What Ansvar does
Ansvar gives your AI assistant cited access to EU and national law, standards and security data, so its compliance answers come with a source you can check instead of a guess. You connect it once to Claude, Copilot, ChatGPT, Cursor or any assistant that supports MCP (the open connector standard). Your assistant then calls Ansvar's tools for law, vulnerability data, structured assessments and audit evidence.
When a source fails or holds nothing, Ansvar returns an explicit error or gap instead of an empty answer, and tells your assistant not to fill the gap from memory.
Find out what your account can do
Paste this into your connected assistant:
Using Ansvar, run get_my_capabilities and describe_capabilities, then tell me which capability areas my plan includes and which tools each one gives me.Not connected yet? Quickstart takes you from sign-up to a first cited answer.
What you can do
Law and regulation research
Search EU and national law, regulations and standards by country, framework, sector or source, and fetch one article word for word.
- You get: The article text with a link to the official publisher, the publisher's name and the licence, so you can check the source yourself.
- Plans: Every plan. Free searches one source or one country at a time; Solo and above search many sources and countries in one call, within what your plan and add-ons include.
- Guide: Quickstart
Try:
Using Ansvar, retrieve GDPR Article 17 and show its official source link.Tools behind it
Case law, legislative history and regulator guidance
Adds court decisions, preparatory works and guidance from regulators to the same search, and fetches one decision or document by reference.
- You get: Decisions and documents with their court or publisher, date and citation.
- Plans: Premium, Team and Company.
- Guide: Case law and legislative history
Try:
Using Ansvar, find recent Dutch court decisions on dismissal for an urgent reason and cite each one.Tools behind it
Claim and citation checking
Fetches the articles your assistant cited again and compares its quotes and conclusions with the source text.
- You get: One verdict per citation, or how strong each conclusion is given its sources. Never a legal verdict.
- Plans: Every plan.
- Guide: Validate a claim
Try:
Using Ansvar, check the GDPR citations in your last answer against the source text before I rely on them.Tools behind it
Structured assessments (workflows)
Step-by-step assessments your assistant runs with you: threat models, gap analyses, DPIA and FRIA, TARA, risk assessments, tender reviews and more.
- You get: A report whose findings cite their sources or are marked unresolved, plus a short summary your assistant shows you word for word.
- Plans: Every plan, with more assessment types and runs on higher plans. See the plan table and the workflow list below.
- Guide: Workflows
Try:
Using Ansvar, run a NIS2 gap analysis for our managed IT services company and deliver the report.Tools behind it
scope_workflow, list_workflow_types, start_workflow, generate_report
Your documents
Upload policies, contracts and evidence, then cite them next to the law.
- You get: Citations that point at one paragraph of your own document and record a fingerprint of its text, so a later edit shows up.
- Plans: Team and Company.
- Guide: Cite your documents
Try:
Using Ansvar, review our uploaded supplier contract against GDPR Article 28 and cite the paragraphs you rely on.Tools behind it
register_document_init, get_document_segments, resolve_document_segment
Your organisation's standards
Search and quote security standards from your own library the same way you query law.
- You get: Clause text with its reference and page, and a citation that points at that clause.
- Plans: The search tools are on Premium, Team and Company. Uploading a standard is not open to customers yet.
- Guide: Org standards library
Try:
Using Ansvar, search my org standards library for access review requirements and quote the clauses.Tools behind it
list_org_standards, search_org_standards, get_org_standard_clause
Regulatory intelligence
Tracks what regulators and the EU Official Journal newly published and which dated obligations are coming, and finds EU acts by number or title.
- You get: Publication records linked to the publisher, deadline rows cited to the act that sets the date, and a report of what the monitor watches.
- Plans: Monitor status, the EU act finder and change records on every plan. New publications and deadlines on Premium and above.
- Guide: Regulatory intelligence
Try:
Using Ansvar, list the EU regulatory deadlines coming in the next six months for a company in Germany.Vulnerability intelligence
Looks up CVEs, CISA's known-exploited list, exploit likelihood scores, public exploits and CISA advisories for industrial systems.
- You get: CVE and advisory records with scores, dates and source links, and when each data feed last updated.
- Plans: Every plan. Premium adds the CAPEC, CWE and D3FEND attack-pattern catalogues.
- Guide: Vulnerability intelligence
Try:
Using Ansvar, is CVE-2024-3400 in CISA KEV, and what is its EPSS score?Tools behind it
search_cve, get_cve_details, check_kev_status, search_ics_advisories
Effective risk (experimental)
Rescores a CVE for one of your assets and its controls, ranks which control investment removes the most risk, and records reviewed exploitability decisions as OpenVEX.
- You get: An adjusted score with the rule behind each change, a ranked investment list, and OpenVEX documents.
- Plans: Team and Company can use effective risk directly. On Premium you cannot call it yourself: the vulnerability assessment, deferral dossier and ICS advisory-to-risk workflows use parts of it for you during a run.
- Guide: Effective risk
Try:
Using Ansvar, score CVE-2024-3400 against our internet-facing firewall with management access limited to a jump host.Tools behind it
effective_risk_inline, simulate_control_investment, export_vex
Control library and crosswalks
One control set, based on NIST SP 800-53 rev. 5, mapped to ISO 27001, NIS2, DORA, CRA and other frameworks.
- You get: Controls, the framework requirements each one maps to with how closely and whether a person has reviewed the link, and crosswalks from one framework to another.
- Plans: Team and Company.
- Guide: Control library
Try:
Using Ansvar, crosswalk NIS2 Article 21 to ISO 27001 through the control library.Tools behind it
EU regulation engines
Decides which EU regulations apply to a product or company, compares how regulations treat one topic, and lists the evidence an auditor expects.
