- Brand
- Ansvar AI
- Category
- Security
- Primary Subcategory
- Regulated-Industry Compliance & Regulatory Research
Integration details
Description
Ansvar Systems AB is a Swedish cybersecurity company that gives AI agents verifiable access to law, regulation and security standards. Customers connect the AI assistant they already use (Claude, Microsoft Copilot, ChatGPT or any MCP-compatible client) to the Ansvar Gateway and run compliance work directly in that assistant: regulatory gap analyses, threat models (STRIDE/LINDDUN, TARA), DPIAs and audit preparation, grounded in more than 300 curated corpora of EU and international legislation, case law, preparatory works, regulator guidance and security standards. Every answer carries paragraph-level citations to the official source. When a source is unavailable, the platform returns an error instead of guessing, accuracy over availability is an architectural rule, not a disclaimer. All content is ingested from the original publisher under verified licensing, so results can be relied on and redistributed. Ansvar serves legal insurers, compliance teams, security consultancies and software teams that need to know which rules apply; NIS2, GDPR, DORA, CRA, the EU AI Act, national and sector regulation — and to prove where every answer came from.
- Integration type
- Plugin
- Verification status
- Not applicable
- Platform
- ChatGPT
- Primary Subcategory
- Regulated-Industry Compliance & Regulatory Research
- Secondary Subcategories
- None listed
- Brand
- Ansvar AI
- Access
- Account required
- First tracked
- 2026-08-18
- Tool count
- 104
- Geography
- US
The Primary Subcategory used for this profile’s headline score.
Other Subcategories where the Integration is listed.
ChatGPT Plugin discovery is coming soon
ChatGPT can surface a Plugin when it matches a user's request.Your Plugin Discovery Score measures how often yours appears.
No spam. Unsubscribe any time.
What discovery looks like

Get alerts for Ansvar Gateway
Get updates when Ansvar Gateway’s Discoverability Score or category rank changes.
Competing in ChatGPT Regulated-Industry Compliance & Regulatory Research
View Category104 tools agents can invoke
Control the BOUNDED seeding window. action=status reports the org's bootstrap state (any team caller): whether a window is open, the one principal it admits, the kinds it covers and when it expires. action=start/stop is org-admin only (permission_denied otherwise). start records one standing assent and opens a window in which ONLY that principal's proposals, and only of the kinds in scope, auto-apply stamped provenance=bootstrap with the window id; every other proposal queues for ordinary review. principal_id names it and is REQUIRED in every profile: it must be a machine principal (an agent seat or a svc: producer identity, never a person) and it may not be the principal opening the window, because a standing assent whose two sides are one account is self-approval. Ids come from arch_grants action=list. scope_kinds defaults to every proposable kind; an empty list is refused. expires_in_hours defaults to 4 and may not exceed 24 — the expiry is checked in the apply transaction, so a window that runs out mid-import applies nothing and needs no sweeper. stop closes it early.
arch_bootstrap
Record that this row is still true as of now: sets last_confirmed_at and confirmed_by on one resource and changes nothing else. Org-admin only (permission_denied otherwise; agent seats are refused, because a machine cannot assert that a human checked something). It is a direct act, not a proposal: it carries no architecture fact, so there is nothing for a reviewer to review. A retired row is refused, and an unknown id errors not_found. arch_overview.currency and arch_coverage.findings.stale_rows report what has not been confirmed inside the workspace's currency_threshold_days.
arch_confirm
unkeyed_obligation_reasons and evidence_less_obligations each return at most obligation_list_limit (200) entries, with a separate *_truncated flag. Compliance-obligation coverage rollup: counts by regime and assessment status, unkeyed obligation/control counts, the obligations with no evidence (ADR/control) links, and the org's unclassified/uncontrolled asset counts. Optionally scope to one regime. Also returns findings: rows typed below the classification of the data they hold, connections crossing a zone boundary with no protocol or no authentication, data objects with special categories and no regulatory regime, internet-exposed nodes on unsupported software, and rows nobody has confirmed inside the currency window. Each finding list is capped at 100 rows and carries its own full count, so a truncated list never understates the problem.
arch_coverage
Read one node's accepted revision, confirmation, latest run per enrolled source, fields_covered and matches_accepted recomputed at the current revision. Conflicting sources return both values, never a majority. not_observed_since requires a complete scan within enrolled scope and never auto-retires. Also returns citation dates, basis summary and latest citation checks per field. A basis check does not establish that the field value remains true.
arch_currency
Mermaid responses carry source under diagram and the diagram name under name, the same shape as each arch_export Mermaid diagram. Render a Mermaid data-flow diagram from the stored graph: trust zones as subgraphs; services, applications, data stores and technology nodes as nodes; connections as edges labeled with protocol[/port], auth mechanism, transit encryption and the data objects carried. Legacy data_flow rows with no connection are still drawn, labeled with data kind + transit encryption and marked (legacy). A flow that names a connection is drawn once, as its connection. Networks are not drawn: they are segments, and trust zones are the boundaries. scope is a zone name/id or a list of service ids (default: the whole org). Output is deterministic. node_ids maps <kind>:<id> to the exact Mermaid id of each declared node and subgraph (trust_zone for zone subgraphs, external for external endpoints); scoped-out rows and empty zones are absent. Clients must use this map, not re-encode row ids. At most 10000 entries; larger maps refuse with mermaid_node_ids_limit_exceeded, never a partial map. level=context derives organisation units, applications, suppliers and external endpoints, aggregating connections per directed pair with counts and protocols. level=container requires application (id), showing its realising services, hosts and stores (owner_service or stored data processed by its members). level=component requires service (id); service.modules[] is not served in this build, so it returns an empty diagram with not_served explaining the gap. C4 levels take no scope; full (default) takes no application/service. C4 responses include connections with connection_ids, omitted_connection_ids, and not_served gaps. External names are not served. C4 identity collisions refuse with mermaid_node_id_collision.
