Your AI Already Decides.
Can You Prove It?
You are not paying for AI. You are
paying for AI you cannot evidence.
Four obligations already have a price attached. None of them is a bill for the model.
| Line | What it costs | Why it is owed |
|---|---|---|
| Annual model validation cycle | [P: to be calibrated] | Lloyd’s validation requirement [V] |
| Article-12 log retrofit | [P: to be calibrated] | EU AI Act Article 12 — automatic recording over the system’s lifetime [V] |
| Adverse-decision explanation, per case | [P: to be calibrated] | CJEU C-203/22 — the reasoning must be explicable to the data subject [V] |
| Reconstructing a decision an auditor asks about | [P: to be calibrated] | EU AI Act Article 14 — human oversight must be substantive, not nominal [V] |
We do not print a euro figure we cannot source. The cost column stays uncalibrated until we have pilot data — so compute it from your own numbers instead.
What does this cost you?
Your numbers, not ours. Nothing is sent anywhere — this runs in your browser.
€122,400
a year, at €335 a day — against a deadline that does not move.
None of this is a bill for AI. It is a bill for AI you cannot evidence — and when the Annex III obligations apply, the evidence becomes the product.
Nine pillars. Four are not
built yet, and they say so.
A pillar grid where every card is a tick is the first thing an experienced buyer disbelieves.
Policy wording
Clause 7.3 excludes betterment.
Engineering
Impact geometry is consistent.
Medical
Treatment plan within schedule.
Adversarial seat · dissent
Two prior claims in 14 months. Flagged, not weighted.
Four seats, and one of them is against you
A room where everyone agrees is a rubber stamp with extra steps. One seat exists only to attack the conclusion, its objection is recorded whether or not it wins, and the chair has to say in writing why it did not.
P1 · for the Chief Underwriting Officer
Convening Triage
A meta-decision agent scores each submission or claim and convenes the right room, the right chair and the right autonomy tier — and the routing decision is itself a logged event.
shipped(shipped)P2 · for the Head of Claims
Deliberation Chamber
Versioned expert personas argue the case from different angles — including one seat whose only job is to attack the conclusion — and a named human chair rules, at a durable waitpoint.
shipped(shipped)P3 · for the Chief Risk Officer
Computed Gate
Two or more heterogeneous models re-derive the answer. A computed — not learned — agreement predicate must pass before anything is released, and the inputs and model versions are sealed into the record.
shipped(shipped)P4 · for the General Counsel
Provable Decisions
Some questions about a policy wording are decidable. Where they are, the answer carries a machine-checkable proof; where they are not, the cross-model gate covers the gap — and the certificate says which lane it used.
designed, not built(designed, not built)P5 · for the Chief Compliance Officer
Evidence Fabric
One governed event stream compiles into every regulator’s artefact, instead of four teams reconstructing four different stories from the same week.
shipped(shipped)P6 · for the Model Risk Lead
Validation Autopilot
The annual validation dossier compiles itself, out of runs that were reproducible on the day they happened — rather than being reconstructed once a year from memory and spreadsheets.
shipped(shipped)P7 · for the Head of Exposure Management
CAT Simulation
Simulation runs inside the decision moment and never contaminates live state — every simulated value is quarantined, marked, and reversible in one transaction.
designed, not built(designed, not built)P8 · for the Head of Field Operations
Field Bench
The surface with no incumbent: a folding-phone bench that captures provenance with the artefact, works offline, and treats an offline ruling as a signed intent rather than a ruling.
designed, not built(designed, not built)P9 · for the Chief Operating Officer
Change Control & A2A
Changing a rule, a threshold, a persona or a model version is itself a governed decision that carries a certificate — and the same discipline extends to actions between companies.
designed, not built(designed, not built)Six people, six questions,
one record that answers all of them
Each of these roles is asking something different about the same decision. The disagreement between their answers is what an audit finding is made of.
Chief Underwriting Officer
“A model moved a price. Six months later, can I show why?”
The pricing decision, its inputs, the challenge it survived, and the person who released it — as one record.
What this role seesHead of Claims
“A declined claim is a decision. Who made it, and on what?”
A named chair on every adverse ruling, the dissent that was argued, and the reasons in the claimant’s own file.
What this role seesChief Risk Officer · model risk
“The validation dossier is rebuilt from memory once a year.”
A standing record that is a by-product of runs that were reproducible on the day they happened.
What this role seesChief Compliance Officer
“Four regulators ask about one week and get four answers.”
One governed stream that each artefact compiles from, rather than four teams re-narrating it.
