welcome to singulari
Underwriting Intelligence for Cyber Insurance
Singulari delivers unmatched intake precision at binding, then maintains live risk visibility across the entire policy lifecycle, enhanced by AI.

Direct System Reads
Extracts configuration data directly from active environments.
Data Origin Integrity
Clearly labels every data point by source to prevent data flattening.
Contextual Risk Engine
Links missing security controls to impacted policy terms.
Post-Bind Visibility
Monitors control drift during the policy term.
Intelligent Submission Intake
Singulari synthesizes risk data across verified system reads, applicant statements, and perimeter scans without conflating sources. Underwriters receive a structured risk profile with deterministic reasoning attached, linking every identified control gap directly to policy exposure.
Evidence-backed underwriting at inception
Lifecycle Risk Monitoring
Traditional cyber policies price risk based on a static, single-point-in-time snapshot that decays immediately after binding. Singulari maintains active connections through the policy term, tracking control drift and flagging security degradation while coverage is still active, no after a claim occurs.
Active control verification throughout the term
verified risk profile
Three distinct sourcing layers. One verified profile.
No single source covers a full cyber risk. Singulari draws on three, and preserves the distinction between them all the way to the desk.
01
Verified Data - Read from the system
Observed directly through read-only integrations (Microsoft 365, Google Workspace, Vanta, Drata). System configurations are verified rather than described, eliminating optimistic responses and interpretation bias at the source.
system Telemetry
02
Attested Data - By the client
Governance, tabletop exercises, offline backups, and wire transfer protocols that cannot be verified via API remain with the applicant. These inputs are clearly flagged as self-reported statements rather than proven configurations.
Self-reported data
03
Observed Data - External Perimeter Scan
Non-intrusive perimeter telemetry covering open services, DNS hygiene, and exposed end-of-life assets. Findings are treated strictly as external indicators. The absence of a scan finding is not misrepresented as an active internal control.
EXTERNALLY OBSERVED
Coverage lines
Written for the lines that share a control set
Cyber, Tech E&O, and AI Liability draw on overlapping technical controls. Singulari evaluates them from a single unified risk profile rather than three siloed applications.
Cyber
Evaluates core security controls and maps gaps directly to impacted policy terms, such as ransomware coinsurance, funds transfer sublimits, and waiting periods.
Technology E&O
Assesses software development lifecycles, change management, and release controls alongside baseline security posture to deliver a combined Cyber and Tech E&O submission.
AI Liability
Evaluates emerging AI governance controls—including human-in-the-loop verification, vendor chain usage, and kill-switch protocols—aligned with evolving carrier standards.
9
Unified control categories evaluated across all three lines
smart submissions
Enriched data for smart underwriting
Each step adds what underwriting actually needs: the answer, the proof, the implication.
An assessment that branches the way an underwriter asks
Not a PDF turned into form fields. Each answer determines the next question.
Branching on the answer
A "no" opens the compensating-control question instead of a dead end.
Written for the insured
An office manager can answer it without hiring a consultant.
Split across the right people
IT answers endpoint controls; finance answers funds transfer.
Save and resume
Partial progress persists. Nobody restarts because a session dropped.
Controls read from the insured's own systems
Where a control can be proven, we prove it. Where it can't, we say so.
Read-only connectors
Microsoft 365, Vanta, Drata. Least privilege, scoped to what's asked.
No write path
Proven by test, documented for your security review.
External scan
Perimeter signal gathered without asking the insured for anything.
Method on every control
Verified or attested, labeled. Never blended into one score.
Every control gap, mapped to the coverage it affects
The step nobody else takes. A gap isn't a finding — it's a term implication.
Authored, not inferred
This is some text inside of a div block.
Gap - exposure - term
MFA missing on remote access reaches ransomware and funds transfer fraud, and lands on coinsurance and sublimit.
Your appetite governs
We ship the standard mapping. You configure thresholds and terms.
Explainable end to end
Every output traces back to the rule that produced it and the evidence beneath it.
A submission that arrives ready to price
One risk object, delivered in the shape your team already works in.