arch_dfd
Export this organisation's accepted graph. format=json-bundle (default) is lossless and versioned (transfer_format_version), deterministically ordered, and round-trips through arch_import_batch into an empty workspace; it carries counts, the self-approved and bootstrap row counts, and meta.omissions naming what it does not carry (credentials and the audit event store). format=mermaid returns two diagrams — the data-flow diagram arch_dfd serves and a trust-zone/network view with connections labelled protocol[/port] — with every label escaped, so a node name cannot become diagram syntax. Each diagram includes node_ids (<kind>:<id> to its exact declared Mermaid id); the top-level node_ids is their union. Zone subgraphs use trust_zone keys; synthetic placeholders use empty_zone and the unassigned-networks subgraph uses diagram_group:unassigned_networks. Maps are bounded at 10000 entries and refuse with mermaid_node_ids_limit_exceeded, never truncation. JSON nodes and edges include their current portable citations; historical citations, proposal ids and verification checks are not transferred. An export reads; it writes nothing.
arch_export
Fetch one resource by kind + id: all fields, its resolved links (relationship name -> target ids, or {kind, id} objects for a relationship that reaches more than one kind), and _provenance. Kinds that derive a classification from the data objects they hold also carry _classification (typed, derived, effective, source, below_content); a dependency carries refined_by, the connections that refine it. Errors not_found when the id is absent in this org. Pass at_revision to read the row as it stood at that revision, with the links it had then; a revision that was never recorded errors not_found, and a kind without revisions (assessment) refuses at_revision. Component values remain immutable, with citation_revision pinning reviewed basis changes. citations is grouped by field, each citation stating its own proof_level; link_citations identifies outgoing edges and their basis. observation_runs maps citation proposal ids to source_id, run_id and batch_id for connector run links. Current reads include last_check; revision reads pin citations and omit later checks. proof carries {level, reason, citations, lowered} for EVERY payload field except id, including the ones no citation reaches, and proof_summary counts those levels; each link_citations entry carries the same proof block for its edge. proof levels, strongest first: observed > stated_structured > stated_prose > answered > assumed > none. observed = basis observed, or a run: locator. stated_structured = basis stated with a repo: locator whose path ends in .json/.yml/.yaml/.csv/.toml or sits under backstage/catalog/fleet-manifests/, backstage/ingest/, deployment/, infrastructure/policy/, infrastructure/scope/ (a path containing @ or : is prose whatever it ends in: those are the locator's own separators). stated_prose = basis stated with any other repo: path, a url: or a path: locator. answered = basis answered. assumed = basis assumed. none = no citation on the field. A field takes the HIGHEST level any of its current citations reaches. A citation whose latest check is moved counts one level lower, and so does one whose latest check is unreachable for a reason that means the source location was reached and the cited text was not there (repository_commit_or_path_missing, source_not_regular_file, url_source_missing). Every other unreachable reason is a check that never compared anything — it could not look, or could not read what it found — and leaves the level exactly where it was, as unchanged and an unchecked citation do. A revision read carries no checks, so it reports unlowered levels.
arch_get
Fetch one assessment by its required id, including its dependency refs and provenance. Causes are newest first, capped at 50; pass causes_next_cursor as causes_cursor to continue. Errors not_found when the id is absent in this org.
arch_get_assessment
Fetch one component version row by its required id, including provenance. Errors not_found when the id is absent in this org.
arch_get_component
Fetch one proposal by proposal_id (id is an alias for one release), including its full diff, evidence, and assenter comment. Errors not_found when absent in this org.
arch_get_proposal
List resources of one kind, cursor-paginated with returned/total. filters keys must be scalar columns of the kind (e.g. service: lifecycle/owner/runtime/data_classification/criticality/exposure); an unknown filter key is rejected, never silently ignored. Offset cursor: a concurrent insert or delete may shift the page, so a row can repeat or be missed across pages (arch_list_components / arch_list_assessments / arch_list_proposals use keyset cursors and cannot). Each row includes citations and basis counts {observed,stated,answered,assumed,none}. filters.has_citation is a boolean: false selects wholly uncited rows; true selects rows with at least one current field citation. Each row also carries proof per field and proof_summary counting those levels. filters.proof_below names a level and selects rows holding at least one field that proves less than it; allowed: ['observed', 'stated_structured', 'stated_prose', 'answered', 'assumed']. filters.proof_at names a level (or a list of levels) and selects rows holding at least one field standing exactly on one of them; allowed: ['observed', 'stated_structured', 'stated_prose', 'answered', 'assumed', 'none']. Pass one of the two filters, never both. A proof level is not a column, so either filter is a bounded SCAN: the page reports proof_scan_cap and proof_scan_truncated, a truncated page's total is a lower bound, and while next_cursor is present total counts the matches classified so far (the scan resumes where the page stopped, so following the cursors classifies each row once). proof levels, strongest first: observed > stated_structured > stated_prose > answered > assumed > none. observed = basis observed, or a run: locator. stated_structured = basis stated with a repo: locator whose path ends in .json/.yml/.yaml/.csv/.toml or sits under backstage/catalog/fleet-manifests/, backstage/ingest/, deployment/, infrastructure/policy/, infrastructure/scope/ (a path containing @ or : is prose whatever it ends in: those are the locator's own separators). stated_prose = basis stated with any other repo: path, a url: or a path: locator. answered = basis answered. assumed = basis assumed. none = no citation on the field. A field takes the HIGHEST level any of its current citations reaches. A citation whose latest check is moved counts one level lower, and so does one whose latest check is unreachable for a reason that means the source location was reached and the cited text was not there (repository_commit_or_path_missing, source_not_regular_file, url_source_missing). Every other unreachable reason is a check that never compared anything — it could not look, or could not read what it found — and leaves the level exactly where it was, as unchanged and an unchecked citation do. A revision read carries no checks, so it reports unlowered levels.
