See what your underwriter sees, before you sign.
Cyber insurance applications ask about email authentication, multi-factor sign-in, backups and patching. Part of the answer can be read from outside by anyone. We show you that outside view first, so you answer with the facts in hand.
Attackers use AI to find openings. We use it to find yours first, and a person checks every finding before you see it.
What your underwriter sees.
Captions on, no sound. Illustrative; no real firm is shown.
Read the transcript
- Your insurer already has questions about you.
- Cyber insurance renewal. See what your underwriter sees, before you sign.
- Do you use SPF, DKIM and DMARC? We read that from outside.
- Is multi-factor sign-in on? We see which sign-in pages answer. Whether it is on is a question for your IT provider.
- Are backups kept apart and tested? Nothing outside shows this, and we say so.
- Is software kept up to date? Partly: what your website advertises, and its certificate dates.
- We do not set or predict your premium; your insurer decides. You answer with the facts in hand.
- Walk into renewal knowing what the questions will find.
What cyber applications ask, and what the outside view shows.
Do you use SPF, DKIM and DMARC? We read the records your domain publishes and say whether forged mail in your name is refused.
Is it on for email and remote access? We see which sign-in pages and remote access services answer on your website host. Whether multi-factor is switched on is a question for your IT provider, and the reading says so.
Are backups kept apart from your systems, and tested? Nothing outside shows this. We list it as a question for your IT provider, not as a finding.
Is software kept up to date? We read the software and versions your website advertises, and its certificate dates, and name what to update.
Before the application, not after it.
The External Exposure Check. No access, no software, nothing to install.
The same public surfaces an underwriter can see: mail records, sign-in pages, website software, staff addresses in breach records.
With proof you can check: every finding comes with a check anyone can run. The paid assessment is approved by a person before it is released.
With your broker and IT provider, knowing what the questions will find.
In the External Cybersecurity Assessment, the Rules and Insurance Briefing puts each finding in the terms an application uses, and the Signed Assessment Record dates what was open on the day. Your evidence pack: an owner summary, the technical evidence for your IT provider, a rules and insurance briefing, and a signed assessment record.
The insurer decides. You decide with the facts.
We do not set, predict or promise your premium, your terms, or whether a policy is offered. Your insurer decides those. What we give you is the outside view, dated, and the steps your IT provider follows to change it.
Next to the people you already work with.
Keeps your systems running and does the fixes. We give them an independent list to act on, with the check that proves each fix. We are paid by no one who sells the fixes, so every finding is independent.
Tries to break in and needs access. We read only what is already public, from outside, and log into nothing.
Feeds your premium and eligibility. We show you the same outside view first, in plain words, so you walk into renewal knowing the answers.
Walk into renewal knowing what the questions will find.
The External Exposure Check: your outside reading, with what we found and a check you can run yourself. No access, nothing tested.