Cyber Resilience Act (Reg (EU) 2024/2847)
IT & cloud security
Threat modelling, product-security law, and live vulnerability context — every finding cited to its source.
Ansvar is a gateway for the AI assistant your team already uses — Claude, Microsoft Copilot, any MCP client. Connect it, and every answer below comes back cited to the provision or marked unresolved.
Security is where Ansvar runs deepest: STRIDE threat models grounded in OWASP, ATT&CK and CAPEC; the Cyber Resilience Act and NIS2 at article level, with US federal cybersecurity regulation from the eCFR beside them; the NIST publications served as full text — 800-53r5, CSF 2.0, SSDF 800-218 and the AI RMF — while ISO 27001 Annex A, CIS and the German BSI landscape stay control mappings; and live CVE / CISA KEV / EPSS context for effective-risk decisions. Ask the requirement, get the source; then run the threat model or gap analysis that turns it into evidence.
The law and standards we ground on
NIS2 (Dir (EU) 2022/2555)
GDPR Art. 32 — security of processing
US federal cybersecurity regulation
the federal cyber code, served verbatim from the eCFR
NIST SP 800-53r5 · CSF 2.0 · SSDF 800-218 · AI RMF — served as full text
the control catalog, the CSF Core, the secure-development framework and the AI risk framework themselves, not a mapping; US public domain
Control mapping: OWASP ASVS · ISO 27001 Annex A · CIS
requirement mapping + cross-references, not the standard text — the ISO 27001 text itself is the SIS-licensed add-on (/standards)
Control mapping: BSI IT-Grundschutz · C5 · Technische Richtlinien · KRITIS · Mindeststandards
the German control landscape as a clause map with cross-references into ISO/IEC 27001 — not the standard text
MITRE ATT&CK · CAPEC · CWE · D3FEND
threat & weakness catalogs, cited per technique; CAPEC / CWE / D3FEND on Premium and above
ENISA Threat Landscape
the EU annual threat report plus the transport and finance-sector landscapes, served verbatim (CC-BY-4.0)
Software supply-chain security · cryptographic algorithm guidance
supply-chain attack patterns, SBOM field references (SPDX, CycloneDX) and Sigstore signing; algorithm status per NIST, ENISA, BSI TR-02102-1 and SOG-IS, with the post-quantum replacements
CVE · CISA KEV · EPSS — live vulnerability context
for effective-risk rescoring; not a scanner
Workflows that turn it into evidence
STRIDE threat model
over your architecture or data-flow diagram, each threat cited to OWASP / ATT&CK / CAPEC patterns
Effective-risk CVE rescoring
re-rank the findings your scanners already produced with CISA KEV, EPSS and NVD context — reproducible and cited, never exploit code
NIS2 gap analysis & ISO 27001 control mapping
Art. 21 measures mapped to the controls you already run
CRA readiness gap analysis
essential requirements (Annex I) for products with digital elements
Document review, paragraph-cited
security policies, ISO 27001 evidence and vendor questionnaires, each finding anchored to a doc:// segment
Security research as cited answers
free single-jurisdiction search; premium adds CAPEC / CWE / D3FEND, the IETF security RFCs, the cryptographic algorithm guidance and the software-supply-chain library
STRIDE threat-model workflows run on every plan against a system you describe — 1 run a month on Free, 2 on Solo, 5 on Premium, which also adds the LINDDUN and TARA families, the rendered reports, and case law inside the run. Document-grounded workflows run on Team and Company. Every tier runs the same corpora as cited research inside your own AI client.
Questions buyers ask first
- Is this a vulnerability scanner or a SIEM?
- No. Ansvar grounds decisions — it re-scores the vulnerabilities your scanners already found (CISA KEV, EPSS, NVD), maps controls, and produces cited threat models and gap registers. It never runs exploit code and never watches your network.
- Do you serve the ISO 27001 text?
- The control mapping cross-references ISO 27001 Annex A without reproducing the standard. But the standard text itself — cited rather than paraphrased — is available as the SIS-licensed standards add-on: ISO 27001, 27002 and 27005 are among the five standards live today, and through SIS any ISO, EN or SS standard can be added; see /standards.
- Are the NIST publications mapped, or served?
- Served. NIST SP 800-53r5, the CSF 2.0 Core, SSDF 800-218 and the AI RMF are US federal public-domain publications, so the text is in the corpus and an answer cites the control, practice or subcategory itself. ISO 27001 is the other case: the Annex A mapping cross-references it without reproducing it, and the standard text arrives only through the SIS-licensed add-on.
Run it against your own systems
Connect the AI client you already use and ask your first cited question — Free, Solo, Premium and Team are self-serve.
Building security compliance? It works today — we take on a few design partners per sector to tune it to your team.