No tracking. No cookie wall.·100 % EU-hosted on Hetzner
Auditable AI · Compliance · Legal · Security

Make Claude, Cursor, and Copilot competent at compliance, legal, and security work.

Article-level citations for compliance, legal, and security work — in the AI client your team already uses. You bring the AI. We bring the regulations, frameworks, and case law.

Free and Premium are open. Team & Company on waitlist.
0
Audited jurisdictions
0
Security frameworks
0
EU regulations
Standards
STRIDELINDDUNOWASP ASVSISO/SAE 21434ISO 27001ISO 42001NIST CSFCIS ControlsGDPREU AI ActDORANIS2STRIDELINDDUNOWASP ASVSISO/SAE 21434ISO 27001ISO 42001NIST CSFCIS ControlsGDPREU AI ActDORANIS2
Workflows by team

One platform. Three audiences. Same evidence trail.

Security engineering, GRC and privacy, and legal teams each get the workflow shape they expect — on a shared corpus of regulation, standards, and your own internal documents.

GRC, privacy, resilience

Gap analysis against the regimes that bite

DORA, NIS2, EU AI Act, and DPIA workflows that surface gaps with article-level citations and exportable audit trails. Structured workflow tools are Team tier (waitlist); Free and Premium answer the same questions as search-grounded citation work in your own AI client.

  • DORA + NIS2 readiness
  • EU AI Act governance
  • Multi-jurisdiction DPIA
  • ISO 42001 control mapping
Legal research

Cross-jurisdiction answers across 29 legal systems

Legislation, case law, and preparatory works — current text, source URLs, freshness dates, with private documents and customer evidence in the same citation contract.

  • Legislation + case law
  • Contract and policy review
  • Cross-border conflicts
  • Private documents inline
Security engineering

Threat models with control evidence

STRIDE, LINDDUN, ISO/SAE 21434 TARA, and OWASP ASVS reviews — findings mapped to ASVS, ISO 27001, and the regulations that make them urgent.

  • STRIDE · LINDDUN · TARA
  • OWASP ASVS evidence
  • ISO 27001 control mapping
  • Architecture review packs
Why Ansvar

What auditable actually means

We do not answer without sources. We do not hide failed lookups. The product is the audit trail.

01

Complex reasoning, not keyword search

Threat models, gap analyses, and legal questions that span standards, regulations, and internal policies — answered across jurisdictions in one pass, with every claim tied to the exact source.

02

Auditability is the product

Every answer carries its sources. Every workflow carries its trace. When a source is unavailable, we show it — we do not invent.

03

Bring your own AI client

One MCP connection (Model Context Protocol — the open standard that lets AI assistants call external tools). Use Claude, Cursor, VS Code, GitHub Copilot, Open WebUI — any client good at tool-calling. Same evidence trail whether the task starts in security engineering, GRC, privacy, or legal.

What customers do

Threat models, gap analyses, legal research — one cited flow

Six of the questions security, compliance, and legal teams bring to Ansvar on any given Tuesday. Every answer ships with its sources. On Free and Premium, your own AI client runs these as search-grounded citation work; structured workflow tools with exportable audit trails are Team and Company tier (waitlist).

Threat modeling · STRIDE

STRIDE mapped to OWASP ASVS and ISO 27001

>Run STRIDE on this payment architecture and map findings to ASVS and ISO 27001 Annex A.
Threat model, control mapping, and cited mitigation evidence in one report.
Automotive cyber · TARA

ISO/SAE 21434 TARA with UNECE R155 evidence

>Does our TARA cover UNECE R155 §7.3 and ISO/SAE 21434 clause 9.5?
Gap list with exact clause numbers, attack paths, and control evidence.
Operational resilience

DORA and NIS2 incident-readiness review

>Compare our incident response runbook against DORA and NIS2 notification duties.
Timeline gaps, owner actions, and source-backed evidence for audit review.
Multi-jurisdiction DPIA

DPIA across three jurisdictions in minutes

>Compare employee-monitoring rules in NL, DE, and FR — is a joint DPIA required?
Cited statutory provisions from three jurisdictions, side by side.
Contract review

Contract and document review with sources

>Flag provisions in this vendor contract that conflict with DORA Art. 28.
Inline findings with article-level citations on both sides.
Live regulatory research

Research across 29 jurisdictions

>Is Article 15 of the Dutch AVG still in force?
Current statute, source URL, and freshness date.
Done for you

Need the deliverable today?

Fixed-scope consulting engagements from €2,000 — threat models, DPIAs, and gap analyses delivered by Ansvar, scoped on a call. See services.

Provenance

Every claim grounded in source documents

Each assertion in a threat model, gap analysis, or research answer is traced back to the exact page and paragraph — with confidence scores and direct links.

Claude, connected to the Ansvar Gateway, answering a DORA Article 28 question with a structured mapping to ISO/IEC 27001:2022 Annex A controls — DORA paragraph on the left, core obligation in the middle, ISO controls cited on the right.

Every answer is source-backed — with jurisdiction, article, and source URL.

Every workflow is traceable — tool calls, data sources, and confidence scores are persisted.

Workflow results are exportable — audit-ready metadata for enterprise review (workflow tools: Team and Company tier).

Failed sources are visible — if a data source is unavailable, we say so; we do not fall back to AI guesswork.

Citations are validated — a deterministic pipeline cross-checks every reference before the answer renders.

How it works

From your AI client to a cited answer

Ansvar connects through MCP, without becoming another chatbot. The gateway handles retrieval and citation validation behind the scenes; the conversation stays in your AI client.

CLAUDE · ~/settings/connectors · add server
url>https://gateway.ansvar.eu/mcp
TLS 1.3 · handshake complete
OAuth 2.1 PKCE · client registered · token issued
tools/list · Ansvar tools loaded
connected// Ansvar tools now visible in your AI client's tool palette.
Trust · Sovereignty · Openness

Inspect every source. Read the open connectors. Verify every answer.

EU-hosted, no model proxy, open connector code. The things your procurement team asks about on call #2.

EUHetzner

EU infrastructure

Hosted in the EU on Hetzner. Cloudflare provides edge and TLS termination under SCCs. GDPR-compliant processor agreements available.

0model proxy

Your model, your traffic

Ansvar runs no server-side AI model. Inference flows directly from your AI client to your model provider — we never see or proxy it.

Apache 2.0connectors

Open legal connectors

Open Law connectors ship under Apache 2.0 — inspect how each corpus is parsed and sourced, and reuse them in your own stack. The hosted gateway runtime is not open source.

For agent builders

Plug in to any agent that speaks MCP

Building an agent? Connect any MCP client to gateway.ansvar.eu/mcp — same OAuth, same citation contract. See setup.

Stop guessing. Start citing.

Run your first threat model, gap analysis, or legal research session in the AI client you already use. Every answer comes back with its sources.