What Ansvar does

    Ansvar gives your AI assistant cited access to EU and national law, standards and security data, so its compliance answers come with a source you can check instead of a guess. You connect it once to Claude, Copilot, ChatGPT, Cursor or any assistant that supports MCP (the open connector standard). Your assistant then calls Ansvar's tools for law, vulnerability data, structured assessments and audit evidence.

    When a source fails or holds nothing, Ansvar returns an explicit error or gap instead of an empty answer, and tells your assistant not to fill the gap from memory.

    Find out what your account can do

    Paste this into your connected assistant:

    Using Ansvar, run get_my_capabilities and describe_capabilities, then tell me which capability areas my plan includes and which tools each one gives me.

    Not connected yet? Quickstart takes you from sign-up to a first cited answer.

    What you can do

    Law and regulation research

    Search EU and national law, regulations and standards by country, framework, sector or source, and fetch one article word for word.

    • You get: The article text with a link to the official publisher, the publisher's name and the licence, so you can check the source yourself.
    • Plans: Every plan. Free searches one source or one country at a time; Solo and above search many sources and countries in one call, within what your plan and add-ons include.
    • Guide: Quickstart

    Try:

    Using Ansvar, retrieve GDPR Article 17 and show its official source link.
    Tools behind it

    search, get_provision, list_coverage, describe_capabilities

    Case law, legislative history and regulator guidance

    Adds court decisions, preparatory works and guidance from regulators to the same search, and fetches one decision or document by reference.

    Try:

    Using Ansvar, find recent Dutch court decisions on dismissal for an urgent reason and cite each one.
    Tools behind it

    search, get_decision, get_preparatory_work, search_guidance

    Claim and citation checking

    Fetches the articles your assistant cited again and compares its quotes and conclusions with the source text.

    • You get: One verdict per citation, or how strong each conclusion is given its sources. Never a legal verdict.
    • Plans: Every plan.
    • Guide: Validate a claim

    Try:

    Using Ansvar, check the GDPR citations in your last answer against the source text before I rely on them.
    Tools behind it

    validate_claim, verify_citations, validate_citation

    Structured assessments (workflows)

    Step-by-step assessments your assistant runs with you: threat models, gap analyses, DPIA and FRIA, TARA, risk assessments, tender reviews and more.

    • You get: A report whose findings cite their sources or are marked unresolved, plus a short summary your assistant shows you word for word.
    • Plans: Every plan, with more assessment types and runs on higher plans. See the plan table and the workflow list below.
    • Guide: Workflows

    Try:

    Using Ansvar, run a NIS2 gap analysis for our managed IT services company and deliver the report.
    Tools behind it

    scope_workflow, list_workflow_types, start_workflow, generate_report

    Your documents

    Upload policies, contracts and evidence, then cite them next to the law.

    • You get: Citations that point at one paragraph of your own document and record a fingerprint of its text, so a later edit shows up.
    • Plans: Team and Company.
    • Guide: Cite your documents

    Try:

    Using Ansvar, review our uploaded supplier contract against GDPR Article 28 and cite the paragraphs you rely on.
    Tools behind it

    register_document_init, get_document_segments, resolve_document_segment

    Your organisation's standards

    Search and quote security standards from your own library the same way you query law.

    • You get: Clause text with its reference and page, and a citation that points at that clause.
    • Plans: The search tools are on Premium, Team and Company. Uploading a standard is not open to customers yet.
    • Guide: Org standards library

    Try:

    Using Ansvar, search my org standards library for access review requirements and quote the clauses.
    Tools behind it

    list_org_standards, search_org_standards, get_org_standard_clause

    Regulatory intelligence

    Tracks what regulators and the EU Official Journal newly published and which dated obligations are coming, and finds EU acts by number or title.

