# RiskRouter > Evidence infrastructure for licensed insurance distributors and the software they run on: an append-only, SHA-256 hash-chained quote ledger and a Merkle-tree evidence log of salted fingerprints of advice records, whose signed heads anyone can verify offline, without trusting RiskRouter. Optional server-side pricing from a published rating matrix. Built for the evidence a distributor needs to show it met Article 20 of the EU Insurance Distribution Directive (IDD). Sold first to broker-management software vendors, so one integration serves every broker on a package. Status, stated plainly so it is not misreported: this is a validation build. Prices come from a published mock rating matrix; no carrier, bank or payment rail is contacted, and no insurance cover is in force. RiskRouter does not sell insurance, holds no insurance licence, never contacts the policyholder, handles no claims and owns no carrier relationship. It is software for distributors who do. There are no customers yet. It is a one-person company; data is hosted in the EU (Frankfurt), with an encrypted weekly backup kept on GitHub for 30 days, outside the EU. What is distinctive: pricing is deterministic and server-side (a client-sent price is ignored); a quote carries no personal data by design; every recorded quote is chained so an altered or deleted entry is detectable; the ledger head is signed with ECDSA P-256; and the verifier is a separate public repository that shares no code with the service, so a distributor's saved export stays checkable even if RiskRouter stops existing. There is no SDK and no lock-in. ## Start here - [Get a sandbox key](https://riskrouter.eu/integrate#get-a-key): a key on screen in seconds, no account, nothing about you stored; records real ledger entries (50 per key per day) - [Integration guide](https://riskrouter.eu/integrate): three integration patterns with working code and the failure cases that matter - [API reference](https://riskrouter.eu/docs): endpoints, error codes and the full rating matrix - [Changelog and rating matrix history](https://riskrouter.eu/changelog): what changed and when, and every rating-matrix version with a SHA-256 fingerprint of its prices - [For broker-software vendors](https://riskrouter.eu/for-software-vendors): what one integration gives every broker on a package, the three calls involved, the boundaries we keep, and what a first integrating vendor can expect (no vendor has integrated yet) - [Integration kit](https://riskrouter.eu/integrate#kit): tested, dependency-free clients in Python, PHP, C# (.NET 8) and Java, and a reference broker app whose evidence packs verify offline - [Postman collection](https://riskrouter.eu/riskrouter.postman_collection.json): generated from the OpenAPI spec; takes a sandbox key first - [OpenAPI 3.1 spec](https://riskrouter.eu/openapi.json): machine-readable, kept identical to the running routes by a test - [Live demo console](https://riskrouter.eu/console): price a configuration with sample rates across four verticals and watch the quote route to the ledger ## Verification - [Open evidence specification](https://riskrouter.eu/spec): every frozen form (v1 canonical form and attestation payload, v2 leaf string, v3 signed leaf and claim payload, signed tree head, witness cosignature), RFC 6962 Merkle proofs, with deterministic [test vectors](https://riskrouter.eu/spec-vectors.json); two independent verifiers (JavaScript and standard-library Python) - [Regime packs](https://riskrouter.eu/regime-packs): what to record for insurance distribution (IDD), MiFID II suitability, the EU AI Act's logging and human oversight, GDPR Article 22 automated decisions and DORA incidents, each field mapped to its article with a link to the EUR-Lex text; published as JSON at /packs/.json; orientation, not legal advice - [Obligations](https://riskrouter.eu/obligations): the record-keeping duties in IDD, MiFID II, the EU AI Act, GDPR Article 22 and DORA, when each record is tested, and what a sealed record adds; no law requires RiskRouter or any product; orientation, not legal advice - [AI agents and assistants](https://riskrouter.eu/ai): connect Claude Code, Cursor or any MCP client to https://api.riskrouter.eu/mcp, the tools and which need a key, agent framework adapters, AI Act logging; no pricing tool - [Full text](https://riskrouter.eu/llms-full.txt): every English page as plain text, rebuilt with the site - [Sealed security logs](https://riskrouter.eu/security-logs): logseal seals any log stream segment by segment into the evidence log, logs stay on the customer's storage, verify shows any changed or missing segment; NIS2 and GDPR breach pack; does not detect intrusions or identify attackers, and cannot protect lines written after a machine is taken over - Translations: the home page and the obligations page in French (https://riskrouter.eu/fr/, https://riskrouter.eu/fr/obligations), Dutch (/nl/, /nl/obligations) and German (/de/, /de/obligations); everything else is in English - [DORA Article 30 contract terms](https://riskrouter.eu/dora): each contractual provision DORA Article 30 requires of an ICT third-party provider, the clause RiskRouter offers for it, and what is in place today, including no service levels yet; proposed terms until a legal entity exists - [Witnesses](https://riskrouter.eu/witnesses): run an independent witness of an evidence log on your own account (a Cloudflare Worker, a GitHub fork or a small server), which co-signs a head only after checking the log never rewrote history; the public registry of logs and witnesses, as JSON at /registry.json; the same log also as C2SP checkpoints and hash tiles at https://api.riskrouter.eu/tlog/evidence-v2/ (the formats of the public witness network) - [MCP endpoint](https://riskrouter.eu/integrate#mcp): https://api.riskrouter.eu/mcp, the evidence log