More than an assistant.A compliance platform.
Source-cited answers from your documents, Agent Mode for complex workflows, and a multi-user workspace for your team. Safety by design, EU hosting*.
Answers
With source
Hosting
EU*
Transport
HTTPS/TLS
Multi-user
Available
2-minute setup · No credit card · EU hosting*
Not another chatbot.
A system designed for compliance.
Generic language models are powerful, but they don't know anything about your company. Normax is a purpose-built application layer on top of them: semantic indexing of your documents, grounded retrieval, multi-step planning, verified citations, per-user permissions. Everything orchestrated to never answer with something that isn't in your files.
| — | Generic assistants | Normax |
|---|---|---|
| Source of answers | Pre-trained knowledge—can fabricate. | Only your documents, with the paragraph cited. |
| Operations | Answers one question at a time. | Agent Mode: plans, searches, synthesises, verifies. |
| Collaboration | One person, one chat. | Multi-user workspace with roles and history. |
| Data & training | Often used to train the model. | Your documents stay yours. No third-party training. |
| Hosting & compliance | Distributed servers, variable residency. | EU* data services, GDPR-aligned. |
| Verifiability | Hard to trace where the answer came from. | Every claim points to a file and a section. |
Built on solid foundations.
Not marketing claims.
Document-grounded answers
Semantic indexing, retrieval tuned for compliance, exact paragraph citation. If the answer is not in your files, Normax says so.
Agent Mode
For multi-step tasks: plans a sequence, crosses multiple documents, cross-references sources and returns structured output—not a single wall of text.
Multi-user workspace
Multiple people on the same workspace: roles, per-folder permissions, shared query history, audit log. Ready for a team, not a single user.
Safety by design
EU* hosting for data services, HTTPS/TLS in transit, encryption at rest managed by the platform, per-tenant isolation, no training on customer content.
Every answer
has a source.
The heart of Normax is a retrieval system built around Italian and European compliance. We index your documents, search the relevant passages and only generate answers we can cite. No bluffing, no inferences outside your files.
Exact citation
Every answer exposes the file, section and paragraph it comes from. One click to verify.
No out-of-context answers
If the information is not in your documents, Normax flags it instead of inventing.
Semantic indexing
Search by meaning, not just keywords. "Inactive customer data handling" finds "data retention" too.
Optional regulatory updates
Turn on web search and Normax integrates the latest public sources—always labelled as external.
💬 You: How long can we keep CRMaccess logs?🤖 Normax: Your Privacy Policy (§4.5)states 24 months for application logs.The Italian DPA 2008 ruling recommendsa maximum of 6 months for systemadministrator access logs.⚠️ Misalignment detected.Suggestion: split the two policies.📄 Sources:Privacy_Policy_v3.pdf §4.5Records_of_Processing.docx §SysAdmin
100%
of answers include a source
5+
document formats supported
0
answers without document grounding
Not a chat.
An operational agent.
For complex requests—the ones that require reading multiple documents, cross-referencing information and checking misalignments—Normax switches to Agent Mode. It plans a sequence of steps, walks through your document corpus, cross-references sources and returns a structured operational output.
What a compliance agent does
Plans
Breaks the request into steps: which documents to read, in which order, which comparisons to run.
Searches
Explores your workspace and retrieves only the relevant passages, not entire files.
Synthesises
Composes a structured answer: thesis, evidence, recommended actions, references.
Verifies
Cross-checks coherence between documents and surfaces weak spots before auditors do.
Always under your control
Scoped access
The agent only reads documents and folders you explicitly enable.
No external actions by default
It does not send emails, mutate files or sign anything. It proposes, you approve.
Full history
Every plan, step and source is logged for internal audit.
Stop at any time
Cancel a task with a click. No hidden background runs.
Compliance
the team actually uses.
Compliance is never a one-person job: HR, legal, IT, tax, leadership, external consultants. Normax is designed to sit at the centre of the team: shared workspaces, roles, per-folder permissions, shared history and built-in audit log.
Roles that match real work
Owner
EverythingFull control over the organisation, billing and permissions.
Admin
ManageManages documents, invitations, folders and workspace configuration.
Member
OperationalQueries allowed documents, exports history, shares answers.
Guest
LimitedLimited access for external consultants: time-bound, scoped, restricted.
Granular per-folder permissions
HR sees HR only, legal sees legal only. No shadow IT, no internal leaks.
Per-person history
See who asked what and when. Useful for internal audit and onboarding.
Shareable answers
Pin an important answer to make it visible to the rest of the team.
Revocable invitations
Revoke an invite in one click. History stays, access goes.
SSO and provisioning
SSO and user provisioning on Enterprise plans.
Full audit log
Access, upload, query and edit events—exportable for compliance officers.
Safety isn't
a feature. It's the foundation.
