
ICO-LUX
German document-forensics software that pairs layout-aware image analysis with a fraud rulebook to flag forged invoices, prescriptions and income statements before insurers, banks or public bodies release a payment or approve a loan.
What is ICO-LUX?
ICO-LUX is document-forensics software built by ICO-LUX GmbH, a spin-off of Friedrich Schiller University Jena and TU Ilmenau entered in the German commercial register in July 2018 and based in Jena, Thuringia. The company calls itself the German market leader in automated document authenticity checking, and sells three products that stack on one another. ICO.Match is the foundation: an intelligent document processing engine that goes past conventional OCR by reading layout rather than characters alone. It straightens skewed perspectives, removes image noise, rebuilds table structures and text positions, then assigns everything to recurring patterns so a page becomes a contextualised, structured record. It is deliberately ready to run, with no algorithm training required, and is sold either standalone or inside its sibling. ICO.Fraud always embeds ICO.Match, then applies a fraud rulebook to the structured output. It combines machine learning with rule-based reasoning, and the site claims it uses roughly a hundred times more information per document than earlier fraud-detection tools. Beyond layout deviation it adds domain checks: a patient calendar cross-referencing treatment dates against practice opening hours and travel distances, and continuity analysis of a practice's invoice numbering. In keeping with European AI rules, it does not merely mark a document suspicious but shows why, leaving the decision to the fraud team. ICO.Link answers a different problem: insurers and banks cannot lawfully swap customer data in the clear. It applies privacy-preserving record linkage, hashing policyholder details into irreversible fingerprints that are compared on a dedicated server, raising an alert only on serious suspicion. Four sectors are addressed: insurance, banking, public administration and property. Deployment runs on-premise via Docker Compose or OpenShift, on customer-managed Kubernetes in AWS or Azure, or as SaaS. Processing takes place in certified German data centres, and the company has held ISO/IEC 27001 certification since August 2026.
What it does
- Detect forged and altered supporting documents before a payout is released or a loan is approved
- Turn poor-quality scans and smartphone photographs into structured, machine-readable data
- Classify incoming documents automatically into customer-extensible document classes
- Group an unsorted archive by document author using addresses or IBANs found on the pages
- Flag the smallest layout deviations against other documents from the same issuer
- Uncover multiple identities and undeclared parallel policies without exchanging readable data
- Explain every alert so the final judgement stays with the case handler
When to use ICO-LUX / When not to
A quick filter to help you decide if ICO-LUX is the right fit.
When to use ICO-LUX
- Private health insurers screening high volumes of medical bills, prescriptions and practitioner invoices for manipulation
- Banks and lenders verifying payslips, pension notices and bank statements inside credit and mortgage application flows
- Liability and household insurers checking submitted invoices and purchase receipts for retrospective alteration
- Customs authorities, tax offices and social benefit agencies inspecting supporting documents at scale
- Organisations already handling at least 10,000 documents a day, or holding an archive of a million, where a retrospective sweep pays for itself
When not to use ICO-LUX
- Consumers and private individuals: the terms exclude any service to consumers under § 13 of the German Civil Code
- Teams whose documents are handwritten, since the software expects predominantly printed text
- Anyone working from scans below 150 dpi, which fall outside the stated input requirements
- Small operations under the on-premise volume threshold of 10,000 documents a day or a million in stock
- Buyers who need a published price, a self-service sign-up or an immediate trial, as every engagement runs through an individual contract
How to use ICO-LUX
A typical end-to-end flow, from setup to results.
