SIS-licensed ISO clauses and controls·an add-on inside the AI clients and agents you already use
    Auditable workflow infrastructure for regulated work

    Do regulated work in the AI you already use. Defend every finding.

    Ansvar brings verified law and security intelligence into Claude, ChatGPT, Copilot Studio, Cursor, or your agents. Add SIS-licensed standards and, on Team and Company, paragraph-cited evidence from your documents. Run structured gap analyses, DPIAs, threat models, and TARAs. Each factual finding cites its evidence or stays unresolved.

    €0 to start · no card · no Ansvar-hosted model

    From a captured workflow run

    NIS2 gap analysis

    Baltika information-security policy

    Fictional sample
    Finding Art.21.2.aPartial
    Requirement
    NIS2 Article 21(2)(a)
    Internal evidence
    Policy §3 · hash 414bf5…521ea
    Standard evidence
    SS-EN ISO/IEC 27001:2023 · 6.1.2 and 8.2 · SIS licensed
    Finding

    The policy defines an annual risk review, but no documented method, acceptance criteria, or reassessment trigger after a significant change.

    Estonian transposition was unavailable during the run. The assessment leaves it unresolved.
    Inspect the captured run →
    EU-hostedBring your own modelPeople and standing agentsDedicated Company infrastructure by agreementCustomer-managed: design-partner path
    Two places to start

    Start with the decision due next.

    Both entry points use the same source contract, structured execution, and review gates. Team and Company can ground supported workflows in customer documents.

    Enterprise security and compliance

    Turn policies and system evidence into a cited assessment.

    Assess the documents your team uses against DORA, NIS2, GDPR, and licensed ISO standards. Get assessed requirements, supporting evidence, gaps, remediation, and named unresolved points.

    DORANIS2ISO 27001DPIA
    Product security and engineering

    Turn an architecture into a cited threat model or TARA.

    Assess software, vehicles, machinery, robotics, medical devices, and OT against product law, licensed standards where entitled, and served threat sources.

    STRIDETARACRAISO 21434
    Need a field-specific path?

    Browse the legal sources, standards, and available workflows for each sector.

    Explore all sectors →
    Where Ansvar fits

    From source material to a reviewable decision.

    The gateway carries served evidence into a structured assessment and records where the evidence stops.

    Typical starting pointAnsvar carries forward
    Regulatory feedOfficial records and coverage state for a cited impact review.
    GRC recordCustomer documents and served sources inside a supported assessment.
    Method-specific toolSupported security, privacy, and compliance workflows over one document library.
    General-purpose AIFactual findings cited to served evidence or left unresolved.
    Jurisdiction-aware DPIA

    Your DPIA should know which country it is in.

    Describe one processing activity. Ansvar checks the GDPR baseline and routes the assessment to the national trigger evidence available for each confirmed jurisdiction.

    Published lists, indicative guidance, an advisory draft, and a jurisdiction without a national-list mechanism do not become the same checkbox. Each source keeps its status, publisher, citation, and verification record. Unsupported conclusions stay unresolved.

    29 jurisdiction evidence paths operationalOfficial-source citationsHuman approval retained
    Jurisdiction source receiptOne activity · distinct evidence paths
    verified sources
    JurisdictionNational evidence pathStatus preserved
    GermanyDSK Muss-Liste under Article 35(4), version 1.1published national material
    EstoniaIsikuandmete töötleja üldjuhend, chapter 5indicative authority material
    CyprusIndicative DPIA list submitted under Article 35(4)advisory draft
    SwitzerlandFederal Act on Data Protection, Articles 22 and 23statutory no-list determination
    Source status is part of the result, not a note added after the assessment.
    One complete workflow

    One policy in. A cited assessment out.

    The sample below comes from a captured Ansvar workflow. It binds a customer document to primary law and licensed ISO controls, then records the finding, the evidence, and the gap in one report.

    01
    Customer evidence

    POL-BLTK-2026-02, split into hash-anchored paragraphs.

    02
    Primary law

    NIS2 Article 21 is fetched from the official EU source and cited in the finding.

    03
    Licensed standard

    Selected ISO/IEC 27001 clauses and controls are resolved through the SIS add-on.

