Coverage & Appetite

One policy for the whole cyber exposure — AI included.

A modern cyber form for companies whose products and operations run on AI. Every module below can be tailored per account; all coverage descriptions are indicative and subject to underwriting.

Coverage modules

What the policy covers.

Third party

Network security & privacy liability

Defense and damages for claims arising from security failures, unauthorized access, data breaches, and privacy violations — including regulatory proceedings, fines and penalties where insurable.

First party

Incident response & breach costs

Digital forensics, breach counsel, notification, call center, credit monitoring, and crisis communications, coordinated by our response panel from the first call.

First party

Ransomware & cyber extortion

Extortion payments where lawful and approved, professional negotiation, and restoration costs.

First party

Business interruption & system failure

Lost income and extra expense from security events and system failure — with dependent business interruption for cloud, API, and model providers your product relies on.

Crime

Cybercrime

Funds transfer fraud and social engineering — explicitly including AI-enabled impersonation, synthetic voice, and deepfake-assisted schemes.

First party

Data recovery

Costs to restore or recreate data and systems corrupted or destroyed in a covered event.

Appetite

Who we write.

Indicative appetite — accounts outside these bands are considered case by case.

DimensionTarget
Target insuredsAI-native software companies; SaaS with embedded AI features; data, ML, and AI infrastructure companies; tech-enabled services automating operations with AI
Company sizeEarly-stage through mid-market
LimitsPrimary and excess placements; limits scaled to account size
RetentionsScaled to revenue and posture
TerritoryUnited States
Generally out of appetiteCryptocurrency exchanges and custody; adult content; online gambling; standalone payment processing

Security expectations: MFA on privileged access, tested backups, and EDR are baseline. For AI features with real authority — payments, data access, system actions — we expect guardrails, human escalation paths, and logging, and we price accounts that have them accordingly.

Submission requirements →