Noxtua
European sovereign legal AI for law firms, in house teams, auditors and tax advisers, courts and public authorities. Three products: Research, Understanding for matrix analysis across document sets, and Drafting, with a Microsoft Word add in. Built on proprietary models rather than third party foundation models, running on European infrastructure from IONOS and Deutsche Telekom independent of US cloud providers. Content comes from exclusive licences with national legal publishers, shipped as jurisdiction specific editions including Beck-Noxtua in Germany, MANZ-Noxtua in Austria, Swiss-Noxtua, Ciela-Noxtua in Bulgaria and Blendow-Noxtua in Sweden. Founded in Berlin in 2017 as Xayn, renamed Noxtua SE, and co-initiated with the law firm CMS. Version 5 introduces knowledge graphs.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The artificial intelligence is the product, and further down the stack than any other record on this index. The vendor states it is built as a complete system with control over infrastructure, model, data and interface, running proprietary models trained on licensed legal data rather than calling third party foundation models. It also publishes its own legal embedding model, Noxtua Voyage Embed, built with Voyage AI and dejure.org. Remove the models and nothing remains.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is real and documented, with published comparative measurement on one component, short of accuracy figures for the product itself. The retrieval method is described in unusual detail: the agent analyses a query, develops a solution plan, and researches systematically across licensed publisher content, with version 5 generating a knowledge graph per query that surfaces relevant sources and maps how they connect. Output carries verifiable source references into a licensed corpus a reader can open. Uniquely on this index the vendor publishes measured figures for its own retrieval model, stating Noxtua Voyage Embed outperforms a named OpenAI embedding model on legal text benchmarks with 1.7 times better search accuracy and 2.2 times better ranking quality at three times lower dimensionality. That is retrieval quality rather than answer accuracy. Not located as of 29 Aug 2026: an accuracy or hallucination rate for generated output, a test set for it, or any abstention behaviour.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Autonomy is claimed and oversight is asserted without a mechanism. The vendor describes agentic AI that independently develops a solution plan and executes systematic research, and states results are traceable at every stage, which is transparency of process rather than a control structure. Searched the site, the three product pages, the security page and the press releases on 29 Aug 2026 and located no description of what the system does on its own versus what a lawyer must approve, no review surface, no threshold at which the agent stops, and no statement of what happens after an output is wrong. Traceability shows a reader what happened; it does not establish who decides.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Customer logos and an unattributed selected clients strip stand in for evidence. A customer stories page exists in the navigation, and a named endorsement appears from Dr Markus Kaulartz, partner at CMS, though CMS is also a co-initiator and investor rather than an arm's length customer, which is disclosed on the page and weakens it as independent evidence. Corpus scale figures are published, 130 million plus searchable documents and 8.5 million plus court decisions, but those describe the database rather than a deployment. Searched the site, the customer stories entry point and the press centre on 29 Aug 2026 and located no named deployment with figures, dates and an assessable method.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
The most complete confidentiality posture on the index so far, and the only one that engages the professional secrecy question in statute. The vendor states compliance with Section 43e BRAO and Section 203 StGB, the German provisions governing what a lawyer bound by professional secrecy may use, and states this permits use by confidentiality bound professionals without requiring anonymisation. Training is addressed directly and in the negative: inputs and outputs are never used to train the AI and never shared with third parties. Segregation is documented at the level this segment requires under the amended band, with every project encrypted in transit and at rest under its own cryptographic key, strictly controlled access, and every action logged. The vendor further states it has no persistent access to plaintext data. Certification covers AI governance as well as security. Short of a full A only in that the underlying customer agreement is not published, so these commitments were read from the security page rather than a contract.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