- Book a demonstration through the contact form; there is no self-service sign-up
- Agree an individual contract, since prices come from a negotiated agreement rather than a published list
- Choose the deployment model: on-premise with Docker Compose or OpenShift, customer-managed Kubernetes on AWS or Azure, or SaaS hosted by the vendor
- Size the hardware from the published figures, roughly 10,000 documents per week per CPU core and 200 KB of disk per document
- Let ICO-LUX install the system using its parameterised bash scripts, a preconfigured VirtualBox image or a ready-built workstation
- Wire up document intake by dropping CSV metadata into a scanned folder, importing Export.xml from an input-management system, or posting JSON to the REST API
- Make the page images reachable, either through an HTTP(S) service the software calls on demand or a mounted network share
- Run the initial retrospective sweep over the existing archive, typically hundreds of thousands to several million documents across a few weeks
- Give the fraud team browser access to the internal frontend, secured by HTTP Basic, a reverse proxy or LDAP against Active Directory
- Move into routine operation, adding new documents continuously and taking a software update once or twice a year
Pros & Cons
Pros
- Processing takes place in certified German data centres, and ICO.Match is stated to store neither source documents nor extracted values
- Every alert is explained, so the case handler keeps the decision rather than inheriting a black-box score
- No customer-specific training is required: ICO.Match and ICO.Link are presented as ready to run from day one
- A genuine choice between on-premise, customer-managed cloud and vendor-hosted SaaS, all documented in detail
- An unusually precise integration page with worked CPU, RAM and disk sizing examples rather than vague requirements
- GDPR compliance confirmed by independent experts for health data and two ICO.Link lines, and ISO/IEC 27001 held since August 2026
- A dense reference list across German insurance and banking, from Allianz and AXA to HUK-COBURG, Debeka and DKB
Cons
- No public pricing whatsoever: no rate card, no free plan and no documented free trial
- A high entry threshold for on-premise use, at 10,000 documents a day or a million in stock
- No differentiated permissions inside the application; every frontend user holds the same rights
- No single sign-on, with SAML, OAuth 2.0 and OpenID Connect available only as a separately commissioned extra
- API documentation is not published and must be requested from the vendor
- A contractual availability of 95% on annual average is modest for software delivered as a service
- The English version of the site is partial, and installation, updates and support all require remote access to the customer's system
Pricing & Plans
There is no free plan and no publicly documented free trial, and ICO-LUX publishes no price at all. Under § 6(1) of its terms, prices follow from the individual contract; where no express price has been agreed, § 6(2) applies the rate card in force at signature, which can be requested from the vendor at any time. Effort-based billing is provided for, with day rates counted as eight person-hours and hourly rates charged per started quarter-hour. Prices are quoted net of VAT, cross-border duties and currency costs, and travel, accommodation and disbursements fall to the customer against receipt. Invoices are payable without deduction within two weeks. Readers should note that the single figure quoted anywhere on the site, 8,000 EUR including tax, prices a physical workstation delivered with the software preinstalled and capable of handling 50 million documents a year; it is not a software entry price.
- the three products are contracted individually and priced case by case
- ICO.Fraud — fraud detection with ICO.Match extraction always embedded
- ICO.Link — cross-company privacy-preserving matching platform
- ICO.Match — document extraction and classification
- sold standalone or inside ICO.Fraud
- standard software supply
- maintenance and support
- bespoke development
- software provision as a service
- and service or works contracts
Data, GDPR & hosting
A consolidated view of how ICO-LUX handles your data.
GDPR overview
GDPR treatment is concrete and detailed. ICO-LUX GmbH is named as controller, with its three managing directors, and the policy enumerates the rights under Articles 15, 16, 17, 18, 20 and 21 plus consent withdrawal, alongside the right to complain to a supervisory authority. An external data protection officer is appointed: Thomas Oettler of ARSI-Q Arbeitssicherheit & Qualität GmbH & Co. KG in Gera, though no email is published for him. Objections under Article 21 go to Jan Franke at the company address. The policy was drafted in part with activeMind AG and last updated on 6 December 2024. On the product side the vendor states its solutions are consistently GDPR-compliant and that independent experts confirmed this for health data and for two ICO.Link insurance lines, though no expert report is published. ISO/IEC 27001 certification was announced on 11 August 2026.
Who owns the data?
Nothing in the terms transfers ownership of customer documents to the vendor. ICO-LUX positions itself as a supplier, and § 24(2) obliges the customer to conclude a data protection agreement on request wherever Article 28 processing or Article 26 joint controllership applies, which places the customer in the controller's seat. Section 43(3) states the vendor is not answerable for content data supplied by or for the customer, and § 12 leaves the customer responsible for the material it provides. Deletion of content data (§ 48) only follows an unheeded formal notice. For ICO.Match the vendor goes further and states it stores neither the documents it reads nor the information it extracts.
Reuse rights
The terms grant the customer usage rights over the software, not a licence over its own data, which it keeps and may reuse freely without asking the vendor. On the vendor's side, use is bounded by purpose: ICO.Match is described as storing neither source documents nor extracted values, while ICO.Fraud persists processing results and reviewer feedback in a PostgreSQL 16 database that sits on the customer's own infrastructure in the on-premise model. ICO.Link never exchanges readable data at all: policyholder records are hashed into irreversible fingerprints before any cross-company comparison. No page anywhere on the site contemplates reusing customer material to train models, and both ICO.Match and ICO.Link are marketed as requiring no customer-specific training. Reference naming of customers is governed separately by § 54.
