Moonlit logo
Gov Legal · Legal Assistants

Moonlit

Moonlit is a legal data layer that aggregates legislation, case law and regulator output from official sources across European jurisdictions, then serves it through a research platform, a Data API and an MCP server with traceable citations.

Active GDPR compliant Free plan Freemium API available 16+ Verified by Guidaio
Overview

What is Moonlit?

Moonlit is a legal data layer built and operated by Moonlit Legal Technologies B.V., a Dutch company based in Amsterdam. Its work is unglamorous and specific: take the raw publications that courts, legislatures, parliaments, regulators and public authorities issue across many jurisdictions, normalise them into one queryable schema, enrich them, and refresh the whole thing every day.

The result is described by the editor as four stacked layers. Jurisdictions give coverage. Sources give depth, spanning courts, legislative and parliamentary material, policy, regulators and authorities. Enrichments give quality, and come from three places at once: in-house review by legal experts, validated user contributions, and automated extraction by agents. Citations give the knowledge graph, linking every document to what it cites and what cites it. Beneath all of it sits a search layer offering keyword, semantic, hybrid, reranked, reference, party and document-retrieval modes.

The same layer is reachable three ways. The platform is the web application, where Luna, the built-in assistant, answers research questions with inline citations, and where monitors, workspaces and alerts live. The Data API exposes six search endpoints, five hierarchical filter endpoints and full document retrieval to anyone integrating the corpus into their own backend or retrieval pipeline. The MCP server puts the same corpus inside Claude, Microsoft Copilot, ChatGPT or any other MCP-compatible client, so a practitioner never leaves the assistant they already use. A separate product, Horizon Scanning, tracks regulatory mandates across more than 190 jurisdictions with a plain-language timeline.

The editor claims more than 100 million references and 19 million documents, and names thirty European jurisdictions in the layer, of which six — the Netherlands, Germany, Belgium, France, Italy and Spain — are at full coverage. Its central argument is traceability: every reference resolves to the official text at document level rather than being generated. Security is certified to ISO/IEC 27001:2022 and the service is hosted on Azure in the EU. The interface is English only, and there is no mobile application.

What it does

  • Search legislation, case law and regulator output across jurisdictions from a single interface
  • Trace a document's citation graph in both directions, down to article level, in one call
  • Ask Luna, the built-in assistant, and get answers carrying inline links to the official text
  • Plug the MCP server into Claude, Microsoft Copilot or ChatGPT and query the corpus from there
  • Embed the same data layer into your own product through the Data API
  • Monitor legal and regulatory change and receive alerts as it happens
  • Organise research in shared workspaces and export findings to Excel or Word
Audience

When to use Moonlit / When not to

A quick filter to help you decide if Moonlit is the right fit.

When to use Moonlit

  • In-house legal teams that research the same question across several European jurisdictions and need every answer tied back to an official text
  • Legal-AI vendors and product builders who want a ready European corpus behind their own application instead of scraping and normalising official sources themselves
  • Compliance, regulatory affairs and tax specialists tracking mandates as they change, using automated alerts and a timeline of what is coming next
  • Law firms and practitioners who already work inside Claude, Microsoft Copilot or ChatGPT and want sourced legal answers without opening another tool
  • Universities, researchers and public institutions: the editor names the Hoge Raad, De Nederlandsche Bank, Deloitte and KPMG among its users, and runs a seven-euro academic plan

When not to use Moonlit

  • Anyone expecting legal advice: Moonlit returns primary sources and citations, it does not give an opinion on a case
  • Practitioners working mainly outside the six fully covered countries, since smaller jurisdictions carry primary legislation and key regulator sources only, with case law still being backfilled
  • Teams that need the interface in their own language: the site and product are English only, with no other locale served
  • Users who work from a phone, as there is no iOS or Android application of any kind
  • Buyers who want to self-serve the Data API and read a published price list before talking to anyone: access is set up by the vendor and billed on usage
Get started

How to use Moonlit

A typical end-to-end flow, from setup to results.

  1. Decide which of the three access modes fits: the platform for research by hand, the MCP server for work inside an AI assistant, the Data API for embedding the corpus in your own product
  2. Create an account on app.moonlit.ai and start on the free Basic plan, which needs no setup and no code
  3. Search the corpus by keyword, semantics or reference, and filter by jurisdiction, document type, field of law or source
  4. Open a document, read its metadata and in-force status, then follow the citation graph forward and backward to article level
  5. Ask Luna a research question and check each inline citation against the official text it links to
  6. Set up monitors and alerts on the topics and jurisdictions you need to follow
  7. Group your sources into workspaces to share them with the team, and export results to Excel or Word
  8. To use the MCP server, add it from app.moonlit.ai, then sign in with your existing Moonlit account through the OAuth flow; organisations can instead authenticate services with MCP keys
  9. To use the Data API, request access from the documentation, then authenticate with the subscription-key header against the versioned base endpoint
  10. Follow the quickstart, then the reference generated from the live OpenAPI specification, and use the Academy material for guided workflows
Quick read

