ICO-LUX logo
Security Fraud · Ocr Doc Parsing

ICO-LUX

German document-forensics software that pairs layout-aware image analysis with a fraud rulebook to flag forged invoices, prescriptions and income statements before insurers, banks or public bodies release a payment or approve a loan.

Active GDPR compliant Contact Sales API available Verified by Guidaio
Overview

What is ICO-LUX?

ICO-LUX is document-forensics software built by ICO-LUX GmbH, a spin-off of Friedrich Schiller University Jena and TU Ilmenau entered in the German commercial register in July 2018 and based in Jena, Thuringia. The company calls itself the German market leader in automated document authenticity checking, and sells three products that stack on one another. ICO.Match is the foundation: an intelligent document processing engine that goes past conventional OCR by reading layout rather than characters alone. It straightens skewed perspectives, removes image noise, rebuilds table structures and text positions, then assigns everything to recurring patterns so a page becomes a contextualised, structured record. It is deliberately ready to run, with no algorithm training required, and is sold either standalone or inside its sibling. ICO.Fraud always embeds ICO.Match, then applies a fraud rulebook to the structured output. It combines machine learning with rule-based reasoning, and the site claims it uses roughly a hundred times more information per document than earlier fraud-detection tools. Beyond layout deviation it adds domain checks: a patient calendar cross-referencing treatment dates against practice opening hours and travel distances, and continuity analysis of a practice's invoice numbering. In keeping with European AI rules, it does not merely mark a document suspicious but shows why, leaving the decision to the fraud team. ICO.Link answers a different problem: insurers and banks cannot lawfully swap customer data in the clear. It applies privacy-preserving record linkage, hashing policyholder details into irreversible fingerprints that are compared on a dedicated server, raising an alert only on serious suspicion. Four sectors are addressed: insurance, banking, public administration and property. Deployment runs on-premise via Docker Compose or OpenShift, on customer-managed Kubernetes in AWS or Azure, or as SaaS. Processing takes place in certified German data centres, and the company has held ISO/IEC 27001 certification since August 2026.

What it does

  • Detect forged and altered supporting documents before a payout is released or a loan is approved
  • Turn poor-quality scans and smartphone photographs into structured, machine-readable data
  • Classify incoming documents automatically into customer-extensible document classes
  • Group an unsorted archive by document author using addresses or IBANs found on the pages
  • Flag the smallest layout deviations against other documents from the same issuer
  • Uncover multiple identities and undeclared parallel policies without exchanging readable data
  • Explain every alert so the final judgement stays with the case handler
Audience

When to use ICO-LUX / When not to

A quick filter to help you decide if ICO-LUX is the right fit.

When to use ICO-LUX

  • Private health insurers screening high volumes of medical bills, prescriptions and practitioner invoices for manipulation
  • Banks and lenders verifying payslips, pension notices and bank statements inside credit and mortgage application flows
  • Liability and household insurers checking submitted invoices and purchase receipts for retrospective alteration
  • Customs authorities, tax offices and social benefit agencies inspecting supporting documents at scale
  • Organisations already handling at least 10,000 documents a day, or holding an archive of a million, where a retrospective sweep pays for itself

When not to use ICO-LUX

  • Consumers and private individuals: the terms exclude any service to consumers under § 13 of the German Civil Code
  • Teams whose documents are handwritten, since the software expects predominantly printed text
  • Anyone working from scans below 150 dpi, which fall outside the stated input requirements
  • Small operations under the on-premise volume threshold of 10,000 documents a day or a million in stock
  • Buyers who need a published price, a self-service sign-up or an immediate trial, as every engagement runs through an individual contract
Get started

How to use ICO-LUX

A typical end-to-end flow, from setup to results.

  1. Book a demonstration through the contact form; there is no self-service sign-up
  2. Agree an individual contract, since prices come from a negotiated agreement rather than a published list
  3. Choose the deployment model: on-premise with Docker Compose or OpenShift, customer-managed Kubernetes on AWS or Azure, or SaaS hosted by the vendor
  4. Size the hardware from the published figures, roughly 10,000 documents per week per CPU core and 200 KB of disk per document
  5. Let ICO-LUX install the system using its parameterised bash scripts, a preconfigured VirtualBox image or a ready-built workstation
  6. Wire up document intake by dropping CSV metadata into a scanned folder, importing Export.xml from an input-management system, or posting JSON to the REST API
  7. Make the page images reachable, either through an HTTP(S) service the software calls on demand or a mounted network share
  8. Run the initial retrospective sweep over the existing archive, typically hundreds of thousands to several million documents across a few weeks
  9. Give the fraud team browser access to the internal frontend, secured by HTTP Basic, a reverse proxy or LDAP against Active Directory
  10. Move into routine operation, adding new documents continuously and taking a software update once or twice a year
Quick read

