Skip to content
HONESTASDecision-Evidence Operating System

The Decision-Evidence Operating System

Your AI Already Decides.
Can You Prove It?

Every consequential AI-touched decision — deliberated by a chaired committee, checked by a second independent model, signed by a named human, and sealed into a record you can reopen years later and re-run.

One record · four regulatorsSovereign · DublinRefusals are a feature

About four minutes, nothing is gated behind a sales call, and you keep the inventory whether or not you ever talk to us.

470Days to Annex III [V]
0 of 12Vendors Publish a Log Schema [V]
2Models Must Agree [O]
1Named Human, Every Ruling [O]
app.honestas.ai/console/gdr/CLM-4471
14:02:07TRIAGEconvening agentMotor TP, €48,200 reserve. Contested. Tier 2, chamber convened.
14:02:11SEATpolicy-wording analystClause 7.3 excludes betterment. The claimed part is a like-for-like replacement.
14:02:11SEATengineering assessorImpact geometry consistent with the reported mechanism.
14:02:12DISSENTadversarial seatTwo prior claims on this policy in 14 months. Not dispositive — flagged, not weighted.
14:02:19GATEcross-model checkTwo independent derivations agree. Predicate PASS.
14:03:44CHAIRA. Ryan, Head of ClaimsSettle at €44,900. Betterment deduction applied and reasoned.
SEALEDCERT-9F31 · 9f31c4…a802 · rules v4.2Illustrative record [D]
EU AI Act Article-12 loggingThree-axis tenant isolationYour own AI provider keysEuropean datacentreDublin, Ireland HQ
The accountability tax

You are not paying for AI. You are
paying for AI you cannot evidence.

Four obligations already have a price attached. None of them is a bill for the model.

What the evidence gap costs, and the obligation behind each line
LineWhat it costsWhy it is owed
Annual model validation cycle[P: to be calibrated]Lloyd’s validation requirement [V]
Article-12 log retrofit[P: to be calibrated]EU AI Act Article 12 — automatic recording over the system’s lifetime [V]
Adverse-decision explanation, per case[P: to be calibrated]CJEU C-203/22 — the reasoning must be explicable to the data subject [V]
Reconstructing a decision an auditor asks about[P: to be calibrated]EU AI Act Article 14 — human oversight must be substantive, not nominal [V]

We do not print a euro figure we cannot source. The cost column stays uncalibrated until we have pilot data — so compute it from your own numbers instead.

What does this cost you?

Your numbers, not ours. Nothing is sent anywhere — this runs in your browser.

€122,400

a year, at €335 a day — against a deadline that does not move.

None of this is a bill for AI. It is a bill for AI you cannot evidence — and when the Annex III obligations apply, the evidence becomes the product.

The platform

Nine pillars. Four are not
built yet, and they say so.

A pillar grid where every card is a tick is the first thing an experienced buyer disbelieves.

app.honestas.ai/console/chamber/CLM-4471
Chamber · 4 seats · chair A. Ryantier 2
  • Policy wording

    Clause 7.3 excludes betterment.

  • Engineering

    Impact geometry is consistent.

  • Medical

    Treatment plan within schedule.

  • Adversarial seat · dissent

    Two prior claims in 14 months. Flagged, not weighted.

Chair ruled. Reasons captured as a required field.Illustrative [D]

Four seats, and one of them is against you

A room where everyone agrees is a rubber stamp with extra steps. One seat exists only to attack the conclusion, its objection is recorded whether or not it wins, and the chair has to say in writing why it did not.

P1 · for the Chief Underwriting Officer

Convening Triage

A meta-decision agent scores each submission or claim and convenes the right room, the right chair and the right autonomy tier — and the routing decision is itself a logged event.

shipped(shipped)

P2 · for the Head of Claims

Deliberation Chamber

Versioned expert personas argue the case from different angles — including one seat whose only job is to attack the conclusion — and a named human chair rules, at a durable waitpoint.

shipped(shipped)

P3 · for the Chief Risk Officer

Computed Gate

Two or more heterogeneous models re-derive the answer. A computed — not learned — agreement predicate must pass before anything is released, and the inputs and model versions are sealed into the record.

