Know every AI system you run, and who approved it
Backsplice keeps a registry of your AI systems, the models they use and the vendors behind them. Assess each system and your program against NIST AI RMF 1.0 and NIST AI 600-1 (Generative AI Profile), route every system through a recorded review and approval, and publish model and system cards. Watney, the AI assistant, drafts and suggests; people decide.
30-day demo · No credit card · Unlimited team members
Everything an AI governance program keeps
Backsplice holds the registry, the assessments, the reviews and the records in one place, so the answer to "which AI systems do we run, and who approved them?" is always current.
AI system registry
Every AI system your organization builds, buys or runs, the models it uses with their versions, and the AI vendors behind them. Vendor records hold your due diligence, including whether the vendor trains on your data and whether an agreement is on file.
Assessments against framework packs
Assess your organization's program once, and each AI system on its own. Questions come from the framework packs (NIST AI RMF 1.0 and NIST AI 600-1 (Generative AI Profile)), and each one is asked at the level it belongs to.
Risk tiers that set the review
Each system's risk tier decides who must approve it and whether any, a majority or all of the approvers must agree. The rule comes from your risk-tier policy; a system can have its own, and one weaker than the tier's needs an org admin and a recorded reason.
Review and approval, with reasons
Submit a system for review. Approvers approve, approve with conditions, reject or send it back, and every decision carries a reason. Each approval carries a review date set by its risk tier; when it arrives a re-review opens automatically, so an approval never quietly outlives its assumptions.
Model and system cards
Write a card for each model and each system. Publishing a card freezes that version with a tamper-evident seal, and published system cards can be listed on your public transparency page on a paid plan.
Governance registers
A risk register, AI incidents, vendors, an AI policy library, training, a change log and access reviews, kept next to the systems they concern.
Watney, which proposes and never decides
Watney drafts cards, suggests how to triage a new system at intake, and answers questions grounded on your organization's records. It does not approve a system, set a risk tier or publish anything. An organization admin opts in before Watney reads your data.
Evidence you can hand over
Export the approval dossier for a system, export registers as CSV or PDF, and share auditor and guest links instead of emailing files around.
A record of who did what
Actions are written to a hash-chained audit log, so a later change to a recorded entry is detectable unless it is made by someone holding the application's signing key and database access. It is tamper-evident, not immutable. Forward the log to your SIEM on a paid plan.
From an inventory to a governed AI system
Register your AI systems
Record each AI system, the models it uses and their versions, and the vendors that supply them, with your due diligence on each vendor.
Assess the program and each system
Answer the framework questions once for your organization's program and again for each AI system, with the questions that apply at each level. Attach evidence as you go.
Review and approve
Submit a system for review. Its risk tier sets the approvers and whether any, a majority or all must agree. Each decision, whether approve, approve with conditions, reject or send back, is recorded with its reason.
Publish and keep it current
Publish model and system cards, each version frozen with a tamper-evident seal. Each approval comes due for re-review on a date set by its risk tier, and the approval dossier exports whenever someone asks how a system was approved.
Less time on the paperwork, more on the program
Structured workflows, reusable evidence, and grounded AI turn a months-long scramble into a repeatable process.
Framework packs included
NIST AI RMF 1.0 and NIST AI 600-1 (Generative AI Profile), on every plan and in the demo. Questions are asked for your program and for each AI system.
Decisions, each with a reason
Approve, approve with conditions, reject or send back. Every approver's decision is recorded with the reason for it, and each approval opens a re-review when its review date arrives.
Decisions made by Watney
Watney drafts cards, suggests intake triage and answers questions from your records. It never approves a system, sets a risk tier or publishes, and it reads nothing until an organization admin opts in.
A governance record, not another spreadsheet
The difference between a list of AI systems and a program that can show who approved each one, and why.
Fits the stack you already run
Connect your identity provider, your security tooling and your own systems through standard protocols.
Two plans. The same features.
Start with a demo, no card needed. The plans differ in how many AI systems you register, and Watney's fair-use limit scales with the plan.
30-day demo
Set up your registry, run assessments and approvals, and invite the people who review and approve.
- ✓ 1 AI system
- ✓ Every framework pack, assessments, approvals and cards
- ✓ SAML single sign-on, SCIM and unlimited team members
- — Watney, exports and scheduled report emails, auditor and guest links, the transparency page and public badge, the API and MCP server, webhooks and SIEM forwarding come with a plan.
