Underwrite agent risk on evidence.
"AI risk" prices badly because it measures badly. The agent-tool supply chain has had no standing, tamper-evident record of which tools hold what posture over time. The Conformant registry is that record: append-only grade history, every report anchored to a public transparency log at issue time.
Why anchoring matters for underwriting
A screenshot of a dashboard proves nothing at claim time. A Rekor-anchored report does: the grade, its timestamp, and its full findings were hashed into a public append-only log the day they were issued. Nobody, including Conformant, can back-date, edit, or quietly delete the record an underwriting decision relied on. Trust is not a screenshot. Trust is a record.
What's available
- The public registry API: every graded server as machine-readable JSON, CORS-open
- Append-only per-server grade history with content hashes and Rekor log indexes
- Aggregate failure-rate statistics by check (CFM-01 through CFM-08), suitable for cohort pricing
- Named grades for consented and publicly-disclosed servers; anonymous aggregates for held findings
- Data-licensing terms for portfolio-wide monitoring and claims-time verification
The honest boundary, stated up front
A grade reflects observable endpoint posture and signed operator attestations at a recorded timestamp. It is an underwriting input, not a guarantee of invulnerability, and the methodology is public so your actuarial team can evaluate exactly what the signal contains.
Talk data licensing
Tell us where to reach you and we'll set up a working session with sample exports against your book's exposure profile.