    • You get: Publication records linked to the publisher, deadline rows cited to the act that sets the date, and a report of what the monitor watches.
    • Plans: Monitor status, the EU act finder and change records on every plan. New publications and deadlines on Premium and above.
    • Guide: Regulatory intelligence

    Try:

    Using Ansvar, list the EU regulatory deadlines coming in the next six months for a company in Germany.
    Tools behind it

    get_regulatory_intelligence_status, search_regulatory_updates, get_regulatory_deadlines, discover_eu_legislation

    Vulnerability intelligence

    Looks up CVEs, CISA's known-exploited list, exploit likelihood scores, public exploits and CISA advisories for industrial systems.

    • You get: CVE and advisory records with scores, dates and source links, and when each data feed last updated.
    • Plans: Every plan. Premium adds the CAPEC, CWE and D3FEND attack-pattern catalogues.
    • Guide: Vulnerability intelligence

    Try:

    Using Ansvar, is CVE-2024-3400 in CISA KEV, and what is its EPSS score?
    Tools behind it

    search_cve, get_cve_details, check_kev_status, search_ics_advisories

    Effective risk (experimental)

    Rescores a CVE for one of your assets and its controls, ranks which control investment removes the most risk, and records reviewed exploitability decisions as OpenVEX.

    • You get: An adjusted score with the rule behind each change, a ranked investment list, and OpenVEX documents.
    • Plans: Team and Company can use effective risk directly. On Premium you cannot call it yourself: the vulnerability assessment, deferral dossier and ICS advisory-to-risk workflows use parts of it for you during a run.
    • Guide: Effective risk

    Try:

    Using Ansvar, score CVE-2024-3400 against our internet-facing firewall with management access limited to a jump host.
    Tools behind it

    effective_risk_inline, simulate_control_investment, export_vex

    Control library and crosswalks

    One control set, based on NIST SP 800-53 rev. 5, mapped to ISO 27001, NIS2, DORA, CRA and other frameworks.

    • You get: Controls, the framework requirements each one maps to with how closely and whether a person has reviewed the link, and crosswalks from one framework to another.
    • Plans: Team and Company.
    • Guide: Control library

    Try:

    Using Ansvar, crosswalk NIS2 Article 21 to ISO 27001 through the control library.
    Tools behind it

    list_controls, get_control, crosswalk, coverage

    EU regulation engines

    Decides which EU regulations apply to a product or company, compares how regulations treat one topic, and lists the evidence an auditor expects.

    • You get: A cited verdict per regulation, side-by-side requirements, and evidence checklists.
    • Plans: Team and Company. On Premium, a deferral dossier workflow uses the applicability check for you.
    • Guide: EU regulation engines

    Try:

    Using Ansvar, check which EU regulations apply to a connected home camera sold in the EU.
    Tools behind it

    check_applicability, compare_requirements, get_evidence_requirements, map_controls

    Audit ledger and receipts

    Keeps a tamper-evident record of your organisation's Ansvar calls, sealed each day with an independent timestamp.

    • You get: Receipts you can list, verify and decrypt, and an audit package your auditor can verify without access to Ansvar.
    • Plans: Company.
    • Guide: Audit ledger

    Try:

    Using Ansvar, export our audit package for last month so our auditor can verify it offline.
    Tools behind it

    list_receipts, get_receipt, verify_receipt, export_audit_package

    Plans and capabilities

    Swipe sideways to see every plan.

