Cyber insurance underwriting
Add outside-in security data to cyber underwriting
Use the same observable fields for every applicant and insured.
The question
What is publicly exposed before binding, and what changes later?
FullHunt returns external security observations, not a risk score. Your platform decides how host, service, vulnerability, and historical data affect its models and review rules.
How it works
01
Identify the company
Submit a company or domain from the application or insured portfolio.
02
Fetch the public footprint
Retrieve the domains, hosts, services, technologies, and certificates FullHunt observed.
03
Pass the fields to underwriting
Send the relevant vulnerability, exploit, credential, and infrastructure records into your own model.
04
Check again after binding
Run the same query later to see how the insured's public exposure changed.
The records behind the answer
Public assets
Domains, hosts, services, and technologies associated with an applicant or insured.
Vulnerabilities
CVE records with Exploit Prediction Scoring System (EPSS), CISA Known Exploited Vulnerabilities (KEV), and public exploits.
Infrastructure history
Passive DNS and prior observations beyond the current snapshot.
Credential and domain findings
Credential exposure, suspected phishing, and typosquatting records where available.
Use FullHunt data inside your own underwriting model.
Your team sets the risk appetite, review rules, and applicant communication.
What you get
- Company and domain enrichment in structured JSON
- Consistent external exposure fields across the portfolio
- API delivery into quoting and monitoring software
- Historical records for comparison after binding
Test FullHunt data in your underwriting flow.
Tell us which API fields you need and how many requests your platform expects.