arch_list
List this org's assessments, keyset-paginated (the cursor is the last id on the page). Optional currentness and kind equality filters are validated. kind and the stored currentness values are filtered in SQL; currentness itself is computed at read time for the returned page plus a bounded look-ahead, so a page may return fewer rows than limit while next_cursor is set — keep paging until next_cursor is null. total is reported only when it is exact (no currentness filter, or superseded/imported); otherwise it is null, total_is_exact is false, and total_candidates carries the SQL upper bound.
arch_list_assessments
List the immutable component version rows of one service, keyset-paginated with returned/total (the cursor is the last id on the page, so a concurrent insert cannot skip a row). service_id is required; an unknown service is refused with not_found.
arch_list_components
List this org's proposals (newest first), keyset-paginated with returned/total (the cursor is the last (proposed_at, id) on the page, so reviewing a proposal while paging cannot skip a pending one). Optional filters: status, kind, proposed_by.
arch_list_proposals
One-call orientation for the caller's org: per-kind resource counts, trust zones with exposure, unclassified/uncontrolled asset counts, unmitigated-threat count, pending-proposal count, waiting import batches (open batches and undecided items — a batch is not a proposal, so the proposal count carries none of them), last-applied-change timestamp (overall and per kind), bootstrap state, and scoring readiness (projectable vs unprojectable assets with top refusal reasons). Recommended first call. node_ids maps trust_zone:<id> to server Mermaid ids for every zone, including empty zones, using the diagram renderer's encoder. The map has one entry per returned zone, with no separate map limit or map-size refusal. red_flag_severity serves the shared rule ranking used by the page (low=1, medium=2, high=3), with authentication and storage ranked by the highest data classification involved. basis_coverage reports fields with and without a citation per kind, counting payload field slots except id. proof_coverage splits the same slots by how well each is proven, one count per level per kind: proof levels, strongest first: observed > stated_structured > stated_prose > answered > assumed > none. observed = basis observed, or a run: locator. stated_structured = basis stated with a repo: locator whose path ends in .json/.yml/.yaml/.csv/.toml or sits under backstage/catalog/fleet-manifests/, backstage/ingest/, deployment/, infrastructure/policy/, infrastructure/scope/ (a path containing @ or : is prose whatever it ends in: those are the locator's own separators). stated_prose = basis stated with any other repo: path, a url: or a path: locator. answered = basis answered. assumed = basis assumed. none = no citation on the field. A field takes the HIGHEST level any of its current citations reaches. A citation whose latest check is moved counts one level lower, and so does one whose latest check is unreachable for a reason that means the source location was reached and the cited text was not there (repository_commit_or_path_missing, source_not_regular_file, url_source_missing). Every other unreachable reason is a check that never compared anything — it could not look, or could not read what it found — and leaves the level exactly where it was, as unchanged and an unchecked citation do. A revision read carries no checks, so it reports unlowered levels.
arch_overview
Propose a create/update of one resource. proposed_by is the injected caller identity (no such argument). payload is validated against the kind's schema (unknown fields and bad enum values are rejected); links add/remove relationship targets, validated to exist in this org. Records a proposal; nothing changes until a reviewer assents. During an open bootstrap window it auto-applies under the standing assent and the response says so.
arch_propose
Propose creation of one immutable component version row. Required arguments are id, service_id, kind, name, version, observed_at, and evidence. A later version must use a new id; updates and retirement are refused. Envelope citations state the field basis; evidence is proposal evidence. A citation-only update preserves the immutable component values.
arch_propose_component
Propose a re-review of one resource: present its FULL current state — every field and every relationship it has right now — for a second principal to approve. This is the only way a self-approved row becomes reviewed. Approving an ordinary field edit leaves the label in place, because that reviewer saw one diff and not the row. The approver must be someone other than the proposer AND other than the principal already recorded on the row (re_review_same_assenter otherwise), and the presented state must still match the live row at apply time (stale_proposal otherwise). It changes no field. Never auto-applies during a bootstrap window.
