Where you stand against a regulation, requirement by requirement — every finding cited to the provision it rests on, or marked unresolved.
Run them yourself, or have us run them
Every Ansvar workflow is a server-enforced process with cited output — a threat model, a TARA, a gap analysis, a DPIA. Your team runs it in the AI client you already use. Or we run it for you and review the result as practitioners.
Workflow families
TARA — Threat Analysis & Risk Assessment
Risk assessment for vehicles, OT, rail, robots and drones — risks banded on NIST 800-30 scales, every regulatory anchor fetched and cited, or marked unresolved.
DPIA — Data Protection Impact Assessment
One processing activity, screened against Article 35 and carried through to a prior-consultation decision — each risk scored for severity and likelihood before any safeguard is credited.
Threats enumerated per component against a data-flow diagram you confirm, scored on impact and likelihood, then mapped to the controls and regimes that bear on them.
Two sides of the same tender: whether a bid covers what the tender demands, and whether the tender's own requirements are lawful.
Vulnerability assessment & deferral
A decision layer over a scan you already ran: findings rescored against your context, a ranked investment plan, and a deferral you can defend.
The families above cover most of it. The rest — LINDDUN privacy threat models, FRIA, SORA operational authorisation, document review and adversary tabletops — has no page of its own yet. Ask your own client for list_workflow_types for the authoritative live list.
Capabilities your agent uses between runs
One NIST 800-53 spine behind ISO 27001, CSF 2.0 and more — crosswalks with provenance on every edge, and licensed text resolved from its source rather than copied.
CVE intelligence & effective risk
Live CVE, CISA KEV and EPSS context, rescored against your controls — read the sample deferral dossier it produces.
An official-publication monitor over EU and national gazettes — what changed, where, with the source. Tool reference in the docs.
Expert-run services
Classify your AI systems against the EU AI Act, then know exactly which obligations apply before they bite.
A structured threat model for your system, built on STRIDE and LINDDUN and your real architecture — typically delivered in 1–2 weeks at a fixed price.
A Data Protection Impact Assessment, done for you and defensible to your regulator.
Where you stand against NIS2, DORA, ISO 27001, GDPR, and the EU AI Act — as a cited report, scoped at article and control level.
Same workflows, run and reviewed by us — scoped per engagement. The services page has deliverables, process and samples; contact us to scope one.