SIS-licensed ISO clauses and controls·an add-on inside the AI clients and agents you already use
    Sector · Security

    IT & cloud security

    Threat modelling, product-security law, and live vulnerability context — every finding cited to its source.

    Ansvar is a gateway for the AI assistant your team already uses — Claude, Microsoft Copilot, any MCP client. Connect it, and every answer below comes back cited to the provision or marked unresolved.

    STRIDEthreat models, source-grounded
    800-53r5NIST catalogs served as full text
    LiveCVE · CISA KEV · EPSS

    Security is where Ansvar runs deepest: STRIDE threat models grounded in OWASP, ATT&CK and CAPEC; the Cyber Resilience Act and NIS2 at article level, with US federal cybersecurity regulation from the eCFR beside them; the NIST publications served as full text — 800-53r5, CSF 2.0, SSDF 800-218 and the AI RMF — while ISO 27001 Annex A, CIS and the German BSI landscape stay control mappings; and live CVE / CISA KEV / EPSS context for effective-risk decisions. Ask the requirement, get the source; then run the threat model or gap analysis that turns it into evidence.

    what we cover

    The law and standards we ground on

    Regulation

    Cyber Resilience Act (Reg (EU) 2024/2847)

    Regulation

    NIS2 (Dir (EU) 2022/2555)

    Regulation

    GDPR Art. 32 — security of processing

    Regulation

    US federal cybersecurity regulation

    the federal cyber code, served verbatim from the eCFR

    Standard

    NIST SP 800-53r5 · CSF 2.0 · SSDF 800-218 · AI RMF — served as full text

    the control catalog, the CSF Core, the secure-development framework and the AI risk framework themselves, not a mapping; US public domain

    Standard

    Control mapping: OWASP ASVS · ISO 27001 Annex A · CIS

    requirement mapping + cross-references, not the standard text — the ISO 27001 text itself is the SIS-licensed add-on (/standards)

    Standard

    Control mapping: BSI IT-Grundschutz · C5 · Technische Richtlinien · KRITIS · Mindeststandards

    the German control landscape as a clause map with cross-references into ISO/IEC 27001 — not the standard text

    Standard

    MITRE ATT&CK · CAPEC · CWE · D3FEND

    threat & weakness catalogs, cited per technique; CAPEC / CWE / D3FEND on Premium and above

    Guidance

    ENISA Threat Landscape

    the EU annual threat report plus the transport and finance-sector landscapes, served verbatim (CC-BY-4.0)

    GuidancePremium

    Software supply-chain security · cryptographic algorithm guidance

    supply-chain attack patterns, SBOM field references (SPDX, CycloneDX) and Sigstore signing; algorithm status per NIST, ENISA, BSI TR-02102-1 and SOG-IS, with the post-quantum replacements

    Guidance

    CVE · CISA KEV · EPSS — live vulnerability context

    for effective-risk rescoring; not a scanner

    what you can do

    Workflows that turn it into evidence

    STRIDE threat model

    over your architecture or data-flow diagram, each threat cited to OWASP / ATT&CK / CAPEC patterns

    Effective-risk CVE rescoring

    re-rank the findings your scanners already produced with CISA KEV, EPSS and NVD context — reproducible and cited, never exploit code

    NIS2 gap analysis & ISO 27001 control mapping

    Art. 21 measures mapped to the controls you already run

    CRA readiness gap analysis

    essential requirements (Annex I) for products with digital elements

    Document review, paragraph-cited

    security policies, ISO 27001 evidence and vendor questionnaires, each finding anchored to a doc:// segment

    assembledPremium

    Security research as cited answers

    free single-jurisdiction search; premium adds CAPEC / CWE / D3FEND, the IETF security RFCs, the cryptographic algorithm guidance and the software-supply-chain library

    STRIDE threat-model workflows run on every plan against a system you describe — 1 run a month on Free, 2 on Solo, 5 on Premium, which also adds the LINDDUN and TARA families, the rendered reports, and case law inside the run. Document-grounded workflows run on Team and Company. Every tier runs the same corpora as cited research inside your own AI client.

    Questions buyers ask first

    Is this a vulnerability scanner or a SIEM?
    No. Ansvar grounds decisions — it re-scores the vulnerabilities your scanners already found (CISA KEV, EPSS, NVD), maps controls, and produces cited threat models and gap registers. It never runs exploit code and never watches your network.
    Do you serve the ISO 27001 text?
    The control mapping cross-references ISO 27001 Annex A without reproducing the standard. But the standard text itself — cited rather than paraphrased — is available as the SIS-licensed standards add-on: ISO 27001, 27002 and 27005 are among the five standards live today, and through SIS any ISO, EN or SS standard can be added; see /standards.
    Are the NIST publications mapped, or served?
    Served. NIST SP 800-53r5, the CSF 2.0 Core, SSDF 800-218 and the AI RMF are US federal public-domain publications, so the text is in the corpus and an answer cites the control, practice or subcategory itself. ISO 27001 is the other case: the Annex A mapping cross-references it without reproducing it, and the standard text arrives only through the SIS-licensed add-on.

    Run it against your own systems

    Connect the AI client you already use and ask your first cited question — Free, Solo, Premium and Team are self-serve.

    Building security compliance? It works today — we take on a few design partners per sector to tune it to your team.