arch_propose_re_review
Propose soft-retirement of a resource (flips its terminal field where one exists: service->retired, adr->deprecated, vulnerability->closed, compliance_obligation->non-compliant-accepted; other accepted kinds record the proposal for the audit trail). Components and assessments are omitted because they are append-only. It always records a proposal; an already-terminal target returns that state explicitly. Auto-applies during a bootstrap window.
arch_propose_retire
The open questions about this organisation's architecture, highest consequence first, each with the arch_propose (or arch_confirm) call its answer turns into and the closed vocabulary to answer from where there is one. The rubric is data, not prose: unset owner, classification, criticality or exposure (including every scoring-readiness input), a connection on protocol or authentication 'unknown', a zone crossing with no encryption stated, a data object carrying special categories with no regime or retention, an application or node in no zone, a supplier whose data access nobody stated, an identity provider with no MFA policy, an internet-reachable node whose patch status is unknown, and rows nobody has confirmed inside the workspace's currency threshold. A question closes when its answer is ASSENTED; a pending proposal marks it answer_pending and leaves it open. Scope it with kind, environment or id_prefix. Each rule evaluates every scoped row in SQL; total and counts_by_rule are exact. Each rule reports open (excluding pending), pending, answered and eligible. Answered counts closed slots filled by applied assented proposals; eligible includes all scoped slots that meet the rule context, including recorded values without an assented answer. Pending answers have no read cap. Only returned questions are paged at 200; pass next_cursor as cursor. Edge rendering reads only selected slots, at most edge_fetch_cap (200) outgoing edges per row. edge_questions_truncated says this page omits some open or pending edge slots in the selected scope; totals stay exact and those slots remain pageable. Edge proposals name only the cited targets. truncated_rules is empty and rule_fetch_cap is null. no_basis_recorded and basis_moved have consequence 2 and ask for a citation while retaining the accepted value or edge. proof_only_assumed has consequence 3 and asks the same way for a field whose only basis is an assumption (proof level exactly assumed), on the five kinds an assessment reasons over (service, data_store, data_object, connection, trust_zone); a field with no basis at all is no_basis_recorded's question, asked once. Its questions carry proof_level. proof levels, strongest first: observed > stated_structured > stated_prose > answered > assumed > none. observed = basis observed, or a run: locator. stated_structured = basis stated with a repo: locator whose path ends in .json/.yml/.yaml/.csv/.toml or sits under backstage/catalog/fleet-manifests/, backstage/ingest/, deployment/, infrastructure/policy/, infrastructure/scope/ (a path containing @ or : is prose whatever it ends in: those are the locator's own separators). stated_prose = basis stated with any other repo: path, a url: or a path: locator. answered = basis answered. assumed = basis assumed. none = no citation on the field. A field takes the HIGHEST level any of its current citations reaches. A citation whose latest check is moved counts one level lower, and so does one whose latest check is unreachable for a reason that means the source location was reached and the cited text was not there (repository_commit_or_path_missing, source_not_regular_file, url_source_missing). Every other unreachable reason is a check that never compared anything — it could not look, or could not read what it found — and leaves the level exactly where it was, as unchanged and an unchecked citation do. A revision read carries no checks, so it reports unlowered levels. Other interview answers explicitly record answered citations with the answering principal and time. Optional rule selects a rule id or kind.rule before applying the question cap.
arch_questions
Substring search across all resource kinds (or the given subset). Returns kind, id, name, and a matching snippet. Cursor-paginated with returned/total counts. Offset cursor: a concurrent insert or delete may shift the page, so a row can repeat or be missed across pages.
arch_search
Breadth-first subgraph walk from a start node across every edge family (adr_link, adr_supersession, composition, connection, control_anchor, data_flow, data_handling, dependency, identity, obligation_link, placement, realisation, supply, threat_mitigation, threat_target, vuln_mitigation, vuln_target, zone_membership). depth is honored, capped at 3; direction filters out|in|both; edges restricts to a subset of families. Returns reached nodes (with hop) and the traversed edges.
arch_traverse
action=status (any caller) reports this workspace: display_name recorded by init --name (null when unnamed), the four version numbers (product, schema, policy, transfer format — an absent one is null WITH a reason), the profile, the organisation, per-kind row counts, the currency threshold and stale-row counts, the open bootstrap window, whether the listener is on an insecure bind, and the newest backup beside the workspace file. action=backup and action=clone are org-admin only and work on a standalone workspace FILE — a central or plane database is backed up with the operator's own tooling and both refuse there by name. A backup is the same workspace, token hashes and sessions included, for restoring onto this machine. A clone is that copy with every session dropped, every token revoked and every live code burned, keeping the Owner principal: for the same Owner moving to a new machine, which then needs a fresh pairing code. The signing key's private half is beside the workspace and is not copied. action=settings is standalone Owner-only and sets require_citations (default false).
arch_workspace
Get details for multiple CVEs in one query (max 100). Efficient for bulk vulnerability assessment.
batch_search
Cancel an active workflow by id. Cancelled workflows cannot be resumed and are excluded from resume_workflow's active listing; their record stays visible in list_workflows. Idempotent — cancelling an already-cancelled workflow returns the same result.
cancel_workflow
Change-tracking status across catalog/mapping versions: each framework's pinned version and source artifact hash, plus migration maps between major framework versions. Change-detection reports (added, withdrawn, or re-versioned requirements; mapping edges whose resolved clause has drifted) are not yet produced — the tool returns an explicit no-change-detection-report status rather than fabricated drift.