shipped(shipped)

P4 · for the General Counsel

Provable Decisions

Some questions about a policy wording are decidable. Where they are, the answer carries a machine-checkable proof; where they are not, the cross-model gate covers the gap — and the certificate says which lane it used.

designed, not built(designed, not built)

P5 · for the Chief Compliance Officer

Evidence Fabric

One governed event stream compiles into every regulator’s artefact, instead of four teams reconstructing four different stories from the same week.

shipped(shipped)

P6 · for the Model Risk Lead

Validation Autopilot

The annual validation dossier compiles itself, out of runs that were reproducible on the day they happened — rather than being reconstructed once a year from memory and spreadsheets.

shipped(shipped)

P7 · for the Head of Exposure Management

CAT Simulation

Simulation runs inside the decision moment and never contaminates live state — every simulated value is quarantined, marked, and reversible in one transaction.

designed, not built(designed, not built)

P8 · for the Head of Field Operations

Field Bench

The surface with no incumbent: a folding-phone bench that captures provenance with the artefact, works offline, and treats an offline ruling as a signed intent rather than a ruling.

designed, not built(designed, not built)

P9 · for the Chief Operating Officer

Change Control & A2A

Changing a rule, a threshold, a persona or a model version is itself a governed decision that carries a certificate — and the same discipline extends to actions between companies.

designed, not built(designed, not built)
Who arrives at this page

Six people, six questions,
one record that answers all of them

Each of these roles is asking something different about the same decision. The disagreement between their answers is what an audit finding is made of.

Chief Underwriting Officer

A model moved a price. Six months later, can I show why?

The pricing decision, its inputs, the challenge it survived, and the person who released it — as one record.

What this role sees

Head of Claims

A declined claim is a decision. Who made it, and on what?

A named chair on every adverse ruling, the dissent that was argued, and the reasons in the claimant’s own file.

What this role sees

Chief Risk Officer · model risk

The validation dossier is rebuilt from memory once a year.

A standing record that is a by-product of runs that were reproducible on the day they happened.

What this role sees

Chief Compliance Officer

Four regulators ask about one week and get four answers.

One governed stream that each artefact compiles from, rather than four teams re-narrating it.

What this role sees

Chief Operating Officer

Every AI pilot stalls at the point somebody has to sign it off.

A sign-off that is a waitpoint in the system rather than a meeting, and it runs in parallel with what you have.

What this role sees

Loss adjuster in the field

I capture evidence at a doorstep with no signal.

Provenance made with the artefact, and an offline ruling that stays a signed intent until it syncs against a receipt.

What this role sees
What changes

What changes on the first Tuesday
you actually use it

Not a roadmap. These are the differences a claims lead or a model-risk officer notices in the first week.

1 log[O]

From four reconstructions to one stream

Four regulators ask about the same week and four teams rebuild four different accounts of it. One governed stream compiles into each artefact instead.

every one[O]

From a chat log to a named ruling

A decision that came out of a thread has no author. Every adverse ruling here carries the person who made it, their reasons, and what was argued against them.

2 models[O]

From one model to two that must agree

A single model producing an answer nobody checked is the default today. Here a second, independent one has to re-derive it before anything is released.

−60%[P]

From an annual scramble to a standing record

The validation dossier stops being rebuilt from memory once a year and starts being a by-product of runs that were reproducible on the day they happened.

replayable[O]

From a screenshot to a re-runnable proof

A sealed record reopens years later and either reproduces exactly or tells you precisely which rule or model version moved underneath it.

12 codes[O]

From “trust us” to “here is the refusal”

When a check cannot complete, nothing is released and the refusal is itself part of the record — with a machine code you can quote back at us.

The evidence fabric

Four regulators, one week,
one account of what happened

Today four teams reconstruct four different stories from the same records. The disagreements between those stories are the audit finding.

one governed event streamwritten once, at the moment it happened

EU AI Act Art-12 log

◆ compiles today

Lloyd’s validation dossier

◆ compiles today

Reinsurer confidence pack

⧖ emitter not built

Policyholder status feed

⧖ emitter not built

Two of the four emitters are designed and not built. Printing four ticks here would be the exact failure this product exists to stop.

