Subsum•ioLEGAL INTELLIGENCE
ProductFeaturesSecurityPricingCompare
EN
Security & data protection

Your data is the product's value.
So it stays under your control.

Subsumio is built for professions where confidentiality is law, not preference: law firms in the DACH region. Here is the architecture — and an honest list of what's still in progress.

Self-hosting, fully

The complete engine runs on your hardware — the full product, nothing held back. Client data never reaches a third party at all, and your IT controls every system that touches your files.

Isolation, fuzz-tested

Per-user and per-source scoped access is enforced on every read path and fuzz-tested for zero cross-tenant leaks. A user sees their scope — never another's.

No training on your data

Your content never trains our or anyone else's models. Synthesis calls go to the LLM provider you configure; self-hosted setups choose their own endpoints or gateways.

Auditable by design

Deterministic citations on every answer, request logging, and a trust boundary that treats every remote caller as untrusted by default — verify exactly where each claim comes from.

Two ways to run it

Both keep you in control. Pick by your compliance posture.

Self-hosted / on-premise (Enterprise)

  • Your hardware, your jurisdiction, your keys
  • No third party processes client data — relevant for statutory professional secrecy
  • The complete engine, auditable, on your infrastructure
  • You manage updates and backups

Managed EU cloud (Pro/Team/Enterprise)

  • EU hosting with a data processing agreement (DPA, Art. 28 GDPR)
  • Contractual confidentiality commitment available for professional-secrecy holders
  • Encryption in transit and at rest
  • Deletion requests handled in one place

What we have today

GDPR-aligned processing

DPA for hosted plans, EU data location, documented subprocessors, deletion on request. Self-hosted deployments process nothing on our side at all.

Professional secrecy (§ 203 StGB, § 43e BRAO)

Self-hosting means no third party is involved — the cleanest answer to professional-secrecy rules for lawyers. Hosted plans add a contractual confidentiality commitment on top of the DPA, covering involved parties under § 43e BRAO / § 203 (4) StGB.

Built-in anonymization before the cloud

A one-click tool redacts client names, IBANs, case numbers and contact data from any text before it is shared or sent to a cloud LLM — with a re-identification map only the authorized holder keeps. Pattern-based offline; name detection adds an optional LLM layer.

Tested isolation

Multi-tenant scoping is enforced in the engine and pinned by fuzz tests across every read path — not a dashboard checkbox.

EU AI Act — where we stand

The AI Act's transparency duties (Art. 50) and most high-risk obligations apply from 2 August 2026. Our honest position before that date:

AI output is labelled (Art. 50)

Every AI-generated draft and answer is marked as AI-generated — visibly in the app and as a machine-readable marker on the API response and on saved documents. A human signs off; the machine never poses as the author.

Human oversight, always

Subsumio drafts and suggests; it never files, books, or sends on its own. A qualified professional reviews and approves every output — the human-in-the-loop the Act requires for high-risk use.

Risk classification, documented

We assess each feature against Annex III instead of assuming. Lawyer-facing assistance is generally not high-risk on its own; where a feature touches deadlines or legal consequences, we document the classification and keep the audit log.

What we don't have yet — honestly

We'd rather tell you here than have you find out in procurement. In progress, in order:

SOC 2 / ISO 27001 certification — not yet held; audit roadmap planned alongside enterprise rollout. Self-hosting sidesteps the question for many buyers.
SSO/SAML for hosted team plans (self-hosted deployments can front the engine with their own auth today).
Source-system permission inheritance for connector-synced content in shared brains — until it lands, we document connectors for single-user brains.

Security questions, answered plainly

Where exactly does my data live?

Self-hosted: on your machines, full stop. Hosted: in EU data centers, with the location named in your DPA. Synthesis requests go to the LLM provider configured for your plan — enterprise setups can route through EU endpoints or their own gateway.

Can Subsumio employees read my brain?

Self-hosted: no, structurally — we have no access path. Hosted: access is restricted to break-glass operational procedures, logged, and covered by the DPA and confidentiality commitment. We don't browse customer content, and your content never trains models.

What happens to my data if I leave?

Export everything at any time (the engine's export is a first-class command, not a support ticket). Hosted data is deleted on contract end per the DPA. Self-hosted: it was never with us.

Is self-hosting less secure than your cloud?

It's the same engine. Security-relevant behavior — scoping, trust boundaries, isolation — is identical and test-pinned. The difference is who operates it: you, instead of us.

Responsible disclosure

Found a vulnerability? Email security@subsum.eu. We confirm receipt within 48 hours, keep you updated, and credit researchers who wish to be named. Please don't test against systems holding real customer data — self-host a copy on your own hardware instead.

Bring your data protection officer.

We speak their language. Hosted with a DPA, or self-hosted so the question never arises.

Subsum•ioLEGAL INTELLIGENCE

The memory layer for your law firm — built for AT, DE and CH.

Your data, your keys — self-hosted on your hardware or our EU cloud. Built for confidentiality-first work.

Product

  • Features
  • Pricing
  • Compare us honestly
  • Dashboard
  • Download the app
  • Docs

Subsumio

  • Product overview
  • WhatsApp copilot
  • Security

Grow with us

  • Partner program
  • Refer a customer — earn 30%

Legal

  • Terms of service
  • Privacy
  • Imprint

© 2026 Subsumio · Legal intelligence for law firms

EU-hosted or self-hosted · GDPR-ready · confidentiality-first

Subsumio — GDPR-compliant legal software security — Subsumio