Questions and answers
Questions and answers about RiskRouter
The questions people ask before they write to us, answered in a sentence or two. Each answer links to the page that holds the detail, so nothing here has to be taken on our word. If your question is not here, ask it.
What RiskRouter is
What is RiskRouter?
Evidence infrastructure for licensed insurance distributors and the software they use. It keeps an append-only, independently verifiable record of what was advised and quoted, so a broker can later prove exactly what existed at the time. It also has an optional server-side pricing engine, which today prices a simulated rate grid. For software vendors · For brokers
Is RiskRouter an insurer or an insurance intermediary?
Neither. It is not an insurer and, in our own analysis, not an insurance intermediary: it gives no advice, proposes and concludes no contracts, never deals with the policyholder, and is paid a flat software fee. It is not registered with the FSMA. What the FSMA said, and what it did not · Regulatory position
Is RiskRouter required by law?
No. No law requires RiskRouter or any other product. The law requires the records themselves: IDD, MiFID II, the AI Act, GDPR Article 22 and DORA each ask a firm to do something and later to show it did. What RiskRouter adds is a way to show a record was never changed that does not rest on anyone’s word. What the law asks you to record
Does RiskRouter sell insurance?
No. Nothing on this site is an offer of insurance and no cover is in force. The prices the demo shows come from a simulated rate grid, and no contract can be concluded through it. Regulatory position
Is it in production?
It is a validation build. The API, the evidence log, the proofs and the verifiers are live and can be used with a sandbox key today; pricing is deterministic mock rules, and there is no customer yet. Status · Usage in numbers
Data and privacy
What data does RiskRouter receive?
For the evidence log, only a salted SHA-256 digest of your record and a short tag such as
ai.decision. The record itself, the customer’s name and the salt stay with you. Pricing a quote
involves no personal data at all. Data protection · How a digest is made
Can an entry be deleted?
No. The log is append-only on purpose, which is what makes it evidence. That is why it holds only digests: the record stays in your own systems, where you can erase it when the law requires, and a salted digest on its own says nothing about anyone. Specification
Where is data stored?
In Frankfurt, inside the EU. An encrypted daily backup of the ledger is kept on GitHub for 90 days, and it never includes contact-form enquiries. Data protection · Trust
Is RiskRouter certified (ISO 27001, SOC 2)?
No. We hold no certification, and our providers’ certifications do not make us certified. What we offer instead is evidence you can check yourself. Security questionnaire
Proof and continuity
How do I check a record without trusting RiskRouter?
With the open-source verifier, offline: it checks that your record gives the recorded digest, that the entry is in the log, and that the log’s signature holds. Public timestamps and a Bitcoin anchor fix when each head existed. Verify a record · Open-source verifier
What happens if RiskRouter disappears?
The evidence outlives us. Every proof checks offline with the public verifier, the log’s keys and anchors are published, and you can export what you recorded at any time. The engine can also run in your own account. Continuity
Who else checks the log?
The log publishes signed checkpoints in the format the public witness network cosigns, and anyone can run a witness of it. No outside witness cosigns it yet, and the page counts them from the published files. Witnesses
Are the timestamps qualified under eIDAS?
No. Every signed head gets RFC 3161 tokens from two independent time-stamping authorities and a Bitcoin anchor, but those authorities are not qualified, and every page and verifier says so. Specification
Getting started
How do I start?
Take a sandbox key yourself, with no form and no contract, and run the integration kit against it. Integrate
How much does it cost?
There is no commercial price yet: this is a validation build, and the sandbox is free. The rating matrix the engine prices is public. API reference · Changelog
Which languages and systems does it support?
Any system that can make an HTTPS request. The integration kit is ready in PHP, C#/.NET, Python and Java using only their standard libraries, and drop-in recorders for Python and Node turn existing decision logs into evidence. No SDK is required. Integrate
Can AI agents use it?
Yes. Any MCP client can connect to https://api.riskrouter.eu/mcp to read the log and, with a key,
record digests. Adapters for LangChain, LangGraph and the OpenAI Agents SDK record each agent run as one entry.
There is no pricing tool for agents. Connect an AI agent
Can we run it ourselves?
Yes: the same engine runs in your own cloud account or on your own servers, against your own database, and calls nothing of ours. Running it needs the source and a licence agreed in writing. Continuity
Is it open source?
The verifier and the drop-in recorders are open source (the recorders under Apache-2.0), and the specification is public. The engine’s source is not licensed. Specification · Recorders