Evidence attached
The proof travels with the answer, not in a separate email thread.
Gaps flagged with their impact
Not a list of findings. A list of coverage consequences.
In your format
Singulari doesn't hold the policy. It prepares the risk and hands it over.
Your underwriter decides
Decision-support, never a decision. Full audit trail behind every field.
Continuous monitoring
Underwriting beyond the bind date
Persistent Connectivity
Read-only integrations established at intake remain active post-binding. Those systems producing submission evidence continue streaming telemetry without requiring additional administrative effort.
Real-Time Posture Visibility
Quiet control decay, such as narrowed MFA scope or unmonitored admin accounts, is flagged mid-term, highlighting drift between bound pricing conditions and active posture before claims or losses occur.
Continuous Risk Alignment
Mid-term control lapses trigger the same deterministic rules engine used at intake. Posture changes are reported alongside impacted policy terms and endorsements rather than raw security alerts.
Evidence-Based Renewals
Renewal cycles open with twelve months of observed control history instead of blank questionnaires. Discrepancies, remediation steps, and posture changes are pre-recorded, grounding renewal conversations in verifiable data.
Portfolio-Wide Analytics
Track security movements across your entire bound book simultaneously. Easily identify systemic control failures, monitor portfolio risk trends, and verify whether flagged vulnerabilities were remediated across accounts.
FAQ
Questions & answers
The questions carriers and MGAs raise before a first conversation, including the ones about what Singulari deliberately does not do.
What is Singulari?
A decision-support layer that sits ahead of the underwriting decision. It assembles a commercial cyber risk from verified evidence, applicant attestation, and external scan, then carries each control gap through to the coverage term it affects. The submission arrives structured, with the reasoning attached.
Is Singulari an MGA or a broker?
Neither. Singulari carries no paper, holds no delegated authority, and takes no risk. No business is produced, quoted, bound, or placed. Singulari sits outside the signature chain entirely, the decision and the authority stay with the carrier.
How is this different from a security rating?
A security rating returns a number. It doesn't say which coverage term the underlying gap affects. Singulari maps each gap to its exposure and the term that responds. Sublimit, coinsurance, subjectivity, through mapping authored by a cyber underwriter against the applications carriers use today.
Does it replace the policy administration system?
No. Singulari prepares the risk and delivers it in the format a carrier already works in. Nothing in the existing stack is replaced or integrated as a condition of use.
Where does the evidence come from?
Three sources, labeled separately throughout: controls read directly from systems an applicant operates through read-only connections; controls no system exposes, which remain attested by the applicant; and an external scan of the perimeter gathered without credentials.
What happens when sources disagree?
Both are shown. A conflict between an attestation and an observation is surfaced rather than resolved automatically, because which version holds is an underwriting judgment rather than a data-cleaning one. The discrepancy is retained through to the submission.
How does Singulari use AI?
Singulari uses AI where language is the bottleneck: reading carrier forms, interpreting applicant answers, and writing the risk up for the desk. The mapping from control gap to coverage term is authored and deterministic by design. So identical inputs produce identical outputs, every line traces to its rule, and the carrier can defend the decision to a regulator.
Can the mapping be configured to a carrier's own appetite?
Yes. Singulari ships a standard mapping. Thresholds, what constitutes a gap, and which terms respond are set to the carrier's own standards during configuration.
Are the connections read-only?
Yes, by construction. Connectors request the narrowest scope that answers the question asked, and there is no write path back into a connected system. This is an architectural property, proven by test and documented for security review.
Who can see an applicant's data?
Access is scoped to the parties in the transaction. Tenant isolation is enforced at the database layer, sensitive fields are encrypted, and every access is recorded in an audit log.
Is data used to train models or benchmark other carriers?
No. A carrier's appetite, rules, and decisions are theirs alone and are never used to inform another carrier. Any future aggregated benchmarking would be explicitly opt-in, anonymized, and revocable, and is off by default.
Which subprocessors are involved?
The infrastructure and service providers behind the platform are documented and available for security review, including the AI provider used for document reading and narrative drafting. Inputs to it are structured and minimized.