AI governance at Ansvar — how we actually operate.
Ansvar keeps model access, data handling, and evidence resolution separate. Reviewers can see who operates each part and reproduce the evidence checks.
Model access (bring your own AI client)
The gateway runs no server-side AI model. You connect your own AI client — Claude Desktop, Microsoft Copilot Studio, Cursor, or a custom MCP client — to the gateway over OAuth 2.1. Model traffic flows directly from your client to your model provider; Ansvar never sees, stores, or proxies it, and never holds your model keys.
Training on customer data
We do not train, fine-tune, or evaluate any model on customer data. Uploaded documents, query text, and citation metadata are used only to serve the user's own workflow. Your model provider's retention terms apply to the traffic between your AI client and that provider — a path Ansvar is not on.
AI-assisted service deliverables
One lane runs on our side. When you commission a professional deliverable from us, a threat model, a gap analysis, a compliance assessment, an agent we operate drafts it against gateway-fetched sources. That inference runs through Anthropic's API under commercial terms that do not permit training on our traffic. A named human reviews and corrects every deliverable before you receive it, and the document itself states the AI assistance and who reviewed it. Treat the content as advisory: your reliance rests on the review, not on the model. If we change the model or provider behind this lane, the disclosure in your next deliverable names the current one.
Citation validation pipeline
A deterministic, non-model pipeline validates citations before the gateway serves them. It resolves article numbers against corpus indexes, checks paragraph anchors, and verifies that source URLs return the cited text. The gateway labels a failed citation unavailable instead of dropping it or substituting model recollection.
Retrieval transparency
Our standalone legal connectors carry Apache 2.0 code and go public only where their source-licensing audit returns GREEN — inspect them at github.com/Ansvar-Systems. You can audit how each one reaches its source; the chassis that serves them in production, and the licensed data itself, stay private.
Data residency
Infrastructure runs on Hetzner in the EU. Cloudflare provides edge and TLS termination in front, under SCCs and the EU-US Data Privacy Framework — the same disclosure our Terms make. Model traffic flows directly from your AI client to your model provider and does not cross our infrastructure. Audit logs stay in-region.
Model versions and reproducible evidence
Model choice and version are set in your AI client, not by Ansvar; the gateway has no Ansvar-side model to pin. The deliverables lane above carries its own disclosure per document. Ansvar validates citation resolution without a model and returns the source identifiers needed to fetch the same served evidence again. Search ranking and your model's synthesis can vary between runs, so we do not promise that the same question returns the same sources or wording.
The EU AI Pact
We signed the European Commission's AI Pact (Pillar II) in August 2026 — a voluntary pledge, run by the EU AI Office, to work towards the AI Act's provisions ahead of their deadlines. We appear on the Commission's list of signatories as Ansvar AI, the trading name we signed under; the legal entity behind the pledge is Ansvar Systems AB. It is a pledge, not a certification: nobody audits it, and we would rather say that than let it read as one. What we signed up to, and where we stand:
- An AI governance strategy. Ours is written down rather than asserted: architecture decision records for every structural choice, an ISO 42001-aligned management posture with ISO 27001 certification in preparation, and production changes that land only as reviewed pull requests.
- A mapping of AI systems in high-risk areas. We provide a retrieval and citation layer, not a decision system — the model is your own client's. On our assessment at signature, nothing we provide or deploy falls into the AI Act's high-risk categories. We re-run that mapping when we ship a new surface rather than treating it as settled.
- AI literacy. Everyone working with AI systems on our behalf is expected to understand what the system can and cannot establish — which, for a citation product, means knowing the difference between a fetched source and a model's recollection of one.
We also took on part of the Pact's developer commitments: risk identification, logging and traceability, information for the organisations deploying our service, risk-mitigation policies, and marking AI-generated content. We deliberately left the rest unticked instead of padding the list — we train no models, we produce no image, audio, or video output, and the deployer commitments target high-risk deployment affecting individuals, which our internal agent use is not. Signatories report to the AI Office on their implementation twelve months in; ours is due in 2027.
Questions? Security overview covers procurement-grade architecture. For a written answer to a specific question, contact team@ansvar.eu.