SIS-licensed ISO clauses and controls·an add-on inside the AI clients and agents you already use

    Changelog

    New corpora, gateway capabilities, and product changes — dated as they ship.

    September 2026

    North Rhine-Westphalia's court decisions join the German case law

    German case law on the gateway was federal: the Bundesgerichtshof, the Bundesverwaltungsgericht, the Bundesfinanzhof, the Bundesarbeitsgericht, the Bundessozialgericht and the Bundesverfassungsgericht, as Rechtsprechung im Internet publishes them. Most German litigation never reaches those benches. Ask about a dismissal dispute or a tenancy case and your agent found the federal court's last word on the question, or nothing.

    The corpus now serves 281,813 decisions from two publishers. Beside the 84,156 federal decisions sit 197,657 from NRWE, the Rechtsprechungsdatenbank of Justiz NRW: the Oberlandesgerichte, Landgerichte and Amtsgerichte of North Rhine-Westphalia, and the state's administrative, labour, social and finance courts. Each row names the publisher that issued it, and your agent can fetch any decision it finds back from that publisher by its reference.

    Ask your agent: "Using Ansvar, how have the North Rhine-Westphalia courts decided on Kündigungsschutz for employees on parental leave?" It answers from the Landesarbeitsgericht and the Arbeitsgerichte, cited to the decision.

    Both publishers place their decisions outside copyright as amtliche Werke under UrhG §5, and both anonymise before publication. German court decisions are available from Premium. Scope with sources=['german-court-decisions'], or let a German or EU-wide search reach them. The coverage page shows the current set.

    The FCA Handbook, now served

    The gateway now serves the FCA Handbook: the rules, guidance and evidential provisions the Financial Conduct Authority publishes for UK financial services firms, from the Principles for Businesses and the Senior Management Arrangements, Systems and Controls sourcebook through the conduct, prudential and specialist sourcebooks. Each provision is served as the FCA's Handbook API publishes it, under the Open Government Licence v3.0, and every row cites the section on handbook.fca.org.uk.

    The Handbook joins the European financial-regulation corpus, so a question about a UK firm's obligations can be answered beside the EU acts the same firm meets abroad, and a gap analysis or threat model for a regulated firm can cite the Handbook provision by its number.

    Ask your agent: "Using Ansvar, what does SYSC 4.1 require of a firm's governance arrangements?" The answer comes from the Handbook, cited to the section.

    The FCA's technical standards and the Handbook glossary are not yet served; they follow when the FCA's endpoints for them answer. The PRA Rulebook is a separate publication under its own licence and is not part of this release.

    NIS2 answered from the national law, across the EU

    A NIS2 question about a member state used to come back as the directive. From today, a jurisdiction-scoped lookup of Article 20, 21 or 23 serves the national transposing provision where one is verified: the Cyberbeveiligingswet for the Netherlands, the loi NIS2 for Belgium, the BSI-Gesetz for Germany, the cybersäkerhetslagen for Sweden, the NISG 2026 for Austria and their counterparts across the Union, each cited to the article of the national gazette text.

    The mapping is deliberately narrow. A whole article is served only where the national statute carries every paragraph the directive does; otherwise the paragraph that is verified is served and the response says so. The reporting stages of Article 23(4), early warning, notification, intermediate report, final report and progress report, resolve to the national provision for each stage where the statute splits them. Where a state has mapped only part of an article, the gateway serves the EU text and names the mapped paragraphs instead of claiming there is no mapping.

    Ask your agent: "Using Ansvar, what does Belgian law require for the 72-hour incident notification under NIS2?" The answer is Article 35 of the loi du 26 avril 2024, cited to Justel, with the directive available by asking for the EU text.

    Portugal joins the same day. The Regime Jurídico da Cibersegurança annexed to Decreto-Lei n.º 125/2025 is served whole again, article by article, after a parser repair, and its governance, risk-management and reporting articles are mapped like the rest.

    National transposition serving is available on every tier. The coverage page shows the jurisdictions with a served statute; remaining gaps stay visible there rather than being papered over.