    04
    Structured execution

    The gap-analysis workflow applies the same review stages to each requirement.

    NIS2 gap analysis

    Baltika information-security policy

    Fictional sample
    Finding Art.21.2.aPartial
    Requirement
    NIS2 Article 21(2)(a)
    Internal evidence
    Policy §3 · hash 414bf5…521ea
    Standard evidence
    SS-EN ISO/IEC 27001:2023 · 6.1.2 and 8.2 · SIS licensed
    Finding

    The policy defines an annual risk review, but no documented method, acceptance criteria, or reassessment trigger after a significant change.

    Estonian transposition was unavailable during the run. The assessment leaves it unresolved.
    Anonymous customer results

    MedTech teams used Ansvar reports in regulated work.

    We publish the scope of each engagement and keep customer names private.

    DEGermanyData protection

    A German MedTech team completed a DPIA for planned health-data processing.

    The team used Ansvar to assess the GDPR baseline and Germany's national DPIA criteria for a pre-launch system.

    Assessment
    Jurisdiction-aware DPIA
    Stage
    Pre-launch system design
    See the DPIA workflow →
    SESwedenProduct security

    A Swedish MedTech company used its threat model in regulated product work.

    The company worked with Ansvar on a system threat model and used the report in work subject to regulatory requirements.

    Assessment
    System threat model
    Use
    Regulated product-security work
    See the threat-model workflow →
    Design-partner pilot

    Bring a live assessment. Shape the workflow with us.

    Run Ansvar on a real compliance or product-security decision. We will identify where the method, evidence, integration, or report needs work, then agree the pilot scope and acceptance criteria with you.

    Discuss a design-partner pilot
    SIS-licensed ISO standards · Available now

    ISO/IEC 27001, 42001 and more — cited, not paraphrased

    Ansvar serves selected clause and control text of five ISO standards through the gateway, licensed from SIS — the Swedish Institute for Standards. Your AI client cites the controls in gap analyses, threat models, and audits, attributed to the source standard. Any standard SIS publishes can be licensed in on request.

    SS-EN ISO/IEC 27001:2023 · SS-EN ISO/IEC 27002:2022 · SS-EN ISO/IEC 27005:2024 · SS-EN ISO/IEC 42001:2026 · SS-ISO/SAE 21434:2021

    See the standards module →
    Reuse the evidence

    One document library. Multiple assessments.

    Team and Company store policies, contracts, architecture documents, and prior reports in one tenant library. Bind the relevant documents to each supported run. Completed reports remain immutable; start a new run when the system or evidence changes.

    Evidence you controlArchitecture documents · policies · contracts · prior reports

    Bind the relevant documents to each new run. The workflow records the segments, source citations, judgments, and unresolved gaps it used.

    Regulatory changeTurn a publication into a review item.

    Ansvar reports the official record and its coverage window. Your agent can combine that record with company context and prepare a cited impact-review queue. A human approves any resulting change.

    See regulatory intelligence
    The guarantee

    The assessment is the product. The evidence contract is the guarantee.

    A reviewer can open the source behind a factual finding, check the customer document it rests on, and see where the available evidence stopped. Source health qualifies an empty result, and analytical judgments remain labelled as judgments.

    Assurance levelWhat you can verifyAvailability
    Source-auditableSource, publisher, licence, lookup, and freshness context for the finding.All plans
    Document-auditableCustomer evidence pinned to hash-anchored paragraphs.Team and Company
    Cryptographically auditableSigned, tenant-specific receipts and an exportable audit ledger.Company
    Product updates

    Recently shipped.

    Dated changes to the evidence layer, workflows, accounts, and platform.

    View all changes →
    coveragegateway

    Ontario law — provincial statutes and regulations, now served

    Ontario joins the gateway as Canada's first provincial corpus: consolidated statutes and regulations from e-Laws, in English and French, each answer cited to the official King's Printer source. Federal and British Columbia coverage refreshed in the same release.

    Connect your AI. Produce work you can defend.

    Start with the free evidence layer, or scope a finished assessment with an Ansvar practitioner.

    Not sure it fits? Have your AI check the fit — one evaluation pack, a verdict against documented coverage, “no current fit” included.