SIS-licensed ISO clauses and controls·an add-on inside the AI clients and agents you already use
    Security & sovereignty

    EU-hosted. No server-side model. Evidence you can inspect.

    Your model traffic stays between your AI client and provider. Ansvar serves evidence with item-level provenance; workflow findings cite that evidence or remain unresolved. Operational security logs and the Company cryptographic ledger serve different purposes.

    Three pillars

    Trust · Sovereignty · Openness

    Each pillar has a concrete answer. Where something is planned rather than shipped, the label says so.

    EU-hosted infrastructure

    The gateway and the MCP server fleet run on our own Kubernetes platform on Hetzner in the EU — immutable node OS with no SSH, and every production change lands as a reviewed GitOps pull request. Cloudflare provides edge and TLS termination in front, under SCCs and the EU-US Data Privacy Framework — we state that plainly rather than claiming nothing ever crosses a border.

    • Hosted on Hetzner in the EU
    • Cloudflare edge/TLS under SCCs · EU-US DPF
    • GDPR-compliant DPA for all paid tiers
    • Swedish entity, EU law governs

    Bring your own AI client

    You connect your own AI client — Claude Desktop, Microsoft Copilot Studio, Cursor, or a custom MCP client. Ansvar runs no server-side model: model traffic flows directly from your client to your model provider. We never see or proxy it, and your model bill stays on your account. The one exception is expert-delivered engagements, where Ansvar operates the run for you — the privacy notice describes that path.

    • Works with any MCP-capable AI client
    • OAuth 2.1 — PKCE + Dynamic Client Registration
    • No server-side model at Ansvar
    • Model traffic never proxied or stored by us

    Inspectable data layer

    Each served evidence row carries its source URL, publisher, and licence, pointing to the original publisher. Ansvar audits source licences before ingestion and fails closed: we do not build a corpus that fails its licensing gate, and we keep a connector repository public only while its audit remains GREEN. The gateway, its hosting chassis, and licensed data remain private. We use digest-pinned builds from version-controlled sources for new and updated corpora; we migrate older corpora as we update them.

    • Source, publisher, and licence cited on every served row
    • Licensing verified before ingestion — fail-closed
    • Deterministic citation resolution
    • Corpus MCP servers store no client data
    Architecture posture

    Defense in depth

    Gateway requests cross three control planes. The hosted service records operational security events; Company adds per-tenant signed receipts for requests and served results.

    1. Request
      From your AI client
    2. S1
      Network perimeter
      • TLS 1.2+ · Cloudflare + Traefik
      • Kubernetes NetworkPolicy isolation
      • Continuous vuln + exposure scanning
    3. S2
      Identity & authZ
      • OAuth 2.1 · PKCE · DCR
      • Per-request tier authZ
      • SCIM: planned
    4. S3
      Data plane
      • EU-hosted · Hetzner Kubernetes
      • Sealed secrets · OpenBao KMS
      • Operational security logging
    5. Customer data
      EU-hosted · corpus servers store none · documents tenant-isolated
    Signed audit receiptsPer-tenant cryptographic records that customers can verify.
    Company tier
    Compliance posture

    Where we stand on frameworks

    Honest labelling. We tell you what is certified, what is aligned, and what is in progress — because the difference matters in procurement.

    GDPR
    Compliant · DPA available
    CSA STAR Level 1
    Self-assessment published · Jul 2026
    ISO 27001
    In preparation · certification planned
    ISO 42001
    Aligned
    EU AI Act
    Aligned · AI Pact signatory, Aug 2026
    NIS2
    Aligned
    Data residency
    EU-hosted (Hetzner) · Cloudflare edge under SCCs
    Where data lives

    EU-hosted infrastructure, model traffic that never reaches us

    Two data paths, stated plainly. Infrastructure data sits on Hetzner in the EU behind Cloudflare's edge; model traffic flows directly between your AI client and your model provider.

    EU-hosted infrastructure

    • Gateway and MCP server fleet on our own Kubernetes platform, hosted on Hetzner in the EU
    • Cloudflare provides edge and TLS termination under SCCs / EU-US DPF
    • Envelope-encrypted secrets (OpenBao KMS), NetworkPolicy isolation between services
    • Immutable node OS with no SSH — every production change is a reviewed GitOps pull request
    • Operational security logging for gateway requests
    • Corpus MCP servers store no client data; registered documents live in tenant-isolated EU storage

    Your model traffic

    • Your AI client calls your model provider directly
    • No server-side model at Ansvar — with your own client connected, we never see or proxy model traffic
    • What we do see: the MCP tool calls your client sends the gateway (queries, lookups)
    • Your provider's retention terms and your model bill stay between you and them
    • MCP-first architecture — no vector store, no RAG copy of your data
    Deployment choices

    Choose where the evidence services run

    Ansvar operates the hosted EU service today and offers a dedicated Company environment by agreement. Customer-managed deployment is in the design-partner stage. Your model remains in your chosen AI environment in all three designs.

    EU-hosted service

    Available now · every plan

    • Ansvar operates the gateway and evidence services on Hetzner in the EU
    • Cloudflare provides edge and TLS termination under the disclosed transfer safeguards
    • Ansvar manages source updates, backups, and operational security logging

    Dedicated Company environment

    Available by agreement

    • Tenant-exclusive Hetzner Kubernetes cluster managed by Ansvar
    • Custom retention and service levels set in the Company contract
    • Per-tenant cryptographic ledger with signed, verifiable receipts
    • First dedicated environment is delivered through a Company-tier design partnership

    Customer-managed deployment

    Design-partner stage

    • A deployable platform build runs in CI on each merge
    • Ansvar has not released this mode as a self-serve product
    • Ansvar and the first production partner must agree on updates, freshness reporting, support, and licensed-content entitlements
    Security FAQ

    Questions we answer before the DPA is signed

    If yours isn't here, request the security questionnaire — available for paid-tier evaluations.