A real position is published and it is grounded in named law rather than a disclaimer. The vendor addresses the professional rules that govern whether a lawyer may use the tool at all, citing Section 43e BRAO and Section 203 StGB and alignment with the EU AI Act, and states the audience precisely across law firms, in house teams, auditors and tax advisers, courts and public authorities. Jurisdiction limits are handled structurally rather than in prose: the product ships as jurisdiction specific editions and the site requires a jurisdiction selection before granting access, which is a real published boundary. Short of an A because competence and supervision duties are not addressed, and because the position is framed around the vendor's own permissibility rather than around what the lawyer remains responsible for.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
A published governance framework with real substance and independent validation, short of testing results or a named owner. ISO 42001 certification covers the AI management system specifically and is stated alongside ISO 27001, 27017, 27018 and 9001, BSI C5 and TISAX, with the vendor stating controls are independently and regularly audited and publishing a trust center for the full current list. Alignment with the EU AI Act is stated. That is a governance regime for AI rather than a principles page, and it is externally audited. Not located as of 29 Aug 2026: a named internal owner of model governance, published pre release testing results for model behaviour, or any disclosure about uneven output across matter types, parties or populations.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive published policy covering most of the ground. Per project encryption in transit and at rest with a distinct cryptographic key per project, strictly controlled access, full action logging, a stated position that the vendor has no persistent access to plaintext data, regular security reviews and risk assessments, and a Vanta backed trust center at a stable URL. Infrastructure providers are named individually with their own certifications, which is effectively a partial subprocessor disclosure at the hosting layer. Not located as of 29 Aug 2026: a stated retention period or deletion control for documents and prompts, a full subprocessor list, and an incident or breach notification practice.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Searched the site, the security page, the imprint, the data privacy statement, the FAQ and the trust center entry point on 29 Aug 2026. No published indemnity, liability cap, carve out, warranty on output or insurance position was located, and no customer terms or general conditions are published at all. Access to the product itself runs through a jurisdiction gated request form, so the agreement is reached through a sales process. Notable given how much else this vendor publishes: the compliance posture is documented in statutory detail while the allocation of loss when output is wrong is not addressed anywhere public.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Integrations are named without documentation an implementer could use. A Microsoft Word integration is stated on the drafting product page, with work possible either in Noxtua directly or in Word. Searched the site, the three product pages, the security page and the FAQ on 29 Aug 2026 and located no other integration: no document management connector such as iManage or NetDocuments, no Outlook, no contract lifecycle or matter management, and no integrations page at all. Nothing describes what the Word integration moves, in which direction, or what an administrator configures.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Where the software runs and where the data sits is published in more concrete detail than by any other vendor on this index, because it is the product's entire proposition. Hosting providers are named individually with their certifications and their roles: IONOS as a BSI C5 certified critical infrastructure provider operating the Bundescloud; Deutsche Telekom's Industrial AI Cloud, the AI Factory in Munich underpinning the Deutschland Stack for regulated sectors including the judiciary; T Cloud Public, BSI C5 certified for critical infrastructures; and T Cloud Public in Switzerland, BSI C5 certified and FINMA compliant, offering Swiss data sovereignty. The vendor states data stays in Europe on infrastructure operated by European providers independent of US cloud providers and shielded from the US CLOUD Act, which addresses jurisdiction of processing and not merely geography of storage. Short only of a per tier statement of what changes between deployment options.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
The broadest certification set on the index, with a trust center reachable without a sales call. Named and current: BSI C5, TISAX, ISO 42001, ISO 27001, ISO 27018, ISO 27017 and ISO 9001, with the vendor stating controls are independently and regularly audited and describing itself as the most comprehensively certified legal AI in Europe. The trust center is a Vanta hosted portal at a stable URL carrying the full current certification list and policies, which is a self serve route rather than a sales conversation. BSI C5 and TISAX are meaningful here rather than decorative, being the German federal cloud computing criteria and the automotive industry information security assessment. Short of the very top only because no coverage period, report date or named auditor was located on the public pages as of 29 Aug 