Noxtua
Europe's sovereign legal AI with its own European-trained legal LLM
About Noxtua
Noxtua, formerly Xayn, is a Berlin-based legal AI company building what it describes as Europe's first sovereign legal AI. Spun out of research from Oxford University and Imperial College London, the company rebranded from Xayn AG to Noxtua SE alongside its April 2025 Series B. Unlike most legal AI vendors that wrap US foundation models, Noxtua runs its own proprietary Noxtua Legal Large Language Model, trained exclusively on high-quality European legal data labelled by legal experts in partnership with German business law firm CMS. The €80.7M Series B was led by Germany's leading legal publisher C.H.Beck, with HPC specialist Northern Data, CMS and global law firm Dentons also participating. The Legal AI Alliance behind Noxtua now spans publishers, computing partners and major law firms across Germany, Austria and beyond, giving the platform deep, jurisdiction-specific legal content (100M+ searchable documents and 7.5M+ court decisions). Noxtua's sovereignty positioning is unusually strong. Processing occurs exclusively on European infrastructure via the Open Telekom Cloud (Deutsche Telekom) and IONOS, with no connection to US cloud providers. Customer data is explicitly never used to train, retrain or improve AI models, and the self-trained model can run either on a sovereign European cloud or locally on-premise. The platform is designed to meet German professional-secrecy obligations (§ 43e BRAO, § 203 StGB), allowing use by confidentiality-bound professionals without anonymisation. Noxtua carries an extensive certification stack: it is the first German company certified to ISO 42001 (AI management), alongside ISO 27001, 27017, 27018 and 9001, plus BSI C5 and TISAX, and is GDPR-compliant. It targets in-house legal teams, law firms, auditors and tax advisers, and public authorities and courts. Exact pricing is not published and is handled via enterprise sales.
TrustKit Score Breakdown
?100% ExcellentPricing
CustomQuick Facts
Frequently Asked Questions
Is Noxtua GDPR compliant?
Noxtua has a TrustKit compliance score of 100% (Excellent). Data Residency: Processing occurs exclusively on European infrastructure (Open Telekom Cloud by Deutsche Telekom and IONOS) with no connection to US cloud providers, plus an on-premise deployment option. Best-in-class EU data residency.. Legal Jurisdiction: Incorporated in Germany as Noxtua SE (formerly Xayn AG), an EU/EEA entity with no US parent. Designed to meet German professional-secrecy law (§ 43e BRAO, § 203 StGB)..
Where does Noxtua store data?
Noxtua hosts data in: EU only — Open Telekom Cloud (Deutsche Telekom) and IONOS, no US cloud providers; on-premise option available. Processing occurs exclusively on European infrastructure (Open Telekom Cloud by Deutsche Telekom and IONOS) with no connection to US cloud providers, plus an on-premise deployment option. Best-in-class EU data residency.
Does Noxtua train on user data?
Noxtua: Customer data is never used to train, retrain or improve AI models. Explicitly states customer data is never used to train, retrain or improve AI models, with sovereign/on-premise deployment and enterprise DPA-level controls. Specific configurable retention windows are not publicly detailed but the no-training and isolation posture is strong.
What certifications does Noxtua hold?
Noxtua holds: ISO 42001, ISO 27001, ISO 27017, ISO 27018, ISO 9001, BSI C5, TISAX. Extensive published certification stack: ISO 42001 (first German company), ISO 27001, 27017, 27018, 9001, plus BSI C5 and TISAX. No SOC 2 (US-oriented), but European sector and AI-specific certifications exceed the baseline.
Compare Noxtua With
Similar Tools
Related Articles
ChatGPT vs Claude: Which Is Better for EU Compliance in 2026?
A detailed comparison of OpenAI's ChatGPT and Anthropic's Claude across data residency, GDPR compliance, certifications, and regulatory suitability for European businesses.
8 min read
GuidesThe 15 Best GDPR-Compliant AI Tools for European Businesses (2026)
Our curated list of the most compliance-friendly AI tools available to EU businesses, rated across data residency, certifications, and regulatory suitability.
12 min read
GuidesSovereign AI in Europe: The Complete Guide to EU-Only AI Platforms
A comprehensive guide to AI platforms that keep data entirely within EU jurisdiction \u2014 no CLOUD Act exposure, no transatlantic data transfers, no compliance gaps.
9 min read