Ansvar
About
Cited compliance, legal & security intelligence for AI agents — 300+ law, regulation and standards corpora (GDPR, NIS2, AI Act, DORA) with article-level citations, plus live CVE/KEV/EPSS vulnerability context. OAuth remote server, free tier
Details
- Transport
- SSE
Explore
Setup
Install Ansvar in your MCP client (Claude Desktop, Cursor, Windsurf, and others).
Repository: https://github.com/ansvar-systems/ansvar-gateway
Follow the installation instructions in the repository README, then restart your MCP client.
search
Search requires at least one jurisdiction, framework, sector, or source; it does not auto-detect scope from the query. Find laws and regulations on a specific topic. TIER LIMITS: free tier takes ONE jurisdiction or ONE framework per call — no sectors=, no multi-source scope, and no fan-out to agency guidance, case law, or preparatory works — with 100 searches/day and 3 concurrent calls. Solo lifts those scope limits — several jurisdictions, frameworks, and sources in one call — at a higher da…
diff
Compare two versions of a legal provision to see what changed. Use this when someone asks 'what changed in the latest DORA amendment', 'how did this article change between versions', or 'show me the differences in GDPR Article 17 after the update'. Returns a structured diff with added, removed, and modified text. The response ends with a 'Sources used' markdown table listing every gateway row. Render a curated version in your answer with these rules: (I1) every row whose content you used, whe…
get_changes
Find observed rows from legislative change feeds in a jurisdiction or framework, or from an explicit source. Use this for questions such as 'what laws changed in Sweden this month' only when the requested scope is listed as amendment-capable. If since is omitted, the gateway defaults to the last 90 days. Coverage is per corpus. The EU Regulations source is baseline-only during the current interim: it is excluded from amendment-capable dispatch, and a framework it owns is advertised only if an…
get_provision
Look up the exact text of a specific legal provision or standards-catalog control. Three addressing forms: (1) jurisdiction + law + article — use this when someone asks 'show me Article 5 of GDPR', 'what does Section 12 of the Swedish Work Environment Act say', or 'read me the text of DORA Article 11'; (2) canonical_ref — the exact ref a `search` row's `citation.lookup` hint advertises (e.g. get_provision(canonical_ref='loi-2018-07-30:art-64', jurisdiction='BE')): the gateway decomposes it an…
validate_citation
Verify whether a legal citation is accurate and still in force. Use this when someone asks 'is this citation correct', 'has this law been amended', or 'check whether Article 28 GDPR still says this'. Returns validation status with the current text if the provision has changed. The response ends with a 'Sources used' markdown table listing every gateway row. Render a curated version in your answer with these rules: (I1) every row whose content you used, whether marked with a citation number or…
list_coverage
Show which countries, frameworks, and legal domains are available. Use this BEFORE calling `search` when the user's topic doesn't name a jurisdiction (e.g., 'what does the law say about consumer protection'); then present the returned jurisdictions to the user or ask which applies. Examples: • 'Which countries do you cover?' → list_coverage() • 'Do you have German law?' → list_coverage(jurisdiction='DE') • 'What jurisdictions for NIS2?' → list_coverage(domain='cybersecurity') • 'Which…
get_my_capabilities
Tier, capabilities, limits, and live usage for the calling identity. Use this to decide what tools and fan-out paths are available before calling them, or to check remaining quota before issuing more requests — lower-tier agents can avoid wasted retries and decide whether to upgrade mid-conversation rather than discover limits by hitting walls. Visible to all tiers; takes no arguments. Returns a JSON document with: tier (free/solo/premium/team/company), capabilities (workflows, audit_ledger, …
describe_capabilities
Discover what Ansvar can do for your agent. Default (detail='summary') is a compact orientation view: one-line about, your tier summary, counts, a per-category index (id, name, available_to_caller, min_tier, entry_hint, tools/workflows counts, caveats for gated families), meta tool names, next_steps, the paid add-ons directory, and a sources count with a drill-down pointer. detail='full' returns the complete catalog (large — over 100k chars): category prose, the intent-keyed `common_use_cases…
start_workflow
Begin a structured workflow selected from the live workflow registry. The registry covers threat and privacy modeling; enterprise, automotive, robot, rail, OT and UAS risk/TARA; DPIA and FRIA; regulatory, medical-device, drone and machinery gap analysis; tender review and audit; document review; SORA authorisation; vulnerability prioritisation; and deferral dossiers. Call list_workflow_types first: it is the authoritative source of exact ids, deliverables, required slots, variants, and availa…
resume_workflow
Continue a compliance workflow that was paused or interrupted. Use this when someone says 'let's continue the gap analysis', 'pick up where we left off on the threat model', or 'resume my DPIA'. Requires the workflow_id from the original start_workflow call.
