Insurer Evidence Guide
For underwriters and claims teams assessing an organization that governs its AI with RAIC. Explains which statements about that organization are cryptographically checkable, how to check them without relying on the vendor or the insured, and where the limits of the evidence sit.
Why this differs from a questionnaire response
A security questionnaire records what an organization said about itself at one moment, usually while renewing. RAIC evidence records what the organization actually did, sealed nightly into a hash chain that cannot be quietly rewritten afterwards. The practical consequence for underwriting is that governance claims become dated and continuous rather than point-in-time and self-reported: an applicant can demonstrate that controls were operating in the months before the application, not only on the day it was filled in.
Checkable statements
- Continuous governance history
- A continuity certificate asserts unbroken sealed evidence for a 30, 90, 180 day or 1, 3, 5 year window. The certificate hash is printed on the document and confirmable against the open endpoint.
- Evidence predates the loss
- Every record sits under a day root sealed that night. A record cannot be back-dated into a sealed day, which is the property that matters most at claim time.
- Human oversight actually occurred
- Where RAIC agents recommend actions, the decision record seals who reviewed it, what evidence and predicted priority they were shown, and what they chose. Reversals append; they do not erase.
- Controls and incidents are linked
- Incidents and their outcomes are bound to the controls and systems involved, so remediation history can be traced rather than asserted.
Verification for underwriting
- Ask the applicant for a signed audit pack covering the policy period, plus a continuity certificate.
- Open verify.html inside the pack and confirm every file digest matches. This runs locally and transmits nothing.
- Confirm issuance with GET https://app.rhindoncyber.com/api/public/verify-evidence?manifest_hash=<64-hex>. No account is required.
- Confirm the continuity certificate hash the same way; the response states whether the hash is known and whether the signature is valid.
- Retain the pack. Re-verification at claim time uses the same digests, so a pack collected at underwriting remains checkable years later.
Verification at claim time
Re-run the same digest checks against the pack collected at underwriting, then request a fresh export covering the loss period and verify it independently. Compare sealed day coverage across the two: a gap in seals between underwriting and loss is a material fact about whether governance ran continuously. Because seals are nightly and immutable, evidence produced after the loss cannot be presented as if it existed before it — a distinction that is otherwise very hard to establish from vendor logs.
Limits an underwriter should price in
- Integrity is not accuracy. RAIC proves a record existed and was not altered; it does not validate the judgment recorded in it.
- Coverage is scoped to what the organization tracks in RAIC. Systems never registered produce no evidence, which is itself informative.
- Benchmark comparisons are k-anonymous with a minimum cohort of 25 organizations, so peer positioning is directional rather than identifying.
- Predictive priority scores are advisory. They are sealed into decision records for auditability, not offered as risk quantification.
Requesting technical support
Underwriting and claims teams can request the verifier specification, sample signed packs, and a technical walkthrough of the sealing and verification path. Contact the insured's RAIC administrator, or reach Rhindon Cyber directly through the support portal. RAIC does not need to be present for verification, and no verification step requires our cooperation.
