No tracking. No cookie wall.·EU-hosted (Hetzner) · Cloudflare edge under SCCs
    Workflows

    Run them yourself, or have us run them

    Every Ansvar workflow is a server-enforced process with cited output — a threat model, a TARA, a gap analysis, a DPIA. Your team runs it in the AI client you already use. Or we run it for you and review the result as practitioners.

    42workflow types served through the gateway
    Citedevery anchor fetched from a served source, or marked unresolved
    Your clientClaude, Copilot, any MCP client — nothing to install
    run it in your own client

    Workflow families

    Workflow family

    Regulatory gap analysis

    Where you stand against a regulation, requirement by requirement — every finding cited to the provision it rests on, or marked unresolved.

    Workflow family

    TARA — Threat Analysis & Risk Assessment

    Risk assessment for vehicles, OT, rail, robots and drones — risks banded on NIST 800-30 scales, every regulatory anchor fetched and cited, or marked unresolved.

    Workflow family

    DPIA — Data Protection Impact Assessment

    One processing activity, screened against Article 35 and carried through to a prior-consultation decision — each risk scored for severity and likelihood before any safeguard is credited.

    Workflow family

    STRIDE threat model

    Threats enumerated per component against a data-flow diagram you confirm, scored on impact and likelihood, then mapped to the controls and regimes that bear on them.

    Workflow family

    Public tender review & audit

    Two sides of the same tender: whether a bid covers what the tender demands, and whether the tender's own requirements are lawful.

    Workflow family

    Vulnerability assessment & deferral

    A decision layer over a scan you already ran: findings rescored against your context, a ranked investment plan, and a deferral you can defend.

    Catalog

    The full served catalog

    The families above cover most of it. The rest — LINDDUN privacy threat models, FRIA, SORA operational authorisation, document review and adversary tabletops — has no page of its own yet. Ask your own client for list_workflow_types for the authoritative live list.

    always-on intelligence

    Capabilities your agent uses between runs

    Capability

    Canonical control library

    One NIST 800-53 spine behind ISO 27001, CSF 2.0 and more — crosswalks with provenance on every edge, and licensed text resolved from its source rather than copied.

    Capability

    Regulatory intelligence

    An official-publication monitor over EU and national gazettes — what changed, where, with the source. Tool reference in the docs.

    have us run it

    Expert-run services

    Service

    AI Act Readiness Assessment

    Classify your AI systems against the EU AI Act, then know exactly which obligations apply before they bite.

    Service

    Threat Model as a Service

    A structured threat model for your system, built on STRIDE and LINDDUN and your real architecture — typically delivered in 1–2 weeks at a fixed price.

    Service

    DPIA as a Service

    A Data Protection Impact Assessment, done for you and defensible to your regulator.

    Service

    Compliance Gap Analysis

    Where you stand against NIS2, DORA, ISO 27001, GDPR, and the EU AI Act — as a cited report, scoped at article and control level.

    Same workflows, run and reviewed by us — scoped per engagement. The services page has deliverables, process and samples; contact us to scope one.