EU-hosted. No server-side model. Provenance on every answer.
The things your procurement team asks about on call #2. Data residency stated plainly, model traffic that never reaches our infrastructure, and source citations you can verify on every served row.
Trust · Sovereignty · Openness
Each pillar has a concrete answer. Where something is planned rather than shipped, the label says so.
EU-hosted infrastructure
The gateway and the MCP server fleet run on our own Kubernetes platform on Hetzner in the EU — immutable node OS with no SSH, and every production change lands as a reviewed GitOps pull request. Cloudflare provides edge and TLS termination in front, under SCCs and the EU-US Data Privacy Framework — we state that plainly rather than claiming nothing ever crosses a border.
- Hosted on Hetzner in the EU
- Cloudflare edge/TLS under SCCs · EU-US DPF
- GDPR-compliant DPA for all paid tiers
- Swedish entity, EU law governs
Bring your own AI client
You connect your own AI client — Claude Desktop, Microsoft Copilot Studio, Cursor, or a custom MCP client. Ansvar runs no server-side model: model traffic flows directly from your client to your model provider. We never see or proxy it, and your model bill stays on your account. The one exception is expert-delivered engagements, where Ansvar operates the run for you — the privacy notice describes that path.
- Works with any MCP-capable AI client
- OAuth 2.1 — PKCE + Dynamic Client Registration
- No server-side model at Ansvar
- Model traffic never proxied or stored by us
Inspectable data layer
Every answer carries item-level provenance: the source URL, publisher, and licence of each cited row, pointing at the original publisher — never a mirror. Source licences are verified before ingestion, fail-closed: a corpus that fails the licensing gate is not built, and a repository is public only while its source-licensing audit stays GREEN; the gateway, its reusable hosting chassis, and licensed data are private. Reproducible, digest-pinned corpus builds from version-controlled sources are the standard for new and updated corpora; the remaining estate migrates as it is touched, and this label changes when coverage is complete.
- Source, publisher, and licence cited on every served row
- Licensing verified before ingestion — fail-closed
- Deterministic citation validation, verifiable
- MCP servers store no client data
Defense in depth
Every request crosses three control planes before it reaches your data. A tamper-evident audit trail records every transition across all of them.
- RequestFrom your AI client
- S1Network perimeter
- TLS 1.3 · Cloudflare + Traefik
- Kubernetes NetworkPolicy isolation
- Continuous vuln + exposure scanning
- S2Identity & authZ
- OAuth 2.1 · PKCE · DCR
- Per-request tier authZ
- SCIM: planned
- S3Data plane
- EU-hosted · Hetzner Kubernetes
- Sealed secrets · OpenBao KMS
- Forensic audit logging
- Customer dataEU-hosted · minimised — MCP servers store none
Where we stand on frameworks
Honest labelling. We tell you what is certified, what is aligned, and what is in progress — because the difference matters in procurement.
EU-hosted infrastructure, model traffic that never reaches us
Two data paths, stated plainly. Infrastructure data sits on Hetzner in the EU behind Cloudflare's edge; model traffic flows directly between your AI client and your model provider.
EU-hosted infrastructure
- Gateway and MCP server fleet on our own Kubernetes platform, hosted on Hetzner in the EU
- Cloudflare provides edge and TLS termination under SCCs / EU-US DPF
- Envelope-encrypted secrets (OpenBao KMS), NetworkPolicy isolation between services
- Immutable node OS with no SSH — every production change is a reviewed GitOps pull request
- Forensic audit logging on every request
- MCP servers store no client data
Your model traffic
- Your AI client calls your model provider directly
- No server-side model at Ansvar — with your own client connected, we never see or proxy model traffic
- What we do see: the MCP tool calls your client sends the gateway (queries, lookups)
- Your provider's retention terms and your model bill stay between you and them
- MCP-first architecture — no vector store, no RAG copy of your data
Questions we answer before the DPA is signed
If yours isn't here, request the security questionnaire. We return it within five business days for paid-tier evaluations.
Do you train on our data?
