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.
The privacy policy addresses disclosure to authorities directly, listing public administrations, supervisory and control authorities and judicial authorities among the categories to which personal data may be communicated, where required by law or by an order of those bodies. It also records that personal data may be used in judicial proceedings to defend Lexroom's own position. Nothing anywhere commits to telling the customer when such a request arrives, and nothing reserves discretion over notice either: the question is simply never reached. Checked the privacy policy, the security page including its governance and continuity section, the research page and the home page on 2 September 2026. The breach notification commitment on the security page, that the customer will be warned as soon as possible and by certified email, addresses security incidents rather than legal process.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Coverage is described by jurisdiction with no identification of the underlying corpus.
Coverage is described by jurisdiction and the corpus itself is not identified. The three markets are stated on every page, Italy, Spain and Germany. The research page describes thousands of legislative and case law sources selected by legal institute and validated by partner jurists across more than fifteen subject modules, and the privacy policy adds that the Lexroom Library is a collection of documents drawn from institutional legal sources, divided by subject, with customers accessing only the modules bought. That identifies the character and the curation method but not a single named source, publisher or database, and no licence or rights basis is stated for any of it. An update cadence is claimed only as sources being current. One inconsistency belongs on the record: the first-party pages say thousands of sources, while Italian trade press in May 2026 reported a company statement of more than six million verified legal sources, a figure that could not be confirmed on any first-party surface.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
Checked the home page, the legal research feature page, the security page and the privacy policy on 2 September 2026. No public material addresses whether an authority returned by the product is still good law. The nearest claims concern the freshness of the collection rather than the standing of an individual authority: sources are described as updated, official and certified, and the stated purpose of retaining the library is to ensure outputs stay current. Neither speaks to subsequent history, to legislation that has been repealed or amended, or to decisions overtaken by later Cassazione rulings. The question bites on this product because it retrieves legislation and case law directly and presents linked authority as the basis for its answers.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
Checked the home page, the legal research feature page, the security page and the privacy policy on 2 September 2026. Nothing describes what the product does when it cannot ground an answer. No abstention path is documented and no confidence or grounding indicator is described. The marketing runs the other way, asserting zero hallucinations and zero risks, which is a claim that the situation does not arise rather than an account of what happens when it does. The architectural answer offered instead is verification by the reader: every statement is linked to its source so the user can check it, which places the burden of detecting an unsupported assertion on the lawyer rather than on the system.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
Searched the AI Hallucination Cases database maintained by Damien Charlotin, and Italian and international reporting drawing on it, on 2 September 2026 on the product and corporate name Lexroom and Lexroom S.r.l. No court order, opinion or disciplinary record naming the product was located. This is a statement about the public record rather than a finding about the product. One structural caveat: the database is heavily weighted to United States filings and its Italian coverage is thin, so an Italian product is less likely to surface even where an incident occurred. Lexroom itself cites the phenomenon in its own marketing, with company material reported in May 2026 referring to more than 1,300 documented filings containing AI-generated hallucinations.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
Checked the home page, the legal research feature page, the security page, the privacy policy and the professional segment pages for advocates and notaries on 2 September 2026. No public material engages with professional or ethics guidance from any of the three markets served, and nothing names the Italian Consiglio Nazionale Forense, the Consiglio Nazionale del Notariato, or any Spanish or German equivalent. Lexroom does engage named instruments, claiming compliance with the GDPR and the European AI Act, and it addresses professional secrecy directly, but both bind the supplier rather than setting out the professional obligations of the lawyers and notaries using the product, which is what this signal records.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Public materials claim time savings without addressing billing or disclosure.
Savings are claimed with figures and nothing addresses the bill. The home page publishes a 40 per cent reduction in time spent on repetitive tasks and 2.5 times more documents drafted, and a named customer is quoted saying the platform is not only a saving of time but a saving of money for the company because she has needed outside counsel less often. No published material addresses how AI-assisted work is recorded, billed or disclosed to a client, and no per matter record of AI-assisted work was located. The buyer mix is relevant to how this signal reads here: Lexroom sells to private practice advocates and law firms who do bill clients, so unlike the in-house products in this pull the assumed direction holds, which makes the silence more pointed rather than less.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A current subprocessor or model provider list is published.
The model providers are named on a public page, which clears the test that infrastructure alone never satisfies this signal: the privacy policy states that Lexroom does not develop its own large language model and transfers data to sub-suppliers, in particular Google and OpenAI, and records that customer prompts are excluded from those suppliers' training under the terms agreed with them. Categories of other recipients are listed, and a software bill of materials is offered on request. It stops short of the top value because the third limb is not published: there is no forwardable client-facing disclosure pack, the data processing agreement is signed at contract activation rather than published, and no consolidated subprocessor register with entities, roles and regions exists. Cloud storage providers are given by category rather than by name, although Google Cloud is identified elsewhere as holding backups.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
No located public material addresses court disclosure or verification certification.
Checked the home page, the legal research feature page, the security page and the privacy policy on 2 September 2026. Nothing addresses court disclosure of AI use or any certification that citations were checked by a person. The product does leave a usable trail for the lawyer's own verification, since every statement is linked to the source that justifies it and search history is retained and retrievable, but nothing is described as an exportable per document record covering which model produced which passage, what was retrieved and who reviewed it. Italian and Spanish courts have not developed the standing-order practice that drives this signal in the United States, so the obligation it tracks is less established in the markets Lexroom serves, but the record here is simply that the question is not addressed.