Written once, at the moment it happened

A record assembled afterwards is a reconstruction, and every regulator knows it. This one is written as the decision is taken, and each artefact is compiled from that single stream rather than re-narrated from it.

Two of the four emitters are not built. They are marked as such on the diagram rather than in a footnote, because a diagram with four ticks would be exactly the failure this product exists to stop.

Projected outcomes

What we expect to be true —
and what would prove us wrong

−38%claims cycle time[P]
8 weekssandbox pilot cycle[V]
1 logfour regulators’ artefacts[P]
−60%validation dossier effort[P]

Projected targets, not yet independently verified. Every one of them is [P: to be calibrated] until we have pilot data — and we would rather say so than dress a model as a measurement.

Watchers and refusals

A dead watcher renders as
a dead watcher

Serving stale data as fresh, or a broken watcher as a quiet row, is how a governance surface lies without anyone deciding to.

app.honestas.ai/console/sentinels
  • 11:04NHC advisory 14Track shifted 40 km north. 1,208 locations enter the cone.
  • 09:31model drift watcherWatcher armed. Detection logic not built — this row is a placeholder, not a signal.
  • 08:12appetite guardThree submissions outside written appetite, referred to a chair.
  • 07:55surge feed (NOAA)Last good reading 4 h old. Serving stale with its age, not as fresh.

A dead watcher renders as a dead watcher. A missing row would be[dp-hidden-degrade]. Illustrative [D]

REFUSED

GATE_DISAGREEMENT

Two models were asked to derive the same answer and did not converge. Nothing was released, no effect was applied, and this refusal is itself an event in the record.

A system that quietly picked one of the two answers would be more useful on the day and indefensible in the year. This is the behaviour, not an error page.

Illustrative [D]

Connect once

It reads your systems.
It does not replace them.

There is no rip-and-replace and a pilot does not require a migration. Each seam below states what actually works today.

Policy administration

Guidewire PolicyCenter · Duck Creek · Sapiens · in-house

read-only intake; the decision seam is per-core and wired per deployment

seam live(shipped)

Claims systems

Guidewire ClaimCenter · Duck Creek Claims · in-house

read-only intake; write-back is a governed dispatch, never a direct update

seam live(shipped)

Model registries

MLflow · SageMaker · in-house run ledgers

run and version capture; automated drift detection is not built

seam incomplete(designed, not built)

Hazard and exposure feeds

NOAA · USGS · FIRMS · Copernicus · OED exposure

live ingest; these are observations, never a settlement index

seam live(shipped)

Identity and access

SAML · OIDC · SCIM · your own directory

tenant, owner and unit resolved from the token and nowhere else

seam live(shipped)

Counterparty corridors

A2A agent cards · ACORD · BiPRO payload rails

our endpoint conforms to v0.3.0; the v1.0.0 migration is not built

seam incomplete(designed, not built)
Where the evidence lives

Isolation is a mechanism,
never a per-customer promise

A boundary that each feature has to remember to respect is a boundary that one feature will forget. These are the six properties that hold whether or not anyone building on top of them knows they exist.

Three axes, in the query primitive

[O]

Every read and every write is scoped on tenant, on owner, and where it applies on business unit. Something personal stays private even inside one organisation.

The predicate lives in the shared query primitive every repository inherits, not in a fragment each route remembers to append.

A surface that cannot scope, refuses

[O]

If the three axes cannot be resolved from the authenticated request, the pane becomes a refusal with a machine code. Nothing is read.

Never a placeholder identity, never a silent organisation-wide read. A default of “unknown” on a tenant boundary is a defect.

Your model keys, your billing

[O]

Model credentials belong to your organisation, in your own encrypted pool, managed by your own admins and resolved at the router.

There is no shared platform key behind a tenant. An organisation with no keys cannot serve AI, and says so plainly.

Dublin, and it stays there

[O]

The platform runs in our own European datacentre. Images are mirrored in, not pulled from public registries at deploy time.

Data residency is a deployment property here, not a contractual assurance about someone else’s cloud region.

Signed at build, verified at admission

[O]

Every image is signed in the build plane and its signature is checked by the cluster before it is allowed to run.