    Chinese national law alongside EU regulatory sources

    Chinese product teams preparing for European markets can now find Ansvar's introduction in Simplified Chinese. The page shows how to bring EU regulatory sources and Chinese national-law evidence into the same review, with each jurisdiction's requirements assessed separately.

    The China coverage record lists the served national layer from the National Database of Laws and Regulations (flk.npc.gov.cn): laws of the National People's Congress and its Standing Committee, legislative decisions, and State Council administrative regulations. Text remains in Chinese, with Ansvar-authored English discovery metadata and citations to the original source. This is an unofficial reproduction; consult the promulgating organ's record. Where portal and corresponding paper text differ, the paper text prevails.

    For example: "Using Ansvar, retrieve GDPR Article 32 and Article 51 of China's Personal Information Protection Law. Keep each source's original text, publisher and URL. Ask what you need to know about our processing activities before assessing applicability, and list the evidence we should gather for each requirement separately."

    Local regulations, judicial interpretations and departmental rules are not yet served. GB/GB-T standard body text is excluded, and a reference to a Chinese standard does not establish equivalence with an ISO standard. Licensed ISO clause text requires the relevant entitlement.

    The evaluation pack carries these national-layer limits too. Mainland connectivity, AI-client availability and working language are confirmed with each prospective customer; the Chinese introduction does not change those arrangements.

    UK cyber security guidance from the NCSC, now served

    UK cyber security obligations are written in two registers. The statutes (the Network and Information Systems Regulations, the Computer Misuse Act, the Data Protection Act) set the duty; the National Cyber Security Centre explains how to meet it, in guidance collections that regulators, insurers and procurement teams treat as the reference. That second register is now searchable through the gateway beside the UK statutes already served.

    Every page comes from ncsc.gov.uk itself, under the Open Government Licence v3.0, with the source URL, publisher and licence on each row. The crawl ran against the NCSC's own sitemap at a declared pace with an identifying user agent, and a page is only in the corpus when the full text was retrieved and retained; holding pages, navigation indexes and forms are excluded and recorded, never served as content.

    Try it: "Using Ansvar, what does the NCSC say a board should ask about ransomware readiness, and which Cyber Assessment Framework outcomes does that map to?" Or scope a search to the United Kingdom with the cyber security sector and a plain term such as supply chain.

    The UK cyber corpus sits in the same consolidated European cyber security service as the Finnish, Dutch and Swedish authorities, so a NIS2 gap analysis for a group with a UK subsidiary can cite the NCSC guidance beside the national regulators' text in one pass.

    Swedish financial rulebook: Finansinspektionen's FFFS now served

    Swedish financial regulation lives on two levels. Riksdagen's acts (lagen om bank- och finansieringsrörelse, värdepappersmarknadslagen, betaltjänstlagen and the rest) set the frame and delegate the detail; Finansinspektionen's författningssamling (FFFS) fills it in — the föreskrifter a bank, fund manager or payment institution is examined against, and the allmänna råd that say how FI reads them. Until today the gateway served the acts only.

    Every FFFS in force now serves from FI's published register: the consolidated text where FI publishes one, the amending instrument where it does not, each provision keyed by chapter and paragraph and cited to the exact PDF on fi.se with the retrieval date FI's terms ask for. Repealed instruments are left out rather than served as if still binding.

    Try it: "Using Ansvar, what does FFFS 2014:1 require of a credit institution's internal control function, and which allmänna råd apply?" — or look a provision up directly, for example FFFS 2014:1 chapter 6.

    The statutes and the rulebook answer together in one search, so a gap analysis or DPIA for a Swedish financial firm can cite the act, the FFFS provision under it, and FI's guidance in one pass.

    Dutch disciplinary tribunal rulings, now served

    The gateway now serves the Netherlands' wettelijk tuchtrecht: the rulings of the statutory tribunals that judge the regulated professions. Decisions of the medical colleges and the Centraal Tuchtcollege voor de Gezondheidszorg sit beside those of the tribunals for advocaten, notaries, accountants, gerechtsdeurwaarders, veterinarians and the maritime disciplinary court. All come from the KOOP Open Data Tuchtrecht collection, refreshed from the index the government publishes each day.

