Solutions / Financial services and insurance
Secondary discoveryThe control changed. Which decisions are now unsupported?
Models inform credit, pricing, claims and surveillance decisions inside obligations that move. When a policy, threshold or regulatory expectation changes, the question is which prior decisions were made under the old rule and whether that matters.
Start with one bounded, non-actuating workflow.
EcoKure does not approve credit, move money or replace model validation. The first financial-services path is a draft customer communication: a control pack checks it, a qualified reviewer handles abstentions, and the record remains independently verifiable.
Draft communication only. No payment or credit action.
Your risk function owns the policy, citations and thresholds.
Observe ALLOW, BLOCK and ABSTAIN without changing production.
Hardship, vulnerability and other cases go to a named reviewer.
Retain the signed decision, reason, control version and sign-off.
APRA concern → EcoKure control → customer evidence
AWS evidence, clearly bounded
KMS signing was independently verified, Terraform-managed PostgreSQL was used, and the evidence chain remained valid after controlled recovery. This is target-environment evidence, not AWS certification, APRA approval or production customer validation.
What the architecture conversation still needs to close.
These are validation items, not hidden claims. The pilot turns them into named decisions, tests and evidence.
Company-owned account
Separate organisational ownership from a single personal cloud workspace.
Staging and production
Use separate environments and keep production data out of test.
Key custody
Run the KMS-backed signing-key migration in the real deployment.
Tenant evidence
Validate per-tenant evidence sets, control packs and database isolation.
Service boundary
Set the customer SLO, incident route, retention policy and support model.
Historical records
Document how pre-commitment chain entries are migrated or treated.
Two responses, both unsatisfying
Attest periodically
Proves the control was designed. It does not prove it operated on any given decision.
Sample and review
Finds patterns. It cannot reconstruct one specific decision two years later.
Operational-risk expectations increasingly ask whether controls were operating rather than merely documented, and model governance functions are being asked to evidence individual decisions rather than aggregate performance.
DCLA does the work here
Deterministic Control Lineage Architecture
The governing rules changed. What does that affect?
DCLA tracks changes to regulations, policies, controls and operating requirements, then identifies the systems, decisions, evidence and previous approvals that may need reassessment. Affected work is held rather than allowed to continue on a superseded rule.
What each of them needs to see
| Role | What they need before this proceeds |
|---|---|
| Chief risk officer | Wants failure behaviour, abstention handling and what happens when the checker itself is unavailable. |
| Model risk and validation | Wants determinism and replay, because a result that cannot be reproduced cannot be validated. |
| Compliance | Wants a mapping from a lane to a specific obligation, not a general assurance. |
| Internal audit | Wants a per-decision record they can test without asking the first line for help. |
The gates that do the checking
This page exists because these implementations exist. We do not publish an industry page without gates behind it.
StatsGate
Open sourceDetects impossible or internally inconsistent statistics using GRIM and p-value consistency checks.
ClaimGate
Interactive labExtracts claims from AI or scientific output and routes each one to the deterministic gate that can settle it.
ClaimLint
Open sourceLints documentation for unsupported AI and science claims. Runs as a CLI or a GitHub Action in CI.
Security Lanes
Open sourceReproducible test cases across CWE and OWASP weakness families with transparent scoring.
ReplayGate
Interactive labRe-runs sealed evidence packs to detect verification drift over time.
EU AI Act Profile
Open sourceAn application profile mapping deterministic lanes and evidence onto specific EU AI Act articles.
What this is not
- EcoKure is not a model risk management platform and does not perform model validation.
- It does not assess creditworthiness, price risk, or make any financial determination.
- Nothing it produces is financial or legal advice, or a compliance opinion.
- This is a discovery market. EcoKure has no financial services deployment and says so.
Start with one workflow
The useful first conversation is thirty minutes on a workflow where a change in rules or evidence has already cost you work. Both sides find out quickly whether this is worth pursuing.
Where it sits in what you already run
Nothing is replaced. The runtime deploys in your own account, so the only thing crossing the seam is a decision request one way and a verdict with its evidence coming back.
What one decision actually does
The same runtime and the same evidence contract as every other pathway. What changes is the control pack and the workflow.
