AI oversight for delegated authority

Prove your AI did what you said it did.

When a carrier's due-diligence team hits the AI section, most partners stall. Castle answers it for you, delivered as a fixed-fee engagement: we run the oversight work on Castle's evidence infrastructure and hand back a signed, self-verifying packet that answers it in one handoff, so the appointment, renewal, or deal keeps moving. The same evidence becomes the carrier's standing record of how it oversees AI across everyone writing on its paper.

For MGAs, TPAs and insurtechs

Stuck behind a carrier's AI due-diligence questionnaire? Hand it to us. We run the assessment and assemble a packet that checks itself: their reviewer runs one command and gets a pass or a fail, instead of reading forty pages they have no time for.

Obligation graph live mapping
For the deal you're trying to close

Outcomes you can take to the examiner, the carrier, and the board.

Nothing to review

The reviewer does not have to read it

The people who receive governance evidence are not short of trust, they are short of time. A Castle packet checks itself: the carrier or auditor runs it on their own machine, offline, without installing Castle, and gets a verdict plus any failures in plain language. They review the exceptions, not the document, so the AI section of a due-diligence questionnaire stops holding up the deal.

Ownership

Every obligation has an owner

Know what you owe, who owns it, and what proves it is handled, across contracts, regulations, vendors, and models, in one connected place instead of scattered spreadsheets.

AI oversight

Cover the AI that acts

Control what your models and agents actually do at the action boundary, with every allow, deny, and block recorded on a tamper-evident chain.

Carrier oversight

The oversight record, not a one-off answer

A carrier reviewing delegated authority has to show its work, and rating criteria now ask it to demonstrate that oversight. Castle checks every producer's submission as it arrives and rolls them into one view: who is covered, what verified, and exactly what failed, reported verbatim rather than smoothed over. Every failure opens a tracked exception with a named producer owner and a cure date, and it closes only when a resubmission verifies clean, with the closing artifact's hash on record. Nobody reads a stack of attachments, because the report says who owes what, by when, and what is already proven closed. It turns into NAIC or NYDFS exam readiness later on the same evidence graph, with no rework.

Coverage

Know how complete the inventory really is

A register only covers what somebody registered, so "how do you know it is complete" is the question every inventory eventually gets asked. Castle does not go hunting for agents. It reconciles against what the access and identity tools you already run have found, and signs the result: how many were observed, how many are registered, how many are under policy, how many carry evidence, and who owns each gap by when. The artifact says plainly what it proves, that the comparison happened against named sources on a stated date, and what it does not, that coverage is bounded by the sources it names.

The difference

Not another GRC module. An obligation graph.

GRC tools silo vendor risk, policy, and compliance. CastleGRC links them: models, vendors, contracts, regulations, and policies in one connected graph.

Every obligation has an owner and the evidence to prove it.
When the auditor asks, the trail is already there.

Governs the AI and cloud you already run
01 The cost

When the obligation is trapped between systems, you can't prove it's handled.

02 How it works

Map it once. Prove it forever.

The graph advantage

Follow one obligation across every connection.

Agentic AI

Govern the agents that act, beyond the models you approved.

Runtime enforcement

Turn a written rule into one that holds.

See it work

A live allow, deny, and block, in under ninety seconds.

This is the real product, not a mockup. Watch Castle authorize an in-policy action, deny regulated data to an unapproved vendor, block a tool outside the agent's declared reach, and catch a forged record on the audit chain.

Real terminal output and operator console. Built and tested, early access.
03 Why it is different

Most GRC tools track frameworks. CastleGRC connects what you signed to what must be governed.

04 Who it is for

Built for whoever owns the deal, and whoever owns the audit.

Built to connect to where AI already happens
05 Getting started

Pull scattered obligations into governance you can defend.

01

Connect your sources

Contracts, policies, regulations, and your AI and vendor inventory.

02

Confirm what matters

Review each candidate obligation and assign it an owner.

03

Report with proof

Audit-ready and board-ready, with verifiable evidence behind every claim.

CastleGRC is the testing engine. AuditBoard, Workiva, and ServiceNow are your filing cabinet. We pull the AI evidence, stamp it so anyone can verify it, and hand you a workpaper to file in the system of record you already run.

For the technical buyer

Under the hood.

The detail your security and architecture reviewers will ask for, tucked away so it does not slow down everyone else.

Technical specs and architecture
  • Obligation graph. Obligations, owners, controls, evidence, vendors, models, contracts, states, and regimes are nodes in one connected graph, with cross-entity traversal.
  • Tamper-evident evidence. Governance events are recorded on a hash-chained log, and every node and edge carries a write-once integrity stamp, so a changed record is detectable.
  • Independent verification. Evidence packets verify offline against a deterministic procedure, with optional public anchoring of hashes only. A one-click NAIC examiner packet bundles Exhibits A-D, a signed attestation, the standalone verifier, and a verify-first cover sheet into one portable deliverable the examiner checks offline.
  • Deployment. Runs in your environment, with an air-gapped mode that is fail-closed for sensitive data.
  • Frameworks. SOC 2, ISO 27001, ISO 42001, NIST AI RMF, and HIPAA, with EU AI Act and GDPR tracked as obligations.
  • Content-guardrail governance. Ingest NeMo Guardrails / Llama Guard / Presidio decisions as hash-chained, obligation-mapped evidence; reconcile declared-vs-actual rails.

Early access. Not SOC 2 certified, and no external penetration test yet. Regulatory content is candidate reference material, counsel reviewable, not legal advice.

Seeking design partner number one

Castle is built. Design partner number one is still open.

Castle is in early access: built, tested, and honest about it. We do not show logos we have not earned. What we offer instead is a product you can verify yourself, a stage we state plainly, and a seat at the table for the teams shaping it now. Delivery is service-first: early engagements are fixed-fee and scoped to one deliverable, an answered questionnaire, an oversight review, or an exam-ready packet, run by us on Castle's evidence infrastructure.

Insurance-first

We go deep on carriers, MGAs, and TPAs before we go wide, so the obligation libraries and exam workflows fit the way your industry is actually examined.

Verifiable, not asserted

Every material claim is checkable. Download a sample examiner packet and verify it offline before you ever talk to us.

Independent by design

Castle governs AI regardless of which platform runs it, and stays neutral toward the tools it sits above. Oversight only counts when it is independent.

Verify it yourself

Don't take our word for it.

CastleGRC is in early access with no production customers yet. Everything material is checkable first.

Get in touch

Bring us the obligation your tools can't connect.

Castle is delivered service-first, and we are selecting a small number of design partners, advisors, and channel partners. If you own AI governance, vendor risk, compliance, legal, security, or advisory work for a regulated enterprise, bring us one deliverable, a stalled questionnaire, an oversight review, an exam-ready packet, and we will run it as a fixed-fee engagement on evidence either side can verify.

Design partners GRC co-founder / advisor Channel & white-label