    The gateway serves each ruling in full text, cited to its source and anonymised as the tribunal publishes it. These sit next to the Dutch statute law, court decisions and parliamentary history already on the gateway, so you can follow how a profession's own tribunal has reasoned, not only what the statute says.

    Ask your agent: "Using Ansvar, how has the medical disciplinary tribunal ruled on informed consent when a patient later disputed the procedure?" The answer comes from the tuchtcollege's own decisions, cited case by case.

    The rulings are available from Premium. Scope a search with sources=['dutch-tuchtrecht'], or let a Netherlands search reach them. The coverage page shows the current set.

    Dutch rechtbanken and gerechtshoven join the case-law corpus, with court and date filters

    Until this week the gateway served Dutch case law from the Hoge Raad alone. It now serves the decisions that rechtspraak.nl publishes as open data from every court in the roster: the highest courts, the gerechtshoven and the rechtbanken, with new decisions following the publisher's own releases.

    search gained filters for case-law evidence. court takes the corpus's own court code (HR, RVS, CRVB, CBB, GHAMS, RBAMS and the rest), date_from and date_to bound the decision date as full ISO dates. Statute rows are unaffected; the filters are available from Premium, and a filter name the tool does not declare is refused with a structured error rather than ignored.

    Ask your agent: "Using Ansvar, what has the Rechtbank Amsterdam decided on ontruimingsbescherming since January 2026?" The answer comes from the court's own decisions, each cited by ECLI with a deeplink to rechtspraak.nl.

    Decisions are available from Premium. Scope a search with sources=['dutch-court-decisions'] or let a Netherlands search reach them, and fetch a decision by ECLI with get_decision. The coverage page shows the current set.

    European Central Bank law and supervisory guidance, now served

    The gateway now serves the European Central Bank's legal acts in force: the regulations, decisions and guidelines the ECB adopts for the Eurosystem and for banking supervision, cited to the article as the Publications Office publishes them. The ECB's opinions on draft national and Union legislation sit beside them, back to the first years of the Bank, together with its memoranda and agreements.

    Banking Supervision material joins in the same source. The ECB guides on capital and liquidity assessment, materiality and assessment methodology, the supervision newsletter articles, the public consultations, the supervisory sanctions register with each decision, the cyber resilience oversight expectations and the TIBER-EU framework are served from the ECB's own pages under the Bank's reuse terms, with the source notice on every row.

    Ask your agent: "Using Ansvar, what does the ECB expect for DORA threat-led penetration testing?" The answer comes from the TIBER-EU guide and the ECB's own opinion on the regulation, cited to the section.

    Legal acts and the sanctions register are on the free tier; the supervisory guidance is available from Premium. Scope with sources=['ecb'], or let an EU-wide search reach it. The coverage page shows the current set.

    August 2026

    Ansvar is in the Microsoft Teams and M365 Copilot store

    The Ansvar agent for Microsoft 365 Copilot passed Microsoft's store validation and is now listed in the Microsoft Teams and M365 Copilot store. Add it from the store (your tenant admin may need to allow it first), sign in with your Ansvar account, and the agent answers from the gateway with a citation to the official source on every answer. Copilot Studio and every other MCP client keep working as before: see Setup.

    Italian law — Normattiva statutes and the Codice Privacy, now served

    Italian national legislation now answers through the gateway, and Italy sits with the live jurisdictions on our coverage page. The corpus is the consolidated text published on Normattiva — the official legislation portal the Istituto Poligrafico e Zecca dello Stato runs for the Presidenza del Consiglio dei Ministri — and every row cites back to its Normattiva URN. Italy's data-protection shelf goes live alongside it: the Codice Privacy (D.Lgs. 196/2003 as amended by D.Lgs. 101/2018) and the Garante's provvedimento n. 467 of 11 October 2018, the list of processing that requires a DPIA under GDPR Article 35(4).

