Skip to content
Cyber insurance renewal evidence

Cyber insurance renewal evidence package: source-linked, freshness-dated, and underwriter-reviewable.

Valty combines source-connected control data with structured policy terms to produce an underwriter-reviewable package. CFOs and CISOs can inspect likely-loss exposure against limits, exclusions, and uninsured tail before submission; Valty does not claim carrier acceptance or a premium outcome.

Design partnerPublic capability
Review proof and audit workflow

Ungated renewal worksheet

Prepare the evidence. Make the gaps visible.

Use one row per system and evidence item. Replace the bracketed fields with your own records; these prompts are a blank preparation aid, not a completed assessment.

Scope and date
[Company, systems, renewal date, evidence as-of date]
Accountable owner
[Name or role, evidence reviewer, next review date]
Broker handoff
[Broker, questionnaire version, handoff date, disclosure approver]
Evidence checklist — complete with your own scope, dates and owners
Evidence itemAttach and dateRecord the gap and next step
Access and endpoint coverageDated MFA and endpoint coverage exports; include the accounts, devices and exclusions in scope.List uncovered accounts or devices, the accountable owner and the next review date.
Backup configurationDated configuration and job records for the named system; identify retention and protected copies.Record missing systems or failed jobs. Configuration and successful jobs do not prove restoration.
Restoration testActual test date, system and data restored, operator, result and supporting test record.If no test record is available, mark restoration evidence missing; assign a validation owner and due date.
Policy questions and disclosuresCurrent questionnaire version and policy wording supplied by the broker or insurer.Keep unanswered questions, evidence limits and proposed disclosures open for broker review.

Evidence checklist — complete with your own scope, dates and owners

  1. Access and endpoint coverage

    Attach and date
    Dated MFA and endpoint coverage exports; include the accounts, devices and exclusions in scope.
    Record the gap and next step
    List uncovered accounts or devices, the accountable owner and the next review date.
  2. Backup configuration

    Attach and date
    Dated configuration and job records for the named system; identify retention and protected copies.
    Record the gap and next step
    Record missing systems or failed jobs. Configuration and successful jobs do not prove restoration.
  3. Restoration test

    Attach and date
    Actual test date, system and data restored, operator, result and supporting test record.
    Record the gap and next step
    If no test record is available, mark restoration evidence missing; assign a validation owner and due date.
  4. Policy questions and disclosures

    Attach and date
    Current questionnaire version and policy wording supplied by the broker or insurer.
    Record the gap and next step
    Keep unanswered questions, evidence limits and proposed disclosures open for broker review.

Before handoff, reconcile each answer to its source, record unresolved gaps and obtain your disclosure approval. Share sensitive evidence through an agreed secure channel. Your broker or insurer determines the submission requirements; this worksheet does not establish coverage, carrier acceptance or a premium outcome.

See how a configuration record and a restoration gap stay distinct →

At a glance

An underwriter-reviewable evidence package, not a questionnaire sprint.

Not self-attestation

Evidence

Source-linked control evidence with collection mode, freshness, and attestation tier so a reviewer can weigh reliance without treating self-attestation as source proof.

Renewal deliverable

Proof pack

An exportable evidence package organized by the control categories underwriters score: MFA, EDR, backup, IR plan, and network segmentation.

Freshness requirement

Fresh

Underwriter evidence requests increasingly specify evidence collection date. Stale controls and point-in-time assessments create coverage gaps at renewal.

Buyer questions

The questions this page needs to answer before anyone treats a number as fact.

CFO question

What evidence does the underwriter need, and how do we produce it without a manual evidence sprint?

Insurance renewal is increasingly evidence-driven. CFOs need an evidence package that can be produced from connected source systems, not assembled from spreadsheets and assessment PDFs weeks before the renewal date.

CISO question

Which controls are the underwriter scoring and what does current evidence actually show?

CISOs need to see the actual control state, source-linked, freshness-dated, and organized by underwriter scoring category, before the renewal questionnaire locks in claims that cannot be substantiated.

Evidence standard

What separates evidence the underwriter accepts from evidence they treat as self-attestation?

The package distinguishes source-verified evidence (scanner, cloud API, identity provider), assisted attestation, and manual self-certification. Source tier gives the reviewer reliance context; it does not predict carrier acceptance or premium outcome.

Renewal evidence package

Controls the underwriter scores, with source, freshness, and collection mode attached.

The renewal package pairs control evidence with structured limits, retentions, coverage terms, and exclusions. It compares modeled likely loss with the policy response, surfaces the uninsured tail, and keeps every control tied to its source and collection date.

  • Policy PDF and structured terms: limits, retention, coverage, and exclusions
  • Likely-loss exposure compared with limits, exclusions, and uninsured tail
  • Carrier and shared-exclusion concentration across the portfolio
  • MFA, EDR, backup, IR plan, and segmentation evidence with collection date
  • Unsupported policy term remains unsupported, never valued as zero

Evidence package reflects the state of connected source systems at the time of export. Coverage scope is bounded by source connector access agreed at setup. Valty does not issue insurance opinions or guarantee underwriter acceptance of any evidence package.

