A managed external security assessment for insurance brokers. We identify issues on one client's public-facing domain, manage remediation follow-up with their MSP, confirm externally detectable fixes through a rescan, and deliver a co-branded summary before renewal.
Founding pilot, one client for $149. No ongoing commitment.
Publicly visible configuration problems can be discovered during underwriting, after the renewal process has already started.
When an issue is flagged, the broker gets stuck between the client, the MSP, and the underwriting process.
Generic scanners identify issues, but they don't manage remediation follow-up, confirm completion through a rescan, or provide a broker-facing summary.
Where a client uses an MSP, we work with them directly on fixing what we find — you're not the go-between.
Test it on one upcoming renewal.
The client authorizes a domain-based external assessment — via DNS record, an approved admin email, or written authorization through you — and we run the non-intrusive assessment.
We manage remediation follow-up directly with the client's IT provider or MSP on any findings — nothing is uploaded or retained, and no internal systems are accessed.
Once findings are addressed, we complete one rescan to confirm the externally detectable fixes.
You receive the completed, co-branded External Security Remediation Summary, prepared by us for your firm.
Run manually during this pilot — not yet a self-serve platform.
What we check
Headers, TLS/certificate health, SPF/DMARC, exposed-file patterns, vulnerable JS libraries, CORS, and subdomain discovery.
What we handle for you
We translate findings into specific actions for the client's MSP, manage follow-up, confirm externally detectable fixes with one rescan, and hand you a consistent summary — so you're not the one chasing status updates.
Sample data — the format your completed summary follows.
| Finding | Severity | Status |
|---|---|---|
| DMARC policy set to monitoring only | Medium | MSP action pending |
| TLS certificate expires in 14 days | Medium | Renewal scheduled |
| Detectable client-side library with a known vulnerability | Low | MSP action pending |
| Missing HSTS header | Low | Accepted for review |
Remediation status
0 of 4 items resolved; remediation is underway with the client's MSP
Rescan status
Scheduled once remaining items are addressed
Single Renewal Pilot — one client, one external security assessment, remediation follow-up with their MSP, one rescan, and one co-branded External Security Remediation Summary. No ongoing commitment.
Scoped to: one domain, one external assessment, one remediation coordination round with the client's MSP, and one rescan, delivered within 21 days. Remediation implementation itself isn't included — that stays with the client's MSP.
If it's useful: continue with four additional clients for $350 after reviewing the first summary.
| Client | Renewal | Status | Priority findings | Action |
|---|---|---|---|---|
| Acme Ltd | Aug 24 | Action required | 3 | Review |
| Nova Inc | Sep 12 | Remediation underway | 1 | Rescan |
| Delta Co | Sep 30 | Assessment complete | 0 | Export |
Future service and platform pricing will be determined after the pilot.
No. It identifies publicly visible security issues that may surface during underwriting or an insurer's external assessment. It does not complete the client's internal-control application questions, and underwriting decisions and pricing remain entirely the insurer's.
Not in this pilot. It's scoped to externally visible risks only — the internal-controls side of a renewal application stays with the client and their IT provider.
Security-rating platforms provide external posture data and monitoring. This pilot is a hands-on, renewal-specific service: we review one client's findings, translate them into MSP actions, manage follow-up, confirm completed fixes through a rescan, and return a co-branded broker summary.
This pilot is scoped to brokers. If an MSP handles remediation for one of your clients, reply and we'll manage the follow-up with them directly.
Tell us about your firm and we'll follow up to schedule the pilot.