Home/Products/Gothink Witness
Gothink Witness / the evidence layer for AI decisions

Every AI decision, examiner-ready.

Gothink Witness is a vendor-neutral evidence layer that turns any AI decision — Gothink AIR’s or another vendor’s — into a signed, replayable receipt and an examiner-ready case file.

One receipt format for every vendor Your KMS keys, RFC 3161 time A senior officer signs the attestation

Status: in 1.0.6 and the public demo — design partners wanted

01 / the problem

Five vendors, five audit trails, none of them in the same shape.

An examiner asks how one AI output shaped one decision. The answer sits in five vendor logs, each in its own format.

What the NAIC report asks for
The ask

Sample case files, vendor by vendor

Exhibit C of the NAIC AI compliance report form asks for sample case files showing how outputs shaped specific decisions.

The gap

Every vendor logs differently

Different fields, formats and retention. Stitching one decision together is manual work, repeated for every file in the sample.

Who signs

A senior officer attests

The report carries a senior officer’s attestation. That signature needs evidence behind it, not a folder of vendor emails.

02 / how it works

Capture, seal, sample, assemble, hand over.

One receipt format for every AI decision, whoever built the model. Five steps from a log line to an examiner’s desk.

Exhibit A· the Gothink Witness flowfive steps

Every decision becomes a receipt; a sample of receipts becomes the case file.

Gothink AIR’s decisions and other vendors’ decisions enter the same chain.

The Gothink Witness flow, from AI decision to examiner Decisions from Gothink AIR and from other AI vendors are captured through the witness API or the vendor kit, sealed into a hash-chained signed receipt, sampled with a recorded seed, assembled into case files, and shared with an examiner through read-only, time-limited access. AI DECISIONS Gothink AIR Vendor A model Vendor B model 01 Capture witness API vendor kit 02 Seal hash-chained signed, timestamped 03 Sample stratified seed recorded 04 Case file one per decision printable 05 Examiner read-only time-limited INPUTS KEPT AS REFERENCES AND FINGERPRINTS OFFICER ATTESTS THE SET
Fingerprints, not copies. Receipts hold references and SHA-256 hashes, never the raw payloads a vendor processed.
StepWhat happensWhat it produces
01 · CaptureGothink AIR records its own decisions; other vendors’ decisions arrive through the witness API, a batch import of their logs, or the vendor kitA validated receipt
02 · SealEach receipt is hash-chained to the one before it and signed with your keyA tamper-evident record
03 · SampleA stratified random sample across use case, decision and vendor, with the seed written downA sample anyone can re-draw
04 · Case fileEach sampled receipt is assembled with its output, how it was used, human review, policy and source pagesOne case file per decision
05 · ExaminerCase files, the sample and the attestation are shared through a read-only portalAccess that expires on its own
What “replayable” means for Gothink AIR and for other vendors

A Gothink AIR decision can be re-run against the policy it was made under, or today’s, to show exactly what would change; a decision from another vendor is signed and chained the same way, and its case file shows the model, version, output, use and who acted on it.

Log formats differ, so a batch import maps each field to the vendor’s log line, and events missing required fields are rejected with the reason rather than stored half-complete.

03 / what an examiner receives

One case file per sampled decision, readable without calling anyone.

Each file shows the decision, the AI output, how it was used, who reviewed it, and whether the signature still verifies.

How this maps to the NAIC report
In the case fileWhat it shows
Decision summaryThe decision, the use case, the system that produced it, and when
AI outputWhat the model returned, and the reasons it gave
How the output was usedWhat the output was used for, and the action a person took on it
Human reviewWho reviewed it, and what they did
PolicyThe policy id, version and hash in force at the time
Source pagesThe document pages the decision relied on, wherever a citation exists
VerificationHash and signature checks, with the signing algorithm and key id
Sample recordThe sampling method, seed and strata, so the same sample can be drawn again
Fairness

Insurance fairness testing

Proxy-weighted adverse-impact testing, plus a data-layer review of the external data sources feeding each model.

Attestation

Senior-officer attestation

An officer signs a scoped, dated statement that is chained and verifiable. Evidence packs flag anything still unattested.

Examiner portal

Read-only, time-limited access

Examiners open the case files and the sample directly. Nothing can be changed, and access expires on its own.

04 / vendor kit

For AI vendors: be exam-ready for every carrier you serve.

The vendor kit emits Gothink Witness receipts from your system, so each carrier gets case-file evidence without a bespoke integration.

For AI vendors

Exam-ready, once

A client library and a published event schema. Send decision events; carriers receive signed receipts in the same format as Gothink AIR’s.

Talk to us about the kit
For carriers

Eight contract terms, tracked

Each vendor’s terms move from missing to requested, received and verified, with document requests and due dates.

Contract termWhat the carrier holds
Audit rightsThe right to review the vendor’s AI system and its records
Model cardA description of the model, its intended use and its limits
Drift noticeNotice when the model or its behaviour changes
Training-data attestationA statement about the data the model was trained on
Sub-processorsWho else handles the data
Fairness-test sharingThe vendor’s fairness test results
Exam cooperationSupport when an examiner asks about the vendor’s system
Exit and escrowWhat happens to the system and its records if the relationship ends
05 / keys and time

Your keys sign the receipts. A trusted clock dates them.

Signing keys stay in your cloud key service, and receipt chains can be timestamped by an RFC 3161 authority.

Keys

Customer-held signing keys

Receipts are signed through Google Cloud KMS, AWS KMS or Azure Key Vault, using a key in your own account.

Time

RFC 3161 trusted timestamps

The head of each receipt chain can be stamped by a timestamp authority, so dates do not rest on our clock.

Verification

Checkable without us

Receipts are RS256-signed with published public keys, and verify offline with one script.

Trust Center
06 / what’s new in 1.0.6

Evidence now arrives from every surface.

in

Gothink AIR

Every processed document seals one receipt.

in · new

AIR Playground

New documents, amendments, answers and exports.

in

MCP tool calls

Every agent call — refusals and errors too.

in

Other vendors

Their decisions through the witness API.

ledger

Gothink Witness

Signed, hash-chained, RFC 3161 time.

out

The examiner

Case files, portal access, officer sign-off.

demo.gothink.ai/hallmark/
Gothink Witness console: decisions recorded, AI vendors, sampled case files, officer attestation and the NAIC AI report checklist
Demo tenant. Decisions, vendors, case files, sign-off and the NAIC report checklist on one console.
Status / in 1.0.6 — design partners wanted

Help shape the case file your examiner will read.

Gothink Witness is new in 1.0.6 and running in the public demo. We are looking for insurers and AI vendors to shape it with.

1

Name your AI vendors

List the AI systems in your book and who supplies them. We map the contract terms and the evidence each can give.

2

Record one use case

Decisions from one use case are captured as receipts, and a sample is assembled into case files.

3

Read it as an examiner would

Your compliance team reviews the case files and tells us what is missing.