SIS-licensed ISO clauses and controls·an add-on inside the AI clients and agents you already use
    Governed workflow execution

    Turn evidence into a reviewable decision.

    Ansvar workflows carry law, standards, security intelligence, and the context you provide through a defined assessment process. The result is a gap analysis, DPIA, threat model, TARA, or other finished artifact with cited facts, labelled judgments, and unresolved gaps.

    42workflow types in the served registry
    Citedfactual anchors resolved from served evidence or left unresolved
    Your clientrun through a supported MCP client or standing agent
    one evidence contract

    Different assessments. The same chain of custody.

    Each run records the source material, selected customer evidence, structured stages, findings, judgments, and missing support behind the deliverable. Team and Company can bind documents from a tenant library to supported workflows. Completed reports remain immutable; a changed system or source starts a new run.

    01

    Bring the evidence

    Retrieve served law, licensed standards where entitled, threat sources, and the documents relevant to the run.

    02

    Run the method

    Server-enforced stages gather scope, evidence, analysis, review, and completion state in a defined order.

    03

    Keep the decision record

    Export a finished artifact with its citations, labelled judgments, unresolved points, and run metadata.

    choose the deliverable

    Run a supported workflow in your own client

    Workflow family

    Regulatory gap analysis

    Where you stand against a regulation, requirement by requirement — every finding cited to the provision it rests on, or marked unresolved.

    Workflow family

    TARA — Threat Analysis & Risk Assessment

    Risk assessment for vehicles, OT, rail, robots and drones — risks banded on NIST 800-30 scales, every regulatory anchor fetched and cited, or marked unresolved.

    Workflow family

    DPIA — Data Protection Impact Assessment

    Ansvar screens one processing activity against GDPR Article 35 and the national trigger evidence available across 29 European jurisdictional source paths.

    Workflow family

    STRIDE threat model

    Threats enumerated per component against a data-flow diagram you confirm, scored on impact and likelihood, then mapped to the controls and regimes that bear on them.

    Workflow family

    Public tender review & audit

    Two sides of the same tender: whether a bid covers what the tender demands, and whether the tender's own requirements are lawful.

    Workflow family

    Vulnerability assessment & deferral

    A decision layer over a scan you already ran: findings rescored against your context, a ranked investment plan, and a deferral you can defend.

    Catalog

    The full served catalog

    The families above have dedicated product pages. Other served workflows include LINDDUN privacy threat models, FRIA, SORA operational authorisation, document review, and adversary tabletops. Ask your client for list_workflow_types for the authoritative live list.

    evidence used inside and between runs

    Retrieve the record before making the judgment

    Capability

    Canonical control library

    A typed relationship model with provenance on each reviewed edge. The current coverage page states which mappings have actually been authored.

    Capability

    CVE intelligence & effective risk

    Retrieve public CVE, CISA KEV, and EPSS records on Free, which also includes one described-system workflow run a month. Premium adds threat-pattern enrichment, the interview-grounded workflow catalog, and run-scoped effective-risk analysis in applicable workflows. Team adds standalone tools with persistent asset contexts, review decisions, and OpenVEX export.

    Capability

    Regulatory intelligence

    See what official publishers released, where, and when. Every record carries its source and the monitor reports the coverage window behind an empty result.

    have us run it

    Expert-run services

    Service

    AI Act Readiness Assessment

    Classify your AI systems against the EU AI Act, then know exactly which obligations apply before they bite.

    Service

    Threat Model as a Service

    A structured threat model for your system, built on STRIDE and LINDDUN and your real architecture — typically delivered in 1–2 weeks at a fixed price.

    Service

    DPIA as a Service

    A Data Protection Impact Assessment, done for you and defensible to your regulator.

    Service

    Compliance Gap Analysis

    Where you stand against NIS2, DORA, ISO 27001, GDPR, and the EU AI Act — as a cited report, scoped at article and control level.

    The same evidence discipline, with the assessment run and reviewed by practitioners under a scoped engagement. The services page has deliverables, process and samples; contact us to scope one.