Security and data protection at Nomoaxis.
Nomoaxis is engineered around legal confidentiality — from the encryption scheme to the audit chain to where the servers live.
Built for the confidentiality demands of legal practice.
- Encryption✓ Active
XChaCha20-Poly1305
Encryption for documents, matter discussions, time-entry notes, AI messages and metadata at rest. Keys do not leave the secure environment.
- Access✓ Active
Role-based permissions
Roles mapped to firm hierarchy — partners, associates and paralegals — enforced server-side.
- MFA✓ Active
Option for mandatory MFA for all members
TOTP enrollment with a recovery phrase.
- Step-up✓ Active
AAL2 for sensitive actions
Key rotation, and member changes require a fresh re-authentication.
- Audit✓ Active
Tamper-evident audit log
Every action signed and chained. Export verifiable trails for any investigation or DSAR.
- DSAR✓ Active
Article 15 & 17 tooling
Built-in client data export and erasure workflows — one click, fully audited.
- Documents✓ Active
Secure document storage
Versioned, encrypted, and bound to the matter. Nothing leaks across engagements.
- Isolation✓ Active
Matter-level access
Access scoped per matter — reads are blocked at the data layer.
- Hosting✓ Active
EU data residency
Hosted exclusively in the European Union.
- Compliance✓ Active
GDPR native
DSAR workflows, data minimization, and retention policies built in.
- Privacy✓ Active
Zero third-party tracking
Your data stays yours.
Internal access
Least-privilege roles, mandatory MFA, peer-reviewed deploys, and continuous vulnerability scanning.
Encryption in motion & at rest
TLS 1.3 in transit, XChaCha20-Poly1305 at rest. Keys live in a hardware-backed KMS hosted in the EU.
Where your data lives. And who can reach it.
Every answer below matches what is written in our Privacy Policy and Data Processing Agreement — nothing here is aspirational.
Where it lives
- Hosted in the European Union
- Keys held in a hardware-backed KMS inside the EU
- TLS 1.3 in transit, XChaCha20-Poly1305 at rest
Who can reach it
- Least-privilege internal roles with mandatory MFA
- Matter-level access enforced server-side
- Every action signed into a tamper-evident chain
Retention and deletion
- Client data export on request, fully audited
- Erasure workflows for Article 17 requests
- Sub-processors named and kept current in the DPA
Security questions we get asked most.
Run your firm smarter.
Manage legal work, collaborate securely, and gain complete visibility into your firm's operations.