Security and data protection at Nomoaxis.

Nomoaxis is engineered around legal confidentiality — from the encryption scheme to the audit chain to where the servers live.

Security

Built for the confidentiality demands of legal practice.

  • Encryption
    ✓ Active

    XChaCha20-Poly1305

    Encryption for documents, matter discussions, time-entry notes, AI messages and metadata at rest. Keys do not leave the secure environment.

  • Access
    ✓ Active

    Role-based permissions

    Roles mapped to firm hierarchy — partners, associates and paralegals — enforced server-side.

  • MFA
    ✓ Active

    Option for mandatory MFA for all members

    TOTP enrollment with a recovery phrase.

  • Step-up
    ✓ Active

    AAL2 for sensitive actions

    Key rotation, and member changes require a fresh re-authentication.

  • Audit
    ✓ Active

    Tamper-evident audit log

    Every action signed and chained. Export verifiable trails for any investigation or DSAR.

  • DSAR
    ✓ Active

    Article 15 & 17 tooling

    Built-in client data export and erasure workflows — one click, fully audited.

  • Documents
    ✓ Active

    Secure document storage

    Versioned, encrypted, and bound to the matter. Nothing leaks across engagements.

  • Isolation
    ✓ Active

    Matter-level access

    Access scoped per matter — reads are blocked at the data layer.

  • Hosting
    ✓ Active

    EU data residency

    Hosted exclusively in the European Union.

  • Compliance
    ✓ Active

    GDPR native

    DSAR workflows, data minimization, and retention policies built in.

  • Privacy
    ✓ Active

    Zero third-party tracking

    Your data stays yours.

Internal access

Least-privilege roles, mandatory MFA, peer-reviewed deploys, and continuous vulnerability scanning.

Encryption in motion & at rest

TLS 1.3 in transit, XChaCha20-Poly1305 at rest. Keys live in a hardware-backed KMS hosted in the EU.

Data handling

Where your data lives. And who can reach it.

Every answer below matches what is written in our Privacy Policy and Data Processing Agreement — nothing here is aspirational.

Where it lives

  • Hosted in the European Union
  • Keys held in a hardware-backed KMS inside the EU
  • TLS 1.3 in transit, XChaCha20-Poly1305 at rest

Who can reach it

  • Least-privilege internal roles with mandatory MFA
  • Matter-level access enforced server-side
  • Every action signed into a tamper-evident chain

Retention and deletion

  • Client data export on request, fully audited
  • Erasure workflows for Article 17 requests
  • Sub-processors named and kept current in the DPA
Questions

Security questions we get asked most.

Run your firm smarter.

Manage legal work, collaborate securely, and gain complete visibility into your firm's operations.