Business
Business Security · Overview Scope · Domain Audit Shadow · Mailbox Forensics Monitoring · Continuous Coverage Fix Session · Implementation
Individual
Personal Protection · Overview Scope · Personal Credential Scan
Solutions
Dark Web Monitoring Domain Impersonation Protection Credential Breach Detection Compliance Monitoring
Intelligence
Threat Intelligence Global Breach Map Breach Feed
Company
Partners How It Works About Press & Media
Sign In
For cyber insurance carriers · MGAs · wholesalers

The threat intelligence your policyholders need. Bundled into your book.

LeakTrace continuously monitors the external attack surface, credential exposure, and executive personal-data footprint of every policyholder in your book. Underwriting-grade risk scoring at bind. Real-time policyholder-side alerts across the policy lifecycle. Claim-reduction data your loss ratio actually sees.

The underwriting + claims problem

You bind on a questionnaire. Your policyholder's exposure changes weekly.

The bind moment
Applicant answers 'yes' to controls they can't defend under scrutiny.
MFA enrolled ≠ MFA enforced. DMARC exists ≠ DMARC at reject. The application is a snapshot of what the applicant remembers being told. The exposure is what's actually publicly indexed.
The 12-month gap
Between bind and renewal, nobody is watching the policyholder's surface.
A partner leaves, the DMARC record shifts, a subdomain gets stood up without SPF alignment. The policy is priced against a posture that stopped being true six weeks later.
The claim moment
By the time the incident is disclosed, the reconnaissance window has closed.
Business email compromise runs 47 days on average between initial access and ransom message. If nobody was watching the attack surface, the loss ratio hits the carrier's book · not the policyholder's IT budget.
What LeakTrace does

Continuous external threat monitoring at every policy in your book.

LeakTrace scans the public attack surface of every domain we're pointed at · DNS, certificates, exposed services, infrastructure identifiers. We cross-reference every staff email against known breach databases. We map every senior executive's personal data footprint across data broker sites. And we surface it all as a single risk score plus prioritized findings, delivered in the format your workflow needs (API, dashboard, report).

Same underlying scan the Fortune 500 buys from Mandiant and Kroll for six figures. Priced for the small-and-mid-market policyholders you actually write.

Three integration models

Bundle, add-on, or referral. Whatever fits your book.

Model 1
Bundled coverage
LeakTrace continuous monitoring included in every cyber policy you write, at a fixed per-policy cost. Reduces loss ratio by giving policyholders the surface intelligence they'd otherwise pay for after the incident. Underwriting adjustments based on bind-day risk score. White-labeled to your brand if needed.
Model 2
Endorsement add-on
LeakTrace as an optional endorsement policyholders can activate at bind or renewal. Revenue share on activation, plus the underwriting-grade risk data on the policyholders who opt in. Lets your book self-select the highest-touch clients into the highest-visibility monitoring.
Model 3
Referral / broker channel
Your brokers refer policyholders directly. Referral fee per closed engagement, plus first-look on any elevated risk we detect on referred policyholders (so the broker knows before the renewal conversation). Zero integration lift.
The math per policy

Illustrative economics on a bundled book.

Assumes a mid-market SMB cyber book. Actuals vary by segment, retention level, and policy mix · happy to model against your specific book on a call.

$50-200
Per-policy LeakTrace cost
(bundled tier, annual)
$120K
Average FBI IC3 2024 BEC loss
per reported incident
47 days
Median dwell time between
initial access and ransom
80%+
Of BEC victims had MFA enrolled
at time of compromise (FBI IC3)
Security posture + compliance

Built for carrier due diligence.

SOC 2 Type II
Audit in progress. Interim security questionnaire responses available on request.
Data handling
All scanning uses public-record sources only. No credential storage. No plaintext PII retention beyond scan-lifecycle windows.
Regulatory framing
Findings mapped to PIPEDA (CA), GLBA + state breach-notification (US), sector-specific overlays (HIPAA, PCI-DSS, SOX).
Institutional voice
Analyst-grade briefing suite: executive summary, technical evidence, statutory mapping, prioritized remediation roadmap. No AI-generated marketing filler.

One carrier deal = thousands of policyholders bundled in.

If you write cyber coverage and want to reduce loss ratio without adding CAC, this is a 20-minute conversation worth having.

Book the partnership call →