Prove your AI did what you said it did.
When a carrier's due-diligence team hits the AI section, most partners stall. Castle answers it for you, delivered as a fixed-fee engagement: we run the oversight work on Castle's evidence infrastructure and hand back a signed, self-verifying packet that answers it in one handoff, so the appointment, renewal, or deal keeps moving. The same evidence becomes the carrier's standing record of how it oversees AI across everyone writing on its paper.
Stuck behind a carrier's AI due-diligence questionnaire? Hand it to us. We run the assessment and assemble a packet that checks itself: their reviewer runs one command and gets a pass or a fail, instead of reading forty pages they have no time for.
Outcomes you can take to the examiner, the carrier, and the board.
The reviewer does not have to read it
The people who receive governance evidence are not short of trust, they are short of time. A Castle packet checks itself: the carrier or auditor runs it on their own machine, offline, without installing Castle, and gets a verdict plus any failures in plain language. They review the exceptions, not the document, so the AI section of a due-diligence questionnaire stops holding up the deal.
Every obligation has an owner
Know what you owe, who owns it, and what proves it is handled, across contracts, regulations, vendors, and models, in one connected place instead of scattered spreadsheets.
Cover the AI that acts
Control what your models and agents actually do at the action boundary, with every allow, deny, and block recorded on a tamper-evident chain.
The oversight record, not a one-off answer
A carrier reviewing delegated authority has to show its work, and rating criteria now ask it to demonstrate that oversight. Castle checks every producer's submission as it arrives and rolls them into one view: who is covered, what verified, and exactly what failed, reported verbatim rather than smoothed over. Every failure opens a tracked exception with a named producer owner and a cure date, and it closes only when a resubmission verifies clean, with the closing artifact's hash on record. Nobody reads a stack of attachments, because the report says who owes what, by when, and what is already proven closed. It turns into NAIC or NYDFS exam readiness later on the same evidence graph, with no rework.
Know how complete the inventory really is
A register only covers what somebody registered, so "how do you know it is complete" is the question every inventory eventually gets asked. Castle does not go hunting for agents. It reconciles against what the access and identity tools you already run have found, and signs the result: how many were observed, how many are registered, how many are under policy, how many carry evidence, and who owns each gap by when. The artifact says plainly what it proves, that the comparison happened against named sources on a stated date, and what it does not, that coverage is bounded by the sources it names.
Not another GRC module. An obligation graph.
GRC tools silo vendor risk, policy, and compliance. CastleGRC links them: models, vendors, contracts, regulations, and policies in one connected graph.
Every obligation has an owner and the evidence to prove it.
When the auditor asks, the trail is already there.
When the obligation is trapped between systems, you can't prove it's handled.
- Unmapped. Obligations accepted in contracts and DPAs that compliance never sees.
- Unowned. Gaps with no owner, no control, and no test that closes them.
- Unproven. Evidence scattered across tools when the auditor asks for the source.
Map it once. Prove it forever.
- Map what you owe. Obligations from your contracts, DPAs, SLAs, policies, and regulations, in one place.
- Give each one an owner, a control, and a due date.
- Prove it on demand. Every obligation links to the evidence that satisfies it.
Follow one obligation across every connection.
- Pick a model, vendor, contract, or state and see every obligation it touches.
- Track deadlines and overdue items, owner attached.
- States and regulators are first-class, tracked as reference material, counsel reviewable.
Govern the agents that act, beyond the models you approved.
- Register every agent: what it can reach, what it may do, who signs off.
- Score each action by fixed rules, so high-impact actions are never ungoverned.
- Human in the loop, every decision on the audit trail.
Turn a written rule into one that holds.
- Your AI layer asks CastleGRC before acting, and stops the moment it says no.
- A disallowed tool, data class, vendor, or action never runs.
- Govern the content guardrails you run: every rail decision (jailbreak, toxicity, PII) becomes obligation-mapped, independently verifiable evidence.
A live allow, deny, and block, in under ninety seconds.
This is the real product, not a mockup. Watch Castle authorize an in-policy action, deny regulated data to an unapproved vendor, block a tool outside the agent's declared reach, and catch a forged record on the audit chain.
Most GRC tools track frameworks. CastleGRC connects what you signed to what must be governed.