changes
Determine which EU regulations apply to an entity based on its sector and optional subsector. Returns applicable regulations with confidence levels (definite / likely / possible), the basis article, and contextual notes. detail_level=summary adds counts + priority deadlines. Team standalone. At premium tier this tool is callable only while executing an admitted premium workflow run — pass the run's workflow_id argument.
check_applicability
Check if a CVE is in the CISA Known Exploited Vulnerabilities (KEV) catalog. Returns KEV details including required remediation actions and due dates.
check_kev_status
Compare how 2+ EU regulations treat the same compliance topic. Uses concept-synonym expansion (incident reporting → breach notification, ICT risk → risk management, etc.) and full-text search over the EU corpus. Returns per-regulation requirement snippets, article numbers, and extracted timelines.
compare_requirements
Compute coverage for a framework, optionally scoped to an applicability profile: covered requirements (>=1 authoritative equivalent/superset-of edge), partially covered (only subset-of/intersects-with edges — with the union of residual_gap texts as the work list), and unmapped. Calls the same compute_coverage code the CI coverage artifact uses, so the served number and the build number cannot diverge. Only reviewed edges count. `detail` bounds the response: 'summary' (per-framework totals), 'requirements' (one edition's requirement rows, filtered by status and paged by limit/offset), or 'full' — pass it explicitly; an omitted detail serves 'full' until the default flips to 'summary'. The unfiltered full report is ~1 MB.
coverage
Validate a DFD artifact and render it as styled Mermaid. Returns {mermaid, validation_errors, structural_warnings}. Use after the DFD specialist (/threat-modeler-dfd) has finished extraction so the graph integrity (valid node types, declared trust_zones, reachable edge endpoints, recognised regulatory tokens) is checked before the artifact is submitted via submit_response on scoping.component_identification. artifact = {nodes, edges, trust_zones, assets}, each a list. node: {id, type, trust_zone, name?} where type is one of process|data_store|external_entity|actor and trust_zone references a trust_zones[].id. edge: {src_node, dst_node, id?, protocol?, authentication?, encrypted?, crosses_boundary?} where src_node/dst_node reference node ids (from/to accepted as aliases). trust_zone: {id, name?}. asset: {owner_node, id?, regulatory_relevance?} where owner_node references a node id and regulatory_relevance tokens are one of GDPR|PCI_DSS|DORA|NIS2|EU_AI_Act|HIPAA|ePrivacy|EBA|EIOPA. Bad input returns validation_errors with mermaid=null; it never raises.
create_dfd
Navigate one requirement of framework A through the shared canonical control spine to the requirements of framework B: requirement A → controls that satisfy it → framework B's requirements on those controls. Paths return the stored directional edge facts and classify the navigation as related-link or review-required; no cross-framework coverage claim is derived from an indirect path (weakest-link semantics — a chain through a subset-of never over-claims). from_ref accepts the bare ref or the qualified requirement id coverage/get_control emit — one ref-space across the tools. Unknown, ambiguous, or mismatched editions and refs return explicit errors naming the known frameworks and nearest refs; an empty result carries empty_result_context naming why (edge-less framework / needs-review-only paths / no connecting path).
crosswalk
Decrypt an audit receipt server-side using the tenant's KMS key. Identify the receipt by the query_id that list_receipts and get_receipt return (this is the id you will normally have), or by the canonical receipt_id from those same responses — pass exactly one of the two. If a query_id matches more than one receipt, the error lists candidate seqs; pass seq alongside query_id to select one. Use this when someone asks 'show me what was returned for this query', 'decrypt the audit record', or 'read the plaintext of this receipt'. Returns the decrypted query, response, and metadata. Writes a decrypt event to the chain for auditability.
decrypt_receipt
Permanently remove a document from your document library. The library is shared across your organization when your sign-in carries the organization (documents uploaded by any member); otherwise it is personal to your account. Deletion removes the document for the whole library — including one a teammate uploaded. Idempotent: returns success even if the document was already deleted or never existed. Use when the user says 'delete that doc', 'remove the old policy', or 'clean up the drafts'. Cannot be undone. Team and Company tier only.
delete_my_document
Discover what Ansvar can do for your agent. Default (detail='summary') is a compact orientation view: one-line about, your tier summary, counts, a per-category index (id, name, available_to_caller, min_tier, entry_hint, tools/workflows counts, caveats for gated families), meta tool names, next_steps, the paid add-ons directory, and a sources count with a drill-down pointer. detail='full' returns the complete catalog (large — over 100k chars): category prose, the intent-keyed `common_use_cases` map, `anti_patterns`, guidance, the tour, and the full sources directory. section='sources' | 'addons' | 'tour' | <category id> returns that one section alone; an unknown section is an error listing the valid ids. section='sources' returns 4 entries by default: compact entries carry a one-sentence address for corpora with get_provision; detail='full' replaces address with lookup, including served shapes, shares, examples, declared form, prefixes and addressing guidance. Filter by query, declared domain or jurisdiction; continue with next_cursor as cursor. query, domain, jurisdiction, cursor and limit require section='sources'. detail is validated before section: an invalid detail is an error even when section= is passed. Every view is tier-aware: `available_to_caller` flags and caveat text reflect the caller, and gated families are shown with caveats, never silently omitted. The workflow lists are reconciled at read time against a TTL-cached snapshot of the live workflow registry (background-refreshed, 15 min): `workflow_types_index` carries the snapshot status (live / stale / unavailable) and `fetched_at`, plus registry types the curated catalog does not list yet; `catalog_drift` lists catalog ids the registry no longer serves (dropped from the payload). `service_notices` names subsystems in a known degraded state and the exact tools affected; a category's `tool_status` marks a catalog tool that currently dispatches on zero scopes fleet-wide and is withheld from tools/list and the category roster until a feed serves (e.g. get_changes during the baseline-only interim), with the same reason_code the tool's own refusal returns. Companion to get_my_capabilities (live tier / quota only). Backed by this repo's data/capabilities-catalog.yml (mirrored for documentation as infrastructure/gateway/capabilities-catalog.yml in arch-docs).
