LEXA was designed so that you can upload and process even the most sensitive legal documents securely — without compromising between data protection and efficiency.
In legal work, data security is not optional. Client data, trade secrets and litigation strategies are among the most sensitive kinds of information. That is why LEXA places data protection at the center, not only as a legal obligation, but as one of its core value propositions.
LEXA handles all data in accordance with European Union data protection rules. This is not merely a legal statement — it is a fundamental design principle of the system.
What does this mean in practice?
Why is this important? General AI tools — such as consumer versions of ChatGPT or Claude — may, by default, store and use question content to train models. LEXA excludes this through the ZDR agreement: the content of legal questions will not become part of anyone else’s AI answer.
In LEXA, you decide what happens to your documents.
Document upload and sensitive-data filtering:
Why does this matter in legal work?
During contract analysis, the client’s name, identification numbers and other personal data may appear in the document. Sensitive-data filtering allows the legal analysis to be carried out without unnecessary processing of these data, in line with professional confidentiality obligations.
Your data is stored encrypted and protected by infrastructure systems that meet strict international standards.
Our database infrastructure is provided by Neon, a cloud provider designed specifically for security and compliance. Neon holds the following independent, third-party audited certifications:
These certifications are verified by independent auditors — it is not enough to claim security; it must be proven. We chose Neon as an infrastructure partner because the security guarantees it provides meet the expectations of the legal profession.
Encryption:
| Aspect | LEXA | ChatGPT (consumer) | Claude (consumer) |
|---|---|---|---|
| Zero Data Retention (AI side) | ✅ Yes | ❌ Not by default | ❌ Not by default |
| Use of data for model training | ✅ Excluded (ZDR) | ⚠️ Yes by default | ⚠️ Yes by default |
| EU data processing | ✅ Yes | ⚠️ Partial (US infrastructure) | ⚠️ Partial (US infrastructure) |
| GDPR-compliant | ✅ Yes | ⚠️ Partial | ⚠️ Partial |
| Optimized for national law | ✅ Yes | ❌ No | ❌ No |
| Sensitive-data filtering from documents | ✅ Yes | ❌ No | ❌ No |
| Document deletion option | ✅ Yes | ⚠️ Limited | ⚠️ Limited |
Because of the nature of the legal profession, professional secrecy and the protection of client data are fundamental obligations. National confidentiality rules for attorneys, as well as general GDPR requirements, mean that every data processing decision carries legal responsibility.
LEXA was designed with this in mind:
LEXA does not merely comply with data protection requirements — we built these principles into the architecture of the system, so you can focus on legal work instead of data protection risks.