Coverwright
How this is built

The questions you would ask a vendor, answered about us.

Coverwright exists because larger customers push security questionnaires down to their suppliers. It would be a poor product that could not answer the same questions about itself. Everything below is checkable, and the parts that have not been professionally reviewed say so.

129
clauses in the library
36
clause families
22
questions asked
47
automated checks per release

Counted from the running engine when this page was built, not stated by hand. Library version 1.8 · last change July 25, 2026.

Review status

What has been reviewed, and what has not.

Not yet reviewed

The clause library is draft pending sign-off by a qualified US attorney. A complete review pack has been prepared from the live library for that purpose. Until it comes back, Coverwright makes no claim of alignment to any named framework clause — no ISO 27001 Annex A numbers, no insurer field mappings, no “satisfies §X”. Where a document names HIPAA, the FTC Safeguards Rule, PCI DSS or a state breach law, it states what the regime asks of a business in scope and leaves whether it applies to you with you and your counsel.

Reviewed and applied

The intake and clause library were revised after a written security review, which is why the questions now cover the controls carriers actually underwrite on, and why no clause asserts a control the intake did not confirm. A subsequent pass corrected the scope statements in the US regulatory clauses — the HIPAA covered-entity test, the conduit exception to business associate agreements, and the Safeguards Rule relief for firms under 5,000 consumers.

Coverwright produces security documentation, not legal or insurance advice. Holding these documents is not the same as being compliant with any regime, and no carrier, auditor or client is obliged to accept them. Your documents say so too.

Engineering

What stops a document saying something untrue.

The same answers always produce the same documents

Clause selection is a rules engine over a fixed library. No language model is involved in deciding what your documents say — not as a fallback, not for edge cases. That is what makes a clause traceable to an answer, and it is the property everything else here protects.

47 honesty checks run before anything ships

An automated suite asserts the properties that matter for a document someone will rely on: that no clause claims a control the intake did not confirm, that a remediation clause never ships as an assertion, that regulatory clauses never claim compliance, that no unmerged placeholder can reach a document, and that the question count promised on the site equals the one the form actually asks. A change that breaks any of them cannot be released.

Documents are typeset, not templated

PDF and Word output are generated from the same assembled structure, so the two files always say the same thing. Clause references print in the margin of both, which is what makes an underwriter or auditor able to ask why a paragraph is there and get an answer.

Changes are versioned and dated

Every change to the clause library or the engine is recorded in a public changelog with the date it shipped. You can see what the library said when you generated your set, and what has changed since.

Your data

What we hold, and what we never see.

Where do my answers live while I’m answering?

In your browser, in localStorage. Nothing is transmitted to Coverwright until you complete a purchase, so you can answer every question, read your full generated set, and close the tab without us ever receiving your business details.

What is stored after I buy?

Your email address, which tier you bought, the amount and tax, a Stripe session reference, and a snapshot of your intake answers — the snapshot is what makes re-download and the annual refresh possible. That is the complete list.

Do you see my card details?

No. Checkout runs on Stripe and card details go directly to them. Stripe in turn never receives your intake answers; the two data sets are only ever joined by a session reference.

Do you run analytics or ad trackers?

Not today. There are no analytics scripts, no advertising pixels, and no third-party tags on the site. If that ever changes, the privacy policy changes with it in the same release.

Is any sensitive data collected in the intake?

No. The intake asks about your business — tools, headcount, controls, state — and has exactly one free-text field: your business name. It never asks for customer records, patient information, or credentials, and the questions are worded to discourage putting them there.

Can I have my data deleted?

Yes. Email hello@coverwright.com and the purchase record and intake snapshot are deleted, subject to the invoicing records Lithuanian tax law requires us to retain. The privacy policy sets out the full detail and your other rights.

The full detail, including legal bases and your rights, is in the privacy policy.

Answering a questionnaire of your own?

That is the job this was built for. Read a full generated set before you decide whether to pay for it.