CVE, KEV and EPSS
Look up vulnerability details, known exploitation and exploit probability from the served feeds.
Describe the system in a guided run. Team and Company can also register architecture records as private evidence. Ansvar runs the structured workflow available on your plan, then grounds the report in served security sources, product law and standards evidence you hold a licence to use.
The workflow asks for a system boundary before it scores a threat or risk. Your engineers confirm the model and challenge the proposed findings.
Provide components, assets, data flows, trust boundaries and operating context.
Review the data-flow diagram or TARA scope before the server advances the run.
The workflow applies its method and fetches the served sources needed for each mapping.
Engineers review threats, risk bands, treatments, citations and unresolved mappings.
Free and Solo include structured runs from the starter workflow set. Premium adds the wider interview-grounded catalog and deeper security enrichment. Public vulnerability facts remain available on Free.
Look up vulnerability details, known exploitation and exploit probability from the served feeds.
Ground threat behavior in served technique records instead of model recollection.
Premium opens the source families used for weakness, attack-pattern and countermeasure enrichment.
Product-law provisions remain distinct from standards evidence. Selected ISO/SAE 21434 text requires a SIS entitlement for the person or machine identity.
Free and Solo return complete structured reports for the workflows included with those plans. Premium adds the wider interview-grounded catalog. Team and Company add registered document evidence and unwatermarked exports.
Confirm the data-flow diagram, review the threat list, score the accepted threats and map mitigations to served controls and regimes.
Review STRIDE →Run the shared risk spine for automotive, OT, rail, robotics or UAS, with sector-specific anchors fetched from served sources.
Review TARA →Supply a scanner export. The workflow rescores the findings with KEV, EPSS and your context, then prepares a ranked plan or deferral record.
Review vulnerability decisions →A plausible security label does not establish a requirement. The report needs the served record behind the claim.
A reviewer can open the CVE, threat record, legal provision or entitled clause used by the workflow and compare it with the finding.
If no served source supports a factual mapping, the workflow records the gap for engineering or legal review. It does not fill the citation from model memory.
Start with a STRIDE threat model, a TARA or a vulnerability decision. Keep your model and engineering tools; add the evidence and workflow contract.