Skip to content
AINew: 5-layer quality architecture for cited answers
Subsum•ioLEGAL INTELLIGENCE
Pricing
Subsum•ioLEGAL INTELLIGENCE

AI legal software that never forgets — the firm brain for lawyers in Europe.

Your data, your keys. Self-hosted on your hardware or our EU cloud with DPA — GDPR-ready, end-to-end encrypted, zero training on your data.

Platform

  • Overview
  • SuperBrain
  • Features
  • Security
  • WhatsApp Copilot
  • Pricing
  • Download

Solutions

  • For Individuals
  • For Legal Professionals
  • For Law Firms
  • For Solo Lawyers
  • For In-House
  • For Mid-Sized Firms
  • For Tax Advisors

Resources

  • Documentation
  • Blog
  • Benchmark
  • Partner Program
  • Dashboard

Company

  • About
  • Contact
  • Imprint

Legal

  • Terms of service
  • Privacy

© 2026 Subsumio · AI legal software & legal intelligence for law firms

EU cloud or self-hosted · GDPR-ready · AVV included · § 203 StGB compliant

Security & data protection

Your data is the product's value.
So it stays under your control.

Subsumio is built for professions where confidentiality is law, not preference: law firms in the DACH region. Here is the architecture — and what enterprise customers use today.

Self-hosting, fully

The complete engine runs on your hardware — the full product, nothing held back. Client data never reaches a third party at all, and your IT controls every system that touches your files.

Isolation, fuzz-tested

Per-user and per-source scoped access is enforced on every read path and fuzz-tested for zero cross-tenant leaks. A user sees their scope — never another's.

No training on your data

Your content never trains our or anyone else's models. Synthesis calls go to the LLM provider you configure; self-hosted setups choose their own endpoints or gateways.

Auditable by design

Deterministic citations on every answer, request logging, and a trust boundary that treats every remote caller as untrusted by default — verify exactly where each claim comes from.

Two ways to run it

Both keep you in control. Pick by your compliance posture.

Self-hosted / on-premise (Enterprise)

  • Your hardware, your jurisdiction, your keys
  • No third party processes client data — relevant for statutory professional secrecy
  • The complete engine, auditable, on your infrastructure
  • You manage updates and backups

Managed EU cloud (Pro/Team/Enterprise)

  • EU hosting with a data processing agreement (DPA, Art. 28 GDPR)
  • Contractual confidentiality commitment available for professional-secrecy holders
  • Encryption in transit and at rest
  • Deletion requests handled in one place

What we have today

DPA for hosted plans, EU data location, documented subprocessors, deletion on request. Self-hosted deployments process nothing on our side at all.

Self-hosting means no third party is involved — the cleanest answer to professional-secrecy rules for lawyers in DE (§ 203 StGB, § 43e BRAO), AT (§ 9 RAO) and CH (Art. 321 StGB). Hosted plans add a contractual confidentiality commitment on top of the DPA, covering involved parties under § 43e BRAO / § 203 (4) StGB (DE) and equivalent provisions in AT/CH.

A one-click tool redacts client names, IBANs, case numbers and contact data from any text before it is shared or sent to a cloud LLM — with a re-identification map only the authorized holder keeps. Pattern-based offline; name detection adds an optional LLM layer.

Multi-tenant scoping is enforced in the engine and pinned by fuzz tests across every read path — not a dashboard checkbox.

GDPR / DPA

EU data location & DPA

Professional secrecy

§ 203 StGB / § 9 RAO / Art. 321 StGB

EU AI Act

Art. 50 compliance

ISO 27001

Audit roadmap

EU AI Act — where we stand

The AI Act's transparency duties (Art. 50) and most high-risk obligations apply from 2 August 2026. Our honest position before that date:

AI output is labelled (Art. 50)

Every AI-generated draft and answer is marked as AI-generated — visibly in the app and as a machine-readable marker on the API response and on saved documents. A human signs off; the machine never poses as the author.

Human oversight, always

Subsumio drafts and suggests; it never files, books, or sends on its own. A qualified professional reviews and approves every output — the human-in-the-loop the Act requires for high-risk use.

Risk classification, documented

We assess each feature against Annex III instead of assuming. Lawyer-facing assistance is generally not high-risk on its own; where a feature touches deadlines or legal consequences, we document the classification and keep the audit log.

Enterprise-ready — today and tomorrow

Subsumio is built from the ground up for firms with the highest security demands. What's live today and what's coming next:

Self-hosting as a direct compliance pathThe complete engine runs on your hardware — no third party, no certification required. For many procurement processes, this is the fastest route to approval.
SSO/SAML via WorkOSSingle Sign-On via SAML 2.0 is integrated for hosted team plans — enterprise customers authenticate through their own identity provider. Self-hosted deployments front the engine with their own auth.
SCIM 2.0 + Ethics WallsAutomated user provisioning via SCIM 2.0 and ethical walls for matter isolation are implemented — not roadmap, but live today.
Audit roadmap for SOC 2 / ISO 27001The engine architecture meets the technical controls (access control, audit logging, encryption at rest, isolation). Formal certification is running alongside the enterprise rollout — self-hosting makes it moot for many buyers.

Security questions, answered plainly

Self-hosted: on your machines, full stop. Hosted: in EU data centers, with the location named in your DPA. Synthesis requests go to the LLM provider configured for your plan — enterprise setups can route through EU endpoints or their own gateway.

Self-hosted: no, structurally — we have no access path. Hosted: access is restricted to break-glass operational procedures, logged, and covered by the DPA and confidentiality commitment. We don't browse customer content, and your content never trains models.

Export everything at any time (the engine's export is a first-class command, not a support ticket). Hosted data is deleted on contract end per the DPA. Self-hosted: it was never with us.

It's the same engine. Security-relevant behavior — scoping, trust boundaries, isolation — is identical and test-pinned. The difference is who operates it: you, instead of us.

WhatsApp is an optional convenience channel, not a core component. The Copilot uses the Meta Business API with a Data Processing Agreement (DPA). For the most sensitive matter content, we recommend the native mobile app or self-hosting. The Copilot is built so every action requires confirmation — nothing reaches the matter unseen. Firms that choose not to use WhatsApp lose no core functionality.

Responsible disclosure

Found a vulnerability? Email security@subsum.eu. We confirm receipt within 48 hours, keep you updated, and credit researchers who wish to be named. Please don't test against systems holding real customer data — self-host a copy on your own hardware instead.

Bring your data protection officer.

We speak their language. Hosted with a DPA, or self-hosted so the question never arises.

Subsumio Security — GDPR-compliant AI for law firms — Subsumio