For businesses of 1–50 · No sales call, ever

Your insurer wants security documents. You don't have a security team.

Answer 20 plain-English questions about your business. Coverwright assembles a security policy, incident response plan, and vendor responsibility matrix — written for your setup, ready for the cyber insurance questionnaire or the client security review.

Answer the 20 questions~10 minutes · see a real preview before you pay
3
documents generated
48
clauses written
9
vendor rows mapped

From one real 10-minute intake — the sample shown here and at /sample.

No AI in the decision path

A rules engine selects your clauses from a fixed library — never a model improvising prose. The same 20 answers always produce the same documents.

Every line traces to a source

Clause references in the margin point back to the rule that included them, built on published NCSC, NIST, and CISA small-business guidance — not invented from scratch.

Judge it before you pay

A real generated document set, and a real sample set built from a fixed persona, are both visible before checkout — nothing about the output is a surprise at the price point.

Coverwright does not guarantee insurance acceptance, claim outcomes, or regulatory compliance.

Cyber insurance questionnaires
Client & vendor security reviews
Annual renewal refreshes
How it works

Rules, not guesswork.

01

Answer 20 questions

Plain-English questions about your business: what you use, what data you handle, what's already in place. Ten minutes, no jargon, no uploads — everything you answer feeds straight into the next step.

02

Rules select your clauses

A deterministic rules engine — not an AI improvising — selects every clause from a curated library based on your answers. Same answers, same documents, every time, for a traceable reason.

03

Download your document set

An information security policy, an incident response plan, and a vendor responsibility matrix — written for your setup, plus a plain-English readiness summary against common insurer questions.

The document set

Three documents. Yours, not a template's.

CW-SP

Information Security Policy

The document every insurer questionnaire and client security review asks for first. States what your business actually does — and where you're still rolling a control out, it says so honestly, with a remediation clause instead of a false claim.

CW-IR

Incident Response Plan

Who does what when something goes wrong — phishing, a hacked account, ransomware. Tailored to your actual stack: containment steps for Microsoft 365 read differently than for a self-managed office server.

CW-VM

Vendor Responsibility Matrix

For each service you rely on: what the vendor secures, what's on you. The exact answer to a client questionnaire's "who manages X?" rows — built from the tools you told us you use.

Content built on published small-business security guidance from government sources (NCSC, NIST, CISA), adapted to your answers.

See it work

What a business like yours generates.

Answer a few questions here and watch the same rules engine assemble a set — live. The real thing runs on all 20 answers; this is a taste of how your setup drives the output.

Team size
Industry
Where the team works
Your set would include
43
clauses
3
documents
7
vendor rows
1 gapwe'd flag — honestly
  • Multi-factor authentication: stated with a remediation clause, never a false claim.
The price gap

What this work costs the usual way.

A security consultant or vCISO
$3,500–$15,000 / month

Or low five figures as a one-off policy project, at $150–$500 per hour.

Coverwright
149–€249 one-time

No retainer, no hourly billing — pay once, renew for €69 a year. Billed in EUR.

Typical published ranges as of 2026-07-18 (US market) · content drawn from NIST and CISA small-business guidance

See pricing
Pricing

Pay once. Renew when your insurance does.

Standard
€149one-time

The core set — what the questionnaire asks for.

  • Information Security Policy
  • Incident Response Plan
  • Readiness summary against common insurer questions
  • Editable document formats
Complete
€249one-time

The full set, tuned to your industry and your vendor stack.

  • Everything in Standard
  • Vendor Responsibility Matrix for your actual tools
  • Renewal reminder timed to your insurance date

Annual refresh — re-answer what changed, regenerate everything — €69. No subscription.

Prices in EUR and billed in EUR, wherever you are, incl. VAT where applicable. UK and US buyers welcome — your card is simply charged the euro amount.

Fair questions

Is this generated by AI?

No. Clause selection is a rules engine over a curated clause library — deterministic and auditable. A document your insurance depends on shouldn't come from a model's best guess.

How is this different from a template pack?

A template says [COMPANY NAME] and lists controls you may not have. Coverwright's documents are assembled from your answers: your tools by name, your working setup, and honest remediation clauses where a control isn't in place yet — which is what an underwriter actually wants to see.

What is the content based on?

The clause library is built on published government and industry guidance for small-business security (the territory covered by the UK NCSC's Small Business Guide, NIST's incident-handling guidance, and CISA resources), adapted into plain English.

Why a renewal, not a subscription?

You need these documents when insurance renews or a client asks — roughly once a year, not monthly. So you pay once to generate, and a smaller fee each year to re-answer what's changed and regenerate.

Why is this so much cheaper than hiring someone?

A security consultant or virtual CISO doing this same work typically charges $3,500–$15,000 a month in the US (£3,000–£15,000 in the UK) as an ongoing retainer, or low five figures as a one-off policy project. Coverwright runs the same underlying task — turning your answers into policy — through a rules engine instead of billed hours, so the price reflects that, not a discount on what's in the documents.