    A jurisdiction reaches the coverage page only after we have read its licence ourselves, on the publisher's own pages. Italy rested on two findings, both re-verified against primary sources this week. Legge 633/1941 Article 5 places the texts of official acts of the Italian State and its public administrations outside copyright. And Normattiva's open-data terms moved to Creative Commons BY 4.0 on 1 January 2026, commercial use included — before that they were non-commercial. Normattiva's Avviso legale permits reproduction on three conditions our rows meet: name the source, and state that the text is not the authentic version and is available free of charge.

    Try it: "Using Ansvar, which types of processing does the Garante's provvedimento 467/2018 make subject to a DPIA?" — or ask in Italian: "Using Ansvar, cosa prevede il Codice Privacy sul trattamento dei dati nel rapporto di lavoro?"

    Court decisions are the known gap. Article 5 covers statutes and administrative acts; it does not reach judgments of the Corte di cassazione, the Consiglio di Stato or the Corte costituzionale, which need a separate basis. Italian case law stays out of the corpus until we have one.

    National consumer protection law, now served

    The gateway now serves national consumer protection statutes for Austria, Germany, Estonia, Finland, Latvia, the Netherlands, Norway and Sweden: consumer sales and contract codes, unfair commercial practice acts, distance and off-premises contract rules, unfair contract terms, product safety law, and the consumer ADR and enforcement acts behind them. Every provision carries a citation to its national publisher.

    The EU layer sits beside it. The Consumer Rights Directive, the Unfair Commercial Practices Directive, the Unfair Contract Terms Directive, the General Product Safety Regulation and the price indication rules are served at EU level, so your agent can read a directive and the national statute that transposes it in one conversation.

    Ask your agent: "Using Ansvar, what does Swedish law require before a consumer can cancel a distance purchase?" The answer comes from the statutes as the Riksdag published them, cited to the provision.

    Search in each statute's own language and scope by country. Coverage grows country by country; the coverage page shows the current set.

    Ontario law — provincial statutes and regulations, now served

    Ontario is Canada's largest provincial jurisdiction, and its law now answers through the gateway: the consolidated statutes and regulations published on e-Laws, served in both English and French, with every citation linking back to ontario.ca. The King's Printer for Ontario permits reproduction of statutes, regulations and judicial decisions without charge; our rows carry that attribution and the required not-an-official-version notice.

    The same release refreshed the rest of the Canadian shelf. The federal corpus and British Columbia are current again, and the corpus data now records each Act's commencement status — groundwork for showing you, in a future release, when a provision you found is not yet in force. Canadian medical-device coverage (SOR/98-282) was refreshed to its 2026 amendments, and its sections now carry their published headings instead of bare section numbers.

    Try it: "Using Ansvar, what does Ontario's PHIPA require before a hospital discloses personal health information?" — or ask in French: "Using Ansvar, que prévoit la Loi de 2010 sur la responsabilisation du secteur parapublic?"

    Case law is the known gap: Supreme Court of Canada decisions are licence-cleared for reproduction but the publisher's access controls block automated retrieval, so we are pursuing the official route rather than working around it. Coverage lands when that conversation does.

    BIO2 — the Dutch government security baseline, now served

    Dutch public-sector bodies — Rijk, provincies, gemeenten, waterschappen — measure their information security against the Baseline Informatiebeveiliging Overheid 2 (BIO2). Version 1.3, as published in the Staatscourant, is now a corpus on the gateway: Deel 1 (the framework — obligations, ISMS, risk management, the statement of applicability, governance, suppliers, the Cbw relationship) and every Deel 2 overheidsmaatregel, served verbatim from the official publication.

    Each measure carries its NEN-EN-ISO/IEC 27002:2022 control number and whether it falls under the Cyberbeveiligingsregeling sector overheid — the ministerial regulation, in force with the Cyberbeveiligingswet since 15 August 2026, that turns the BIO2 measures into the statutory minimum for the sector overheid. So a DPIA, gap analysis or threat model for a Dutch public body can cite the measure, the ISO control behind it, and the legal duty that binds it, in one pass.