    Do you train on our data?

    No. Ansvar runs no server-side model and never sees model traffic — it flows directly from your AI client to your model provider. Customer data is never used for training, evaluation, or fine-tuning. Your provider's own retention terms apply on that direct path. Where Ansvar operates a run for you — expert-delivered engagements — the same no-training rule applies, and the model provider's published retention terms govern that path.

    How is our data isolated?

    Corpus MCP servers store no client data. The gateway holds account records, entitlement records, and operational security logs on EU-hosted Kubernetes infrastructure with NetworkPolicy isolation between services and envelope-encrypted secrets (OpenBao KMS). Document grounding on Team and Company stores registered documents and workflow evidence in tenant-isolated EU storage under your retention policy, and the same tools that register a document can remove it. Company adds a separate per-tenant cryptographic ledger with signed receipts.

    What's your incident response?

    We notify affected customer admins without undue delay, per our DPA — early enough to support your own clocks, including your GDPR Art. 33 notification to your authority (72 hours, controller to authority) and a NIS2 24-hour early warning where it applies to you.

    Do you support SSO and SCIM?

    SSO: yes — sign in with Microsoft Entra ID, Google, or username and password. SCIM 2.0 is planned; it is not built today.

    Can we self-host?

    Customer-managed deployment is at the design-partner stage. A deployable platform build exists and runs in CI on each merge. Ansvar has not released it as a self-serve product. Ansvar and the first production partner must agree on corpus updates, freshness reporting, support, and licensed-content entitlements. The gateway runtime and base images remain private; Ansvar publishes a small set of connector repositories where licensing allows.

    What about penetration testing?

    We performed a white-box penetration test of our platform in August 2026, covering the MCP gateway, authentication, and web applications. Our first independent third-party penetration test is planned for 2026 ahead of ISO 27001 certification — and until that report exists, we will not claim it.

    How do I report a security vulnerability?

    Email security@ansvar.eu, with a PGP key on request. We aim to acknowledge within one business day and commit to three. Our Terms otherwise prohibit probing the Service, so the responsible disclosure section on this page is the permission: it authorises good-faith research, sets the scope, and states the safe harbour that applies if you stay inside it. We run no paid bounty — a valid finding may earn a credit in our acknowledgments and a numbered “I hacked Ansvar” coin, decided after triage.

    Didn't see your question? .

    Responsible disclosure

    Report a vulnerability

    Our Terms otherwise prohibit probing the Service, so this section is the permission: we authorise good-faith security research on the systems below, and we will not take legal action over research that follows this policy.

    In scope

    • ansvar.eu, app.ansvar.eu, and gateway.ansvar.eu
    • Reaching another tenant's data, audit logs, organisation membership, or billing, whether you can read it or change it
    • Authentication and authorisation flaws: OAuth and MCP token confusion, session leakage, tier or entitlement bypass
    • Injection, server-side request forgery, and remote code execution
    • Exposed credentials, keys, or customer data, including our own misconfiguration of Cloudflare, Vercel, or Hetzner
    • Corpus integrity: source or cache poisoning, provenance tampering, or a bypass of licensing suppression

    Out of scope

    • Missing security headers, cookie flags, or TLS settings with no demonstrated impact
    • SPF, DKIM, and DMARC gaps without impact you can demonstrate on a domain or mailbox you control
    • Clickjacking on pages that change no state, and rate limits with no demonstrated security impact
    • Version banners, and scanner output with no proof of concept
    • Denial of service and load testing, social engineering, physical testing, and flaws in Cloudflare, Vercel, or Hetzner themselves
    • Wrong or missing citations in served content. That is a support matter, and rights complaints go through content claims.

    How to report

    • Email security@ansvar.eu. PGP key on request.
    • Send what you found, the steps to reproduce it, and the impact as you read it.
    • We aim to acknowledge within one business day and commit to three, and we tell you what we decided once we have triaged it.
    • Stop at proof. Do not pull customer data, pivot further into our estate, or run load tests.
    • If you reach another tenant's data, stop and tell us. That finding is already complete.
    • Give us 90 days before you publish, and tell us when you plan to.

    What we offer

    • No paid bounty. We would rather say so than imply a payout that is not there.
    • A credit in the acknowledgments below, under your name, your handle, or nothing at all. We ask before we publish anything.
    • A numbered “I hacked Ansvar” coin, which we make ourselves and do not sell.
    • We decide both after triage, at our discretion. Recognition is not compensation, and we do not price a finding before we have read it.

    Safe harbour

    • Stay in scope, use only accounts you own or may use, and avoid disrupting the service.
    • Access no more data than proves the finding, keep no copies, and delete what you took.
    • Report promptly and agree publication timing with us.
    • Do that and we will not start legal action over your research, and we will confirm to others that it was authorised.
    • We cannot waive our customers' or licensors' rights, and this binds no public authority.

    Acknowledgments

    We have not credited anyone yet. Once we have fixed a valid report, we list the researcher here the way they asked to be named.