Your carrier wants security documents. You don’t have a security team.
Answer 21 plain-English questions about your business. Coverwright assembles a written information security program, an incident response plan carrying your state’s notification duties, and more — written for your setup, ready for the cyber insurance application or the client security review.
~10 minutes · see a real preview before you pay. The free check takes about a minute and asks for no email.
From one real 10-minute intake — the sample shown here and at /sample.
Why you can trust the output
No AI in the decision path
A rules engine selects your clauses from a fixed library — never a model improvising prose. The same 21 answers always produce the same documents.
Every line traces to a source
Clause references in the margin point back to the rule that included them, built on published NIST, CISA, and FTC small-business guidance — not invented from scratch.
Judge it before you pay
A real generated document set, and a real sample set built from a fixed persona, are both visible before checkout — nothing about the output is a surprise at the price point.
Coverwright is not a law firm and does not provide legal advice, and does not guarantee insurance acceptance, claim outcomes, or regulatory compliance. How this is built, what is reviewed, and what happens to your answers.
The reasons someone asks you for this.
Most often it’s a cyber insurance renewal — the free check covers that in a minute. The rest depends on what your business actually does:
Coverwright produces the documentation these ask for. It does not make you compliant with any of them on its own — where a rule wants something beyond a document, your set names it and says who owns it.
Work with clients like these — as their accountant, bookkeeper, broker or IT provider? See the partner programs.
Rules, not guesswork.
The same answers always produce the same documents, and every paragraph can point at the answer that put it there.
- 01
Answer 21 questions
Plain-English questions about your business: what you use, what data you handle, what’s already in place, and which state you’re in. Ten minutes, no jargon, no uploads — everything you answer feeds straight into the next step.
- 02
Rules select your clauses
A deterministic rules engine — not an AI improvising — selects every clause from a curated library based on your answers. Same answers, same documents, every time, for a traceable reason.
- 03
Download your document set
A one-page security summary for whoever you forward it to, a written information security program, an incident response plan built around US notification deadlines, and — on Complete — an acceptable use policy, continuity plan, and vendor matrix. Plus a plain-English readiness summary and a ranked plan for your gaps.
This is what lands in your inbox.
Not a template with your name dropped in. A prepared document, typeset, with a reference against every clause pointing back to the answer that selected it.
Written Information Security Program
Information security policy for Harborview Accounting LLC
1. Purpose & scope
This program sets out how Harborview Accounting LLC protects its information, systems, and the data entrusted to it by customers and partners. It applies to everyone who works in or with the business — employees, contractors, and temporary staff — and to every device and service used for business purposes.
The controls in this program are proportionate to the size and nature of the business. They exist to keep the business operating, to meet the expectations of customers and insurance carriers, and to satisfy legal obligations around the data the business handles.
Because Harborview Accounting LLC handles personal information, this program also supports the business’s legal obligations for protecting it — the specific regimes that apply are set out under “Legal & regulatory obligations” below. Questions that go beyond day-to-day security practice are escalated to the owner, who takes advice where the answer isn’t obvious.
2. Roles & responsibilities
The business owner (or managing director) is accountable for this policy. A named security lead is responsible for day-to-day operation: managing accounts, checking that controls remain in place, and acting as the first point of contact for concerns. The current security lead is recorded alongside this policy.
Every member of staff is responsible for following this policy, for reporting anything suspicious promptly, and for asking before working around a control. No one is expected to diagnose a security problem — only to report it.
Five documents. Yours, not a template’s.
Written Information Security Program (WISP)
The document a cyber insurance application, a client security review, and the FTC Safeguards Rule all ask for — under three different names. It is not the whole of what a rule like the Safeguards Rule asks for; where more is required, your set names it and says who owns it. States what your business actually does, and where you’re still rolling a control out, says so honestly with a remediation clause instead of a false claim.
Incident Response Plan
Who does what when something goes wrong — phishing, a hacked account, ransomware. Tailored to your actual stack, and to the notification clocks that may apply to you: state breach-notification deadlines, the 60-day HIPAA timetable, the FTC’s 30-day rule.
Acceptable Use Policy
The one your staff actually read, written at them rather than about them. Covers accounts, phishing, devices, and what may and may not be pasted into a public AI assistant — the question every small business now has and few policies answer.
Business Continuity Plan
A one-pager, deliberately: what gets restored first, how long you can work without it, and how you keep invoicing while it’s down. Recovery targets are written as decisions you record — never as a capability you didn’t tell us you had.
Vendor Responsibility Matrix
For each service you rely on: what the vendor secures, what’s on you. The exact answer to a client questionnaire’s “who manages X?” rows — built from the tools you told us you use.
Content built on published small-business security guidance from US government sources (NIST, CISA, FTC), adapted to your answers.
