Your insurer wants security documents. You don't have a security team.
Answer 20 plain-English questions about your business. Coverwright assembles a security policy, incident response plan, and vendor responsibility matrix — written for your setup, ready for the cyber insurance questionnaire or the client security review.
From one real 10-minute intake — the sample shown here and at /sample.
No AI in the decision path
A rules engine selects your clauses from a fixed library — never a model improvising prose. The same 20 answers always produce the same documents.
Every line traces to a source
Clause references in the margin point back to the rule that included them, built on published NCSC, NIST, and CISA small-business guidance — not invented from scratch.
Judge it before you pay
A real generated document set, and a real sample set built from a fixed persona, are both visible before checkout — nothing about the output is a surprise at the price point.
Coverwright does not guarantee insurance acceptance, claim outcomes, or regulatory compliance.
Rules, not guesswork.
Answer 20 questions
Plain-English questions about your business: what you use, what data you handle, what's already in place. Ten minutes, no jargon, no uploads — everything you answer feeds straight into the next step.
Rules select your clauses
A deterministic rules engine — not an AI improvising — selects every clause from a curated library based on your answers. Same answers, same documents, every time, for a traceable reason.
Download your document set
An information security policy, an incident response plan, and a vendor responsibility matrix — written for your setup, plus a plain-English readiness summary against common insurer questions.
Three documents. Yours, not a template's.
Information Security Policy
The document every insurer questionnaire and client security review asks for first. States what your business actually does — and where you're still rolling a control out, it says so honestly, with a remediation clause instead of a false claim.
Incident Response Plan
Who does what when something goes wrong — phishing, a hacked account, ransomware. Tailored to your actual stack: containment steps for Microsoft 365 read differently than for a self-managed office server.
Vendor Responsibility Matrix
For each service you rely on: what the vendor secures, what's on you. The exact answer to a client questionnaire's "who manages X?" rows — built from the tools you told us you use.
Content built on published small-business security guidance from government sources (NCSC, NIST, CISA), adapted to your answers.
What a business like yours generates.
Answer a few questions here and watch the same rules engine assemble a set — live. The real thing runs on all 20 answers; this is a taste of how your setup drives the output.
- —Multi-factor authentication: stated with a remediation clause, never a false claim.
What this work costs the usual way.
Or low five figures as a one-off policy project, at $150–$500 per hour.
No retainer, no hourly billing — pay once, renew for €69 a year. Billed in EUR.
Typical published ranges as of 2026-07-18 (US market) · content drawn from NIST and CISA small-business guidance
See pricingPay once. Renew when your insurance does.
The core set — what the questionnaire asks for.
- ✓Information Security Policy
- ✓Incident Response Plan
- ✓Readiness summary against common insurer questions
- ✓Editable document formats
The full set, tuned to your industry and your vendor stack.
- ✓Everything in Standard
- ✓Vendor Responsibility Matrix for your actual tools
- ✓Renewal reminder timed to your insurance date
Annual refresh — re-answer what changed, regenerate everything — €69. No subscription.
Prices in EUR and billed in EUR, wherever you are, incl. VAT where applicable. UK and US buyers welcome — your card is simply charged the euro amount.
Is this generated by AI?
No. Clause selection is a rules engine over a curated clause library — deterministic and auditable. A document your insurance depends on shouldn't come from a model's best guess.
How is this different from a template pack?
A template says [COMPANY NAME] and lists controls you may not have. Coverwright's documents are assembled from your answers: your tools by name, your working setup, and honest remediation clauses where a control isn't in place yet — which is what an underwriter actually wants to see.
What is the content based on?
The clause library is built on published government and industry guidance for small-business security (the territory covered by the UK NCSC's Small Business Guide, NIST's incident-handling guidance, and CISA resources), adapted into plain English.
Why a renewal, not a subscription?
You need these documents when insurance renews or a client asks — roughly once a year, not monthly. So you pay once to generate, and a smaller fee each year to re-answer what's changed and regenerate.
Why is this so much cheaper than hiring someone?
A security consultant or virtual CISO doing this same work typically charges $3,500–$15,000 a month in the US (£3,000–£15,000 in the UK) as an ongoing retainer, or low five figures as a one-off policy project. Coverwright runs the same underlying task — turning your answers into policy — through a rules engine instead of billed hours, so the price reflects that, not a discount on what's in the documents.