As of 23 July 2026, Ansvar Gateway is listed in the CSA STAR Registry. The entry is a STAR Level 1 self-assessment: the full Consensus Assessments Initiative Questionnaire (CAIQ v4.0.3), all 261 questions, downloadable by anyone. Of those answers, 190 are Yes, 4 are N/A — and 67 are No.
We want to talk about the 67.
What the listing is#
The STAR Registry is the Cloud Security Alliance's public repository of cloud-provider security assessments. It exists to solve a specific procurement problem: every security review starts with a questionnaire, every vendor answers it privately, and every buyer starts from zero. STAR inverts that. The provider answers one standardized questionnaire — the CAIQ, built on the Cloud Controls Matrix, covering 17 domains from identity management to supply-chain governance — and publishes it once, in public, where any prospective customer's security team can pull it before the first call.
Level 1 is a self-assessment. Nobody audited these answers; that is what Level 2 is for, and we are not there yet. What Level 1 gives you is specificity and checkability: 261 concrete claims in a standard format, on the record, renewed annually, diffable over time.
Why the No answers are published#
A CAIQ where everything is Yes is not a good sign — it is a sign the questionnaire was answered by the marketing department. Real companies, at every size, have controls that are implemented, controls that are partial, and controls that are planned. The only question is whether the questionnaire admits it.
Ours does, because the alternative would contradict the product. The gateway's core design rule is that a wrong answer is worse than no answer: when a data source is unavailable, the gateway returns an error instead of letting a model improvise; when a regulatory claim cannot be grounded in a fetched provision, our workflows mark it unresolved instead of inventing a citation. That rule is worthless if we suspend it for our own paperwork. So the CAIQ was answered the same way the platform answers: a Yes requires citable evidence from our ISMS, a control that is approved on paper but not yet operating is a No, and uncertainty is flagged rather than rounded up.
Two examples from our own No column, so this is concrete rather than rhetorical: our first external penetration test is planned for 2026 but has not happened yet, and our disaster-recovery rebuild drill is defined and scheduled but has not had its first full run. Both were answered No. Both come with dates. When the next annual renewal is published, those rows are the ones to check.
How to read a Level 1 entry — ours or anyone's#
If you are evaluating us (or any vendor with a STAR entry), the useful reading order is the opposite of the flattering one:
- Read the No and N/A answers first. That is where the real information is. An N/A should come with an architectural reason — for example, questions about securing customer-facing model inference do not apply the same way to a gateway that serves law and evidence to your agent rather than running its own frontier model over your data.
- Distinguish gap from design. Some No answers mean "not yet"; others mean "the control the question assumes does not match how the system is built." The notes column is where a serious respondent explains which is which.
- Ask for evidence on the controls that are load-bearing for you. A self-assessment is a map, not the territory. If encryption key management or audit logging is what your review hinges on, take the CAIQ row as the starting point and ask us for the specifics behind it.
- Diff it next year. STAR listings renew annually. A provider whose No count shrinks with dates attached is telling you something no point-in-time Yes can.
Where this sits in our assurance picture#
The STAR entry joins the other public, checkable signals on our recognition page: it is a published self-assessment, and we label it exactly that. Our ISO 27001 implementation is in progress and pointed at independent certification; the penetration test is scheduled; the gaps in the CAIQ's No column are the working backlog of our security program, not a separate marketing artifact. The platform side of that same posture — what we log, what we refuse to serve without a citation, how tenant data is isolated — is on /security, and the mechanics behind the citation discipline are in how article-level citations are validated.
The entry is live in the registry now. Download the CAIQ, read the No answers, and if one of them matters to your assessment, ask us about it directly at team@ansvar.eu — the honest answer is the product.