When a platform reads your contracts, GDPR policies, articles of association and employment agreements, the required level of trust is maximum. Normax is built so you don't have to trust us on our word: principles here, details in the Terms and DPA.
Per-tenant isolation
Each organisation lives in a separate logical space. No cross-contamination between customers.
Your data stays yours
Customer content is not used to train general-purpose models. Everything stays inside your workspace.
EU* data hosting
Documents and application data are hosted on European services. Full provider and location details in the Terms.
Encrypted in transit and at rest
HTTPS/TLS on communications; encryption at rest managed by the underlying cloud platform.
Firebase auth + revocable tokens
Authenticated access via Firebase ID tokens. Centralised revocation; expired session means no access.
Structural anti-hallucination
The architecture forces citation: no source found, no fabricated answer. A design constraint, not a disclaimer.
GDPR alignment
Clear privacy roles (Controller/Processor), DPA available, sub-processors listed.
Model transparency
We disclose which AI providers we use and how we handle document extracts. No magic, no vague promises.
How your data moves
From browser to answer—no opaque steps.
Authenticated upload
The document leaves your browser over HTTPS toward EU* Firebase Storage.
Server-side indexing
The file is processed in an isolated environment to extract relevant passages.
Retrieval query
When you ask, we retrieve only the useful fragments—not the whole corpus.
Cited generation
The AI provider receives only the needed passages and returns the answer with its source.
Answer to your browser
The response returns over HTTPS, with clickable references to the original document.
Not just headlines.
The whole product.
The complete list of what Normax already does or is about to. Transparent, no invented claims. Items marked "Rolling out" are arriving on the plans where they're scheduled.
Multi-format
PDF, DOCX, TXT, RTF, Markdown—uploaded and indexed automatically.
Folders and sub-folders
Organise documents like in Drive. Per-folder permissions.
Built-in preview
Open the cited file directly in the chat, jump to the paragraph.
Always-cited source
File, section and paragraph for every claim.
Operational answer style
Answers with thesis, evidence and actions—not only descriptive text.
Automatic disclaimer
If the internal source is missing, Normax flags it instead of inventing.
Multi-step planning
For complex requests, the agent designs the analysis sequence.
Cross-document analysis
Crosses clauses, registers and procedures to find misalignments.
Structured output
Returns tables, checklists and drafts—not only prose.
Multi-user workspace
Multiple users, roles and permissions on the same workspace.
Audit log
Access, upload and query events—exportable for compliance officers.
Pinned answers
Pin an important answer to make it part of the shared knowledge.
EU* hosting
Data services hosted on European providers. Details in the Terms.
HTTPS/TLS end-to-end
All traffic between browser, backend and providers is encrypted.
No training on customer content
Your documents don't end up in external training datasets.
Optional regulatory updates
Enable web search to integrate up-to-date public sources.
External source labelling
External sources are always distinct from internal ones.
History export
Export questions and answers for audit, training and onboarding.
Everything
you want to know.
No. Normax is a purpose-built application platform for Italian and European compliance. The language model is just one component: the architecture around it (indexing, grounded retrieval, exact citation, Agent Mode, tenant management) is specifically designed to prevent fabricated answers and to work on your real documents.
Agent Mode is what Normax uses for complex requests where it has to cross multiple documents, cross-reference information and produce structured output. The agent plans a sequence of steps, retrieves relevant paragraphs, synthesises an operational answer and flags misalignments. Everything stays under your control: scoped access, no automatic external actions, full history.
Yes. Normax is designed as a multi-user workspace: roles (Owner, Admin, Member, Guest), per-folder permissions, shared history, audit log. It is built to sit at the centre of cross-functional teams—HR, legal, IT, tax, leadership—without exposing documents to people who shouldn't see them.
No. Customer content is not used to train general-purpose models. Full details on data processing, sub-processors and data flows are in the Terms of Service, DPA and Privacy Policy.
Normax data services are hosted on EU infrastructure (Firebase Storage and Google Cloud, European regions). Communications use HTTPS/TLS; data at rest benefits from the underlying cloud platform's encryption. Full provider and location details are in the Terms and DPA.
Normax says so. It's a design constraint: the system is built not to answer when it can't find a source. No hallucinations, no claims without document backing.
Yes. By enabling web search in chat, Normax can pull regulator decisions, circulars and recent legislative updates. External sources are always labelled as such and kept distinct from internal documents.
A general assistant answers from its pre-trained knowledge and may fabricate. Normax only answers from your documents, cites the exact paragraph, crosses multiple files in Agent Mode, handles multi-user roles and permissions, runs on EU* hosting and doesn't use your content to train general models.
2 minutes: create the account, upload your first documents, ask your first question. No technical setup, no API, no IT consultant required.
Clear, agentic,
multi-user compliance.
Start with the documents you already have. Normax reads, indexes, answers with the source and—when needed—plans the steps for you.
2-minute setup · No credit card · EU hosting*