list_workflows
List your organisation's workflows (id, type, status, current step, last update). Filter with status='active', 'completed', or 'cancelled'. Results are paginated with limit (default 20, max 100) and offset; follow next_offset until null. Use it to recover a lost workflow_id or review past assessments.
cancel_workflow
Cancel an active workflow by id. Cancelled workflows cannot be resumed and are excluded from resume_workflow's active listing; their record stays visible in list_workflows. Idempotent — cancelling an already-cancelled workflow returns the same result.
get_current_step
Check which step a compliance workflow is currently on and what input is needed next. Use this when someone asks 'where are we in the gap analysis', 'what's the next step', or 'what do I need to provide now'. Returns the current step description and expected input format. questions_for_user is advisory — answerable from context or uploaded documents; requires_user_input=true is the server-enforced human-input gate, and the step then lists user_provided_fields that must be filled before callin…
submit_response
Provide an answer to the current step in a compliance workflow. Use this when someone provides information requested by the workflow, such as 'our system processes health data' or 'we use AES-256 encryption'. The workflow engine validates the response and advances to the next step. Pass user_acknowledged=true only after the user has supplied the fields listed in user_provided_fields. evidence_references accepts document UUIDs, doc:// segment URIs, or regulatory URLs. For an unattended gate, p…
get_progress
See how far along a compliance workflow is and which steps remain. Use this when someone asks 'how much of the gap analysis is done', 'what percentage is complete', or 'how many steps are left'. Returns completed and remaining steps with a progress percentage and quality score.
get_workflow_threats
Review the threats identified during a threat-modeling workflow. Use this when someone asks 'what threats were found', 'show me the risk assessment results', or 'list the identified vulnerabilities'. Returns threats with severity ratings and recommended mitigations from completed STRIDE analysis steps.
generate_report
Produce the final compliance report from a completed workflow. Use this when someone says 'generate the gap analysis report', 'I need the DPIA report as a document', or 'create the threat model output'. Refuses until every quality gate passes, returning the failing check and a hint. Returns a structured report with findings, citations, and recommendations. Pass format html, pdf, docx, or all to additionally receive branded rendered artifacts as short-lived download URLs in a sibling render ke…
list_workflow_types
Find the authoritative live structured-workflow registry. Call this before start_workflow instead of guessing an id from examples or a static catalog. It covers every deployed workflow family, including risk/TARA, DPIA/FRIA, regulatory and medical-device gap analysis, procurement, document review, drone/OT workflows, and vulnerability decisions. Each entry carries workflow_type, base_type, display_name, description, produces (the final deliverable), required_slots, overridable_configurable, l…
create_dfd
Validate a DFD artifact and render it as styled Mermaid. Returns {mermaid, validation_errors, structural_warnings}. Use after the DFD specialist (/threat-modeler-dfd) has finished extraction so the graph integrity (valid node types, declared trust_zones, reachable edge endpoints, recognised regulatory tokens) is checked before the artifact is submitted via submit_response on scoping.component_identification. artifact = {nodes, edges, trust_zones, assets}, each a list. node: {id, type, trust_z…
recommend_subagents
Plan the parallel sub-analyses for a threat-modeling phase. Given the current phase of a threat_model workflow (its id comes from get_current_step) and your workflow context, returns the recommended breakdown: which analysis prompts to run, with what arguments, which can run in parallel, and an inline fallback for MCP clients that cannot invoke prompts. phase_id is one of: phase_0b_scope_check, phase_1_scope_and_dfd, phase_2_stride_enumeration, phase_2b_domain_challenge, phase_3_scoring, phas…
search_cve
Search CVEs by keyword, severity, score range, and filters. Returns matching CVE records with CVSS scores, KEV status, and EPSS data. Use get_cve_details for full information on a specific CVE. Supports full-text search on descriptions.
get_cve_details
Get complete details for a specific CVE including CVSS scores, references, CPE mappings, KEV status, EPSS score, exploit references, and any CISA ICS/OT advisories (ICSA/ICSMA/ICSV) referencing it with their affected industrial products — use this to enrich an OT/ICS or robot-cell TARA with live advisory context.
check_kev_status
Check if a CVE is in the CISA Known Exploited Vulnerabilities (KEV) catalog. Returns KEV details including required remediation actions and due dates.
get_epss_score
Get the EPSS (Exploit Prediction Scoring System) score for a CVE. Returns the probability of exploitation in the next 30 days and percentile ranking.
search_by_product
Find CVEs affecting a specific product and version. Useful for vulnerability assessment of software components.
get_exploits
Get public exploit code references for a CVE from Metasploit, ExploitDB, GitHub PoCs, and other sources.
