Vulnerability Assessment & Control-Investment Plan
Rescore a finding set against your context, then rank what to fix first.
A decision layer over a scan you already ran: findings rescored against your context, a ranked investment plan, and a deferral you can defend.
Ansvar is a gateway for the AI assistant your team already uses — Claude, Microsoft Copilot, any MCP client. Connect it and your agent runs the workflow; the server enforces the stages and fetches every citation.
Ansvar consumes a scan; it does not run one. Feed a run the finding set you already have — a Dependency-Track export, a Trivy result, your own list — and it rescores each finding through the effective-risk engine with KEV, EPSS and the controls you actually hold, then runs a greedy-set simulation to rank what to buy first. The plan states its own limit: findings that no control moves sit on an immovable floor instead of padding the ranking. The deferral dossier is the other half, for findings you are not fixing yet — it anchors each deferral to the regimes that bear on it and computes the reporting flags the decision triggers.
Vulnerability Assessment & Control-Investment Plan
Rescore a finding set against your context, then rank what to fix first.
Vulnerability Deferral Dossier & Control-Investment Plan
Evidence a decision not to fix yet, with the regulatory anchors and reporting flags it triggers. Adds a regulatory-anchoring stage to the spine below.
Where findings carry SBOM references, the run merges the per-finding fragments into one CycloneDX VEX you can apply in Dependency-Track. Where they do not, no VEX is emitted and the report says why — a VEX that cannot re-match is worse than none.
your scanner's export, with the asset context and the controls you hold, confirmed by you before scoring starts
optional; on Team and above the run grounds itself in your own attestations
each finding rescored through the engine verbatim, with a VEX fragment where the finding carries a bom-ref
a greedy-set simulation ranks the candidates and stops when nothing further reduces risk
the rescored set, the plan and its floor — structured for your agent, rendered for your auditor
Using Ansvar, rescore this Dependency-Track export against our asset context and give me a ranked control-investment plan.
Using Ansvar, assemble a deferral dossier for the findings we are not fixing this quarter, with the reporting flags each deferral triggers.
A prompt starts one run. The skill is the same guidance installed once — the run loop, the evidence and citation rules, and the starters — so your agent works this way in every conversation, not only the ones you remember to paste into. Install it as a skill in Claude or Claude Code, or paste the same file into Microsoft Copilot or a custom GPT's instructions.
Vulnerability Decisions · version 1.0.4 · SKILL.md · ZIP · how to install it
The Vulnerability decisions family runs on Premium and above — run allowances and what each tier adds live on the pricing page.
Every workflow here is also an expert-run service: we run it against your systems, review the output as practitioners, and hand over the finished deliverable. See the services page for how engagements work, or contact us to scope one.
Related: Sample deferral dossier · CRA explained · TARA workflows · Control library · Security sector · Tool reference · Have us run it
Connect the AI client you already use and ask your first cited question — Free, Solo, Premium and Team are self-serve.