    Try it: "Using Ansvar, which BIO2 measures apply to logging and monitoring, and are they mandatory under the Cyberbeveiligingswet?" — or look a measure up directly by its number (for example 5.01.01).

    The ISO 27002 controls themselves are not reproduced — the BIO2 references them by number, and so do we; the norm text stays with NEN.

    A DPIA that knows which country it is in

    GDPR Article 35 is shared; the national lists that sit on top of it are not. A DPIA run now screens against the supervisory authority's own Article 35(4) material for 29 jurisdictions — the EU, Iceland, Liechtenstein, Norway, Switzerland and the United Kingdom — querying each in the authority's own language, because an English meta-query misses a list published in Greek, Lithuanian or Icelandic. What comes back keeps the status the authority gave it: Germany's published DSK list and Estonia's expressly indicative guidance are not the same thing, Cyprus's material is a pre-opinion advisory draft and is labelled as one, and Switzerland has no list mechanism at all — its screen runs on the statutory high-risk test in DSG Articles 22 and 23. Luxembourg, Malta and Slovakia are identified but not reproduced: the run records the source as unavailable rather than rebuilding it from model memory, and a negative screening outcome is never grounded on a list that was not actually fetched. The DPIA coverage register publishes the state of every jurisdiction — authority, source, legal status, verification date, known limitation. Try it: "Using Ansvar, run a GDPR Article 35 DPIA for our new HR analytics platform. Confirm the relevant jurisdictions with me, screen the applicable national trigger sources, then continue to the prior-consultation determination."

    An agent skill for every workflow family

    Every workflow family now has an installable agent skill: gap analysis, threat modelling, impact assessments (DPIA and FRIA), TARA, tender review, vulnerability decisions, adversary tabletop, document review, and SORA drone operations — nine in all. A skill is one markdown file the agent reads once and then applies in every conversation, and each of these carries the run loop (how to open a run, what each stage asks for, how to resume one), the delivery rules that govern what a finished report must contain and how the agent relays the receipt the server hands back, the family's own method, and starter questions to paste. They are not copy written for the website: each is generated from the same instruction library the workflow engine runs, then imported here by checksum — the published file, the release manifest that hashes it, and the pinned build are checked against each other in CI, so a skill cannot describe a workflow the engine no longer implements. Install from agent skills: take the SKILL.md or the ready-made ZIP, and connect the gateway. Try it: "Using Ansvar, run a DPIA for our new HR analytics platform and take it through to the prior-consultation determination."

    Medical-device gap analysis, proven end to end

    "Using Ansvar, run a gap_analysis_mdr workflow for our device and assess the Annex I GSPRs against our current technical documentation." Your agent can now run that against a workflow we have proven in production, not just published. On 2026-08-11 each of the three medical-device workflows completed a full run on the live platform, from scoping interview to rendered report, and the runs were accepted on correctness: citations round-trip through the platform's lookup tools with their source, publisher and licence intact, and requirements without supporting evidence carry an explicit flag rather than a decorative citation.

    gap_analysis_mdr assesses all General Safety and Performance Requirements of MDR Annex I, surfaces the Annex VIII device class because it sets the conformity route, and maps each requirement to the harmonised-standard clauses that demonstrate conformity: IEC 62304, IEC 81001-5-1, ISO 14971, IEC 62366-1 and their siblings. gap_analysis_ivdr does the same for IVDR Annex I, with analytical and clinical performance under Annex XIII treated as the load-bearing requirement. gap_analysis_mdcg_cyber assesses device cybersecurity against MDCG 2019-16 rev. 1 across secure design, technical documentation and post-market obligations, with MITRE ATT&CK available for adversary context.

    The proof runs assessed fictional manufacturers built with deliberate weaknesses, and the point is what happened to those weaknesses: every planted gap surfaced as a finding, and the assessments found gaps beyond the planted ones, including one requirement the fixture had misclassified as inapplicable. Where the case-law layer returned nothing on point, the finding says case_law_unconfirmed: true instead of citing something adjacent. An assessment you would hand a notified body has to behave that way.

