Evidence and validation infrastructure for your AI agents.
Your models, your orchestration, your interface stay yours. Ansvar supplies the sources, re-fetches and checks the citations an answer rests on, and hands back compliance work your people can review.
Building on it? One endpoint, published contracts, agents on seats
Works in Claude, ChatGPT, Copilot, Cursor and your own agents.
“supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers”
Current state: Roughly 30 cloud and data suppliers, no register; contracts on supplier paper with no security clauses; customs-data integrations rely on provider defaults.
Your agents, the evidence, your systems and your obligations, joined by one connection.
One MCP connection between them. It fetches and cites, or refuses.
- Your AI clientsClaude · ChatGPT · Copilot · Cursor · your own agents
- One MCP connectiongateway.ansvar.eu/mcp · cited, or refused · receipt on every report · OAuth 2.1, EU-hosted
- Four productsLegal and regulatory evidence · Living security architecture · Compliance assessments · Security risk and threat intelligence
Each answers one question.
What does the law say. What is our system. What must we do. What are we exposed to, and what do we fix first. Buy one or all four; they share the same evidence.
Legal and regulatory evidence
Law, regulation, standards, case law and guidance across Europe, the UK, the US and Canada, every row traced to its publisher.
Living security architecture
A model of components, data flows and trust zones that your agents keep current and your people approve.
- ExternalBrowser
- Application zonePortal API → Event queue (proposed, owner unknown)
- Restricted dataRecords store, written by Portal API
Compliance assessments
Gap analyses, DPIAs and conformity runs your own agent walks end to end on a system you describe, or on your documents from Team. Every finding cited, every report with a receipt.
The information-security policy names supplier risk but sets no requirements for contracts, monitoring or offboarding. Article 21(2)(d) expects the measures to cover supply-chain security.
Security risk and threat intelligence
CVE, KEV, EPSS and ICS advisory lookups on every plan. Threat models and TARAs your agent runs. A vulnerability assessment scores each finding against the system you described.
- CVE-2021-44228
- Apache Log4j2 remote code execution, CVSS 10.0KEV: listed
- EPSS
- 0.99999, top 1% most likely to be exploited in the next 30 daysFIRST.org
- context
- Portal API, internet-facing, restricted datayour model
- verdict
- Fix first: reachable from the internet and in the ransomware cataloguecritical
- export
- Review decision recorded, exported as OpenVEXopenvex
The frames show illustrative sessions. The cited rows in them are served citations.
Built for the agents you already run.
One MCP endpoint under your existing stack. Nothing here asks you to move it.
One endpoint
An MCP connection with OAuth 2.1 and dynamic client registration. Your client, your model, your prompts — the evidence comes from us.
Agents on seats
Service credentials from Premium for n8n, CI and scheduled monitors. Published quotas, and refusals that name your usage, the reset time and the next step.
Citations you can check
Every row carries publisher, source URL and licence — and the gateway will re-fetch the citations a draft already relies on and say which held. On every plan.
Agents investigate. Experts decide.
Agents prepare decisions from how a system was designed, how it runs and which obligations apply; your experts inspect and decide.
- Company context, two inputs in parallel
- DocumentationPolicies · architecture · decisions · Responsibilities · trust boundaries
- Company systemsConfigs · identities · SBOMs · Vulnerabilities · logs · alerts
- MCP connectorsScoped, read-only access · No write operations
- Two inputs to the agents, in parallel
- Living architectureAssets · identities · data flows · Controls · suppliers · owners
- Knowledge MCPsLaw · controls · MITRE · sector rules · Reg intel · cited, with freshness
- Specialist agentsInvestigate · simulate · assess · Threat models · DPIAs · Micro threat models · options
- Human expertsChallenge · decide · authorize · Through your existing processes
Three things that sit beside the products.
Buy them with any plan, or on their own contract. Each one keeps the same evidence and the same connection.
ISMS as Code
The management system as a repository your agent operates and your people approve. Annual contract, with a paid pilot credited on conversion.
How it worksLicensed ISO standards (SIS)
Any ISO, EN or SS standard SIS publishes can be licensed into your workspace and read clause by clause, cited. Per seat, reported to SIS, served from the gateway.
The standards moduleExpert delivery
Our team runs or reviews the assessment, with the scope agreed before work starts.
What we deliverHosted by us, or inside your perimeter.
Hosted is available today and free to start. Your Kubernetes and on-prem run as design-partner pilots, with the production scope agreed before either side calls it available.
Your Kubernetes
Pilot phase · design-partner pilotsAnsvar runs in your own cluster; law and regulation are still answered from the central gateway.
DetailsOn-prem and air-gapped
Pilot phase · design-partner pilotsSigned content packs, no call home. Updates delivered offline on an annual contract.
DetailsRecently shipped.
Dated changes to the corpora, the gateway, the workflows and the account.
Search refuses an over-long query and tells your agent how to split it
search and search_guidance now refuse a query longer than 500 characters before any source is searched. The refusal is a typed error that tells the agent to split the matter into short issue queries. Before, a pasted case description failed inside the corpus and read as a source outage.
Ansvar Compliance Skills is in Anthropic's plugin directory
The ansvar-compliance-skills plugin is listed in Anthropic's plugin directory. One install adds our task skills and the Ansvar gateway connector to Claude, Cowork and Claude Code.
Slovenian law: the core statutes, consolidated and in force
The Slovenian statutes corpus now carries the acts a company, its lawyers and its compliance team work with every week: the civil and commercial codes, labour, tax, procurement, procedure, data protection and cyber security, each in its current consolidated text from PISRS, the state's legal information system.
Start with one cited answer, or one free assessment.
Free for businesses, no card. The free assessment runs on a system you describe; your own documents come with Team.