Noxtua icon

Noxtua

Europe's sovereign legal AI with its own European-trained legal LLM

by NoxtuaDEGermany🌐EU only — Open Telekom Cloud (Deutsche Telekom) and IONOS, no US cloud providers; on-premise option available
TrustKit Score100%Excellent

About Noxtua

Noxtua, formerly Xayn, is a Berlin-based legal AI company building what it describes as Europe's first sovereign legal AI. Spun out of research from Oxford University and Imperial College London, the company rebranded from Xayn AG to Noxtua SE alongside its April 2025 Series B. Unlike most legal AI vendors that wrap US foundation models, Noxtua runs its own proprietary Noxtua Legal Large Language Model, trained exclusively on high-quality European legal data labelled by legal experts in partnership with German business law firm CMS. The €80.7M Series B was led by Germany's leading legal publisher C.H.Beck, with HPC specialist Northern Data, CMS and global law firm Dentons also participating. The Legal AI Alliance behind Noxtua now spans publishers, computing partners and major law firms across Germany, Austria and beyond, giving the platform deep, jurisdiction-specific legal content (100M+ searchable documents and 7.5M+ court decisions). Noxtua's sovereignty positioning is unusually strong. Processing occurs exclusively on European infrastructure via the Open Telekom Cloud (Deutsche Telekom) and IONOS, with no connection to US cloud providers. Customer data is explicitly never used to train, retrain or improve AI models, and the self-trained model can run either on a sovereign European cloud or locally on-premise. The platform is designed to meet German professional-secrecy obligations (§ 43e BRAO, § 203 StGB), allowing use by confidentiality-bound professionals without anonymisation. Noxtua carries an extensive certification stack: it is the first German company certified to ISO 42001 (AI management), alongside ISO 27001, 27017, 27018 and 9001, plus BSI C5 and TISAX, and is GDPR-compliant. It targets in-house legal teams, law firms, auditors and tax advisers, and public authorities and courts. Exact pricing is not published and is handled via enterprise sales.

TrustKit Score Breakdown

?100% Excellent
Data Residency
Where is your data stored and processed?
Processing occurs exclusively on European infrastructure (Open Telekom Cloud by Deutsche Telekom and IONOS) with no connection to US cloud providers, plus an on-premise deployment option. Best-in-class EU data residency.
5/5
Legal Jurisdiction
Which laws govern the company and your data?
Incorporated in Germany as Noxtua SE (formerly Xayn AG), an EU/EEA entity with no US parent. Designed to meet German professional-secrecy law (§ 43e BRAO, § 203 StGB).
5/5
Data Retention & Training
Is your data used for model training?
Explicitly states customer data is never used to train, retrain or improve AI models, with sovereign/on-premise deployment and enterprise DPA-level controls. Specific configurable retention windows are not publicly detailed but the no-training and isolation posture is strong.
5/5
Certifications
ISO 27001, SOC 2, Cyber Essentials, etc.
Extensive published certification stack: ISO 42001 (first German company), ISO 27001, 27017, 27018, 9001, plus BSI C5 and TISAX. No SOC 2 (US-oriented), but European sector and AI-specific certifications exceed the baseline.
5/5
Regulatory Fit
Suitability for regulated industries and professional services
Purpose-built for regulated EU legal work, explicitly meeting attorney confidentiality and professional-secrecy requirements, with backing from major law firms and legal publishers. Suitable for the most demanding EU regulated legal and public-sector use.
5/5

Pricing

Custom
EnterpriseContact Sales
Full pricing details →

Quick Facts

Starting PriceCustom / enterprise pricingData HostingEU only — Open Telekom Cloud (Deutsche Telekom) and IONOS, no US cloud providers; on-premise option availableTrains on Your DataCustomer data is never used to train, retrain or improve AI modelsFounded2017Employees51-200

Frequently Asked Questions

Is Noxtua GDPR compliant?

Noxtua has a TrustKit compliance score of 100% (Excellent). Data Residency: Processing occurs exclusively on European infrastructure (Open Telekom Cloud by Deutsche Telekom and IONOS) with no connection to US cloud providers, plus an on-premise deployment option. Best-in-class EU data residency.. Legal Jurisdiction: Incorporated in Germany as Noxtua SE (formerly Xayn AG), an EU/EEA entity with no US parent. Designed to meet German professional-secrecy law (§ 43e BRAO, § 203 StGB)..

Where does Noxtua store data?

Noxtua hosts data in: EU only — Open Telekom Cloud (Deutsche Telekom) and IONOS, no US cloud providers; on-premise option available. Processing occurs exclusively on European infrastructure (Open Telekom Cloud by Deutsche Telekom and IONOS) with no connection to US cloud providers, plus an on-premise deployment option. Best-in-class EU data residency.

Does Noxtua train on user data?

Noxtua: Customer data is never used to train, retrain or improve AI models. Explicitly states customer data is never used to train, retrain or improve AI models, with sovereign/on-premise deployment and enterprise DPA-level controls. Specific configurable retention windows are not publicly detailed but the no-training and isolation posture is strong.

What certifications does Noxtua hold?

Noxtua holds: ISO 42001, ISO 27001, ISO 27017, ISO 27018, ISO 9001, BSI C5, TISAX. Extensive published certification stack: ISO 42001 (first German company), ISO 27001, 27017, 27018, 9001, plus BSI C5 and TISAX. No SOC 2 (US-oriented), but European sector and AI-specific certifications exceed the baseline.

Compare Noxtua With

Similar Tools

Related Articles