What a business like yours generates.
Answer a few questions here and watch the same rules engine assemble a set — live. The real thing runs on all 21 answers; this is a taste of how your setup drives the output.
Change an answer on the left and the clauses it selects appear here, by reference. Same answers in, same clauses out — every time.
- —Multi-factor authentication: stated with a remediation clause, never a false claim.
What this work costs the usual way.
Or low five figures as a one-off policy project, at $150–$500 an hour.
No retainer, no hourly billing — pay once, renew for $99 a year. The price you see is the price charged; nothing is added at checkout.
Typical published US ranges as of 2026-07-18. Content drawn from NIST, CISA, and FTC small-business guidance.
Pay once. Renew when your insurance does.
The core set — what the application asks for.
- ✓One-page security summary, for whoever you forward it to
- ✓Written Information Security Program (WISP)
- ✓Incident Response Plan with your state’s notification duties
- ✓Readiness summary and a ranked action plan for your gaps
- ✓PDF and editable Word, both included
Two documents. See yours before you pay.
The full set — everything a client security review asks for too.
- ✓Everything in Standard
- ✓Acceptable Use Policy, including AI-tool rules
- ✓Business Continuity Plan
- ✓Vendor Responsibility Matrix for your actual tools
- ✓Renewal reminder timed to your insurance date
Five documents. See yours before you pay.
Added to Standard or Complete at checkout — not sold on its own.
- ✓Documents refresh automatically each year
- ✓Monthly check: is your email domain authenticated (SPF/DKIM/DMARC)?
- ✓Monthly check: has your domain appeared in a known, disclosed data breach?
- ✓Results tracked on your dashboard
Priced above the $99 manual renewal on purpose — for $80 more than remembering to renew yourself, it’s automatic and checked.
Annual refresh — re-answer what changed, regenerate everything — $99, or add Continuous above to make it automatic.
Prices in USD. The price shown is the price charged — nothing added at checkout.
The things worth asking before you buy.
Is this generated by AI?
No. Clause selection is a rules engine over a curated clause library — deterministic and auditable. A document your insurance depends on shouldn’t come from a model’s best guess.
How is this different from a template pack?
A template says [COMPANY NAME] and lists controls you may not have. Coverwright’s documents are assembled from your answers: your tools by name, your working setup, your state’s notification duties, and honest remediation clauses where a control isn’t in place yet — which is what an underwriter actually wants to see.
What is a WISP, and is that what I need?
A Written Information Security Program is the same document an insurance application calls an information security policy and a client questionnaire calls a security policy. If you prepare taxes, keep books, advise on finances, or arrange financing, the FTC Safeguards Rule expects you to have one in writing if it applies to you. Coverwright generates it under both names so you can hand it to whoever asked.
Does this make me HIPAA or FTC compliant?
No, and anyone selling you that is overselling. Documentation is one requirement among several — HIPAA also requires a written security risk analysis and signed business associate agreements; the Safeguards Rule requires a named responsible individual and a risk assessment. Your documents name those obligations and who owns them, so you can see what’s still outstanding rather than assuming a PDF covered it.
What is the content based on?
The clause library is built on published US government and industry guidance for small-business security — NIST, CISA, and FTC small-business guidance, including NIST’s incident-handling lifecycle — adapted into plain English.
Why a renewal, not a subscription?
You need these documents when insurance renews or a client asks — roughly once a year, not monthly. So the default is: pay once to generate, and $99 each year to re-answer what’s changed and regenerate. Continuous (below) is there if you’d rather that happen automatically.
What does Continuous actually check?
Two things, monthly: whether your email domain has SPF, DKIM, and DMARC records configured (the control that most reduces invoice-fraud and impersonation risk), and whether your domain or an address on it has appeared in a known, disclosed data breach. Both are stated facts fed into the same rules engine as your intake answers — never an AI judgment, and never a claim broader than what was actually checked.
Can my accountant manage this for multiple clients?
There’s a referral programme for accountants, bookkeepers, and brokers, with a dashboard to see what a referral code has earned — see /partners. It doesn’t yet include bulk-buying document sets or managing several clients’ Continuous subscriptions from one screen; that’s the next thing we’re building for it.
Why is this so much cheaper than hiring someone?
A security consultant or virtual CISO doing this same work typically charges $3,500–$15,000 a month as an ongoing retainer, or low five figures as a one-off policy project, at $150–$500 an hour. Coverwright runs the same underlying task — turning your answers into policy — through a rules engine instead of billed hours, so the price reflects that, not a discount on what’s in the documents.
Ten minutes now, or a scramble at renewal.
Answer the 21 questions and read your own document set in full before you decide whether to pay for it. Nothing is sent anywhere until you do.
No account needed to see your documents · no sales call, ever