describe_capabilities
Compare two versions of a legal provision to see what changed. Use this when someone asks 'what changed in the latest DORA amendment', 'how did this article change between versions', or 'show me the differences in GDPR Article 17 after the update'. Returns a structured diff with added, removed, and modified text. The response ends with a 'Sources used' section — a markdown table carrying the audit receipt for each returned row, or a labelled zero-result note — and meta.render_contract carries the versioned evidence-curation contract for reproducing source attributions when the answer is rendered.
diff
Find EU legal acts by CELEX/ELI identifier, official title, reviewed alias, or LEXICAL match on title and EuroVoc labels (not semantic); filter by EuroVoc topic id or label, Ansvar sector, document type and availability. Returns bounded candidates with per-edition currency state and hold reasons, a framework crosswalk to eu-regulations where the same act is keyed there, and exact search/lookup hints.
discover_eu_legislation
EXPERIMENTAL — results must be verified by qualified security and safety experts before use; do not act on them blindly. Score the operational impact of a CVE against a specific asset using context-aware CVSS adjustment rules. Call this when someone asks 'what is the real risk of CVE-2024-1234 on our payment gateway', 'does this CVE actually affect us given our network controls', or 'adjust the CVSS score for our environment'. Send the asset configuration IN the call as scoring_context (the ScoringContext document from your living-architecture twin's scoring projection or your own pipeline; there is no central context registry) plus a scoring_policy_id (use list_scoring_policies). Returns a full EffectiveRiskResult with the adjusted score, metric-by-metric provenance, and the policy rules that triggered each modification. cvss_version is '3.1' (4.0 falls through to its own micro-plan). mode is 'contextual_severity' (rescore CVSS metrics only) or 'operational_risk' (also apply ignored-control filters). By default only rules that fired are returned, with a rule_evaluation_summary count; pass verbose=true for the full rule library. An experimental robot/OT safety rule pack fires only when the context attests robot or OT asset context; such verification-class predicates are accepted only from an authenticated human session. Nothing is stored at Ansvar: the result comes back with a review_token (a signed Ed25519 statement of what the engine computed for your organization) and a twin_record (the producer facts for your living-architecture recorder). To record a human review decision pass that review_token, unchanged, to record_review_decision; to publish OpenVEX pass review tokens to export_vex. A result with no token says why in review_token_unavailable. Team and Company tier only.
effective_risk
EXPERIMENTAL — results must be verified by qualified security and safety experts before use; do not act on them blindly. Score one CVE against an asset described inline — no pre-registered scoring_context_id needed. Use this during workflows (threat_model, linddun, dpia, tender_review, gap_analysis) where you have an asset description in the workflow frame. Builds an ephemeral ScoringContext from the call args, runs the same scoring pipeline as effective_risk, returns the same EffectiveRiskResult shape. No DB write — context lives only for this call. controls is a list of {control_ref: str, attested: bool=true, evidence_refs?: [doc-segment URIs]} entries. A control with evidence_refs is graded 'evidenced' once the gateway resolves each ref against YOUR registered tamper-evident document segment (only resolved refs are forwarded; an unresolvable, malformed, or whole-document ref fails the call — no self-asserted evidenced). This is how an evidenced-class rule (e.g. RULE-MVC-0003, which needs scf_NET-12 at evidence_class='evidenced') fires from inline; without evidence_refs a control is 'attested'. Whether a control fires a rule depends on TWO independent gates: (1) the rule's evidence_class must be satisfied (an 'evidenced' rule needs a control with resolved evidence_refs; an attested-only control will not satisfy it), and (2) the scoring policy's compensating_control_evidence_requirement must allow it (policy_v1_audit='evidenced_only' blocks attested-tier evidence entirely; policy_v1_engineering='evidenced_or_attested' accepts it). Rules also have CWE / exposure / attack_vector preconditions independent of evidence — a control may be properly attested AND policy may permit it, but if the CVE's CWE isn't in the rule's cwe_includes_any list, the rule won't fire. Alternatively — do NOT combine with controls in one call (a mixed call is rejected) — use the unified evidence surface: evidence[] = a deployed control SHAPE on the vulnerable path, each {claim, evidence_refs?} where claim is an SCF provision ref (scf_<id>) OR a registered observed-control token; attributes{} = deployment-scope / platform QUALIFIERS of the asset (e.g. target_platform_linux: true). The gateway resolves each evidence_ref against YOUR registered tamper-evident documents (only resolved refs forwarded; an unresolvable, malformed, or whole-document ref fails the call — no self-asserted evidenced path); refs on a token claim are resolved but do not upgrade the shape to SCF grade. Optionally assert asset fail-safe attestations — asset_end_to_end_tls_not_decrypted_at_control, asset_no_forwarding_tier_relay, asset_replay_resistant_authentication — analyst affirmations that let the matching transport / forwarding-relay / replay reduction rules apply; omit them to leave unasserted (no reduction). product_identifier (purl/CPE) makes the result OpenVEX-exportable. Disposition semantics: disposition.status stays 'under_investigation' (review_required=true) unless a disposition rule fires or a human review is recorded — KEV listing / high EPSS never auto-assert a disposition. In-the-wild exploitation signals are CVE-level, not asset-level: they surface in operational_signals (kev_listed, epss_score, exploit_evidence) and act only as a brake on not_affected, by design. Nothing is stored at Ansvar: the result comes back with a review_token (a signed Ed25519 statement of what the engine computed for your organization) and a twin_record (the producer facts for your living-architecture recorder). To record a human review decision pass that review_token, unchanged, to record_review_decision; to publish OpenVEX pass review tokens to export_vex. A result with no token says why in review_token_unavailable. By default only rules that fired are returned, with a rule_evaluation_summary count; pass verbose=true for the full rule library. Team standalone. At premium tier this tool is callable only while executing an admitted premium workflow run — pass the run's workflow_id argument.