- You get: A cited verdict per regulation, side-by-side requirements, and evidence checklists.
- Plans: Team and Company. On Premium, a deferral dossier workflow uses the applicability check for you.
- Guide: EU regulation engines
Try:
Using Ansvar, check which EU regulations apply to a connected home camera sold in the EU.Tools behind it
check_applicability, compare_requirements, get_evidence_requirements, map_controls
Audit ledger and receipts
Keeps a tamper-evident record of your organisation's Ansvar calls, sealed each day with an independent timestamp.
- You get: Receipts you can list, verify and decrypt, and an audit package your auditor can verify without access to Ansvar.
- Plans: Company.
- Guide: Audit ledger
Try:
Using Ansvar, export our audit package for last month so our auditor can verify it offline.Tools behind it
list_receipts, get_receipt, verify_receipt, export_audit_package
Plans and capabilities
Swipe sideways to see every plan.
| Capability | Free | Solo | Premium | Team | Company |
|---|---|---|---|---|---|
| Search and fetch law, regulations and standards | Partial ¹ | Yes | Yes | Yes | Yes |
| Check citations and claims | Yes | Yes | Yes | Yes | Yes |
| Vulnerability data (CVE, KEV, EPSS, ICS advisories) | Yes | Yes | Yes | Yes | Yes |
| Monitor status, EU act finder, change records | Yes | Yes | Yes | Yes | Yes |
| New regulatory publications and upcoming deadlines | No | No | Yes | Yes | Yes |
| Case law, legislative history, regulator guidance | No | No | Yes | Yes | Yes |
| CAPEC, CWE, D3FEND and IETF RFCs | No | No | Yes | Yes | Yes |
| Assessment runs (workflows) | 1 run/month, 7 types | 2 runs/month, 7 types | 5 runs/month, most types ² | 20 runs per seat/month, all types | All types ³ |
| Assessment report formats | Watermarked HTML or PDF, or JSON | Watermarked HTML or PDF, or JSON | JSON, HTML, PDF, Word | JSON, HTML, PDF, Word | JSON, HTML, PDF, Word |
| Upload and cite your own documents | No | No | No | Yes | Yes |
| Search your organisation's standards | No | No | Partial ⁴ | Partial ⁴ | Partial ⁴ |
| Effective risk | No | No | Partial ⁵ | Yes | Yes |
| Control library and crosswalks | No | No | No | Yes | Yes |
| EU regulation engines | No | No | Partial ⁶ | Yes | Yes |
| Audit ledger and receipts | No | No | No | No | Yes |
- Free searches one source or one country at a time. Solo and above search many sources and countries in one call, within what your plan and add-ons include.
- Premium runs every assessment that works from your description of a system. Assessments that read your uploaded documents, and a few specialist types, need Team.
- Company runs are counted but have no fixed monthly limit; use falls under the fair-use terms of your contract.
- The search tools are on these plans, but uploading a standard is not open to customers yet, so the library starts empty.
- On Premium you cannot call effective risk yourself: the vulnerability assessment, deferral dossier and ICS advisory-to-risk workflows use parts of it for you during a run.
- On Premium, a deferral dossier workflow uses the applicability check for you. The other engines need Team.
Quotas and prices are on pricing. A tool outside your plan does not appear in your assistant's tool list; if your assistant calls it anyway, the error names the plan that includes it.
Add-ons on any plan
- ISO standards. SIS-licensed ISO standards (27001, 27002, 27005, 42001, 21434), bought one standard at a time on any plan and searched like any other source. See ISO standards add-on.
- Sources served on instruction. Some court-decision sources are not searchable on any plan by default. Ansvar serves them only to an organisation that instructs it in writing, and grants start after our legal review. See Sources served on instruction.
Which assessments each plan can run
Free and Solo (1 and 2 runs a month), on a system you describe:
- STRIDE threat model
- Gap analysis: general, NIS2, DORA, CRA and the EU AI Act
- DPIA
Premium (5 runs a month) adds:
- LINDDUN privacy threat model, and threat models for AI/ML systems, operational technology (industrial control systems) and drones
- Threat analysis and risk assessment (TARA) for vehicles, robots, rail, operational technology and drones, and a counter-drone resilience assessment
- Fundamental rights impact assessment (FRIA) under the EU AI Act, the German and Swedish DPIA, and a DPIA for drone data capture
- Gap analyses for Dutch NIS2, medical devices (MDR, IVDR, medical-device cybersecurity), machinery, UNECE R155, AMLR and MiCA, and drone operator and product rules
- SORA, the risk assessment behind a drone operating authorisation in the EU specific category
- Enterprise risk assessment
- Vulnerability assessment, vulnerability deferral dossier and ICS advisory-to-risk
Team and Company (every type) add:
- Document review with paragraph citations
- Public tender review and tender audit (general, Sweden, Netherlands)
- DORA ICT contracts and DORA register of information
- Polish NIS2 gap analysis
- Adversary tabletop exercise
- Scoped threat update for an existing threat model
- Defensibility Assessment (experimental): tests a proposed legal or compliance decision against supporting and contrary authority
- Supplier Assurance Review (experimental): checks a supplier's certificates and assurance reports against law, standards and your own policy
Your assistant can list the live set with list_workflow_types. The Workflows guide covers how a run works and how the report is delivered.
Why Ansvar refuses instead of guessing
A wrong compliance answer costs more than no answer. Each capability on this page reports a gap or names the unavailable source rather than filling the hole with a guess. Tell your assistant to pass those messages on to you; see Instruct your agent for the wording.