batch_search
Get details for multiple CVEs in one query (max 100). Efficient for bulk vulnerability assessment.
get_data_freshness
Check the freshness and sync status of all data sources. Returns last sync time, data age in hours, record counts, and health status (current/stale/critical) for each source: NVD, CISA KEV, EPSS, ExploitDB. Use this to verify data is up-to-date before making security assessments.
get_regulatory_intelligence_status
Report what this service actually monitors and how current each source is: the enrolled sources, their publisher, channel kind and jurisdictions, when each last synced successfully, its freshness state (current / stale / critical / unfetched / baseline-only), how many records it holds, and when its baseline backfill ran. Also reports the state of the signed licensing verdict that governs which sources may be fetched at all. Read this before concluding anything from an empty search: a source …
- Search regulations, standards, and threat intel—searchacross audited law corpora, EU regulations (GDPR, NIS2, DORA, AI Act), security frameworks, and live CVE/KEV/EPSS data with cited results.
- Retrieve exact provision text— useget_provisionto resolve a canonical reference to the full, cited text of a specific article or clause.
- Fetch court decisions—get_decisionreturns the exact text of a referenced court ruling with source attribution.
- Discover available jurisdictions and corpora—list_coverageshows which law domains, frameworks, and jurisdictions are currently live and searchable.
EU regulatory intelligence over MCP — law, regulations, standards & threat intel, every answer cited or refused.
Ansvar Gateway is aremote MCP serverfor compliance, legal, and security work. One OAuth connection gives your agent scopedsearchandget_provisionacross audited law corpora — Europe-led, with growing North American and APAC coverage; the live, licence-audited jurisdiction list is atansvar.eu/coverage— plus the EU regulations corpus (GDPR, NIS2, DORA, AI Act, CRA, …), the security-frameworks corpus, and live CVE/KEV/EPSS intelligence.
Every result carries a source citation (_citation: URL, publisher, licence) — answers are cited from fetched text or explicitly refused, never guessed from model memory. Paid tiers add full-fleet fan-out, case law / preparatory works / agency guidance, and structured workflows (DPIA, STRIDE/LINDDUN, gap analysis) that return exportable deliverables.
Claude Desktop / Claude Code / any MCP client that supports remote servers: addhttps://gateway.ansvar.eu/mcpas a remote MCP server and complete the OAuth flow. Free-tier signup is in-flow.
- searchlegislation, regulations, standards and threat intel across jurisdictions — results return matching provisions with article-level citations, not paraphrases.
- get_provision/get_decision— resolve a canonical reference to the exact provision or court decision text.
- list_coverage— discover what corpora and jurisdictions are live, by domain.
- Premium tiers: automatic case-law / preparatory-works fan-out insidesearch, agency guidance, and workflow prompts that produce finished, cited deliverables (DPIA, threat model, gap analysis).
- Accuracy over availability:if a source is unreachable, the gateway returns a data-source-unavailable error — it never answers from model memory.
- Per-item attribution:every served row carries source URL, publisher, and licence; content with unresolved licensing is withheld with an explicit notice, not silently dropped.
- EU-hosted(Hetzner, Germany/Finland), no server-side model, no tracking. Operated byAnsvar Systems AB(Sweden, org.nr 559547-2225).
This is the public home of the hosted Ansvar Gateway — documentation and listing anchor only; the gateway service itself is not developed in this repository. Open-source law-connector code lives across theAnsvar-Systemsorganization (Apache-2.0).
Issues and questions are welcome here; commercial contact:https://ansvar.eu/contact.
Search global news using natural language. Webz.io News Search API returns the most relevant articles and content, with filters for source, country, language, date, sentiment, and category.
ISO 42001 AI management system compliance — gap analysis, control mapping, certification readiness by MEOK AI Labs
Multi-framework AI governance reports across EU AI Act, NIST AI RMF, ISO 42001, and DORA with automated gap analysis
Lightning-Fast, High-Accuracy Deep Research Agent 👉 8–10x faster 👉 Greater depth & accuracy 👉 Unlimited parallel runs
Verified, tier-0 regulatory data for your AI: connect Claude, ChatGPT or Cursor to 850+ official sources across 50+ jurisdictions.
Query 37 EU regulations (DORA, NIS2, GDPR, AI Act, CRA) with full-text search, cross-regulation comparison, and ISO 27001/NIST CSF control mappings. Auto-updates via EUR-Lex monitoring.
Free AI-industry intelligence for agents: briefings, regulation tracker & regional lenses
Airtight math for AI agents: 3.7M-theorem search, PSLQ constant ID, OEIS, real Lean 4 kernel checks. No LLM inside, no API key.
Search PubMed and summarize biomedical literature — designed for AI health agents.
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.