Evidence Proof Pack product surface
Evidence Proof PackExportable proof pack with source, confidence, freshness, and publication state per claim, for auditors, underwriters, and board review.Open full-size product view ↗
Renewal evidence workflow

Source controls in. Underwriter-reviewable policy stress and evidence out.

The renewal workflow connects source systems and policy terms to a publication-gated export, so CISOs and CFOs can review the evidence and uninsured tail before renewal without implying an underwriting decision.

Catalog

Controls organized by underwriter scoring category

Valty organizes control evidence by the categories underwriters weight most heavily: multi-factor authentication, endpoint detection and response, backup and recovery, incident response plan, and network segmentation.

Underwriter control taxonomy
Source

Evidence tied to source system with collection date

Each control is evidence-backed to its source: identity provider signals for MFA, EDR platform API for endpoint coverage, backup system logs for recovery cadence. Collection date and freshness are attached.

Source adapter → evidence object
Mode

Collection mode visible to underwriter

The evidence package labels each control as automated (source-verified), assisted (agent-supported), or manual (owner-attested), so the underwriter can apply appropriate reliance without guessing.

Automated / assisted / manual evidence mode
Pack

Policy stress and renewal evidence export with claim state

The pack includes publishable evidence, likely-loss-versus-limit treatment, exclusions, and uninsured tail. Stale controls or unsupported policy terms remain in the blocked ledger.

Publication-gated renewal export
Evidence collection mode

Show how each record was collected. Let the reviewer assess its weight.

T1–T4 are Valty evidence-collection labels: hardware-attested, API-verified, agent-assisted and owner-attested. They are not an insurer rating system or a universal hierarchy of reliance. Source, scope, freshness and the test performed determine what a record can support; each recipient decides whether to accept it.

Direct source collection

Source-verified (T1–T2)

Record the actual basis: hardware attestation for T1 or provider API evidence for T2. Preserve collection time and scope. A collected setting is not automatically a test of control effectiveness.

  • MFA enforcement from IdP API
  • EDR coverage from endpoint platform
  • Backup cadence from storage API
Assisted collection

Agent-assisted (T3)

Evidence where Valty prompts the owner, validates the response format, and records the attestation chain. Used for policy documents, vendor questionnaires, and IR plan reviews.

  • IR plan version and review date
  • Vendor security questionnaire intake
  • Network diagram attestation
Disclosed self-attestation

Owner-attested (T4)

Manual owner submission with reviewer and date recorded. Labeled clearly in the renewal package, so underwriters see it as self-attestation, not source-verified evidence.

  • Physical control statement
  • Exception documentation
  • Manual policy sign-off
Proof matrix

Renewal evidence claims and their proof requirements.

Each renewal claim requires source, collection mode, and freshness before it enters the evidence package. The blocked-claim ledger discloses gaps honestly rather than burying them in questionnaire language.

ClaimMFA enforcement evidence
SourceIdentity provider API: enrollment rate and enforcement scope
ConfidenceSource-verified (T2), labeled by IdP signal date
FreshnessAPI sync cadence; flagged when the IdP signal exceeds the configured freshness window (e.g. 30 days)
ClaimEDR coverage evidence
SourceEndpoint platform API: coverage %, last alert, agent version
ConfidenceSource-verified (T2), labeled by platform export date
FreshnessPlatform sync; flagged when the agent falls outside the configured version-currency window (e.g. 90 days behind current)
ClaimBackup and recovery evidence
SourceBackup system logs: cadence, last test date, offsite replication
ConfidenceSource-verified (T2) or agent-assisted (T3) for test records
FreshnessBackup API sync; recovery test date manually tracked
ClaimIncident response plan evidence
SourceDocument version, review date, tabletop exercise record
ConfidenceOwner-attested (T4), labeled as self-attestation in package
FreshnessRe-review date set at attestation; flagged when it exceeds the configured attestation window (e.g. 12 months)
ClaimBlocked renewal claim (stale evidence)
SourceControl artifact expired or source not connected
ConfidenceNot publishable. Appears in gap ledger with action required
FreshnessOwner or source refresh required before renewal submission
ClaimPolicy stress and uninsured tail
SourceStructured policy limits, retention, exclusions + modeled likely loss
ConfidenceDecision-support; no carrier acceptance or premium outcome claimed
FreshnessRecomputed on policy-term, evidence, or model-version change
ClaimUnsupported policy term
SourceMissing or unparsed policy language
ConfidenceUnsupported, never treated as zero coverage or zero loss
FreshnessRequires source policy or reviewer resolution

Arrive at renewal with source-linked evidence, not a questionnaire sprint.

Valty organizes control evidence and policy terms, labels each claim by collection mode and freshness, and packages the review with a clean blocked-claim ledger. It reduces manual assembly without claiming an underwriting outcome.

Valty is in the design-partner stage. All financial figures are illustrative decision-support estimates with method, confidence, and limitation stated adjacent to the claim. No fabricated customers or published pricing.