Pros & Cons

Pros

  • Processing takes place in certified German data centres, and ICO.Match is stated to store neither source documents nor extracted values
  • Every alert is explained, so the case handler keeps the decision rather than inheriting a black-box score
  • No customer-specific training is required: ICO.Match and ICO.Link are presented as ready to run from day one
  • A genuine choice between on-premise, customer-managed cloud and vendor-hosted SaaS, all documented in detail
  • An unusually precise integration page with worked CPU, RAM and disk sizing examples rather than vague requirements
  • GDPR compliance confirmed by independent experts for health data and two ICO.Link lines, and ISO/IEC 27001 held since August 2026
  • A dense reference list across German insurance and banking, from Allianz and AXA to HUK-COBURG, Debeka and DKB

Cons

  • No public pricing whatsoever: no rate card, no free plan and no documented free trial
  • A high entry threshold for on-premise use, at 10,000 documents a day or a million in stock
  • No differentiated permissions inside the application; every frontend user holds the same rights
  • No single sign-on, with SAML, OAuth 2.0 and OpenID Connect available only as a separately commissioned extra
  • API documentation is not published and must be requested from the vendor
  • A contractual availability of 95% on annual average is modest for software delivered as a service
  • The English version of the site is partial, and installation, updates and support all require remote access to the customer's system
Pricing

Pricing & Plans

There is no free plan and no publicly documented free trial, and ICO-LUX publishes no price at all. Under § 6(1) of its terms, prices follow from the individual contract; where no express price has been agreed, § 6(2) applies the rate card in force at signature, which can be requested from the vendor at any time. Effort-based billing is provided for, with day rates counted as eight person-hours and hourly rates charged per started quarter-hour. Prices are quoted net of VAT, cross-border duties and currency costs, and travel, accommodation and disbursements fall to the customer against receipt. Invoices are payable without deduction within two weeks. Readers should note that the single figure quoted anywhere on the site, 8,000 EUR including tax, prices a physical workstation delivered with the software preinstalled and capable of handling 50 million documents a year; it is not a software entry price.

No named commercial tiers are published
  • the three products are contracted individually and priced case by case
Plan 3
  • ICO.Link — cross-company privacy-preserving matching platform
Plan 4
  • ICO.Match — document extraction and classification
  • sold standalone or inside ICO.Fraud
The terms structure engagements by contract type rather than by package
  • standard software supply
  • maintenance and support
  • bespoke development
  • software provision as a service
  • and service or works contracts
Special offers — No discounts, promotions or special pricing schemes are published · A demonstration can be booked free of charge through the contact form · The strategy white paper on fraud detection for banks and financial services, around 50 pages and dated August 2026, is sent free on request · Two integration one-pagers, one for insurers and one for banks, are freely downloadable as PDFs
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how ICO-LUX handles your data.

GDPR overview

GDPR treatment is concrete and detailed. ICO-LUX GmbH is named as controller, with its three managing directors, and the policy enumerates the rights under Articles 15, 16, 17, 18, 20 and 21 plus consent withdrawal, alongside the right to complain to a supervisory authority. An external data protection officer is appointed: Thomas Oettler of ARSI-Q Arbeitssicherheit & Qualität GmbH & Co. KG in Gera, though no email is published for him. Objections under Article 21 go to Jan Franke at the company address. The policy was drafted in part with activeMind AG and last updated on 6 December 2024. On the product side the vendor states its solutions are consistently GDPR-compliant and that independent experts confirmed this for health data and for two ICO.Link insurance lines, though no expert report is published. ISO/IEC 27001 certification was announced on 11 August 2026.

Who owns the data?

Nothing in the terms transfers ownership of customer documents to the vendor. ICO-LUX positions itself as a supplier, and § 24(2) obliges the customer to conclude a data protection agreement on request wherever Article 28 processing or Article 26 joint controllership applies, which places the customer in the controller's seat. Section 43(3) states the vendor is not answerable for content data supplied by or for the customer, and § 12 leaves the customer responsible for the material it provides. Deletion of content data (§ 48) only follows an unheeded formal notice. For ICO.Match the vendor goes further and states it stores neither the documents it reads nor the information it extracts.

