No tracking. No cookie wall.·EU-hosted (Hetzner) · Cloudflare edge under SCCs
    Security & sovereignty

    EU-hosted. No server-side model. Provenance on every answer.

    The things your procurement team asks about on call #2. Data residency stated plainly, model traffic that never reaches our infrastructure, and source citations you can verify on every served row.

    Three pillars

    Trust · Sovereignty · Openness

    Each pillar has a concrete answer. Where something is planned rather than shipped, the label says so.

    EU-hosted infrastructure

    The gateway and the MCP server fleet run on our own Kubernetes platform on Hetzner in the EU — immutable node OS with no SSH, and every production change lands as a reviewed GitOps pull request. Cloudflare provides edge and TLS termination in front, under SCCs and the EU-US Data Privacy Framework — we state that plainly rather than claiming nothing ever crosses a border.

    • Hosted on Hetzner in the EU
    • Cloudflare edge/TLS under SCCs · EU-US DPF
    • GDPR-compliant DPA for all paid tiers
    • Swedish entity, EU law governs

    Bring your own AI client

    You connect your own AI client — Claude Desktop, Microsoft Copilot Studio, Cursor, or a custom MCP client. Ansvar runs no server-side model: model traffic flows directly from your client to your model provider. We never see or proxy it, and your model bill stays on your account. The one exception is expert-delivered engagements, where Ansvar operates the run for you — the privacy notice describes that path.

    • Works with any MCP-capable AI client
    • OAuth 2.1 — PKCE + Dynamic Client Registration
    • No server-side model at Ansvar
    • Model traffic never proxied or stored by us

    Inspectable data layer

    Every answer carries item-level provenance: the source URL, publisher, and licence of each cited row, pointing at the original publisher — never a mirror. Source licences are verified before ingestion, fail-closed: a corpus that fails the licensing gate is not built, and a repository is public only while its source-licensing audit stays GREEN; the gateway, its reusable hosting chassis, and licensed data are private. Reproducible, digest-pinned corpus builds from version-controlled sources are the standard for new and updated corpora; the remaining estate migrates as it is touched, and this label changes when coverage is complete.

    • Source, publisher, and licence cited on every served row
    • Licensing verified before ingestion — fail-closed
    • Deterministic citation validation, verifiable
    • MCP servers store no client data
    Architecture posture

    Defense in depth

    Every request crosses three control planes before it reaches your data. A tamper-evident audit trail records every transition across all of them.

    1. Request
      From your AI client
    2. S1
      Network perimeter
      • TLS 1.3 · Cloudflare + Traefik
      • Kubernetes NetworkPolicy isolation
      • Continuous vuln + exposure scanning
    3. S2
      Identity & authZ
      • OAuth 2.1 · PKCE · DCR
      • Per-request tier authZ
      • SCIM: planned
    4. S3
      Data plane
      • EU-hosted · Hetzner Kubernetes
      • Sealed secrets · OpenBao KMS
      • Forensic audit logging
    5. Customer data
      EU-hosted · minimised — MCP servers store none
    Audit trailAppend-only and tamper-evident. Every transition across every stage.
    Company tier
    Compliance posture

    Where we stand on frameworks

    Honest labelling. We tell you what is certified, what is aligned, and what is in progress — because the difference matters in procurement.

    GDPR
    Compliant · DPA available
    CSA STAR Level 1
    Self-assessment published · Jul 2026
    ISO 27001
    In preparation · certification planned
    ISO 42001
    Aligned
    EU AI Act
    Aligned
    NIS2
    Aligned
    Data residency
    EU-hosted (Hetzner) · Cloudflare edge under SCCs
    Where data lives

    EU-hosted infrastructure, model traffic that never reaches us

    Two data paths, stated plainly. Infrastructure data sits on Hetzner in the EU behind Cloudflare's edge; model traffic flows directly between your AI client and your model provider.

    EU-hosted infrastructure

    • Gateway and MCP server fleet on our own Kubernetes platform, hosted on Hetzner in the EU
    • Cloudflare provides edge and TLS termination under SCCs / EU-US DPF
    • Envelope-encrypted secrets (OpenBao KMS), NetworkPolicy isolation between services
    • Immutable node OS with no SSH — every production change is a reviewed GitOps pull request
    • Forensic audit logging on every request
    • MCP servers store no client data

    Your model traffic

    • Your AI client calls your model provider directly
    • No server-side model at Ansvar — with your own client connected, we never see or proxy model traffic
    • What we do see: the MCP tool calls your client sends the gateway (queries, lookups)
    • Your provider's retention terms and your model bill stay between you and them
    • MCP-first architecture — no vector store, no RAG copy of your data
    Security FAQ

    Questions we answer before the DPA is signed

    If yours isn't here, request the security questionnaire. We return it within five business days for paid-tier evaluations.

    Do you train on our data?

    No. Ansvar runs no server-side model and never sees model traffic — it flows directly from your AI client to your model provider. Customer data is never used for training, evaluation, or fine-tuning. Your provider's own retention terms apply on that direct path. Where Ansvar operates a run for you — expert-delivered engagements — the same no-training rule applies, and the model provider's published retention terms govern that path.

    How is our data isolated?

    MCP servers store no client data. What the gateway does hold — account and entitlement records, audit logs — sits on EU-hosted Kubernetes infrastructure with NetworkPolicy isolation between services and envelope-encrypted secrets (OpenBao KMS).

    What's your incident response?

    72-hour notification to customer admins for any security incident affecting customer data, aligned to GDPR Art. 33 timelines.

    Do you support SSO and SCIM?

    SSO: yes — sign in with Microsoft Entra ID, Google, or username and password. SCIM 2.0 is planned; it is not built today.

    Can we self-host?

    Not as a self-serve product today — the gateway is a hosted EU service. But on-prem is where we are heading: a customer-deployable version of the platform exists and is exercised in CI on every merge, and we are open to a design partner to shape the first production deployment inside a customer's own perimeter. If that is you, get in touch. The gateway runtime and base images remain private; a small set of connector repositories is public on GitHub where licensing allows.

    What about penetration testing?

    Our first third-party pentest is planned for 2026. No report exists yet — we will not claim one until it does.

    Didn't see your question? .