A workload whose signature does not verify is refused admission. That check is not advisory and has no bypass.

First-party analytics, disclosed

[O]

This site carries no third-party trackers. What is measured is measured by us and written down on the privacy page.

A page arguing for evidence integrity may not ship analytics that contradict its own privacy policy.

The honest comparison

What you are actually
choosing between

No vendor is named and none is caricatured. Our own column prints four gaps, because a table where one column is all ticks is the first thing an experienced buyer disbelieves.

Capability comparison across four approaches
CapabilityYour core vendor’s AI layerPoint AI toolsConsultant-delivered validationHONESTAS
Runs beside your core systemyesyesyesyes
Records every AI-touched decision as one governed streamnononoyes
A second independent model must agree before releasenononoyes
A named human signs every adverse rulingnonodesigned, not builtyes
The record reopens and re-runs years laternononoyes
One stream compiles into each regulator’s artefactnonodesigned, not builtdesigned, not built
Machine-checkable proof of a policy-wording questionnononodesigned, not built
Catastrophe financial modellingdesigned, not builtdesigned, not builtnodesigned, not built

designed, not built — four of ours are, and they are in the table rather than in a footnote.

How it works

Connect → Convene → Certify

Three steps, and one dispatch path underneath all of them.

STEP 01

Connect

It reads from your policy admin and claims systems. Nothing is replaced, and a pilot does not require a migration.

STEP 02

Convene

Each case is scored, routed to the right room with the right chair, and argued from different angles — including one seat whose job is to attack the conclusion.

STEP 03

Certify

A second, independent model has to agree. A named human signs. The whole thread seals into a record you can reopen years later.

What Certify actually produces

Not a badge. A document that names its chair, its gate, its inputs, the rule and model versions it ran against — and, in its own block, what it did not check.

SEALEDCERT-9F3119 Aug 2026 · 14:03:44 UTC
chair
A. Ryan — Head of Claims
gate
gpt-class ✓ · claude-class ✓ · predicate PASS
inputs
sha256:2ae7f0…91cb
rules
wording v4.2 · model v2026.07
tier
T2 — callback against tenant data

Scope. This certificate does not verify policy-wording interpretation, reserve adequacy, or fraud intent. It names what it checked and nothing more — a certificate that does not state its scope is [dp-scope-inflation].

Illustrative record [D]

Everything runs through one dispatch path

Every piece of work — a model call, a room, a training run, a scenario, a verification — goes through the same governed path and carries a tier. That is why the logging, the audit trail, the quota and the tenant boundary are inherited rather than re-implemented per feature.

marketing siteconsoleFold apppartner seat
POST /api/v1/dispatchgovernance · Article-12 log · quota · tenant boundary

T1

Inline

◆ live

T2

Callback + your data

◆ live

T3

Accelerated

⧖ designed

T4

Long-running

⧖ designed

T5

Verified

⧖ designed

Nothing reaches a model, an engine or a queue around this path. A diagram showing a surface calling an engine directly would be a defect, not a shortcut.

  1. T1Inlinein production(shipped)

    A model answers inside the request. The result can come back on the same call.

  2. T2Callback + your datain production(shipped)

    Work that needs your records runs against them and calls back when it is done.

  3. T3Accelerateddesigned(designed, not built)

    Work that needs specialised compute — the same path, a different machine.

  4. T4Long-runningdesigned(designed, not built)

    Scenario runs and large ingests. Durable, resumable, with progress you can watch.

  5. T5Verifieddesigned(designed, not built)

    Nothing is released until a second model agrees and the record is sealed. Fails closed.

User journeys

Four people whose Tuesday
changes shape

Illustrative personas [P], but every one names the use cases behind it — a journey that cannot name its use case is marketing fiction.

Priya

Model risk lead

Today

Six weeks a year rebuilding a validation dossier from notebooks, chat threads and a model version that has since been replaced.

After

The dossier compiles from runs that were reproducible on the day they happened. She spends the six weeks on the models that actually moved.

Use cases:UC061UC064UC067

The standing register

Eight things this does not do —
printed on the homepage, not the footnotes

A product about the difference between an assertion and an evidenced decision forfeits its case the moment it asserts something it cannot show. So the register lives here, where a buyer reads it before a demo rather than after one.