Data retention & training
Hosting summary
ICO-LUX states that data processing takes place in certified data centres in Germany, and for ICO.Match that it stores neither the documents it reads nor the information it extracts. Three deployment models exist. On-premise, the software runs on the customer's own infrastructure through Docker Compose on Linux or through OpenShift, using a vendor Docker repository and per-customer Helm charts. In the cloud model it runs on Kubernetes inside an AWS or Azure account managed by the insurer or bank itself. Alternatively it is offered as software as a service hosted in data centres commissioned by ICO-LUX; for banks the site indicates SaaS. All processing results are persisted in a PostgreSQL 16 database, with PgBouncer recommended in front of it. The frontend is configured to be reachable only from inside the customer network, over HTTPS with TLS 1.2. Under the terms, services are otherwise performed at the vendor's registered office, with access to customer systems by remote connection. The public website itself is hosted in Germany with Mittwald CM Service GmbH und Co. KG.
Things to keep in mind
Risks and trade-offs to weigh before adopting ICO-LUX.
- The company contradicts itself on its own founding date: one page says July 2018 while the fifth-anniversary post is pegged to 27 June, the date of the articles of association. The register settles it at 16 July 2018, nineteen days after the deed.
- The only figure on the site, 8,000 EUR including tax, prices a physical workstation and not a licence. Reading it as an entry price would badly misstate the cost of ownership.
- ISO/IEC 27001 is announced in a news post naming the certifier, Proks Certification GmbH, but no certificate number or validity period is published and no attestation is available.
- The logos on the reference page are customers, not technology partners or integrations, and should not be read as an ecosystem.
- GDPR compliance is described as confirmed by independent experts, yet the expert report itself is not published and no subprocessor list is disclosed.
- No beneficial owner can be identified anywhere: the German transparency register requires registration and a legitimate interest, and the commercial data aggregator paywalls its shareholder list.
- Because every frontend user holds identical rights and there is no single sign-on, access governance falls entirely on the customer's reverse proxy or directory, which is easy to under-engineer.
Setup & Integrations
Technical difficulty
Moderate to high, but well supported. The system is containerised and needs three components — a PostgreSQL 16 database, a frontend server and workers — plus a low-latency gigabit link to the database. Sizing must be calculated: about 10,000 documents per week per CPU core, 2 GB of RAM per core, 200 KB of disk per document. ICO-LUX insists container knowledge is not required and supplies parameterised bash install scripts, a preconfigured VirtualBox image or even a ready-built workstation. Document intake still has to be wired up, and installation, updates and support all require remote access.
Deployment
Integrations
Behind ICO-LUX
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What does ICO-LUX actually do?
What are the three products and how do they fit together?
Who uses it?
Can it run on our own infrastructure?
Is there an API?
Where is our data processed?
Will our documents be used to train models?
What does it cost?
What document formats and quality does it need?
Is there a mobile app?
Should you pick ICO-LUX?
ICO-LUX is a narrow, serious tool aimed at a narrow, serious problem. It is not a general-purpose AI assistant but vertical software sold under contract to regulated enterprises, and it should be judged on that basis. The strengths are real and unusually well documented: processing in certified German data centres, a stated policy of not retaining documents or extracted values in ICO.Match, explainable alerts that leave the decision with the case handler, no requirement to train algorithms on customer data before going live, and an integration page carrying worked CPU, RAM and disk calculations that most vendors would never publish. The reference list across German insurance and banking is dense, the company has been registered since July 2018, is backed by High-Tech Gründerfonds, and has collected seven awards since 2017. The weaknesses are equally concrete. Nothing about pricing is public, so no reader can judge affordability without entering a sales conversation. The on-premise volume threshold, 10,000 documents a day or a million in stock, rules out smaller organisations outright. Inside the application there are no differentiated permissions, single sign-on is absent and modern federation protocols are a chargeable extra. A contractual availability of 95% on annual average is modest. API documentation is withheld until requested, no subprocessor list is published, and the ISO/IEC 27001 announcement names a certifier but no certificate number. For a European insurer or lender losing money to document fraud and constrained by data protection, this is a credible and well-argued option. For anyone below its volume threshold, or unwilling to negotiate a bespoke contract, it is out of reach.
- Choosing a selection results in a full page refresh.
- Opens in a new window.