What this role seesChief Operating Officer
“Every AI pilot stalls at the point somebody has to sign it off.”
A sign-off that is a waitpoint in the system rather than a meeting, and it runs in parallel with what you have.
What this role seesLoss adjuster in the field
“I capture evidence at a doorstep with no signal.”
Provenance made with the artefact, and an offline ruling that stays a signed intent until it syncs against a receipt.
What this role seesWhat changes on the first Tuesday
you actually use it
Not a roadmap. These are the differences a claims lead or a model-risk officer notices in the first week.
From four reconstructions to one stream
Four regulators ask about the same week and four teams rebuild four different accounts of it. One governed stream compiles into each artefact instead.
From a chat log to a named ruling
A decision that came out of a thread has no author. Every adverse ruling here carries the person who made it, their reasons, and what was argued against them.
From one model to two that must agree
A single model producing an answer nobody checked is the default today. Here a second, independent one has to re-derive it before anything is released.
From an annual scramble to a standing record
The validation dossier stops being rebuilt from memory once a year and starts being a by-product of runs that were reproducible on the day they happened.
From a screenshot to a re-runnable proof
A sealed record reopens years later and either reproduces exactly or tells you precisely which rule or model version moved underneath it.
From “trust us” to “here is the refusal”
When a check cannot complete, nothing is released and the refusal is itself part of the record — with a machine code you can quote back at us.
Four regulators, one week,
one account of what happened
Today four teams reconstruct four different stories from the same records. The disagreements between those stories are the audit finding.
EU AI Act Art-12 log
◆ compiles today
Lloyd’s validation dossier
◆ compiles today
Reinsurer confidence pack
⧖ emitter not built
Policyholder status feed
⧖ emitter not built
Two of the four emitters are designed and not built. Printing four ticks here would be the exact failure this product exists to stop.
Written once, at the moment it happened
A record assembled afterwards is a reconstruction, and every regulator knows it. This one is written as the decision is taken, and each artefact is compiled from that single stream rather than re-narrated from it.
Two of the four emitters are not built. They are marked as such on the diagram rather than in a footnote, because a diagram with four ticks would be exactly the failure this product exists to stop.
What we expect to be true —
and what would prove us wrong
Projected targets, not yet independently verified. Every one of them is [P: to be calibrated] until we have pilot data — and we would rather say so than dress a model as a measurement.
THE FALSIFIER
If a chair approves more than 80% of verdicts in under sixty seconds, the committee is a rubber stamp and the whole argument fails. We measure that rate, we will publish it, and we are telling you the number that would sink us before you ask.
A dead watcher renders as
a dead watcher
Serving stale data as fresh, or a broken watcher as a quiet row, is how a governance surface lies without anyone deciding to.
- 11:04⧖NHC advisory 14Track shifted 40 km north. 1,208 locations enter the cone.
- 09:31▒model drift watcherWatcher armed. Detection logic not built — this row is a placeholder, not a signal.
- 08:12◆appetite guardThree submissions outside written appetite, referred to a chair.
- 07:55▒surge feed (NOAA)Last good reading 4 h old. Serving stale with its age, not as fresh.
A dead watcher renders as a dead watcher. A missing row would be[dp-hidden-degrade]. Illustrative [D]
REFUSED
GATE_DISAGREEMENT
Two models were asked to derive the same answer and did not converge. Nothing was released, no effect was applied, and this refusal is itself an event in the record.
A system that quietly picked one of the two answers would be more useful on the day and indefensible in the year. This is the behaviour, not an error page.
Illustrative [D]
It reads your systems.
It does not replace them.
There is no rip-and-replace and a pilot does not require a migration. Each seam below states what actually works today.
Policy administration
Guidewire PolicyCenter · Duck Creek · Sapiens · in-house
read-only intake; the decision seam is per-core and wired per deployment
seam live(shipped)Claims systems
Guidewire ClaimCenter · Duck Creek Claims · in-house
read-only intake; write-back is a governed dispatch, never a direct update
seam live(shipped)Model registries
MLflow · SageMaker · in-house run ledgers
run and version capture; automated drift detection is not built
seam incomplete(designed, not built)Hazard and exposure feeds
NOAA · USGS · FIRMS · Copernicus · OED exposure
live ingest; these are observations, never a settlement index
seam live(shipped)Identity and access
SAML · OIDC · SCIM · your own directory
tenant, owner and unit resolved from the token and nowhere else
seam live(shipped)Counterparty corridors
A2A agent cards · ACORD · BiPRO payload rails
our endpoint conforms to v0.3.0; the v1.0.0 migration is not built
seam incomplete(designed, not built)Isolation is a mechanism,
never a per-customer promise
A boundary that each feature has to remember to respect is a boundary that one feature will forget. These are the six properties that hold whether or not anyone building on top of them knows they exist.