    CapabilityFreeSoloPremiumTeamCompany
    Search and fetch law, regulations and standardsPartial ¹YesYesYesYes
    Check citations and claimsYesYesYesYesYes
    Vulnerability data (CVE, KEV, EPSS, ICS advisories)YesYesYesYesYes
    Monitor status, EU act finder, change recordsYesYesYesYesYes
    New regulatory publications and upcoming deadlinesNoNoYesYesYes
    Case law, legislative history, regulator guidanceNoNoYesYesYes
    CAPEC, CWE, D3FEND and IETF RFCsNoNoYesYesYes
    Assessment runs (workflows)1 run/month, 7 types2 runs/month, 7 types5 runs/month, most types ²20 runs per seat/month, all typesAll types ³
    Assessment report formatsWatermarked HTML or PDF, or JSONWatermarked HTML or PDF, or JSONJSON, HTML, PDF, WordJSON, HTML, PDF, WordJSON, HTML, PDF, Word
    Upload and cite your own documentsNoNoNoYesYes
    Search your organisation's standardsNoNoPartial ⁴Partial ⁴Partial ⁴
    Effective riskNoNoPartial ⁵YesYes
    Control library and crosswalksNoNoNoYesYes
    EU regulation enginesNoNoPartial ⁶YesYes
    Audit ledger and receiptsNoNoNoNoYes
    1. Free searches one source or one country at a time. Solo and above search many sources and countries in one call, within what your plan and add-ons include.
    2. Premium runs every assessment that works from your description of a system. Assessments that read your uploaded documents, and a few specialist types, need Team.
    3. Company runs are counted but have no fixed monthly limit; use falls under the fair-use terms of your contract.
    4. The search tools are on these plans, but uploading a standard is not open to customers yet, so the library starts empty.
    5. On Premium you cannot call effective risk yourself: the vulnerability assessment, deferral dossier and ICS advisory-to-risk workflows use parts of it for you during a run.
    6. On Premium, a deferral dossier workflow uses the applicability check for you. The other engines need Team.

    Quotas and prices are on pricing. A tool outside your plan does not appear in your assistant's tool list; if your assistant calls it anyway, the error names the plan that includes it.

    Add-ons on any plan

    • ISO standards. SIS-licensed ISO standards (27001, 27002, 27005, 42001, 21434), bought one standard at a time on any plan and searched like any other source. See ISO standards add-on.
    • Sources served on instruction. Some court-decision sources are not searchable on any plan by default. Ansvar serves them only to an organisation that instructs it in writing, and grants start after our legal review. See Sources served on instruction.

    Which assessments each plan can run

    Free and Solo (1 and 2 runs a month), on a system you describe:

    • STRIDE threat model
    • Gap analysis: general, NIS2, DORA, CRA and the EU AI Act
    • DPIA

    Premium (5 runs a month) adds:

    • LINDDUN privacy threat model, and threat models for AI/ML systems, operational technology (industrial control systems) and drones
    • Threat analysis and risk assessment (TARA) for vehicles, robots, rail, operational technology and drones, and a counter-drone resilience assessment
    • Fundamental rights impact assessment (FRIA) under the EU AI Act, the German and Swedish DPIA, and a DPIA for drone data capture
    • Gap analyses for Dutch NIS2, medical devices (MDR, IVDR, medical-device cybersecurity), machinery, UNECE R155, AMLR and MiCA, and drone operator and product rules
    • SORA, the risk assessment behind a drone operating authorisation in the EU specific category
    • Enterprise risk assessment
    • Vulnerability assessment, vulnerability deferral dossier and ICS advisory-to-risk

    Team and Company (every type) add:

    • Document review with paragraph citations
    • Public tender review and tender audit (general, Sweden, Netherlands)
    • DORA ICT contracts and DORA register of information
    • Polish NIS2 gap analysis
    • Adversary tabletop exercise
    • Scoped threat update for an existing threat model
    • Defensibility Assessment (experimental): tests a proposed legal or compliance decision against supporting and contrary authority
    • Supplier Assurance Review (experimental): checks a supplier's certificates and assurance reports against law, standards and your own policy

    Your assistant can list the live set with list_workflow_types. The Workflows guide covers how a run works and how the report is delivered.

    Why Ansvar refuses instead of guessing

    A wrong compliance answer costs more than no answer. Each capability on this page reports a gap or names the unavailable source rather than filling the hole with a guess. Tell your assistant to pass those messages on to you; see Instruct your agent for the wording.