No tracking. No cookie wall.·EU-hosted (Hetzner) · Cloudflare edge under SCCs

    Changelog

    New corpora, gateway capabilities, and product changes — dated as they ship.

    August 2026

    Ask what regulators actually published

    Your agent can now ask what has actually been published, and get an answer from records rather than from memory. Each one carries its title, a link to the original publisher page, the publication and observation dates, official identifiers where the source assigns them, and a full citation naming the licence and linking its terms.

    What is monitored is the EU Official Journal L series — regulations, directives, implementing and delegated acts as they appear — alongside announcements from the European Commission, the EDPB and ENISA, and the national gazettes of a growing set of European jurisdictions. Every source passes the same per-source licensing gate before a single fetch, and get_regulatory_intelligence_status reports the live enrolment: which sources are watched, how fresh each one is, and when its baseline ran. That tool is the authoritative list, and it works on every plan including Free.

    Coverage is bounded, and the tools say where the boundary is. Each source reports only from its own enrolment baseline onward, so an empty result means nothing matched inside that window — never that the regulators were quiet. When every selected source is stale or has never synced, the search fails and names the state of each one instead of returning an empty list that would read as silence.

    This is publication monitoring, not amendment tracking: it tells you an act was published, not how a law you already follow changed. For that diff, get_changes remains the tool.

    search_regulatory_updates and get_regulatory_update are available from the Premium plan. get_regulatory_intelligence_status is free on every plan.

    Workflows and the control library, explained

    The site now has a Workflows section covering both ways you can run the same work: yourself, in the AI client you already use, or as an engagement we run and review as practitioners. The first workflow family has its own page — TARA, the threat-analysis-and-risk-assessment family for vehicles, OT, rail, robots and drones, sharing one enterprise risk spine. Services keep their URL and now live in the Workflows menu.

    The canonical control library also has a page for the first time. It explains what a canonical control is, why a flat framework tag cannot carry a coverage claim, the five relationships a mapping can record, and why the library stores citation pointers rather than licensed clause text. It is candid about where coverage stands: published crosswalks arrive untyped and claim nothing until a person reviews them, so the page shows what one control reaches today and names the frameworks that are registered but not yet mapped. A worked crosswalk from a real session walks ISO/IEC 27001 Annex A.5.26 through the spine to 24 NIST CSF 2.0 subcategories, with the provenance of every hop. The control library is available on Team and Company plans.

    Service credentials are full seats

    A service credential — the org-owned seat a Team or Company admin mints for headless clients such as n8n, CI, or a scheduled monitoring agent — now carries the same tool surface as a signed-in seat on its plan: search, workflow runs, document upload and report generation, under the same tier gates, drawing from the organization's pooled quota. This supersedes the read-only boundary the launch entry of 2026-07-26 described. Each credential keeps a monthly workflow-run ceiling, by default half of what one seat contributes to the pool, so one runaway agent cannot drain what the rest of the organization shares. A credential takes a seat of its own, next to yours; add seats as your agents grow. Setup guide: Service credentials.

    July 2026

    Sign up with email and password

    Free-tier signup is now identity-native two ways: sign in with Microsoft Entra ID or Google as before, or register directly with an email address and password at app.ansvar.eu. Registration asks for terms acceptance up front, verifies the address by email before the account is usable, and sits behind a fail-closed bot check. Nothing about the tier changed — a free account still connects your own MCP client to the gateway with the same limits, and paid plans still upgrade through checkout. If your organisation blocks third-party SSO, this removes the last reason you couldn't try the connector.

    ISO Standards Expert: an agent skill for the standards add-on

    The iso-standards-expert skill teaches an AI assistant to answer standards questions from served clause text instead of model memory: it fetches the clauses a question needs through the ISO Standards add-on, quotes them verbatim with the SIS copyright notice on every excerpt, and reports an unevaluated-scope list whenever the licence coverage ceiling withholds a fetch — only selected parts of a standard are ever displayed, never the complete standard. Without an add-on the skill still runs, answering ISO 27001-shaped questions from the free Secure Controls Framework cross-reference with every such result labelled. The sequence: install the skill, connect the Ansvar Gateway connector, sign in (a free account is enough), and subscribe per standard. Also available bundled in the ansvar-compliance-skills Claude Code plugin. Try it: "Using Ansvar, what does ISO/IEC 27001 require for a risk treatment plan, and what should ours contain?" Details in the agent skills guide.

    Free tier: seven workflow types with rendered reports

    A free account runs one workflow a month, picked from seven types: STRIDE threat model, generic gap analysis, NIS2, DORA, CRA and EU AI Act gap analyses, and DPIA. Solo doubles that to two runs. The report arrives as JSON or as a watermarked HTML or PDF render with a visible banner marking the inputs as self-asserted. Premium runs the full interview-grounded catalog; Team adds your own documents as evidence. Plans on Pricing.

    Data protection: Austrian DSB decisions and EDPB guidelines

    Scope a search to Austria and you now get the Datenschutzbehörde's enforcement practice: 1,642 DSB and DSK decisions harvested from the official RIS registry, each linking its ris.bka.gv.at page. The corpus also adds 330 EDPB guidelines, recommendations and opinions; on Premium and higher plans these arrive inside EU-scoped search results and through the guidance tool. Both join the French CNIL deliberations already served, and every row cites the official publisher page.

    Free tier signup no longer goes through checkout

    Signing up for the free tier is now a plain sign-in: pick Google, Microsoft, or email at app.ansvar.eu/account and the account is provisioned on the spot. The €0 checkout flow is retired; existing free subscriptions keep working unchanged. Paid plans still go through Stripe checkout.