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The clearest supply chain answer on the index, because the vendor owns the chain. Models are proprietary and trained in house on licensed legal data rather than sourced from a third party foundation model provider, which is stated plainly and is the point of the sovereignty positioning. Where models run is named to the specific provider and facility, IONOS and Deutsche Telekom's Industrial AI Cloud in Munich among them. One named external component is disclosed with its partner: the retrieval model Noxtua Voyage Embed, built with Voyage AI and dejure.org, with the model identifier published. A customer therefore inherits a dependency chain that is both short and named. Not located: a commitment to notify customers when the model or its hosting changes.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
Searched the site, the navigation, the three product pages, the jurisdictions page and the FAQ on 29 Aug 2026. No pricing page exists, no rate is published, no unit of charge is stated and no tier structure appears. The only commercial entry point is a Get Access request that first requires selecting a jurisdiction, so a buyer cannot reach a figure or even a product edition without entering a sales process. Third party pricing figures were not located either.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segment coverage is described with substance and with an unusual axis of precision. Four segments carry their own published sections: in house legal teams, law firms, auditors and tax advisers, and courts and public authorities, the last being the first explicit judiciary and public administration positioning on this index. Jurisdictional coverage is stated concretely as named editions per country rather than as a count, spanning Germany, Austria, Switzerland, Poland, Czech Republic, Slovakia, Bulgaria and Sweden, each tied to its national legal publisher. Short of an A because practice areas supported are not enumerated beyond a general research, analysis and drafting framing, and because what is not supported is nowhere stated.
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
A public policy or trust page states no training on customer content, with no matching term located in the published agreement.
The security page states directly that inputs and the product's outputs are never used to train the AI and are never shared with third parties, and separately that the vendor has no persistent access to plaintext data. The commitment as located sits on a public security page rather than in a customer agreement, and no customer terms are published on this property, so it records at the policy level. Worth noting the training relationship runs the other way as well and is disclosed: the vendor states it trains its proprietary models on legal data licensed from publishers, which is publisher content rather than customer content.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
No located public material states how long prompts and outputs are retained.
Searched the security page, the data privacy statement, the FAQ, the imprint and the trust center entry point on 29 Aug 2026. No public material states how long inputs, outputs or uploaded documents are retained, whether the customer controls the window, or whether deletion is available. The vendor does publish related architecture, per project encryption under a distinct key and a statement that it holds no persistent access to plaintext data, but neither answers the retention question. Second vendor on this index to record an absence rather than a period.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
The product maintains its own permission model, documented, requiring the firm to keep it aligned.
The product maintains its own documented segregation model rather than inheriting one from a document management system. Every project is encrypted in transit and at rest under its own cryptographic key, access is strictly controlled and every action is logged, and the vendor states it has no persistent access to plaintext data. Per project cryptographic separation is a stronger mechanism than most and it is documented, but it is the vendor's own model, which the firm must keep aligned with its walls. No document management integration was located whose permissions retrieval could enforce at query time, and no material addresses conflicts or ethical walls as such.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
No located term or policy addresses third party requests for customer data.
Searched the security page, the data privacy statement, the imprint, the FAQ and the trust center entry point on 29 Aug 2026. No clause committing to notify a customer of a government or law enforcement request for their data was located, and no transparency report was located. The vendor does address the adjacent question of foreign jurisdiction directly, stating data stays in Europe shielded from the US CLOUD Act on infrastructure operated by European providers, which speaks to which state could compel production rather than to whether the customer would be told.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
The vendor names its primary law sources and the licence or public domain basis for each, with an update cadence.