The catastrophe financial chain[P]

Exposure and portfolio objects, vulnerability and damage curves, deductible and limit application, exceedance-probability curves, a stochastic event catalogue.

What runs today is peril physics and the analytics shell around it. That is not a catastrophe model and we will not call it one.

The UNO → simulator dispatch seam[P]

The executor that lets the orchestrator drive the simulator.

Both halves are deployed. The seam between them is not, so a scenario is launched by hand rather than by a governed dispatch.

The formal-methods lane[P]

The policy-wording compiler and the solver integration behind it.

The cross-model gate that backs a formal claim up is built and running. The lane that would produce the formal claim is not.

Drift detection[P]

The logic that notices a model or a population has moved underneath a live decision.

The alert taxonomy and the stores exist. Nothing is watching them yet, and an empty watcher renders as an empty watcher.

A2A v1.0.0[P]

The migration from v0.3.0, plus the party model, claim-state synchronisation and conflict surfacing.

Our endpoint conforms to v0.3.0 today. Anything describing a multi-party claim conversation is describing a design.

Tiers 3 to 5 of the dispatch ladder[P]

Accelerated compute, long-running stateful runs, and the verified tier that fails closed.

Tiers 1 and 2 run in production. The upper three are drawn dashed on our own diagram for exactly this reason.

The Fold field client[P]

The Android field bench across its four postures, and its iOS companion.

The design is complete and the token pipeline already emits its theme. The client itself has not shipped.

Jurisdiction packs and lineage gates[P]

The jurisdiction-pack emitters and the lineage and context gates.

The evidence stream they would read from is real. The emitters that turn it into a regime-specific pack are not.

Every item above is designed and not built. Nothing on this site, in a demo, or in a commit message may present one of them as existing — and if you find one that does, that is a defect worth telling us about. The trust centre carries the full register.

Pricing

Priced on artefacts.
Never on your book.

Incumbent licensing meters on premium volume, which charges you more for growing. This meters on what it produces: a validated model, a chair’s seat, a sealed certificate, a regime.

DOSSIER

per external model, per year

A model-risk lead with an annual validation cycle to survive.

  • Reproducible validation runs — shipped
  • Article-12 interaction logging — shipped

[P: to be calibrated]

Start here

CHAMBER

per named chair seat, plus metered certificates

A claims or underwriting function putting decisions through a governed room.

  • Reproducible validation runs — shipped
  • Article-12 interaction logging — shipped
  • Chaired deliberation rooms — shipped
  • Cross-model computed gate — shipped
  • Per-jurisdiction evidence packs — designed, not built

[P: to be calibrated]

Book a demo

FABRIC

Chamber, plus jurisdiction packs, read-seats, CAT compute and corridors

A carrier answering to more than one regulator, with exposure to model.

  • Reproducible validation runs — shipped
  • Article-12 interaction logging — shipped
  • Chaired deliberation rooms — shipped
  • Cross-model computed gate — shipped
  • Per-jurisdiction evidence packs — designed, not built
  • Governed CAT simulation — designed, not built
  • Inter-company corridors — designed, not built

[P: to be calibrated]

Book a demo

KERNEL

OEM, white-label, tenant-isolated — the full estate

A core vendor or a group embedding the whole thing.

  • Reproducible validation runs — shipped
  • Article-12 interaction logging — shipped
  • Chaired deliberation rooms — shipped
  • Cross-model computed gate — shipped
  • Per-jurisdiction evidence packs — designed, not built
  • Governed CAT simulation — designed, not built
  • Inter-company corridors — designed, not built
  • Tenant-isolated white-label — shipped

Talk to us

Talk to us

No price is printed until it is calibrated. See the full feature ladder — seven of its thirty-two cells are ⧖.

Honest answers

Questions insurance leaders ask,
and our honest answers

The deadline does not move

470 days — and the queue in front of it does not move either.

The cost per day is the one you computed above, from your own numbers. We are not going to print a figure of our own and pretend it is yours. What we can tell you is that it runs in parallel with what you have, there is no rip-and-replace, and a sandbox pilot cycle takes about eight weeks [V].