    The guidance layer behind these workflows is current: the served corpus is reconciled against the Commission's MDCG guidance register including the 2026 series and revisions, and the MDR and IVDR harmonised-standards lists follow the June 2026 implementing decisions.

    All three workflows are available from the Premium plan. Ask list_workflow_types for the catalog, or start with the prompt above.

    Ask which regulatory deadlines are ahead

    "Using Ansvar, what regulatory deadlines hit us in the next 18 months?" Your agent can now answer that from a curated calendar rather than a client alert's prose. get_regulatory_deadlines returns dated obligation events, soonest first: application dates, commencement dates, transposition deadlines. Each row cites the provision that states the date, so you can read the source yourself.

    The calendar tracks instruments as amended. Where an omnibus regulation moved a date, or a corrigendum corrected one, the row carries the corrected date and cites the document that states it. Rows name their date precision, record when a curator last verified them, and carry a day count computed at request time.

    Ask for a jurisdiction and the answer includes the EU-level instruments that bind there. A query for Germany returns the AI Act's staged application dates alongside German national instruments, because an EU regulation binds in every member state. A request parameter turns that off.

    Coverage at launch is curated and leans European. Every response names what was in scope, and states on every call that absence of a row is not absence of an obligation. The tool serves only from a signature-verified dataset: if a newer dataset fails verification, the previous one keeps serving and every response says so, and if none has ever loaded, the tool refuses with a typed error.

    get_regulatory_deadlines is available from the Premium plan. Dataset state and freshness report through get_regulatory_intelligence_status, free on every plan.

    Let your AI decide whether Ansvar fits

    Before you connect anything, your own AI can now tell you whether Ansvar is worth connecting. The new /evaluate page carries a single evaluation pack — copy it into Claude, ChatGPT, Copilot, Gemini, or any client your team already uses. No account, and no browsing capability needed: the pack is self-contained, with the audited coverage snapshot embedded.

    Your agent asks four questions — jurisdictions, frameworks in play, which AI clients you run, what your agents should do — and then writes a fit report bound to the evidence in the pack. The verdict is one of four: documented fit, conditional fit, no current fit, or insufficient evidence. The rules are explicit and visible on the page: coverage claims may come only from the embedded snapshot, one missing non-negotiable jurisdiction outweighs any number of adjacent matches, and on a negative verdict the report must recommend against signing up rather than steer you to adjacent coverage. We wrote the pack, and it says so — vendor-authored evidence, weighed accordingly.

    Agents that can fetch URLs find the same pack at /agent-evaluation.md, versioned copies alongside. On a fit, the report ends with the free verification path: connect on the Free plan and re-check the coverage it leaned on with live calls.

    Ask what regulators actually published

    Your agent can now ask what has actually been published, and get an answer from records rather than from memory. Each one carries its title, a link to the original publisher page, the publication and observation dates, official identifiers where the source assigns them, and a full citation naming the licence and linking its terms.

    What is monitored is the EU Official Journal L series — regulations, directives, implementing and delegated acts as they appear — alongside announcements from the European Commission, the EDPB and ENISA, and the national gazettes of a growing set of European jurisdictions. Every source passes the same per-source licensing gate before a single fetch, and get_regulatory_intelligence_status reports the live enrolment: which sources are watched, how fresh each one is, and when its baseline ran. That tool is the authoritative list, and it works on every plan including Free.

    Coverage is bounded, and the tools say where the boundary is. Each source reports only from its own enrolment baseline onward, so an empty result means nothing matched inside that window — never that the regulators were quiet. When every selected source is stale or has never synced, the search fails and names the state of each one instead of returning an empty list that would read as silence.

    This is publication monitoring, not amendment tracking: it tells you an act was published, not how a law you already follow changed. Provision-level amendment feeds are not available today, so the gateway withholds get_changes until a supported feed can answer it.

    search_regulatory_updates and get_regulatory_update are available from the Premium plan. get_regulatory_intelligence_status is free on every plan.

