The record of every AI system you run, and how it was approved
Backsplice is an AI governance platform. It keeps a registry of your AI systems, the models they use and the vendors behind them; assesses your program and each system against NIST AI RMF 1.0 and NIST AI 600-1 (Generative AI Profile); routes each system through a review whose approvers are set by its risk tier; and publishes model and system cards. Watney, the AI assistant, drafts and suggests. People decide.
Framework packs, starting with the NIST AI RMF
Questions come from framework packs. Every plan, and the demo, includes every pack that ships:
- NIST AI Risk Management Framework 1.0. A question for each of its 72 subcategories, across Govern, Map, Measure and Manage.
- NIST AI 600-1, the Generative AI Profile. Its 12 generative AI risks: asked of each system that uses generative AI, and in the program assessment once any live system does.
Questions are asked at the level they belong to: governance questions once, in your organization's program assessment, and system questions for each AI system you register. ISO/IEC 42001 and the EU AI Act are next; they are not included today. Adding a framework adds a pack with its own questions. On a plan, Watney can suggest where an answer you have already given also covers a control in another pack, for an admin to approve.
Every AI system, the models it uses, and who supplies them
Governance starts with knowing what you run. Backsplice keeps the inventory as a structured registry:
-
AI systems. Each use of AI in your organization, whether you build it, buy it, or get it inside other software, with its risk tier and where it is in its lifecycle.
-
Models, with versions. The models each system uses, recorded by version, so a model change is visible rather than silent.
-
AI vendors and due diligence. Whether a vendor trains on your data, and whether an agreement is on file.
-
Intake triage. Watney can suggest how to triage a newly registered system. The suggestion is yours to accept or change.
Assess the program once, and each system on its own
An AI governance program has two subjects: the organization that governs, and the systems it governs. Backsplice assesses both:
- The program assessment. Governance questions about your policies, roles and oversight, answered for the organization as a whole.
- System assessments. The questions that apply to one AI system, answered for that system, with the generative AI questions asked only where they apply.
- Evidence. Attach evidence files to answers. Watney can review an answer against its evidence or summarize a file, and a person decides what to do with the result.
- Scoped by the question's own level. A question is only ever asked where it belongs, so a system assessment does not collect program answers.
A decision with a name and a reason behind every system
A system moves into use through a recorded review, never by someone editing a status field:
- Submit for review. The system's risk tier decides who reviews it, under your tier policy; a weaker per-system policy needs an org admin and a reason.
- Any, a majority, or all. The risk-tier policy also decides how many of the approvers must agree.
- Every decision carries a reason. Approve, approve with conditions, reject or send back. Conditions attached to an approval must be met before the system moves on.
- Approvals come due for re-review. Each approval carries a review date set by its risk tier; when it arrives a re-review opens automatically, and the system keeps its stage until that review decides.
Cards that say what a system is, frozen when you publish
A card is the plain description of a model or a system that a reviewer, an auditor or the public can read:
- Model cards and system cards. One for each model you record and each system you run.
- Drafted by Watney, edited by you. Watney can draft a card from the records you have kept. You decide what it says.
- A sealed version on publish. Publishing freezes that version with a tamper-evident seal, so a later edit makes a new version rather than rewriting the old one.
- A public transparency page. On a paid plan, list your published system cards on a public page.
An AI assistant that proposes and never decides
Watney does the drafting and the reading. It does not approve a system, set a risk tier, or publish anything; those stay with the people your policy names.
- Drafts cards. A first draft of a model or system card from the records you have kept.
- Suggests intake triage. A suggested starting point for a newly registered system, for you to accept or change.
- Reviews answers and summarizes evidence. Reads an assessment answer against its evidence, or summarizes an uploaded file.
- Answers questions from your records. Answers are grounded on your organization's own records.
An organization admin must opt in before Watney reads the organization's data. Watney is included with Premium and Enterprise.
Watney sends the model provider only what a task needs: the records you typed, documentation you paste in, and the contents of uploaded evidence files (or its earlier summaries of them) when it reviews or drafts an answer or summarizes evidence. Watney's own system card names the provider and the models.
The rest of the program, next to the systems it concerns
An approval is one moment. The registers hold what happens around it, so the record stays current between reviews.
Risk Register
Record the risks your AI systems carry and what is being done about each one.
AI Incidents
Log what went wrong with an AI system and follow it through to a close.
Vendors
Every AI vendor, with your due diligence: whether it trains on your data and whether an agreement is on file.
AI Policy Library
Keep the policies your program runs on, in one place your team can find.
Training
Keep a record of the AI training your team has completed.
Change Log
Log changes to your AI systems as they happen. A material change can prompt a new review.
Access Reviews
Run periodic reviews of who has access, and keep each one as a dated record.
Audit Log
Actions are written to a hash-chained audit log, so a later change to a recorded entry is detectable unless it is made by someone holding the application's signing key and database access. It is tamper-evident, not immutable.
Show how a system was approved, when someone asks
Exports and access links come with a plan, and turn the record into something you can hand over.
Approval Dossier
Export the record of a system's approval: the review, the approvers, their decisions and the reasons given.
CSV and PDF Exports
Export your registers and assessments as CSV or PDF.
Auditor Access Links
Give an auditor read access through a link instead of emailing files around.
Guest Links
Let someone outside your organization answer a question or complete a task through a link, without an account.
Transparency Page
A public page listing the system cards you have published.
Fits the stack you already run
Connect your identity provider, your security tooling and your own systems through standard protocols.
See the API reference and webhook event catalog for details.