Skip to content
    NEWISMS as Code: the management system as a repository your agent operates. Our own passed ISO 27001 Stage 1.Read how it works
    Evidence infrastructure for regulated work

    Evidence and validation infrastructure for your AI agents.

    Your models, your orchestration, your interface stay yours. Ansvar supplies the sources, re-fetches and checks the citations an answer rests on, and hands back compliance work your people can review.

    Building on it? One endpoint, published contracts, agents on seats

    Works in Claude, ChatGPT, Copilot, Cursor and your own agents.

    Art. 21(2)(d) supply chain security
    GAP

    “supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers”

    Current state: Roughly 30 cloud and data suppliers, no register; contracts on supplier paper with no security clauses; customs-data integrations rely on provider defaults.

    4 mapped controlsremediation R2
    From the sample gap analysis for a fictional client; the NIS2 rows are served citations.
    How it fits together

    Your agents, the evidence, your systems and your obligations, joined by one connection.

    One MCP connection between them. It fetches and cites, or refuses.

    YOUR AI CLIENTSClaudeChatGPTCopilot · CursorYour own agentsANSVAR GATEWAYOne MCP connectiongateway.ansvar.eu/mcpcited, or refusedreceipt on every reporttier · products · add-onsOAuth 2.1 · EU-hostedFOUR PRODUCTSLegal and regulatory evidenceLiving security architectureCompliance assessmentsSecurity risk and threat intelligence
    • Your AI clientsClaude · ChatGPT · Copilot · Cursor · your own agents
    • One MCP connectiongateway.ansvar.eu/mcp · cited, or refused · receipt on every report · OAuth 2.1, EU-hosted
    • Four productsLegal and regulatory evidence · Living security architecture · Compliance assessments · Security risk and threat intelligence
    Four products, one connection

    Each answers one question.

    What does the law say. What is our system. What must we do. What are we exposed to, and what do we fix first. Buy one or all four; they share the same evidence.

    Compare plans

    Legal and regulatory evidence

    Law, regulation, standards, case law and guidance across Europe, the UK, the US and Canada, every row traced to its publisher.

    You
    Using Ansvar, what does the GDPR say about the right to erasure?
    Claude
    A controller must erase personal data without undue delay when one of the Article 17(1) grounds applies. Paragraph 3 lists the exceptions, including legal obligations and the establishment of legal claims.
    Regulation (EU) 2016/679, Article 17
    publisher Publications Office of the EUlicence EUR-Lex-Decision-2011-833source data.europa.eu/eli/reg/2016/679/oj
    Estonian implementing act: not served in this scope. Refused rather than guessed.
    receipt 0000-2f6a-91c3row verified 2026-09-20

    See the full example

    Free · every jurisdiction from €29 a monthExplore

    Living security architecture

    A model of components, data flows and trust zones that your agents keep current and your people approve.

    • ExternalBrowser
    • Application zonePortal API → Event queue (proposed, owner unknown)
    • Restricted dataRecords store, written by Portal API
    ExternalApplication zoneRestricted dataBrowserPortal APIRecords storeEvent queueproposed

    See the full example

    30-day evaluation · licence from €149 a monthExplore

    Compliance assessments

    Gap analyses, DPIAs and conformity runs your own agent walks end to end on a system you describe, or on your documents from Team. Every finding cited, every report with a receipt.

    Supply-chain security policy is not documented
    GAP

    The information-security policy names supplier risk but sets no requirements for contracts, monitoring or offboarding. Article 21(2)(d) expects the measures to cover supply-chain security.

    report receipt 0000-19ac-7e21reviewer decision pending

    See the full example

    From €249 a month · on your documents from €490Explore

    Security risk and threat intelligence

    CVE, KEV, EPSS and ICS advisory lookups on every plan. Threat models and TARAs your agent runs. A vulnerability assessment scores each finding against the system you described.

    CVE-2021-44228
    Apache Log4j2 remote code execution, CVSS 10.0KEV: listed
    EPSS
    0.99999, top 1% most likely to be exploited in the next 30 daysFIRST.org
    context
    Portal API, internet-facing, restricted datayour model
    verdict
    Fix first: reachable from the internet and in the ransomware cataloguecritical
    export
    Review decision recorded, exported as OpenVEXopenvex
    CISA KEV, added 2021-12-10EPSS read 2026-09-21
    Effective risk for portal-api, finding 1 of 14. Illustrative example; the CVE and KEV rows are served records.

