Skip to main content

Boardroom Answers · Security & Compliance · Security & Cyber Risk

Do you carry cyber insurance, and what's your incident track record? "We've never been breached" from a company with no customers isn't the reassurance you think it is.?

The question a Chief Risk Officer (CRO) asks.

The short answer

No policy yet and no track record to sell you — pre-launch honesty. Coverage binds at commercial launch, sized with real contracts; until then, what you can verify is inspectable engineering, and what protects you contractually is the DPA's notification and cooperation duties.

The full executive answer

You've pre-empted the weak answer, so let me not give it. Correct: we have no incident history because we have no operating history — we are pre-launch, and "never breached" is a statement about elapsed time, not resilience. I won't offer it as evidence. On insurance: as of today we do not carry a cyber liability policy; binding appropriate cyber and technology E&O coverage is a commercial-launch gate on our roadmap — it's sequenced with first customer contracts because policy scope should match actual exposure, and underwriters price on the controls we've spent this conversation describing. If your procurement requires named coverage amounts as a condition, that's a contract-stage conversation we're prepared for, and frankly your requirement helps us scope the policy correctly.

What substitutes for a track record at our stage is inspectable engineering rather than survivable history: the CI-enforced control gates, the tamper-evident audit trail, the supply-chain register with honest statuses, and the third-party attack surface running continuously (CodeQL, ZAP, gitleaks) — all of which you can verify directly rather than take on faith. Additionally, much of the operational risk sits with providers who do have deep incident track records and insurance: AWS, Vercel, Clerk, Stripe have collectively weathered thousands of incidents, and we inherit both their hardening and their contractual liability frameworks.

And the risk-transfer picture you actually care about: our terms cap our liability (fees paid, trailing twelve months — standard SaaS), which means your residual risk management shouldn't assume our balance sheet absorbs a catastrophe; it should assume our controls reduce likelihood, our DPA obligations guarantee notification and cooperation, and your own cyber programme covers the tail. That's the honest allocation, and I'd rather state it plainly than let an insurance line-item imply coverage that contract language would cap anyway.

Grounded in: SOC 2 TSC CC3.2 (risk mitigation incl. insurance); NIST CSF 2.0 GV.RM (risk strategy); ISO 27001 A.5.7 (threat intelligence context).

Want this answered live, on your data?