Frequently asked questions

26 answers about Sertainly, decision governance, and the role of policy in an AI-driven world. If your question isn't here, get in touch.

About Sertainly
Isn't this over-engineering?

Not really—Sertainly doesn't introduce new complexity, it exposes complexity that already exists.

Most organizations already have the same decision logic duplicated across APIs, UIs, workflows, and integrations. That logic inevitably drifts, creating inconsistencies and risk.

Sertainly makes those decisions explicit, centralized, and governable.

Where is this actually a must-have?

Anywhere a wrong decision has real consequences:

  • Compliance and regulatory environments
  • Pricing, eligibility, underwriting
  • Multi-channel systems (API, UI, agents)
  • Situations requiring auditability

If you ever need to answer “Why did this decision happen?”, you already need this.

How is this different from rules engines or BPM tools?

Traditional tools like Drools or Pega focus on executing decisions within a specific system.

Sertainly defines decisions as a portable, governed source of truth across systems.

It's not just execution—it's alignment:

  • Across runtimes
  • Across teams
  • Across channels

And critically, it's alignment across time: every version is effective-dated, so a case is judged by the rules in force on its business date and that outcome stays reproducible forever—something rules engines and BPM tools don't give you out of the box.

What happens when a policy or regulation changes?

You publish a new version and bind it to an effective date. The previous version doesn't change—it's retired but stays valid history for every decision it already made.

Sertainly distinguishes two kinds of change:

  • Editions — the rules genuinely changed (a new rate, a new threshold). The old edition is retired: still-correct history for cases judged under it.
  • Corrections — the old version was wrong. It's withdrawn, and the decisions it produced can be replayed and remediated.

Live versions are immutable. Nothing you've already decided silently shifts underneath you. See Versioning decisions.

Can you prove which rules applied to a decision made last year?

Yes. Every decision is routed by the case's business date to the version in force on that date, and the full source→snapshot→version→release lineage is immutable.

That means an auditor can re-run the exact decision years later and get the exact same result—same rules, same inputs, same outcome—reproducible on demand rather than reconstructed from memory.

More on how date-based routing and immutable lineage work in Versioning decisions.

A rule turned out to be wrong — now what?

You mark the version as a correction (it's withdrawn) and publish the corrected version.

Sertainly then replays every decision the wrong version made and gives you the list of affected cases—and people—as a remediation worklist. You don't reconstruct the blast radius by hand; the system tells you exactly who was impacted and lets you act on it.

Isn't this hard to adopt?

It doesn't require a full migration.

Sertainly can be introduced incrementally:

  • Start with a single high-risk decision area
  • Run in parallel (“shadow mode”)
  • Compare outputs with existing logic

There's no need to disrupt existing systems upfront.

Who owns this?

Sertainly creates a shared contract across functions:

  • Engineering → execution
  • Product → intent
  • Compliance → constraints

Rather than creating confusion, it aligns ownership around a single source of truth.

What about performance?

Sertainly is not inherently a runtime bottleneck.

Policies can be precompiled, cached, and executed locally or as a service.

This is fundamentally a distribution and evaluation problem, not a latency problem.

What's the ROI?

Sertainly delivers value in three areas:

  • Risk reduction — prevent inconsistent decisions, reduce compliance exposure
  • Speed — change logic once, propagate everywhere; reduce regression testing
  • Leverage — safely enable automation, agents, and AI

In many cases, it pays for itself by preventing a single bad decision at scale.

AI & The Future
Can't AI handle this?

AI generates decisions—but it doesn't guarantee they are allowed.

Sertainly ensures decisions are compliant, consistent, and controlled.

AI without policy introduces risk. Policy without AI limits adaptability. Modern systems require both.

Won't AGI make this obsolete?

The opposite. As AI becomes more powerful, the need for explicit governance increases — more decisions are made, faster, and with less human oversight.

Sertainly ensures those decisions remain bounded and accountable.

Why not encode policies directly in the model?

Policies inside models are opaque, non-deterministic, and difficult to audit or version.

Sertainly keeps policy explicit, testable, and enforceable outside the model.

Won't AI agents handle rules dynamically?

Agents still need a source of truth. Without explicit policy, agents behave inconsistently, constraints drift, and outcomes become unpredictable.

Sertainly provides the shared policy layer that agents rely on.

Isn't this too rigid for an AI-driven future?

No—this is about enabling bounded adaptability.

AI explores possibilities. Sertainly defines what is allowed. This combination enables flexibility without losing control.

What if models become perfectly reliable?

Even perfect models don't replace business intent. Organizations still need to define strategy, risk tolerance, and compliance rules.

Sertainly expresses that intent explicitly and consistently.

Is this just a transitional architecture?

No—this follows a clear industry pattern toward declarative systems:

  • Infrastructure → Terraform
  • APIs → contract-driven design
  • Data → governed schemas

Decisions are the next layer to become declarative and governed.

Could AI vendors just build this in?

Vendors like OpenAI or Anthropic can provide general guardrails. But they cannot define your business rules, your compliance requirements, or your risk tolerance.

That's Sertainly's job.

Security, compliance & deployment
How does Sertainly handle security and certifications?

Sertainly is built for regulated-industry enterprises. Data is encrypted at rest and in transit.

SOC 2 Type II is currently in progress. We're happy to share our current security posture, controls, and roadmap under NDA as part of your evaluation.

Do you support SSO?

Yes. Sertainly supports enterprise single sign-on via SAML and OIDC, so access is governed by your existing identity provider and offboarding controls.

What are the deployment and data-residency options?

Sertainly meets you where your compliance requirements are. Deployment options include:

  • Managed multi-tenant — fastest to stand up
  • Dedicated — isolated single-tenant environment
  • VPC — deployed into your own cloud account
  • On-premises — inside your data center
  • Air-gapped — for the most restricted environments

Data residency follows the deployment model you choose.

How do you handle our data and AI?

We don't sell customer data, and we don't train models on your content.

Sertainly also supports bring-your-own AI credentials, so LLM calls can run against your own provider account and stay within your governance boundary.

Buying & onboarding
How do enterprises buy Sertainly?

Sertainly is enterprise-only. Buying is via order form and MSA—there's no public self-serve pricing or sign-up.

The right starting point is a conversation with our team about your use case, scope, and deployment model.

Do you provide a DPA and a list of subprocessors?

Yes. A Data Processing Agreement and our current subprocessor list are available as part of contracting and security review.

What does onboarding look like?

Onboarding covers tenant provisioning, identity and SSO setup, and standing up your first governed decision area—often run in parallel with existing logic before you cut over.

The exact scope and timeline are tailored to your deployment model and use case.

What about SLAs and support?

Support tiers and service levels are defined in your agreement and matched to your deployment model and criticality.

We'll scope the right level of support with you during contracting.

Still have questions?

Our team is quick to respond and happy to go deep on architecture, governance, or integration specifics.

Talk to SalesBack to Home