SIS-licensed ISO clauses and controls·an add-on inside the AI clients and agents you already use
    Sector · Automotive

    Automotive

    Make your TARA — and your CSMS evidence — hold up to UN R155 type approval.

    Ansvar is a gateway for the AI assistant your team already uses — Claude, Microsoft Copilot, any MCP client. Connect it, and every answer below comes back cited to the provision or marked unresolved.

    R155 · R156provision-level
    ISO 21434clause map + cross-refs
    TARAthreat analysis & risk assessment

    Vehicle cybersecurity grounded in the regulations and standards that gate type approval. UN R155 and R156 are addressable provision by provision, with ISO/SAE 21434 and the diagnostic standards surfaced as clause maps and Ansvar cross-references — never the standard text. Run the TARA, the CSMS gap, or an ECU effective-risk pass and cite every finding.

    what we cover

    The law and standards we ground on

    Regulation

    UN R155 (cybersecurity) · UN R156 (software update)

    addressable provision-level

    Standard

    Control mapping: ISO/SAE 21434

    requirement mapping + cross-references — the ISO/SAE 21434 text itself is available as the SIS-licensed add-on (/standards)

    Standard

    Control mapping: UDS · DoIP · SOVD · AUTOSAR diagnostics

    clause mapping, not the standard text

    Regulation

    Repair & maintenance information access — RMI / SERMI

    Reg (EU) 2018/858

    Regulation

    Horizontal: Cyber Resilience Act · GDPR (connected-vehicle data)

    what you can do

    Workflows that turn it into evidence

    assembledPremium

    Vehicle threat model & TARA

    ISO/SAE 21434 over the ECU and asset model — an available analysis, not a type-approval verdict

    UN R155 CSMS gap analysis

    cybersecurity-management-system evidence for type approval

    UN R156 software-update gap analysis

    SUMS evidence for software-update management

    Effective-risk CVE rescoring

    re-rank ECU and component vulnerabilities with CISA KEV / EPSS context — never exploit code

    Document review, paragraph-cited

    TARA reports and CSMS/SUMS evidence packs against R155/R156

    STRIDE threat-model workflows run on every plan against a system you describe — 1 run a month on Free, 2 on Solo, 5 on Premium, which also adds the LINDDUN and TARA families, the rendered reports, and case law inside the run. Document-grounded workflows run on Team and Company. Every tier runs the same corpora as cited research inside your own AI client.

    Questions buyers ask first

    Do you give us the ISO/SAE 21434 text?
    By default, ISO/SAE 21434 and the diagnostic standards are surfaced as requirement and clause mappings with Ansvar cross-references, not the reproduced standard. But the ISO/SAE 21434 text itself — licensed and cited verbatim inside your workflows — is available as the SIS-licensed standards add-on, one of the five standards live today; see /standards. UN R155 and R156 are the regulations, addressable provision by provision.
    Does this produce a type-approval verdict?
    No. The TARA and CSMS/SUMS gap analyses are decision-support — cited evidence you take into the type-approval process, not the approval itself.

    Run it against your own systems

    Connect the AI client you already use and ask your first cited question — Free, Solo, Premium and Team are self-serve.

    Building automotive compliance? It works today — we take on a few design partners per sector to tune it to your team.