Three axes, in the query primitive
[O]Every read and every write is scoped on tenant, on owner, and where it applies on business unit. Something personal stays private even inside one organisation.
The predicate lives in the shared query primitive every repository inherits, not in a fragment each route remembers to append.
A surface that cannot scope, refuses
[O]If the three axes cannot be resolved from the authenticated request, the pane becomes a refusal with a machine code. Nothing is read.
Never a placeholder identity, never a silent organisation-wide read. A default of “unknown” on a tenant boundary is a defect.
Your model keys, your billing
[O]Model credentials belong to your organisation, in your own encrypted pool, managed by your own admins and resolved at the router.
There is no shared platform key behind a tenant. An organisation with no keys cannot serve AI, and says so plainly.
Dublin, and it stays there
[O]The platform runs in our own European datacentre. Images are mirrored in, not pulled from public registries at deploy time.
Data residency is a deployment property here, not a contractual assurance about someone else’s cloud region.
Signed at build, verified at admission
[O]Every image is signed in the build plane and its signature is checked by the cluster before it is allowed to run.
A workload whose signature does not verify is refused admission. That check is not advisory and has no bypass.
First-party analytics, disclosed
[O]This site carries no third-party trackers. What is measured is measured by us and written down on the privacy page.
A page arguing for evidence integrity may not ship analytics that contradict its own privacy policy.
What you are actually
choosing between
No vendor is named and none is caricatured. Our own column prints four gaps, because a table where one column is all ticks is the first thing an experienced buyer disbelieves.
| Capability | Your core vendor’s AI layer | Point AI tools | Consultant-delivered validation | HONESTAS |
|---|---|---|---|---|
| Runs beside your core system | yes | yes | yes | yes |
| Records every AI-touched decision as one governed stream | no | no | no | yes |
| A second independent model must agree before release | no | no | no | yes |
| A named human signs every adverse ruling | no | no | designed, not built | yes |
| The record reopens and re-runs years later | no | no | no | yes |
| One stream compiles into each regulator’s artefact | no | no | designed, not built | designed, not built |
| Machine-checkable proof of a policy-wording question | no | no | no | designed, not built |
| Catastrophe financial modelling | designed, not built | designed, not built | no | designed, not built |
⧖ designed, not built — four of ours are, and they are in the table rather than in a footnote.
Connect → Convene → Certify
Three steps, and one dispatch path underneath all of them.
STEP 01
Connect
It reads from your policy admin and claims systems. Nothing is replaced, and a pilot does not require a migration.
STEP 02
Convene
Each case is scored, routed to the right room with the right chair, and argued from different angles — including one seat whose job is to attack the conclusion.
STEP 03
Certify
A second, independent model has to agree. A named human signs. The whole thread seals into a record you can reopen years later.
What Certify actually produces
Not a badge. A document that names its chair, its gate, its inputs, the rule and model versions it ran against — and, in its own block, what it did not check.
- chair
- A. Ryan — Head of Claims
- gate
- gpt-class ✓ · claude-class ✓ · predicate PASS
- inputs
- sha256:2ae7f0…91cb
- rules
- wording v4.2 · model v2026.07
- tier
- T2 — callback against tenant data
Scope. This certificate does not verify policy-wording interpretation, reserve adequacy, or fraud intent. It names what it checked and nothing more — a certificate that does not state its scope is [dp-scope-inflation].
Illustrative record [D]
Everything runs through one dispatch path
Every piece of work — a model call, a room, a training run, a scenario, a verification — goes through the same governed path and carries a tier. That is why the logging, the audit trail, the quota and the tenant boundary are inherited rather than re-implemented per feature.
T1
Inline
◆ live
T2
Callback + your data
◆ live
T3
Accelerated
⧖ designed
T4
Long-running
⧖ designed
T5
Verified
⧖ designed
Nothing reaches a model, an engine or a queue around this path. A diagram showing a surface calling an engine directly would be a defect, not a shortcut.
- T1Inlinein production(shipped)
A model answers inside the request. The result can come back on the same call.
- T2Callback + your datain production(shipped)
Work that needs your records runs against them and calls back when it is done.
- T3Accelerateddesigned(designed, not built)
Work that needs specialised compute — the same path, a different machine.
