Skip to content
FullHunt

Cyber insurance underwriting

Add outside-in security data to cyber underwriting

Use the same observable fields for every applicant and insured.

Applicant lookup Portfolio monitoring Exposure history OEM APIs

The question

What is publicly exposed before binding, and what changes later?

FullHunt returns external security observations, not a risk score. Your platform decides how host, service, vulnerability, and historical data affect its models and review rules.

How it works

01

Identify the company

Submit a company or domain from the application or insured portfolio.

02

Fetch the public footprint

Retrieve the domains, hosts, services, technologies, and certificates FullHunt observed.

03

Pass the fields to underwriting

Send the relevant vulnerability, exploit, credential, and infrastructure records into your own model.

04

Check again after binding

Run the same query later to see how the insured's public exposure changed.

The records behind the answer

Public assets

Domains, hosts, services, and technologies associated with an applicant or insured.

Vulnerabilities

CVE records with Exploit Prediction Scoring System (EPSS), CISA Known Exploited Vulnerabilities (KEV), and public exploits.

Infrastructure history

Passive DNS and prior observations beyond the current snapshot.

Credential and domain findings

Credential exposure, suspected phishing, and typosquatting records where available.

Use FullHunt data inside your own underwriting model.

Your team sets the risk appetite, review rules, and applicant communication.

What you get

  • Company and domain enrichment in structured JSON
  • Consistent external exposure fields across the portfolio
  • API delivery into quoting and monitoring software
  • Historical records for comparison after binding

Test FullHunt data in your underwriting flow.

Tell us which API fields you need and how many requests your platform expects.