    Workflows and the control library, explained

    The site now has a Workflows section covering both ways you can run the same work: yourself, in the AI client you already use, or as an engagement we run and review as practitioners. The first workflow family has its own page — TARA, the threat-analysis-and-risk-assessment family for vehicles, OT, rail, robots and drones, sharing one enterprise risk spine. Services keep their URL and now live in the Workflows menu.

    The canonical control library also has a page for the first time. It explains what a canonical control is, why a flat framework tag cannot carry a coverage claim, the five relationships a mapping can record, and why the library stores citation pointers rather than licensed clause text. It is candid about where coverage stands: published crosswalks arrive untyped and claim nothing until a person reviews them, so the page shows what one control reaches today and names the frameworks that are registered but not yet mapped. A worked crosswalk from a real session walks ISO/IEC 27001 Annex A.5.26 through the spine to 24 NIST CSF 2.0 subcategories, with the provenance of every hop. The control library is available on Team and Company plans.

    Service credentials are full seats

    A service credential — the org-owned seat a Team or Company admin mints for headless clients such as n8n, CI, or a scheduled monitoring agent — now carries the same tool surface as a signed-in seat on its plan: search, workflow runs, document upload and report generation, under the same tier gates, drawing from the organization's pooled quota. This supersedes the read-only boundary the launch entry of 2026-07-26 described. Each credential keeps a monthly workflow-run ceiling, by default half of what one seat contributes to the pool, so one runaway agent cannot drain what the rest of the organization shares. A credential takes a seat of its own, next to yours; add seats as your agents grow. Setup guide: Service credentials.

    July 2026

    Sign up with email and password

    Free-tier signup is now identity-native two ways: sign in with Microsoft Entra ID or Google as before, or register directly with an email address and password at app.ansvar.eu. Registration asks for terms acceptance up front, verifies the address by email before the account is usable, and sits behind a fail-closed bot check. Nothing about the tier changed — a free account still connects your own MCP client to the gateway with the same limits, and paid plans still upgrade through checkout. If your organisation blocks third-party SSO, this removes the last reason you couldn't try the connector.

    ISO Standards Expert: an agent skill for the standards add-on

    The iso-standards-expert skill teaches an AI assistant to answer standards questions from served clause text instead of model memory: it fetches the clauses a question needs through the ISO Standards add-on, quotes them verbatim with the SIS copyright notice on every excerpt, and reports an unevaluated-scope list whenever the licence coverage ceiling withholds a fetch — only selected parts of a standard are ever displayed, never the complete standard. Without an add-on the skill still runs, answering ISO 27001-shaped questions from the free Secure Controls Framework cross-reference with every such result labelled. The sequence: install the skill, connect the Ansvar Gateway connector, sign in (a free account is enough), and subscribe per standard. Also available bundled in the ansvar-compliance-skills Claude Code plugin. Try it: "Using Ansvar, what does ISO/IEC 27001 require for a risk treatment plan, and what should ours contain?" Details in the agent skills guide.

    Free tier: seven workflow types with rendered reports

    A free account runs one workflow a month, picked from seven types: STRIDE threat model, generic gap analysis, NIS2, DORA, CRA and EU AI Act gap analyses, and DPIA. Solo doubles that to two runs. The report arrives as JSON or as a watermarked HTML or PDF render with a visible banner marking the inputs as self-asserted. Premium runs the full interview-grounded catalog; Team adds your own documents as evidence. Plans on Pricing.

    Data protection: Austrian DSB decisions and EDPB guidelines

    Scope a search to Austria and you now get the Datenschutzbehörde's enforcement practice: 1,642 DSB and DSK decisions harvested from the official RIS registry, each linking its ris.bka.gv.at page. The corpus also adds 330 EDPB guidelines, recommendations and opinions; on Premium and higher plans these arrive inside EU-scoped search results and through the guidance tool. Both join the French CNIL deliberations already served, and every row cites the official publisher page.

    Free tier signup no longer goes through checkout

    Signing up for the free tier is now a plain sign-in: pick Google, Microsoft, or email at app.ansvar.eu/account and the account is provisioned on the spot. The €0 checkout flow is retired; existing free subscriptions keep working unchanged. Paid plans still go through Stripe checkout.