Pros & Cons

Pros

  • Every citation resolves to the official source at document level, which is the whole point of the product and its main defence against fabricated references
  • One data layer reachable three ways — platform, Data API and MCP server — under a single key
  • ISO/IEC 27001:2022 certification is nominative and checkable: certificate number, certification body and validity dates are published
  • A full Data Processing Agreement and a dated subprocessor list are public, with the region named for each provider and thirty days' notice on any change
  • The vendor states plainly that it does not train models on customer queries or tool-call content, and its generative-AI subprocessor operates with zero retention
  • The service and its logs are hosted on Azure in the EU, which independent DNS checks corroborate
  • Permanent free plans on both the platform and the MCP server, plus a seven-euro monthly academic plan open on a university email address

Cons

  • Coverage is very uneven: only six of the thirty European jurisdictions are at full depth, the rest carrying primary legislation and key regulator sources while case law is still being backfilled
  • The coverage figures move from page to page, between thirty, thirty-plus, thirty-seven-plus and one hundred and ninety-plus, which makes the real scope hard to pin down
  • Pricing is split across three separate pages, and the same thirty-nine euro figure is labelled per month in one place and per user per month in another
  • Neither the platform's Enterprise tier nor Horizon Scanning carries a public price, and the Data API is usage-based with no published rate card
  • The Data API is not self-service: access is arranged by the vendor's team rather than opened on sign-up
  • The interface is English only, with no other language served, and there is no mobile application
  • The Connect page claims no US subprocessors while the official list names an American identity provider, and the contact page offers no email address at all
Pricing

Pricing & Plans

There is a permanent free plan, and in fact two: the platform's Basic tier at zero euros per month, and an MCP tier at zero euros per month allowing one hundred calls. The lowest paid entry point available without an eligibility condition is 39.00 EUR per month, excluding VAT, for MCP Basic with five hundred calls per month; the same page shows 47.19 EUR including the twenty-one percent Dutch rate. On the platform side the first paid tier is Premium at 150 EUR per month, and Enterprise is quoted individually. A restricted plan sits below all of these at 7 EUR per month, reserved for holders of a student or university email address. The Data API is billed on usage, with volume buckets and bespoke contracts, and carries no public rate. Amounts shown for MCP are the monthly view; the annual view is stated to save around fifteen percent. No free trial is offered anywhere on the site.

Plan 1
  • Basic — 0 EUR per month — access to the full legal database
  • continuously updated global sources
  • basic search and navigation
  • unlimited browsing
Plan 3
  • Enterprise — custom pricing — everything in Premium plus team workspaces and shared monitoring
  • SSO and user management
  • admin dashboard and insights
  • priority support and onboarding
Plan 4
  • Moonlit Academic Program — 7 EUR per month — premium access to the European legal corpus
  • open to student or university email addresses only
Plan 5
  • MCP Free — 0 EUR per month — one hundred calls per month
  • described as free forever
Plan 6
  • MCP Basic — 39.00 EUR per month excluding VAT
  • 47.19 EUR including VAT — five hundred calls per month
Plan 7
  • MCP Pro — 79.00 EUR per month excluding VAT
  • 95.59 EUR including VAT — one thousand two hundred calls per month
Plan 8
  • Moonlit Connect · Data API — usage-based — production access within a day
  • six search endpoints on one schema
  • pay per call with volume buckets available
Special offers — Moonlit Academic Program: 7 EUR per month for premium access to the European legal corpus, with no promotional code required — registration with a student or university email address is enough · Annual billing on the MCP plans is stated to save around fifteen percent against the monthly price · Two permanent free plans rather than a trial: Basic on the platform, and a free MCP tier allowing one hundred calls per month
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Moonlit handles your data.

GDPR overview

Implementation is concrete and documented rather than merely claimed. The editor states it is GDPR compliant and EU-hosted on Azure, and backs this with a full Data Processing Agreement covering Article 28 obligations, plus a dated public list of subprocessors with the region named for each and thirty days' notice before any change. Transfers are papered: Standard Contractual Clauses for turbopuffer, whose parent sits in Canada while the data stays in Frankfurt, and the EU-U.S. Data Privacy Framework for Clerk. Query, retrieval and generative-AI processing are declared to take place inside the EEA. No Article 27 representative is named, and none is required since the company is established in the Netherlands; no data protection officer is named either. One inconsistency deserves attention: the Connect page claims no US subprocessors, while the official list names one.

