Skip to content
Cyber insurance renewal evidence

Cyber insurance renewal evidence package: source-linked controls, freshness-dated, organized by underwriter scoring category.

Valty produces a cyber insurance renewal evidence package from source-connected control data. CFOs and CISOs get a proof pack organized by the controls underwriters score most heavily, with collection mode, freshness, and claim state visible before submission.

Design partnerPublic / indexed
Review proof and audit workflow
At a glance

An underwriter-ready evidence package, not a questionnaire sprint.

Not self-attestation

Evidence

Source-linked control evidence with collection mode, freshness, and attestation tier. This is what underwriters increasingly require instead of questionnaire-only responses.

Renewal deliverable

Proof pack

An exportable evidence package organized by the control categories underwriters score: MFA, EDR, backup, IR plan, and network segmentation.

Freshness requirement

Fresh

Underwriter evidence requests increasingly specify evidence collection date. Stale controls and point-in-time assessments create coverage gaps at renewal.

Buyer questions

The questions this page needs to answer before anyone treats a number as fact.

CFO question

What evidence does the underwriter need, and how do we produce it without a manual evidence sprint?

Insurance renewal is increasingly evidence-driven. CFOs need an evidence package that can be produced from connected source systems, not assembled from spreadsheets and assessment PDFs weeks before the renewal date.

CISO question

Which controls are the underwriter scoring and what does current evidence actually show?

CISOs need to see the actual control state, source-linked, freshness-dated, and organized by underwriter scoring category, before the renewal questionnaire locks in claims that cannot be substantiated.

Evidence standard

What separates evidence the underwriter accepts from evidence they treat as self-attestation?

Underwriters distinguish between source-verified evidence (scanner, cloud API, identity provider), agent-assisted attestation, and manual self-certification. Source tier affects both coverage and premium outcome.

Renewal evidence package

Controls the underwriter scores, with source, freshness, and collection mode attached.

The renewal evidence package is structured around the control categories that determine cyber insurance coverage and premium: MFA enforcement, EDR deployment and alerting, backup cadence and recovery testing, incident response plan currency, and network segmentation. Each control is evidence-backed to its source system with collection date visible.

  • MFA evidence: identity provider API signal with enrollment rate and enforcement scope
  • EDR evidence: endpoint platform coverage percentage with collection date
  • Backup evidence: recovery cadence, last test date, and offsite replication state
  • IR plan evidence: document version, review date, and tabletop exercise record
  • Network segmentation: architecture attestation with reviewable source artifact

Evidence package reflects the state of connected source systems at the time of export. Coverage scope is bounded by source connector access agreed at setup. Valty does not issue insurance opinions or guarantee underwriter acceptance of any evidence package.

Evidence Proof Pack product surface
Evidence Proof PackExportable proof pack with source, confidence, freshness, and publication state per claim, for auditors, underwriters, and board review.
Renewal evidence workflow

Source controls in. Underwriter-ready evidence package out.

The renewal workflow connects source systems to a publication-gated evidence export, so CISOs and CFOs arrive at renewal with proof, not with a last-minute questionnaire sprint.

Catalog

Controls organized by underwriter scoring category

Valty organizes control evidence by the categories underwriters weight most heavily: multi-factor authentication, endpoint detection and response, backup and recovery, incident response plan, and network segmentation.

Underwriter control taxonomy
Source

Evidence tied to source system with collection date

Each control is evidence-backed to its source: identity provider signals for MFA, EDR platform API for endpoint coverage, backup system logs for recovery cadence. Collection date and freshness are attached.

Source adapter → evidence object
Mode

Collection mode visible to underwriter

The evidence package labels each control as automated (source-verified), assisted (agent-supported), or manual (owner-attested), so the underwriter can apply appropriate reliance without guessing.

Automated / assisted / manual evidence mode
Pack

Renewal evidence package exported with claim state

The renewal pack includes only publishable claims. Stale or unattested controls appear in the blocked ledger so gaps are disclosed cleanly rather than hidden in a questionnaire response.

Publication-gated renewal export
Evidence collection mode

Underwriters distinguish evidence tier. Valty makes it visible.

Source-verified evidence (T1 hardware-attested, T2 API-verified) carries higher reliance than owner-attested manual responses. The renewal package labels each control so the underwriter, and the CISO, can see exactly what is backing each claim.

Highest reliance

Source-verified (T1–T2)

Control evidence collected directly from identity providers, EDR platforms, cloud APIs, or backup systems. Collection timestamp and API scope preserved.

  • MFA enforcement from IdP API
  • EDR coverage from endpoint platform
  • Backup cadence from storage API
Mid-tier reliance

Agent-assisted (T3)

Evidence where Valty prompts the owner, validates the response format, and records the attestation chain. Used for policy documents, vendor questionnaires, and IR plan reviews.

  • IR plan version and review date
  • Vendor security questionnaire intake
  • Network diagram attestation
Disclosed self-attestation

Owner-attested (T4)

Manual owner submission with reviewer and date recorded. Labeled clearly in the renewal package, so underwriters see it as self-attestation, not source-verified evidence.

  • Physical control statement
  • Exception documentation
  • Manual policy sign-off
Proof matrix

Renewal evidence claims and their proof requirements.

Each renewal claim requires source, collection mode, and freshness before it enters the evidence package. The blocked-claim ledger discloses gaps honestly rather than burying them in questionnaire language.

ClaimMFA enforcement evidence
SourceIdentity provider API: enrollment rate and enforcement scope
ConfidenceSource-verified (T2), labeled by IdP signal date
FreshnessAPI sync cadence; flagged when the IdP signal exceeds the configured freshness window (e.g. 30 days)
ClaimEDR coverage evidence
SourceEndpoint platform API: coverage %, last alert, agent version
ConfidenceSource-verified (T2), labeled by platform export date
FreshnessPlatform sync; flagged when the agent falls outside the configured version-currency window (e.g. 90 days behind current)
ClaimBackup and recovery evidence
SourceBackup system logs: cadence, last test date, offsite replication
ConfidenceSource-verified (T2) or agent-assisted (T3) for test records
FreshnessBackup API sync; recovery test date manually tracked
ClaimIncident response plan evidence
SourceDocument version, review date, tabletop exercise record
ConfidenceOwner-attested (T4), labeled as self-attestation in package
FreshnessRe-review date set at attestation; flagged when it exceeds the configured attestation window (e.g. 12 months)
ClaimBlocked renewal claim (stale evidence)
SourceControl artifact expired or source not connected
ConfidenceNot publishable. Appears in gap ledger with action required
FreshnessOwner or source refresh required before renewal submission

Arrive at renewal with source-linked evidence, not a questionnaire sprint.

Valty organizes control evidence by underwriter scoring category, labels each claim by collection mode and freshness, and packages the renewal submission with a clean blocked-claim ledger. No manual assembly required.

Valty is in design-partner and early-access stage. All financial figures are illustrative decision-support estimates with method, confidence, and limitation stated adjacent to the claim. No fabricated customers, no published pricing.