The claim is verifiable.The evidence stays yours.
A cyber incident can be proven and its loss quantified without the underlying records ever leaving the policyholder's environment.
Insurance runs on trust.
Lenders check the history. Motor insurers check the driving.Cyber insurance still checks the form.
Both sides pay for that gap.
74%
of US cyber insurance claims closed in 2024 ended without a payment.
8 of 9
underwriters interviewed price the risk from the applicant's own form.
CA$18.3M
in recovery costs for one city whose claim was denied over MFA it had not fully deployed.
Who pays for the gap
Insurer pays
- To verify, not to protect: a forensic investigation decides whether it is liable at all.
- For what it cannot see: an incident is easy to stage, and the evidence cannot show who made it.
- In court: one insurer funded a $4.125M settlement, then sued to take it back.
Policyholder pays
- Up front: the investigation that proves the claim can be required, and paid for, before the claim is filed.
- At the worst moment: a control ticked on the form and found missing after the loss can void the policy from the start.
- With its privacy: the logs, tickets and forensic reports it was insured to protect.
Why the usual fixes fall short
Records that a control was bought, not that it works.
Sees the perimeter, not the controls inside it.
Moves the question to the claim instead of checking it.
Answers after the loss, once it is a dispute.
Needs the very records the company insured.
Problem
- One side describes what happened; the other decides whether to believe it.
- The insurer prices in the fraud it cannot detect.
- The policyholder proves its case by handing over the very data it was insured to protect.
Approach
- An incident can be proven.
- A loss can be quantified.
- Neither requires the evidence to change hands.
How a claim is settled on evidence
The same move, without the data changing hands.Five steps. Each one can be inspected.
What the platform does
Real-time underwriting
Underwriting built into your stack. No data leaves your environment.
Security dashboard
Visual risk assessment drawn from the security systems you already run, updated as things change.
Incidents detection
Real-time incident signals from the security systems you already run.
pub fn verify_claim_proof( pvk: &PreparedVerifyingKey<Bls12_381>, proof: &Proof<Bls12_381>, public_inputs: &[Fr],) -> bool {Claims verification
Insurers receive a result backed by cryptographic proof rather than by an account of what happened.
Settlement handoff
The output is a verified claim with a quantified loss, handed to the insurer's existing settlement process.
Underwriting from what is already running
Watch Guardian connects to the policyholder's existing security systems and assesses exposure in place.
The security data stays inside the policyholder's perimeter. Only the underwriting result crosses it.
The incident is recorded where it happens
When an incident occurs, it is captured in real time from the signals the policyholder's security systems already produce.
Capture is local. Nothing is transmitted at this stage.
What it cost, from the same evidence
The signals that establish the incident are also used to quantify the loss it caused.
Assessment runs inside the perimeter, on data that never leaves it.
A proof instead of a submission
The policyholder generates a signed, verifiable proof that the incident occurred and what it cost.
The proof crosses. The evidence does not.
Checked, not believed
The insurer verifies the proof. Acceptance rests on a mathematical result rather than on a judgement about the policyholder's account.
The output is a verified claim with a quantified loss, handed to the insurer's existing settlement process. Protectorium's responsibility ends at verification.
The insurer learns that the claim is valid and what it is worth. Nothing else.
Discuss a pilot
Only the proof and the assessed amount leave your perimeter.
Pilot
One environment. A decision at the end.
Enterprise
Inside the process that already runs.
Pilot
For a team that wants to see it work before signing.
- One environment, one claim path, agreed in writing.
- Records stay inside. The proof and the amount leave.
- A decision against criteria set at the start.
Enterprise
For an insurer adding verified claims to a running process.
- Sits beside your policy and claims systems.
- Security, legal and procurement, on your schedule.
- Scoped to the deployment. No price list.
Why this is different
The alternative is not a worse tool. The alternative is trust.
- Underwriting reads the systems already running
- The incident is recorded where it happens
- Claims are verified automatically
- Evidence stays inside the perimeter
- The proof is checked without the records
- Underwriting reads a self-reported form
- Forensics reconstructs it after the fact
- The loss is argued cost by cost
- Checking controls opens the network to auditors
- The form is tested only after a loss
Contact
If you underwrite cyber risk, or you are insured against it, we would like to hear how claims work for you today.
Frequently asked questions
What is Protectorium?
Infrastructure for cyber insurance claims. It records an incident inside the policyholder's environment, quantifies the loss, and produces a proof the insurer can verify without receiving the underlying evidence.
What is a zero-knowledge proof, and why use one?
A zero-knowledge proof establishes that a statement is true without revealing the information the statement is about. In a claim, it lets a policyholder demonstrate that an incident occurred and what it cost while keeping the records that show it private.
How do you prevent fraud?
A claim is only accepted if it comes with a proof that verifies. There is no path that accepts a claim on description alone.
How is confidentiality maintained?
Security data is read and processed inside the policyholder's environment. What crosses the boundary is the proof and the assessed amount. The records themselves do not, so the insurer never has custody of them.
Is this an AI judgement?
No. Verification is a check, not an opinion. It either passes or it does not, and the result does not depend on who is reading it.
How long does verification take?
Verification is an automatic check rather than an investigation, so it does not wait on scheduling, correspondence, or a forensic report.