Who owns the data?

The published Data Processing Agreement makes Moonlit a processor and the customer the controller: Moonlit processes personal data only on the customer's documented instructions, and must flag any instruction it believes breaches data protection law. The customer keeps its own data, and Moonlit undertakes to delete or return it within thirty days of termination. Two boundaries matter. First, the legal corpus itself is public material that Moonlit maintains independently of any customer relationship, so it is not deleted when a contract ends. Second, the platform is licensed per user: under the terms of use a subscription may be used by one named person only.

Reuse rights

The terms of use license the platform on a per-user basis and forbid the customer from modifying, translating, reproducing, decompiling or reverse engineering it, or creating derivative works from it, except where mandatory law allows. The underlying material is public legal information taken from official publications, and the whole promise of the product is that every passage links back to its official source, so the source text can be consulted and cited directly. What the customer may not do is treat the structured layer, the enrichments and the citation graph as its own to redistribute: those are Moonlit's product, not open output. On the vendor's side the position is narrow and stated plainly. Query content is stripped from operational logs, only aggregated usage counts are kept, and neither Moonlit nor its generative-AI subprocessor uses queries or tool-call content to train models.

Data retention & training

Retention summary
Moonlit keeps very little of what passes through the service. The content of MCP queries and the documents returned are not stored beyond operational caching, and query content is stripped from operational logs, leaving only aggregated usage counts. Logs are kept on a published schedule: general operational logs for at least thirty days, system access logs for up to one hundred and eighty days, and user access logs for up to three hundred and sixty-five days. When a contract ends, Moonlit undertakes to delete or return customer data within thirty days and to confirm deletion in writing on request, with the log schedule as the only carve-out. The generative-AI subprocessor operates on a zero-retention basis. The legal corpus itself is public material maintained independently of any customer, so it is not deleted when a contract ends.
Trains on customer data
No
Subprocessors disclosed
Yes
DPA available
Yes
GDPR contact

Hosting summary

The service runs in the European Union. Moonlit states that the MCP server, its database and its operational logs are hosted on Microsoft Azure in EU regions, currently West Europe in the Netherlands, and that it does not route MCP tool calls or their responses outside the EU. Full-text search is operated by Elasticsearch B.V., a Dutch entity, in the same Azure region. Vector and full-text search over the corpus runs on turbopuffer in AWS eu-central-1 in Frankfurt; the provider is headquartered in Ottawa, and Standard Contractual Clauses plus the UK addendum cover the engagement. Query embeddings and reranking go through Google Vertex AI in europe-west4 in the Netherlands, on a zero-retention basis and with no customer identifiers transmitted. The one non-EU element is authentication: Clerk, Inc. in the United States, certified under the EU-U.S. Data Privacy Framework. Independent DNS checks corroborate the Azure picture. The marketing site itself is served from a content delivery network and says nothing about where the platform runs.

Hosting countries
🇳🇱 Netherlands🇩🇩 Germany🇺🇸 United States
Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Moonlit.

  • The vendor contradicts itself on subprocessors: the Connect page promises EU-only infrastructure with no US subprocessors, while the official list names an American identity provider operating under the EU-U.S. Data Privacy Framework. Read the list, not the sales page
  • Jurisdiction counts differ from page to page — thirty, thirty-plus, thirty-seven-plus, forty-six in a demo panel, one hundred and ninety-plus for Horizon Scanning. Confirm the depth of the specific jurisdiction you need before committing
  • Pricing lives on three separate pages and the same thirty-nine euro figure is billed per month in one place and per user per month in another. The published amounts are exclusive of VAT and shown in the monthly view
  • The cheapest advertised plan, at seven euros, is restricted to student and university email addresses; treating it as the general entry price would understate the real cost by a wide margin
  • Traceable citations reduce fabrication risk but do not remove professional judgement. An assistant that always cites can still cite something irrelevant, superseded or read out of context, and the responsibility for checking remains with the practitioner
  • The privacy policy covering the website and the one covering the MCP service are two different documents with different scopes, and the stated minimum age of sixteen appears only in the second
  • The company behind the product was registered in April 2024 while the brand has existed online since 2021, and its ownership runs through a holding company and a share administration foundation, with no natural person disclosed in any public register
Setup

Setup & Integrations

Technical difficulty

Low to moderate, depending on the route. The platform needs nothing at all: create an account, start on the free plan, no setup and no code. The MCP server is nearly as light — add it from the web application and sign in with the account you already have, with no new login to create. The Data API is the only route needing engineering work, and even there the burden is modest: request access, authenticate with a subscription-key header, and follow a three-step quickstart with cURL, Python and JavaScript examples generated from the live specification. The vendor advertises production access within a day.