    See the full example

    Free lookups and one teaser run · from €249 a monthExplore

    The frames show illustrative sessions. The cited rows in them are served citations.

    Build on it

    Built for the agents you already run.

    One MCP endpoint under your existing stack. Nothing here asks you to move it.

    Build on Ansvar

    One endpoint

    An MCP connection with OAuth 2.1 and dynamic client registration. Your client, your model, your prompts — the evidence comes from us.

    Agents on seats

    Service credentials from Premium for n8n, CI and scheduled monitors. Published quotas, and refusals that name your usage, the reset time and the next step.

    Citations you can check

    Every row carries publisher, source URL and licence — and the gateway will re-fetch the citations a draft already relies on and say which held. On every plan.

    How the check works

    Where this is going

    Agents investigate. Experts decide.

    Agents prepare decisions from how a system was designed, how it runs and which obligations apply; your experts inspect and decide.

    How the connected company works
    The connected companyWorking vision
    Documentation and company systems feed read-only MCP connectors into a living architecture. Specialist agents combine it with Ansvar knowledge MCPs and prepare decisions for human experts, who decide and authorize.DocumentationPolicies · architecture · decisionsResponsibilities · trust boundariesCompany systemsConfigs · identities · SBOMsVulnerabilities · logs · alertsMCP connectorsScoped, read-only accessNo write operationsLiving architectureAssets · identities · data flowsControls · suppliers · ownersPOWERED BY ANSVARKnowledge MCPsLaw · controls · MITRE · sector rulesReg intel · cited, with freshnessSpecialist agentsInvestigate · simulate · assessThreat models · DPIAsMicro threat models · optionsHuman expertsChallenge · decide · authorizeThrough your existing processesCOMPANY CONTEXTREAD-ONLY CAPABILITIESSOURCES + FRESHNESS + UNKNOWNSDECISION AUTHORITY
    1. Company context, two inputs in parallel
      • DocumentationPolicies · architecture · decisions · Responsibilities · trust boundaries
      • Company systemsConfigs · identities · SBOMs · Vulnerabilities · logs · alerts
    2. MCP connectorsScoped, read-only access · No write operations
    3. Two inputs to the agents, in parallel
      • Living architectureAssets · identities · data flows · Controls · suppliers · owners
      • Knowledge MCPsLaw · controls · MITRE · sector rules · Reg intel · cited, with freshness
    4. Specialist agentsInvestigate · simulate · assess · Threat models · DPIAs · Micro threat models · options
    5. Human expertsChallenge · decide · authorize · Through your existing processes
    Each source keeps its observation time. Missing evidence, and conflicts between documented intent and observed state, stay visible.
    Add-ons and contracts

    Three things that sit beside the products.

    Buy them with any plan, or on their own contract. Each one keeps the same evidence and the same connection.

    Choose where it runs

    Hosted by us, or inside your perimeter.

    Hosted is available today and free to start. Your Kubernetes and on-prem run as design-partner pilots, with the production scope agreed before either side calls it available.

    Compare deployments

    Hosted

    Available

    EU infrastructure, operated by Ansvar. Start free, no card.

    Details

    Your Kubernetes

    Pilot phase · design-partner pilots

    Ansvar runs in your own cluster; law and regulation are still answered from the central gateway.

    Details

    On-prem and air-gapped

    Pilot phase · design-partner pilots

    Signed content packs, no call home. Updates delivered offline on an annual contract.

    Details
    Product updates

    Recently shipped.

    Dated changes to the corpora, the gateway, the workflows and the account.

    All changes
    • gateway

      Search refuses an over-long query and tells your agent how to split it

      search and search_guidance now refuse a query longer than 500 characters before any source is searched. The refusal is a typed error that tells the agent to split the matter into short issue queries. Before, a pasted case description failed inside the corpus and read as a source outage.

    • docsgateway

      Ansvar Compliance Skills is in Anthropic's plugin directory

      The ansvar-compliance-skills plugin is listed in Anthropic's plugin directory. One install adds our task skills and the Ansvar gateway connector to Claude, Cowork and Claude Code.

    • coveragegateway

      Slovenian law: the core statutes, consolidated and in force

      The Slovenian statutes corpus now carries the acts a company, its lawyers and its compliance team work with every week: the civil and commercial codes, labour, tax, procurement, procedure, data protection and cyber security, each in its current consolidated text from PISRS, the state's legal information system.

    Start with one cited answer, or one free assessment.

    Free for businesses, no card. The free assessment runs on a system you describe; your own documents come with Team.