effective_risk_inline
EXPERIMENTAL — results must be verified by qualified security and safety experts before use; do not act on them blindly. Score multiple CVEs against the same inline asset description. Same semantics as effective_risk_inline but accepts cve_ids[] (1-100) and returns one EffectiveRiskResult per CVE. The asset, controls, and policy are described once and reused. Suited for 'given these N CVEs, what's the real risk against this server' questions during a threat model or gap analysis. Like effective_risk_inline you may instead use the unified evidence surface — evidence[] ({claim, evidence_refs?}: an SCF provision ref or an observed-control token, a deployed control SHAPE) and attributes{} (deployment-scope / platform QUALIFIERS, e.g. target_platform_linux). These are asset-global: described once and applied to every CVE. The gateway resolves each evidence_ref against YOUR tamper-evident documents (an unresolvable, malformed, or whole-document ref fails the call — no self-asserted evidenced path). Do NOT combine controls with evidence/attributes in one call (a mixed call is rejected). Nothing is stored at Ansvar: the result comes back with a review_token (a signed Ed25519 statement of what the engine computed for your organization) and a twin_record (the producer facts for your living-architecture recorder). To record a human review decision pass that review_token, unchanged, to record_review_decision; to publish OpenVEX pass review tokens to export_vex. A result with no token says why in review_token_unavailable. By default only rules that fired are returned per result, with a rule_evaluation_summary count; pass verbose=true for the full rule library. When emit_vex is true the response gains top-level vex and vex_meta keys beside results (which stays a list); vex is a standalone CycloneDX 1.6 VEX document for Dependency-Track 'Apply VEX', keyed to caller-supplied SBOM bom-refs via component_identifiers (cve_id -> bom-ref). vex_scope 'adjusted_only' (default) includes only context-adjusted findings, 'all' includes every scored finding; nothing is ever suppressed (no not_affected). Team standalone. At premium tier this tool is callable only while executing an admitted premium workflow run — pass the run's workflow_id argument.
effective_risk_inline_batch
Export an audit bundle for a date range, in one of two forms. The FULL bundle (the default) carries every receipt's encrypted envelope plus anchors, TSA timestamps and signatures — offline-verifiable without Ansvar API access, and many megabytes for a week of activity. The SUMMARY bundle (include_envelopes=false) carries receipt metadata and anchors only: about a hundred times smaller, sized for a chat client, and explicitly NOT offline-verifiable — a view of the trail, not evidence. Use the full bundle for 'export the audit trail for the regulator' or 'create an evidence package'; use the summary to see what the trail holds. scope selects 'range' (whole organisation, org-admin only), 'mine' (your own receipts), 'chat' (one conversation) or 'message' (one message). Either form is refused with the observed size if it would exceed the response cap, and is never truncated.
export_audit_package
EXPERIMENTAL — results must be verified by qualified security and safety experts before use; do not act on them blindly. Serialize VEX dispositions into an OpenVEX document so a customer can publish SBOM-matchable not_affected / affected / fixed / under_investigation statements. Pass review_tokens[] (the tokens the scoring and review calls returned, unchanged, up to 100; scored tokens export as review pending, review events as decided; every statement is marked provenance signed) or dispositions[] verbatim (marked caller_asserted). Nothing is stored at Ansvar. explanation_ids is retired and refused. Fail-closed: refuses statements that are not OpenVEX-conformant (e.g. a disposition whose subject lacks a product_identifier). Always pass an ISO-8601 timestamp; author and doc_id are optional. Team and Company tier only.
export_vex
Produce the final compliance report from a completed workflow. Use this when someone says 'generate the gap analysis report', 'I need the DPIA report as a document', or 'create the threat model output'. Refuses until every quality gate passes, returning the failing check and a hint. Returns a structured report with findings, citations, and recommendations. Pass format html, pdf, docx, or all to additionally receive branded rendered artifacts as short-lived download URLs in a sibling render key; render failures attach render_error and never drop the report JSON. Rendering is served by the document plane and starts at the team tier; on free and solo an included run also returns html or pdf carrying an Ansvar watermark. Every other tier receives the report as JSON, and a format the caller's tier does not serve is refused explicitly rather than quietly downgraded.
