Blog

Our security questionnaire is public: Ansvar Gateway joins the CSA STAR Registry

Ansvar Gateway is listed in the CSA STAR Registry — a Level 1 CAIQ v4.0.3 self-assessment with all 261 answers published, including the No answers. How to read it.

As of 23 July 2026, Ansvar Gateway is listed in the CSA STAR Registry. The entry is a STAR Level 1 self-assessment: the full Consensus Assessments Initiative Questionnaire (CAIQ v4.0.3), all 261 questions, downloadable by anyone. Of those answers, 190 are Yes, 4 are N/A — and 67 are No.

We want to talk about the 67.

What the listing is#

The STAR Registry is the Cloud Security Alliance's public repository of cloud-provider security assessments. It exists to solve a specific procurement problem: every security review starts with a questionnaire, every vendor answers it privately, and every buyer starts from zero. STAR inverts that. The provider answers one standardized questionnaire — the CAIQ, built on the Cloud Controls Matrix, covering 17 domains from identity management to supply-chain governance — and publishes it once, in public, where any prospective customer's security team can pull it before the first call.

Level 1 is a self-assessment. Nobody audited these answers; that is what Level 2 is for, and we are not there yet. What Level 1 gives you is specificity and checkability: 261 concrete claims in a standard format, on the record, renewed annually, diffable over time.

Why the No answers are published#

A CAIQ where everything is Yes is not a good sign — it is a sign the questionnaire was answered by the marketing department. Real companies, at every size, have controls that are implemented, controls that are partial, and controls that are planned. The only question is whether the questionnaire admits it.

Ours does, because the alternative would contradict the product. The gateway's core design rule is that a wrong answer is worse than no answer: when a data source is unavailable, the gateway returns an error instead of letting a model improvise; when a regulatory claim cannot be grounded in a fetched provision, our workflows mark it unresolved instead of inventing a citation. That rule is worthless if we suspend it for our own paperwork. So the CAIQ was answered the same way the platform answers: a Yes requires citable evidence from our ISMS, a control that is approved on paper but not yet operating is a No, and uncertainty is flagged rather than rounded up.

Two examples from our own No column, so this is concrete rather than rhetorical: our first external penetration test is planned for 2026 but has not happened yet, and our disaster-recovery rebuild drill is defined and scheduled but has not had its first full run. Both were answered No. Both come with dates. When the next annual renewal is published, those rows are the ones to check.

How to read a Level 1 entry — ours or anyone's#

If you are evaluating us (or any vendor with a STAR entry), the useful reading order is the opposite of the flattering one:

  1. Read the No and N/A answers first. That is where the real information is. An N/A should come with an architectural reason — for example, questions about securing customer-facing model inference do not apply the same way to a gateway that serves law and evidence to your agent rather than running its own frontier model over your data.
  2. Distinguish gap from design. Some No answers mean "not yet"; others mean "the control the question assumes does not match how the system is built." The notes column is where a serious respondent explains which is which.
  3. Ask for evidence on the controls that are load-bearing for you. A self-assessment is a map, not the territory. If encryption key management or audit logging is what your review hinges on, take the CAIQ row as the starting point and ask us for the specifics behind it.
  4. Diff it next year. STAR listings renew annually. A provider whose No count shrinks with dates attached is telling you something no point-in-time Yes can.

Where this sits in our assurance picture#

The STAR entry joins the other public, checkable signals on our recognition page: it is a published self-assessment, and we label it exactly that. Our ISO 27001 implementation is in progress and pointed at independent certification; the penetration test is scheduled; the gaps in the CAIQ's No column are the working backlog of our security program, not a separate marketing artifact. The platform side of that same posture — what we log, what we refuse to serve without a citation, how tenant data is isolated — is on /security, and the mechanics behind the citation discipline are in how article-level citations are validated.

The entry is live in the registry now. Download the CAIQ, read the No answers, and if one of them matters to your assessment, ask us about it directly at team@ansvar.eu — the honest answer is the product.

Frequently asked

What is the CSA STAR Registry?
The STAR Registry is a public repository run by the Cloud Security Alliance where cloud providers document their security and privacy posture against the Cloud Controls Matrix. A Level 1 entry is a published self-assessment: the provider answers the Consensus Assessments Initiative Questionnaire (CAIQ) — 261 structured questions across 17 control domains — and the completed questionnaire is downloadable by anyone from the provider's registry entry. It is the standard first artifact a security team requests during vendor review, published before anyone has to ask.
What is the difference between STAR Level 1 and Level 2?
Level 1 is a self-assessment: the provider answers the CAIQ about its own controls and the registry publishes it as-is. Level 2 adds independent assurance — a third-party audit (STAR Certification or STAR Attestation) that verifies the answers against evidence. Our entry is Level 1. Read it as a structured, checkable statement of what we claim about our own posture — not as an audit result. Independent verification is the next rung, and our ISO 27001 work is pointed at exactly that.
Why would a vendor publish No answers in a security questionnaire?
Because a questionnaire with 261 unqualified Yes answers from a company of any size is not credible, and security reviewers know it. A No with a date and a remediation plan tells a buyer more than a Yes they cannot check: it shows the assessment was answered against evidence rather than aspiration, and it gives you a baseline to diff at the next annual renewal. Our platform's core rule is that a wrong answer is worse than no answer — the same rule applied to our own paperwork means an honest gap beats a confident claim we could not support.
How should I use a vendor's CAIQ in my own vendor review?
Download it and read the No and N/A answers first — that is where the information density is. For each No, check whether the stated reason is a genuine gap, a control that does not apply to the architecture, or a control handled by a different mechanism than the question assumes. Then pick the handful of controls that are load-bearing for your use case and ask the vendor for evidence on those specifically. A CAIQ does not replace your assessment; it gives it a structured starting point and makes silence on any control visible.