No. Ansvar runs no server-side model and never sees model traffic — it flows directly from your AI client to your model provider. Customer data is never used for training, evaluation, or fine-tuning. Your provider's own retention terms apply on that direct path. Where Ansvar operates a run for you — expert-delivered engagements — the same no-training rule applies, and the model provider's published retention terms govern that path.
How is our data isolated?
MCP servers store no client data. What the gateway does hold — account and entitlement records, audit logs — sits on EU-hosted Kubernetes infrastructure with NetworkPolicy isolation between services and envelope-encrypted secrets (OpenBao KMS).
What's your incident response?
72-hour notification to customer admins for any security incident affecting customer data, aligned to GDPR Art. 33 timelines.
Do you support SSO and SCIM?
SSO: yes — sign in with Microsoft Entra ID, Google, or username and password. SCIM 2.0 is planned; it is not built today.
Can we self-host?
Not as a self-serve product today — the gateway is a hosted EU service. But on-prem is where we are heading: a customer-deployable version of the platform exists and is exercised in CI on every merge, and we are open to a design partner to shape the first production deployment inside a customer's own perimeter. If that is you, get in touch. The gateway runtime and base images remain private; a small set of connector repositories is public on GitHub where licensing allows.
What about penetration testing?
Our first third-party pentest is planned for 2026. No report exists yet — we will not claim one until it does.
How do I report a security vulnerability?
Email security@ansvar.eu, with a PGP key on request. We aim to acknowledge within one business day. Our Terms otherwise prohibit probing the Service, so the responsible disclosure section on this page is the permission: it authorises good-faith research, sets the scope, and states the safe harbour that applies if you stay inside it. We run no paid bounty — a valid finding may earn a credit in our acknowledgments and a numbered “I hacked Ansvar” coin, decided after triage.
Didn't see your question? .
Report a vulnerability
Our Terms otherwise prohibit probing the Service, so this section is the permission: we authorise good-faith security research on the systems below, and we will not take legal action over research that follows this policy.
In scope
- ansvar.eu, app.ansvar.eu, and gateway.ansvar.eu
- Reaching another tenant's data, audit logs, organisation membership, or billing, whether you can read it or change it
- Authentication and authorisation flaws: OAuth and MCP token confusion, session leakage, tier or entitlement bypass
- Injection, server-side request forgery, and remote code execution
- Exposed credentials, keys, or customer data, including our own misconfiguration of Cloudflare, Vercel, or Hetzner
- Corpus integrity: source or cache poisoning, provenance tampering, or a bypass of licensing suppression
Out of scope
- Missing security headers, cookie flags, or TLS settings with no demonstrated impact
- SPF, DKIM, and DMARC gaps without impact you can demonstrate on a domain or mailbox you control
- Clickjacking on pages that change no state, and rate limits with no demonstrated security impact
- Version banners, and scanner output with no proof of concept
- Denial of service and load testing, social engineering, physical testing, and flaws in Cloudflare, Vercel, or Hetzner themselves
- Wrong or missing citations in served content. That is a support matter, and rights complaints go through content claims.
How to report
- Email security@ansvar.eu. PGP key on request.
- Send what you found, the steps to reproduce it, and the impact as you read it.
- We aim to acknowledge within one business day, and to tell you what we decided once we have triaged it.
- Stop at proof. Do not pull customer data, pivot further into our estate, or run load tests.
- If you reach another tenant's data, stop and tell us. That finding is already complete.
- Give us 90 days before you publish, and tell us when you plan to.
What we offer
- No paid bounty. We would rather say so than imply a payout that is not there.
- A credit in the acknowledgments below, under your name, your handle, or nothing at all. We ask before we publish anything.
- A numbered “I hacked Ansvar” coin, which we make ourselves and do not sell.
- We decide both after triage, at our discretion. Recognition is not compensation, and we do not price a finding before we have read it.
Safe harbour
- Stay in scope, use only accounts you own or may use, and avoid disrupting the service.
- Access no more data than proves the finding, keep no copies, and delete what you took.
- Report promptly and agree publication timing with us.
- Do that and we will not start legal action over your research, and we will confirm to others that it was authorised.
- We cannot waive our customers' or licensors' rights, and this binds no public authority.
Acknowledgments
We have not credited anyone yet. Once we have fixed a valid report, we list the researcher here the way they asked to be named.