Reuse rights

The terms grant the customer usage rights over the software, not a licence over its own data, which it keeps and may reuse freely without asking the vendor. On the vendor's side, use is bounded by purpose: ICO.Match is described as storing neither source documents nor extracted values, while ICO.Fraud persists processing results and reviewer feedback in a PostgreSQL 16 database that sits on the customer's own infrastructure in the on-premise model. ICO.Link never exchanges readable data at all: policyholder records are hashed into irreversible fingerprints before any cross-company comparison. No page anywhere on the site contemplates reusing customer material to train models, and both ICO.Match and ICO.Link are marketed as requiring no customer-specific training. Reference naming of customers is governed separately by § 54.

Data retention & training

Retention summary
On the public website, server log files are deleted after at most 14 days, or the IP addresses in them are anonymised. Contact form data is erased six months after the enquiry has been handled, and quote request forms are cleared once the matter is settled. Job applications are kept up to six months after the process ends, unless a dispute, a consent or a legal duty extends that. Where a contract results, statutory German commercial retention periods apply. On the product side, ICO.Match retains neither the documents it reads nor the values it extracts, while ICO.Fraud persists processing results and reviewer feedback in the customer's database, with daily backup recommended only for the feedback since results can be recomputed. No contractual retention period for customer data is published.
Trains on customer data
No
DPA available
Yes
GDPR contact

Hosting summary

ICO-LUX states that data processing takes place in certified data centres in Germany, and for ICO.Match that it stores neither the documents it reads nor the information it extracts. Three deployment models exist. On-premise, the software runs on the customer's own infrastructure through Docker Compose on Linux or through OpenShift, using a vendor Docker repository and per-customer Helm charts. In the cloud model it runs on Kubernetes inside an AWS or Azure account managed by the insurer or bank itself. Alternatively it is offered as software as a service hosted in data centres commissioned by ICO-LUX; for banks the site indicates SaaS. All processing results are persisted in a PostgreSQL 16 database, with PgBouncer recommended in front of it. The frontend is configured to be reachable only from inside the customer network, over HTTPS with TLS 1.2. Under the terms, services are otherwise performed at the vendor's registered office, with access to customer systems by remote connection. The public website itself is hosted in Germany with Mittwald CM Service GmbH und Co. KG.

Hosting countries
🇩🇩 Germany
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting ICO-LUX.

  • The company contradicts itself on its own founding date: one page says July 2018 while the fifth-anniversary post is pegged to 27 June, the date of the articles of association. The register settles it at 16 July 2018, nineteen days after the deed.
  • The only figure on the site, 8,000 EUR including tax, prices a physical workstation and not a licence. Reading it as an entry price would badly misstate the cost of ownership.
  • ISO/IEC 27001 is announced in a news post naming the certifier, Proks Certification GmbH, but no certificate number or validity period is published and no attestation is available.
  • The logos on the reference page are customers, not technology partners or integrations, and should not be read as an ecosystem.
  • GDPR compliance is described as confirmed by independent experts, yet the expert report itself is not published and no subprocessor list is disclosed.
  • No beneficial owner can be identified anywhere: the German transparency register requires registration and a legitimate interest, and the commercial data aggregator paywalls its shareholder list.
  • Because every frontend user holds identical rights and there is no single sign-on, access governance falls entirely on the customer's reverse proxy or directory, which is easy to under-engineer.
Setup

Setup & Integrations

Technical difficulty

Moderate to high, but well supported. The system is containerised and needs three components — a PostgreSQL 16 database, a frontend server and workers — plus a low-latency gigabit link to the database. Sizing must be calculated: about 10,000 documents per week per CPU core, 2 GB of RAM per core, 200 KB of disk per document. ICO-LUX insists container knowledge is not required and supplies parameterised bash install scripts, a preconfigured VirtualBox image or even a ready-built workstation. Document intake still has to be wired up, and installation, updates and support all require remote access.