The strongest corpus disclosure on the index so far and the first to state a licence basis. Sources are named individually as national legal publishers and tied to the jurisdiction each serves: C.H.Beck for Germany, Poland, Czech Republic and Slovakia, MANZ for Austria, Ciela for Bulgaria and Blendow for Sweden, plus a Swiss edition, with dejure.org named in the retrieval model partnership. The rights basis is stated as exclusive publisher partnerships, described as the first Europe licence of its kind. Scale is quantified at more than 130 million searchable documents and more than 8.5 million court decisions. Short of the top value only because no update cadence or lag for the corpus was located as of 29 Aug 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
Searched the site, the three product pages, the jurisdictions page and the press releases on 29 Aug 2026. No material was located addressing whether authority returned carries a treatment signal or whether subsequent history is checked. The Understanding product is described as assessing the validity of clauses, which is contract clause analysis rather than the standing of cited authority, and was not treated as evidence here. Noted for context: continental civil law jurisdictions do not use citators in the Anglo American sense, so this signal reads differently for a vendor selling into Germany, Austria and Switzerland than for a US product.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
Searched the site, the three product pages, the security page and the press releases on 29 Aug 2026. No published material describes what the product does when it cannot ground an answer, and no explicit no answer path or confidence signal exposed to the user was located. The vendor publishes that results are traceable at every stage and that version 5 surfaces a knowledge graph of the sources behind an answer, which lets a reader inspect the basis of an answer that was given rather than telling them when the system found nothing.
Fabricated Citation Record
Does a public court record exist involving output from this product?
No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.
No court order, opinion or disciplinary record naming this product has been located as of 29 Aug 2026. Instrument searched: the AI Hallucination Cases database maintained by Damien Charlotin, which tracks court decisions worldwide involving AI generated hallucinated content and records the AI tool implicated where it is known. Also checked published 2026 sanctions summaries and secondary sanctions trackers. The entries located name filers, and in some rows other products, rather than this one. This is a statement about the public record on the date shown and not a clearance. The bound is worth stating plainly for this vendor: that database is weighted toward US and other common law filings, and this product sells into German speaking and central European jurisdictions whose decisions are less comprehensively covered by it.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
Public materials engage with at least one named ethics opinion.
Public materials engage with named professional obligations by statutory citation rather than in general terms: Section 43e of the German Federal Code for Lawyers and Section 203 of the German Criminal Code, the provisions governing what a lawyer bound by professional secrecy may use, plus stated alignment with the EU AI Act. The vendor states this permits use by confidentiality bound professionals without requiring anonymisation, which is a specific claim about the rules its buyers are bound by. Short of the mapped by jurisdiction value because the engagement is with German law only, despite the product shipping in eight national editions, and no equivalent Austrian, Swiss, Polish, Czech, Slovak, Bulgarian or Swedish provision was addressed in located material.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
No located public material addresses billing, fee or disclosure treatment.
Searched the site, the three product pages, the customer stories entry point and the press centre on 29 Aug 2026. No published guidance on billing, fee or client disclosure treatment was located, and no per matter record of AI assisted work intended for fee purposes was located. Distinct from the other vendors on this index in that no time savings or efficiency figures were located either: the vendor's published framing is precision, verifiability and permissibility rather than hours saved, so there is no savings claim to weigh against the client's side of the equation.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A current subprocessor or model provider list is published.
A trust center is published at a stable URL, reachable without a sales conversation, carrying what the vendor describes as the full list of current certifications and policies. The certification set named on the public security page is broad and specific: BSI C5, TISAX, ISO 42001, 27001, 27018, 27017 and 9001. Infrastructure providers are named individually with their own certifications, which covers the hosting layer of the supply chain, and the model layer is proprietary rather than third party, which removes the model provider question a firm would normally have to answer for its client. Short of the full disclosure pack because no formal subprocessor list was located and no client facing consent or notification material was located as of 29 Aug 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
Several elements of a disclosure record are available and unusually well documented. The vendor states every action is logged, that agentic research is traceable at every stage, and that version 5 generates a knowledge graph per query surfacing the sources relied on and mapping how they connect, with verifiable source references throughout. Sources retrieved and the reasoning path are therefore recoverable. Two elements are missing: no per document export covering model used, sources retrieved and human verification together was located, and human verification is not recorded as such. The model question is simpler here than elsewhere, since the model is the vendor's own proprietary system rather than a rotating third party.