Premium
or $999/year, about two months free
For a team governing its first AI system, adding systems as it goes.
- ✓ 1 AI system (more at $49/month or $499/year each)
- ✓ Watney, the AI assistant, within fair-use limits
- ✓ Every framework pack, assessments, approvals, model and system cards, and the registers
- ✓ Exports, auditor and guest links, and the public transparency page
- ✓ API, MCP, webhooks and SIEM forwarding
- ✓ SAML single sign-on, SCIM and unlimited team members
Enterprise
or $4,999/year, about two months free
For an organization with many AI systems.
- ✓ Unlimited AI systems
- ✓ Watney, the AI assistant, within fair-use limits
- ✓ Every framework pack, assessments, approvals, model and system cards, and the registers
- ✓ Exports, auditor and guest links, and the public transparency page
- ✓ API, MCP, webhooks and SIEM forwarding
- ✓ SAML single sign-on, SCIM and unlimited team members
Premium and Enterprise have the same features, Watney included; they differ in how many AI systems you register, and Watney's fair-use limit scales with the plan. Every system counts except rejected, suspended and retired ones. Your demo lasts 30 days. If you have not chosen a plan by then, the organization is locked; 90 days after the lock, it and everything in it is permanently deleted, unless you choose a plan first.
Questions, answered
How is this different from tracking AI systems in a spreadsheet? +
A spreadsheet can list your AI systems, but it does not hold the structure a governance program needs: the models each system uses and their versions, due diligence on each AI vendor, assessment answers against the framework, a review with approvers set by policy and a recorded reason for every decision, approvals that come due for re-review, and an audit trail of who changed what. Backsplice keeps all of that as you work.
Which frameworks are included? +
Every plan, and the demo, includes every framework pack: NIST AI RMF 1.0 and NIST AI 600-1 (Generative AI Profile). Assessments run at two levels: your organization's program, and each AI system. ISO/IEC 42001 and the EU AI Act are next; they are not included today.
Who makes the approval decision? +
People do. A system is submitted for review, and its risk tier sets who must approve it and whether any, a majority, or all of them must agree. Each approver can approve, approve with conditions, reject, or send it back, and each decision carries a reason. Each approval carries a review date set by its risk tier; when it arrives a re-review opens automatically, and the system keeps its stage until that review decides. Watney does not approve a system, set a risk tier, or publish anything.
Will our data be safe? +
Every page is served over HTTPS with HSTS, and session cookies are Secure, HttpOnly and SameSite=Strict. Sign-in supports multi-factor authentication with TOTP or passkeys, SAML single sign-on, SCIM provisioning, and a per-organization IP allowlist. Access is role-based (admin, contributor, auditor). The audit log is hash-chained, so a later change to a recorded entry is detectable unless it is made by someone holding the application's signing key and database access: it is tamper-evident, not immutable. TOTP secrets, and the payment-processor API keys we store, are encrypted with AES-256-GCM; card numbers go to Stripe and never reach us. An organization admin accepts our data processing agreement for the organization before any governance records can be created or changed. Organization setup (profile, members, sign-in and integration settings) can be done first. See the security page for more.
What does Watney send to the model provider? +
Only what a task needs: the records you typed, documentation you paste in, and the contents of uploaded evidence files (or its earlier summaries of them) when Watney reviews or drafts an answer or summarizes evidence. An organization admin must opt in before Watney reads your organization's data. Watney proposes and never decides. Its own system card names the model provider and the models it uses.
Is Watney included on every plan? +
Watney is included on Premium and Enterprise at no extra charge, within fair-use limits. It is not part of the 30-day demo.
Can we try it before we buy? +
Yes. There is a 30-day demo with no card. Watney, exports and scheduled report emails, auditor and guest links, the transparency page and public badge, the API and MCP server, webhooks and SIEM forwarding come with a plan. Your demo lasts 30 days. If you have not chosen a plan by then, the organization is locked; 90 days after the lock, it and everything in it is permanently deleted, unless you choose a plan first.
Does using Backsplice mean we meet a law or a standard? +
No product can confer that. Backsplice supports your AI governance program: it keeps the registry, runs the assessments, records who approved what and why, and produces the evidence. Whether your organization meets a law or a standard is a judgment for your organization and its advisers.
More on plans and data handling in our pricing FAQ, security overview and Watney's system card.