Deployment

Web appAPIPlugin

Integrations

Claude ChatGPT Microsoft Copilot Microsoft Excel Microsoft Word

Supported languages

English
Company

Behind Moonlit

Company name
Moonlit Legal Technologies B.V.
Founded
10/04/2024
Country of origin
🇳🇱 Netherlands
Headquarters
Westeinde 14, 1017 ZP Amsterdam, the Netherlands
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Support contact

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What exactly is Moonlit?
It is a legal data layer. Moonlit aggregates legislation, case law and regulator output from official sources, normalises them into one queryable schema, enriches them and refreshes them daily. The same layer is reachable through a web platform, a Data API and an MCP server.
How many jurisdictions does it actually cover?
Thirty European jurisdictions sit in the data layer, of which six are at full coverage: the Netherlands, Germany, Belgium, France, Italy and Spain. Smaller jurisdictions carry primary legislation and key regulator sources, with case law still being backfilled. The Horizon Scanning product separately tracks mandates across more than 190 jurisdictions. Note that the site quotes several different figures depending on the page.
Is there a free version, and is there a free trial?
There are two permanent free plans: Basic on the platform, and a free MCP tier allowing one hundred calls per month. There is no time-limited free trial mentioned anywhere on the site; the free plans take that role instead.
What does the cheapest paid plan cost?
MCP Basic is 39.00 EUR per month excluding VAT, or 47.19 EUR including the Dutch twenty-one percent rate, for five hundred calls a month. On the platform, Premium is 150 EUR per month. Students and university staff can subscribe at 7 EUR per month using an academic email address.
Is there an API, and how is it accessed?
Yes. The Data API exposes six search endpoints, five filter endpoints and full document retrieval, authenticated with a subscription-key header. An interactive Swagger reference is published and the endpoint documentation is generated from the live OpenAPI specification. Access itself is set up by Moonlit's team rather than opened on sign-up.
Which AI assistants does the MCP server work with?
Claude, Microsoft Copilot, ChatGPT and any other MCP-compatible client. You sign in with an existing Moonlit account, so no separate login is created, and organisations can authenticate services with MCP keys instead.
Where is the data hosted?
The MCP service, its database and its operational logs run on Microsoft Azure in the EU, currently West Europe in the Netherlands. Vector and full-text search runs on AWS in Frankfurt under Standard Contractual Clauses, and embeddings go through Google Vertex AI in the Netherlands with zero retention. Authentication is handled by Clerk in the United States under the EU-U.S. Data Privacy Framework.
Is customer data used to train AI models?
No. Moonlit states that it does not train models on your queries or on your tool-call content, and that no MCP telemetry or OAuth metadata is used for that purpose either. Its generative-AI subprocessor operates on a zero-retention basis and does not use queries for training.
What security certification does Moonlit hold?
ISO/IEC 27001:2022, certificate number 202506-107, issued by AssuranceLab Pty Ltd on 30 June 2025 and valid until 30 June 2028. The scope covers the development, operation and support of the software-as-a-service platform for European legal research. No SOC 2 report is claimed.
Is there a mobile app, and what languages are supported?
There is no iOS or Android application. The interface is English only: no other locale is served by the site, and the minimum age stated for the MCP service is sixteen.
Conclusion

Should you pick Moonlit?

Moonlit is infrastructure before it is a research tool, and is best judged on that basis. What it sells is a normalised, enriched and daily-refreshed corpus of European primary law, delivered three ways — web platform, Data API and MCP server — with the guarantee that every reference resolves to the official text rather than being generated. That promise is supported by unusually solid paperwork: a nominative ISO/IEC 27001:2022 certificate with number, body and validity dates, a full Data Processing Agreement, a dated subprocessor list naming each provider's hosting region, and an explicit undertaking not to train models on customer queries.

The reservations are equally concrete. Coverage is uneven, with only six of thirty European jurisdictions at full depth, and the site quotes several different jurisdiction counts depending on the page. Pricing is scattered across three pages, and the same amount is labelled per month in one place and per user per month in another. The Data API has no public rate card and is not self-service. The interface is English only, there is no mobile application, and the contact page offers no email address. One claim contradicts the vendor's own documentation: the Connect page states there are no US subprocessors while the official list names an American identity provider.

A note on age. The operating company was entered in the Dutch commercial register on 10 April 2024, yet the site has been archived under the Moonlit brand since December 2021 — the product predates the legal entity by more than two years, which is worth knowing when weighing the track record.

For a legal team working across the six fully covered countries, or a vendor needing a European corpus quickly, Moonlit is a serious candidate. Outside that perimeter, verify your jurisdiction's depth first.