Deployment

Web appAPIDesktop app

Integrations

PostgreSQL Docker Kubernetes OpenShift Amazon Web Services Microsoft Azure Active Directory In|sure Health Claims
Company

Behind ICO-LUX

Company name
ICO-LUX GmbH
Founded
16/07/2018
Country of origin
🇩🇩 Germany
Headquarters
Hans-Knöll-Str. 6, 07745 Jena, Germany
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
INFORMATION_NOT_FOUND
Legal contact

Fundraising

Seed round announced on 27 November 2020: High-Tech Gründerfonds (HTGF) invested in ICO-LUX to accelerate growth, professionalise sales and open further markets. The amount was not disclosed, and HTGF investment manager Dominik Lohle was quoted in the announcement.
In its fifth-anniversary post of 27 June 2023 the company names HTGF and VENPACE as its investors.
Share capital has risen from 25,000 EUR at incorporation to 40,738 EUR through three registered increases: 26,389 EUR in July 2020, 31,667 EUR in October 2020, 34,306 EUR in January 2021 and 40,738 EUR in April 2023.

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What does ICO-LUX actually do?
It combines document forensics with artificial intelligence to spot forged or altered supporting documents before an insurer pays out or a bank approves a loan. The software reads the page image itself, not just the text on it.
What are the three products and how do they fit together?
ICO.Match extracts and classifies documents. ICO.Fraud always embeds ICO.Match and adds the fraud rulebook on top. ICO.Link is separate: it matches records across companies using irreversible cryptographic fingerprints instead of readable data.
Who uses it?
Insurers, banks, public authorities and the property sector. The reference page shows customer logos including Allianz, AXA, ARAG, Barmenia, Continentale, Debeka, DKB, HUK-COBURG, Itzehoer, LVM, BBBank, PSD Bank and Wüstenrot Bank.
Can it run on our own infrastructure?
Yes. It deploys on-premise through Docker Compose on Linux or OpenShift, on Kubernetes in an AWS or Azure account the customer manages, or as SaaS hosted in data centres commissioned by ICO-LUX. For banks the site indicates SaaS.
Is there an API?
Yes. New documents can be submitted for processing through a REST API in JSON, and results can be queried in detail through a REST API as well. The documentation is not published on the site and must be requested from ICO-LUX.
Where is our data processed?
In certified data centres in Germany. For ICO.Match the vendor states it stores neither the documents it reads nor the information it extracts. ICO.Fraud persists processing results in a PostgreSQL 16 database, which in the on-premise model sits on your own infrastructure.
Will our documents be used to train models?
The site never contemplates it, and describes both ICO.Match and ICO.Link as requiring no training on customer data. No opt-out mechanism is documented either, because the subject is never raised.
What does it cost?
No price is published. Under the terms, prices come from the individual contract, and the current rate card can be requested from the vendor at any time. There is no free plan and no documented free trial.
What document formats and quality does it need?
JPG, PNG, PDF and TIFF, with PDF and TIFF allowed to be multi-page. Documents must be at least 150 dpi and contain predominantly printed text. Scans and smartphone photographs both work.
Is there a mobile app?
No. The only downloadable application, the ICO.Link app, is a Windows executable distributed to existing customers inside a password-protected ZIP archive. The main interface is a browser frontend reachable only from the customer's internal network.
Conclusion

Should you pick ICO-LUX?

ICO-LUX is a narrow, serious tool aimed at a narrow, serious problem. It is not a general-purpose AI assistant but vertical software sold under contract to regulated enterprises, and it should be judged on that basis. The strengths are real and unusually well documented: processing in certified German data centres, a stated policy of not retaining documents or extracted values in ICO.Match, explainable alerts that leave the decision with the case handler, no requirement to train algorithms on customer data before going live, and an integration page carrying worked CPU, RAM and disk calculations that most vendors would never publish. The reference list across German insurance and banking is dense, the company has been registered since July 2018, is backed by High-Tech Gründerfonds, and has collected seven awards since 2017. The weaknesses are equally concrete. Nothing about pricing is public, so no reader can judge affordability without entering a sales conversation. The on-premise volume threshold, 10,000 documents a day or a million in stock, rules out smaller organisations outright. Inside the application there are no differentiated permissions, single sign-on is absent and modern federation protocols are a chargeable extra. A contractual availability of 95% on annual average is modest. API documentation is withheld until requested, no subprocessor list is published, and the ISO/IEC 27001 announcement names a certifier but no certificate number. For a European insurer or lender losing money to document fraud and constrained by data protection, this is a credible and well-argued option. For anyone below its volume threshold, or unwilling to negotiate a bespoke contract, it is out of reach.