as Model Context Protocol tools (Streamable HTTP): read the signed head, inclusion and consistency proofs, the C2SP checkpoint and usage without a key; record a digest (never a record) with a key. No pricing tool. - [Drop-in recorders](https://riskrouter.eu/integrate#recorders): Python and Node recorders (logging handler, decorator, OpenTelemetry span processors) that keep each decision record and its salt on the customer's side and send only its salted digest to the evidence log, plus agent adapters (LangChain and LangGraph callback handler, OpenAI Agents SDK tracing processor, an MCP server with a record_decision tool) that turn each agent run into one record of digests; Apache-2.0, source at /kit/recorder/ - [SCITT](https://riskrouter.eu/spec#scitt): the evidence log registers IETF SCITT Signed Statements (hash envelopes, ES256) at POST /api/v2/evidence/statement and returns RFC 9942 COSE Receipts; only the statement's digest is kept - [Conformance suite](https://riskrouter.eu/spec#conformance): grades any implementation of the formats, in any language, against the vectors and against deliberately broken proofs, and checks the exports and proofs it writes; the result is the implementer's own statement, RiskRouter certifies nothing - [Every claim, and where to check it](https://riskrouter.eu/evidence): one page for due diligence, each claim with its artefact and who other than RiskRouter can check it, with a plain "none yet" where that is the truth - [Usage](https://riskrouter.eu/usage): how much is recorded and by whom, counted live from the ledger by a public endpoint (`GET /api/v1/usage`); entries recorded by keys that are not RiskRouter's own are shown as the figure that matters - [Continuity and self-hosting](https://riskrouter.eu/continuity#self-host): the same engine can run in a customer's own account (their Cloudflare and Supabase, or containers anywhere), signing with its own key and calling nothing of RiskRouter's; the source is private and running it needs a licence agreed in writing - [Age of the record](https://riskrouter.eu/proof-of-age.json): how many signed heads are anchored, since when, the earliest Bitcoin block they are in, how many carry RFC 3161 time-stamp tokens (not qualified under eIDAS) and how many independent witnesses co-sign, computed from the published anchors at build time - [Evidence log API (v2)](https://riskrouter.eu/docs#evidence): record the SHA-256 of any regulated decision (investment suitability, credit advice, KYC, claims decisions, AI decision logs) without sending the record; the record never reaches RiskRouter - [Verify the ledger](https://riskrouter.eu/verify): current signed head, the canonical hash form, and an in-browser checker for your own export (nothing uploaded) - [Trust and verification](https://riskrouter.eu/trust): what is sent, what is stored, where, and what is deliberately not claimed - [Offline verifier](https://github.com/aniljangrabe-dev/riskrouter-verify): standard-library Node scripts and the published public key ## Who it is for - [For insurance distributors, brokers and MGAs](https://riskrouter.eu/for-distributors): seal the fingerprint of each advice note so an IDD Article 20 record can be shown unchanged; the note never leaves the broker's system - [For platforms embedding insurance](https://riskrouter.eu/for-embedded-insurance): the evidence layer under insurance at checkout; the platform and its licensed partner bring the cover, RiskRouter places none - [Worked rate cards by vertical](https://riskrouter.eu/solutions): sample rates, not products: urban mobility, digital nomad and freelance, urban rental and housing, micro-travel and sports, each with a published rate card ## Guides - [IDD Article 20: what you need to be able to show](https://riskrouter.eu/guide-idd-article-20): each duty in Article 20, the question you will be asked about it, and who holds the evidence (much of it stays with the distributor) - [Audit-trail checklist for insurance brokers](https://riskrouter.eu/guide-audit-trail-checklist): twelve questions to ask of any system holding quote records, with RiskRouter's own answers including where they are no - [Database log vs tamper-evident ledger](https://riskrouter.eu/guide-database-log-vs-ledger): what a hash chain, an append-only table and a signed head add to an ordinary audit log, and what none of them proves ## Regulation and data - [Regulatory position](https://riskrouter.eu/compliance): where RiskRouter sits under the IDD, Belgian insurance law and DORA, and what is not in place yet - [Data protection](https://riskrouter.eu/privacy): what is stored, what is not, processors, and GDPR rights - [Continuity and exit plan](https://riskrouter.eu/continuity): what a distributor keeps if RiskRouter stops, what stops, the exit steps, and facts for a DORA register of information (no legal entity yet; engine source not public, available on request) - [Service status](https://riskrouter.eu/status): the API, the ledger and the evidence log checked live from the visitor's browser, with the running commit; no uptime history until one has been measured - [Bill of materials](https://riskrouter.eu/sbom.json): CycloneDX, derived from the Workers' own imports; no third-party package runs in production - [Security and vulnerability disclosure](https://riskrouter.eu/security): how to report, scope, and the controls in place (hash-based CSP, key digests, one outbound destination); no penetration test or certification is claimed - [Security questionnaire, answered](https://riskrouter.eu/security-questionnaire): data, access, integrity, development, logging, continuity and third parties, each answer linked to evidence, with plain noes (no certification, no pen test, no MFA claim, no managed backups) ## Optional - [Contact](https://riskrouter.eu/contact): pilots, integrations, regulatory questions