Security
Security and data protection at Nomoaxis.
Nomoaxis is engineered around legal confidentiality — from the encryption scheme to the audit chain to where the servers live.
Built for the confidentiality demands of legal practice.
- Encryption✓ Active
XChaCha20-Poly1305
Encryption for documents, matter discussions, time-entry notes, AI messages and metadata at rest. Keys do not leave the secure environment.
- Access✓ Active
Role-based permissions
Roles mapped to firm hierarchy — partners, associates and paralegals — enforced server-side.
- MFA✓ Active
Two-step sign-in
Required for all members by default (TOTP with a recovery phrase); the firm owner sets the policy.
- Step-up✓ Active
AAL2 for sensitive actions
Key rotation, and member changes require a fresh re-authentication.
- Audit✓ Active
Tamper-evident audit log
Every action signed and chained. Export verifiable trails for any investigation or DSAR.
- DSAR✓ Active
Article 15 & 17 tooling
Built-in client data export and erasure workflows — one click, fully audited.
- Documents✓ Active
Secure document storage
Versioned, encrypted, and bound to the matter. Nothing leaks across engagements.
- Isolation✓ Active
Matter-level access
Access scoped per matter — reads are blocked at the data layer.
- Hosting✓ Active
EU data residency
Hosted exclusively in the European Union.
- Compliance✓ Active
GDPR native
DSAR workflows, data minimization, and retention policies built in.
- Privacy✓ Active
Zero third-party tracking
Your data stays yours.
Internal access
Least-privilege roles, mandatory MFA, peer-reviewed deploys, and continuous vulnerability scanning.
Encryption in motion & at rest
TLS 1.3 in transit, XChaCha20-Poly1305 at rest. Keys live in a hardware-backed KMS hosted in the EU.
Where your data lives. And who can reach it.
Every answer below matches what is written in our Privacy Policy and Data Processing Agreement — nothing here is aspirational.
Where it lives
- Hosted in the European Union
- Keys held in a hardware-backed KMS inside the EU
- TLS 1.3 in transit, XChaCha20-Poly1305 at rest
Who can reach it
- Least-privilege internal roles with mandatory MFA
- Matter-level access enforced server-side
- Every action signed into a tamper-evident chain
Retention and deletion
- Client data export on request, fully audited
- Erasure workflows for Article 17 requests
- Sub-processors named and kept current in the DPA