generate_report
Find observed rows from legislative change feeds in a jurisdiction or framework, or from an explicit source. Use this for questions such as 'what laws changed in Sweden this month' only when the requested scope is listed as amendment-capable. If since is omitted, the gateway defaults to the last 90 days. Coverage is per corpus. The EU Regulations source is baseline-only during the current interim: it is excluded from amendment-capable dispatch, and a framework it owns is advertised only if another reachable feed supports that framework. A successful empty response is not evidence that no amendments occurred. On a capability miss, the response names supported source, framework, and jurisdiction scopes — or, when no corpus advertises change feeds at all, says so explicitly with supported_scopes empty on every axis. Every dispatched response reports whether baseline rows were actually withheld and whether the producer supplied typed event metadata. Legacy rows without typed event metadata remain visible with event_kind unknown. A scope value that names nothing we serve is refused, not ignored: the call errors and names the value, never returning changes for only the part that resolved. Use diff for a known provision. Boundary: this tool reports amendments observed in SERVED corpus text; for newly published official acts and regulator announcements (what is new, not what changed in a text we serve), use search_regulatory_updates. The response ends with a 'Sources used' section — a markdown table carrying the audit receipt for each returned row, or a labelled zero-result note — and meta.render_contract carries the versioned evidence-curation contract for reproducing source attributions when the answer is rendered.
get_changes
Get one canonical control by id (NIST paren form, e.g. 'AC-2', 'AC-2(1)', or 'ANSV-PV-001'): its statement, family, CSF 2.0 function, and a summary of the framework requirements it maps to with the relationship type of each edge.
get_control
Check which step a compliance workflow is currently on and what input is needed next. Use this when someone asks 'where are we in the gap analysis', 'what's the next step', or 'what do I need to provide now'. Returns the current step description and expected input format. questions_for_user is advisory — answerable from context or uploaded documents; requires_user_input=true is the server-enforced human-input gate, and the step then lists user_provided_fields that must be filled before calling submit_response.
get_current_step
Get complete details for a specific CVE including CVSS scores, references, CPE mappings, KEV status, EPSS score, exploit references, and any CISA ICS/OT advisories (ICSA/ICSMA/ICSV) referencing it with their affected industrial products — use this to enrich an OT/ICS or robot-cell TARA with live advisory context.
get_cve_details
Check the freshness and sync status of all data sources. Returns last sync time, data age in hours, record counts, and health status (current/stale/critical) for each source: NVD, CISA KEV, EPSS, ExploitDB. Use this to verify data is up-to-date before making security assessments.
get_data_freshness
Look up a specific court decision (case) by its citation and return the decision plus its cross-references: the legislation it interprets or cites (`cross_references`, a list on every case-law corpus — only as complete as that corpus's reference extractor, so an empty list means the build resolved no statute reference in the text, never that the judgment cites no legislation) and, on common-law corpora only, the prior cases it cites (`cited_cases`, with `cited_statutes` beside it). Civil-law corpora (ECLI-keyed, such as NL and the other continental courts) do not yet carry case-to-case links, so an absent `cited_cases` there means not built, never 'cites no prior case'. Use this after a `search` whose results include case-law rows (premium tiers receive case law inside `search` automatically — there is no separate case-law search tool), with the jurisdiction and the case's canonical reference (ECLI such as ECLI:NL:HR:2019:2006, or the corpus's neutral citation), to expand which regulations a judgment interprets and which provisions it cross-links to. The case-law counterpart of get_provision. Premium tiers and above. The response ends with a 'Sources used' section — a markdown table carrying the audit receipt for each returned row, or a labelled zero-result note — and meta.render_contract carries the versioned evidence-curation contract for reproducing source attributions when the answer is rendered.
get_decision
Break a registered document into its structural sections and paragraphs. Use this when someone asks 'show me the sections of this document', 'what topics does this policy cover', or 'give me an outline of this uploaded document'. Returns the document's section hierarchy with paragraph-level references for citation in doc:// URI format. Pass section_ref to drill into a node and get its children, including sentence-level segments for the narrowest possible citation. To present the resulting citations, see the `cite-document` prompt (numbered-text or rich-HTML rendering).
get_document_segments
Ansvar Gateway ChatGPT Plugin FAQ
How the directory, categories and Discoverability Score work.
Read the methodologyHow do I improve Ansvar Gateway's ChatGPT Plugin discoverability?
The levers are the listing surface agents actually read: names, descriptions, keywords, tool metadata, and registry health. Which lever matters depends on where discovery breaks, which is what continuous measurement shows.
What are Ansvar Gateway alternatives on ChatGPT?
As of 2026-10-05, Ansvar Gateway competes with Amok, BoardWise, Brokly, CMS Coverage, COLA Cloud, Dovetail Regulatory, England CQC — RegEvidenceHub, H-INNO FCC/KC Insight and 12 more in ChatGPT Regulated-Industry Compliance & Regulatory Research, ranked by public Discoverability Score.
Where is this profile measured?
This profile uses the geography attached to the latest public registry snapshot: US. Locale tags are intentionally omitted.