- T4Long-runningdesigned(designed, not built)
Scenario runs and large ingests. Durable, resumable, with progress you can watch.
- T5Verifieddesigned(designed, not built)
Nothing is released until a second model agrees and the record is sealed. Fails closed.
Four people whose Tuesday
changes shape
Illustrative personas [P], but every one names the use cases behind it — a journey that cannot name its use case is marketing fiction.
Priya
Model risk lead
Today
Six weeks a year rebuilding a validation dossier from notebooks, chat threads and a model version that has since been replaced.
After
The dossier compiles from runs that were reproducible on the day they happened. She spends the six weeks on the models that actually moved.
Eight things this does not do —
printed on the homepage, not the footnotes
A product about the difference between an assertion and an evidenced decision forfeits its case the moment it asserts something it cannot show. So the register lives here, where a buyer reads it before a demo rather than after one.
Exposure and portfolio objects, vulnerability and damage curves, deductible and limit application, exceedance-probability curves, a stochastic event catalogue.
What runs today is peril physics and the analytics shell around it. That is not a catastrophe model and we will not call it one.
The executor that lets the orchestrator drive the simulator.
Both halves are deployed. The seam between them is not, so a scenario is launched by hand rather than by a governed dispatch.
The policy-wording compiler and the solver integration behind it.
The cross-model gate that backs a formal claim up is built and running. The lane that would produce the formal claim is not.
The logic that notices a model or a population has moved underneath a live decision.
The alert taxonomy and the stores exist. Nothing is watching them yet, and an empty watcher renders as an empty watcher.
The migration from v0.3.0, plus the party model, claim-state synchronisation and conflict surfacing.
Our endpoint conforms to v0.3.0 today. Anything describing a multi-party claim conversation is describing a design.
Accelerated compute, long-running stateful runs, and the verified tier that fails closed.
Tiers 1 and 2 run in production. The upper three are drawn dashed on our own diagram for exactly this reason.
The Android field bench across its four postures, and its iOS companion.
The design is complete and the token pipeline already emits its theme. The client itself has not shipped.
The jurisdiction-pack emitters and the lineage and context gates.
The evidence stream they would read from is real. The emitters that turn it into a regime-specific pack are not.
Every item above is designed and not built. Nothing on this site, in a demo, or in a commit message may present one of them as existing — and if you find one that does, that is a defect worth telling us about. The trust centre carries the full register.
Priced on artefacts.
Never on your book.
Incumbent licensing meters on premium volume, which charges you more for growing. This meters on what it produces: a validated model, a chair’s seat, a sealed certificate, a regime.
DOSSIER
per external model, per year
A model-risk lead with an annual validation cycle to survive.
- Reproducible validation runs — shipped
- Article-12 interaction logging — shipped
[P: to be calibrated]
Start hereCHAMBER
per named chair seat, plus metered certificates
A claims or underwriting function putting decisions through a governed room.
- Reproducible validation runs — shipped
- Article-12 interaction logging — shipped
- Chaired deliberation rooms — shipped
- Cross-model computed gate — shipped
- Per-jurisdiction evidence packs — designed, not built
[P: to be calibrated]
Book a demoFABRIC
Chamber, plus jurisdiction packs, read-seats, CAT compute and corridors
A carrier answering to more than one regulator, with exposure to model.
- Reproducible validation runs — shipped
- Article-12 interaction logging — shipped
- Chaired deliberation rooms — shipped
- Cross-model computed gate — shipped
- Per-jurisdiction evidence packs — designed, not built
- Governed CAT simulation — designed, not built
- Inter-company corridors — designed, not built
[P: to be calibrated]
Book a demoKERNEL
OEM, white-label, tenant-isolated — the full estate
A core vendor or a group embedding the whole thing.
- Reproducible validation runs — shipped
- Article-12 interaction logging — shipped
- Chaired deliberation rooms — shipped
- Cross-model computed gate — shipped
- Per-jurisdiction evidence packs — designed, not built
- Governed CAT simulation — designed, not built
- Inter-company corridors — designed, not built
- Tenant-isolated white-label — shipped
Talk to us
Talk to usNo price is printed until it is calibrated. See the full feature ladder — seven of its thirty-two cells are ⧖.
Questions insurance leaders ask,
and our honest answers
The deadline does not move
470 days — and the queue in front of it does not move either.
The cost per day is the one you computed above, from your own numbers. We are not going to print a figure of our own and pretend it is yours. What we can tell you is that it runs in parallel with what you have, there is no rip-and-replace, and a sandbox pilot cycle takes about eight weeks [V].