Every AI decision, examiner-ready.
Gothink Witness is a vendor-neutral evidence layer that turns any AI decision — Gothink AIR’s or another vendor’s — into a signed, replayable receipt and an examiner-ready case file.
Status: in 1.0.6 and the public demo — design partners wanted
Five vendors, five audit trails, none of them in the same shape.
An examiner asks how one AI output shaped one decision. The answer sits in five vendor logs, each in its own format.
Sample case files, vendor by vendor
Exhibit C of the NAIC AI compliance report form asks for sample case files showing how outputs shaped specific decisions.
Every vendor logs differently
Different fields, formats and retention. Stitching one decision together is manual work, repeated for every file in the sample.
A senior officer attests
The report carries a senior officer’s attestation. That signature needs evidence behind it, not a folder of vendor emails.
Capture, seal, sample, assemble, hand over.
One receipt format for every AI decision, whoever built the model. Five steps from a log line to an examiner’s desk.
Every decision becomes a receipt; a sample of receipts becomes the case file.
Gothink AIR’s decisions and other vendors’ decisions enter the same chain.
| Step | What happens | What it produces |
|---|---|---|
| 01 · Capture | Gothink AIR records its own decisions; other vendors’ decisions arrive through the witness API, a batch import of their logs, or the vendor kit | A validated receipt |
| 02 · Seal | Each receipt is hash-chained to the one before it and signed with your key | A tamper-evident record |
| 03 · Sample | A stratified random sample across use case, decision and vendor, with the seed written down | A sample anyone can re-draw |
| 04 · Case file | Each sampled receipt is assembled with its output, how it was used, human review, policy and source pages | One case file per decision |
| 05 · Examiner | Case files, the sample and the attestation are shared through a read-only portal | Access that expires on its own |
What “replayable” means for Gothink AIR and for other vendors
A Gothink AIR decision can be re-run against the policy it was made under, or today’s, to show exactly what would change; a decision from another vendor is signed and chained the same way, and its case file shows the model, version, output, use and who acted on it.
Log formats differ, so a batch import maps each field to the vendor’s log line, and events missing required fields are rejected with the reason rather than stored half-complete.
One case file per sampled decision, readable without calling anyone.
Each file shows the decision, the AI output, how it was used, who reviewed it, and whether the signature still verifies.
| In the case file | What it shows |
|---|---|
| Decision summary | The decision, the use case, the system that produced it, and when |
| AI output | What the model returned, and the reasons it gave |
| How the output was used | What the output was used for, and the action a person took on it |
| Human review | Who reviewed it, and what they did |
| Policy | The policy id, version and hash in force at the time |
| Source pages | The document pages the decision relied on, wherever a citation exists |
| Verification | Hash and signature checks, with the signing algorithm and key id |
| Sample record | The sampling method, seed and strata, so the same sample can be drawn again |
Insurance fairness testing
Proxy-weighted adverse-impact testing, plus a data-layer review of the external data sources feeding each model.
Senior-officer attestation
An officer signs a scoped, dated statement that is chained and verifiable. Evidence packs flag anything still unattested.
Read-only, time-limited access
Examiners open the case files and the sample directly. Nothing can be changed, and access expires on its own.
For AI vendors: be exam-ready for every carrier you serve.
The vendor kit emits Gothink Witness receipts from your system, so each carrier gets case-file evidence without a bespoke integration.
Exam-ready, once
A client library and a published event schema. Send decision events; carriers receive signed receipts in the same format as Gothink AIR’s.
Talk to us about the kitEight contract terms, tracked
Each vendor’s terms move from missing to requested, received and verified, with document requests and due dates.
| Contract term | What the carrier holds |
|---|---|
| Audit rights | The right to review the vendor’s AI system and its records |
| Model card | A description of the model, its intended use and its limits |
| Drift notice | Notice when the model or its behaviour changes |
| Training-data attestation | A statement about the data the model was trained on |
| Sub-processors | Who else handles the data |
| Fairness-test sharing | The vendor’s fairness test results |
| Exam cooperation | Support when an examiner asks about the vendor’s system |
| Exit and escrow | What happens to the system and its records if the relationship ends |
Your keys sign the receipts. A trusted clock dates them.
Signing keys stay in your cloud key service, and receipt chains can be timestamped by an RFC 3161 authority.
Customer-held signing keys
Receipts are signed through Google Cloud KMS, AWS KMS or Azure Key Vault, using a key in your own account.
RFC 3161 trusted timestamps
The head of each receipt chain can be stamped by a timestamp authority, so dates do not rest on our clock.
Checkable without us
Receipts are RS256-signed with published public keys, and verify offline with one script.
Trust CenterEvidence now arrives from every surface.
Gothink AIR
Every processed document seals one receipt.
AIR Playground
New documents, amendments, answers and exports.
MCP tool calls
Every agent call — refusals and errors too.
Other vendors
Their decisions through the witness API.
Gothink Witness
Signed, hash-chained, RFC 3161 time.
The examiner
Case files, portal access, officer sign-off.
Help shape the case file your examiner will read.
Gothink Witness is new in 1.0.6 and running in the public demo. We are looking for insurers and AI vendors to shape it with.
Name your AI vendors
List the AI systems in your book and who supplies them. We map the contract terms and the evidence each can give.
Record one use case
Decisions from one use case are captured as receipts, and a sample is assembled into case files.
Read it as an examiner would
Your compliance team reviews the case files and tells us what is missing.