- Contracts are first-class. The duties buried in your DPAs and SLAs get governed.
- One connected map for vendor risk, policy, and compliance, instead of separate tools.
- Evidence that holds up, traced to a verifiable source, independent of the platforms it governs.
Built for whoever owns the deal, and whoever owns the audit.
- Deal owners: CEOs, COOs, Heads of Partnerships at MGAs, TPAs, and insurtechs.
- AI governance, compliance, and risk leads.
- Vendor risk, legal, privacy, and security teams.
Pull scattered obligations into governance you can defend.
Connect your sources
Contracts, policies, regulations, and your AI and vendor inventory.
Confirm what matters
Review each candidate obligation and assign it an owner.
Report with proof
Audit-ready and board-ready, with verifiable evidence behind every claim.
CastleGRC is the testing engine. AuditBoard, Workiva, and ServiceNow are your filing cabinet. We pull the AI evidence, stamp it so anyone can verify it, and hand you a workpaper to file in the system of record you already run.
Under the hood.
The detail your security and architecture reviewers will ask for, tucked away so it does not slow down everyone else.
Technical specs and architecture
- Obligation graph. Obligations, owners, controls, evidence, vendors, models, contracts, states, and regimes are nodes in one connected graph, with cross-entity traversal.
- Tamper-evident evidence. Governance events are recorded on a hash-chained log, and every node and edge carries a write-once integrity stamp, so a changed record is detectable.
- Independent verification. Evidence packets verify offline against a deterministic procedure, with optional public anchoring of hashes only. A one-click NAIC examiner packet bundles Exhibits A-D, a signed attestation, the standalone verifier, and a verify-first cover sheet into one portable deliverable the examiner checks offline.
- Deployment. Runs in your environment, with an air-gapped mode that is fail-closed for sensitive data.
- Frameworks. SOC 2, ISO 27001, ISO 42001, NIST AI RMF, and HIPAA, with EU AI Act and GDPR tracked as obligations.
- Content-guardrail governance. Ingest NeMo Guardrails / Llama Guard / Presidio decisions as hash-chained, obligation-mapped evidence; reconcile declared-vs-actual rails.
Early access. Not SOC 2 certified, and no external penetration test yet. Regulatory content is candidate reference material, counsel reviewable, not legal advice.
Castle is built. Design partner number one is still open.
Castle is in early access: built, tested, and honest about it. We do not show logos we have not earned. What we offer instead is a product you can verify yourself, a stage we state plainly, and a seat at the table for the teams shaping it now. Delivery is service-first: early engagements are fixed-fee and scoped to one deliverable, an answered questionnaire, an oversight review, or an exam-ready packet, run by us on Castle's evidence infrastructure.
Insurance-first
We go deep on carriers, MGAs, and TPAs before we go wide, so the obligation libraries and exam workflows fit the way your industry is actually examined.
Verifiable, not asserted
Every material claim is checkable. Download a sample examiner packet and verify it offline before you ever talk to us.
Independent by design
Castle governs AI regardless of which platform runs it, and stays neutral toward the tools it sits above. Oversight only counts when it is independent.
Don't take our word for it.
CastleGRC is in early access with no production customers yet. Everything material is checkable first.
- Watch the 90 second demo: a live allow, deny, and block.
- Download a sample one-click NAIC examiner packet (demo data, signed with a demo key), then verify it yourself offline: unzip it, open
00-START-HERE.md, and runpython castle_verify.py packet.json. No Castle install, no trust required. - Verify a packet in your browser: the same castle_verify.py, unmodified, running on a Python runtime compiled to WebAssembly on this site, so checking a packet is one drag and drop with zero install. The packet format itself is an open specification (v0.2 draft), and the verifier is byte-identical to the copy in that public repository.
- Read the architecture and the honest limits.
Bring us the obligation your tools can't connect.
Castle is delivered service-first, and we are selecting a small number of design partners, advisors, and channel partners. If you own AI governance, vendor risk, compliance, legal, security, or advisory work for a regulated enterprise, bring us one deliverable, a stalled questionnaire, an oversight review, an exam-ready packet, and we will run it as a fixed-fee engagement on evidence either side can verify.