Your premiums are priced against incomplete data.
The CVE database covers less than 1% of actual security fixes in the protocols you insure. The other 99% are silent. When they get exploited, your book takes the loss.
You are pricing risk using a dataset that is missing 99.56% of the actual vulnerability surface.
Every DeFi underwriting model we have seen prices protocol risk against public CVE data, disclosed audits, and bug bounty records. These sources share one structural flaw: they only capture what maintainers chose to disclose. According to Chainguard’s 2024 analysis, more than 50% of open-source security fixes are never publicly disclosed. Our own pipeline, analyzing 4,121 patches across 9 ecosystems, found a disclosure rate of just 0.44%.
That means for every vulnerability that appears in the data your underwriting model uses, there are approximately 227 that do not. Those 227 silent patches represent real, exploitable weaknesses in the protocols you are covering. They are not hypothetical risk. They are the risk your book is actually carrying, priced as if they do not exist.
The result is systematic underpricing. Not because your models are wrong, but because the input data is structurally incomplete. No public source can fix this. The only solution is independent monitoring of upstream commit behavior — finding fixes that maintainers never announced.
The patch existed months before the exploit. The insurer had no idea.
██████████‘s exchange rate manipulation vulnerability was fixed upstream and never disclosed. Four forks of the same codebase were exploited over thirteen months. Total losses across the fork chain: $31.6 million. At least three of those claims were insurable events that occurred after the upstream fix was available — fix that the downstream protocols never received because no disclosure was ever made.
From an underwriting standpoint, this is the key fact: the patch that would have prevented the claim was merged to the upstream repository months before the exploit. The protocol’s maintainers didn’t pull it because they didn’t know it existed. The underwriter had no way to know it existed either. The claim was paid against a risk that had a known fix sitting in a public commit history.
This is not an isolated case. Our pipeline has identified this pattern — known fix, no disclosure, downstream exposure, eventual exploit — across every category of DeFi infrastructure we monitor.
The Risk Intelligence Feed is continuous monitoring of every protocol in your coverage book. When our pipeline detects a silent security patch — a fix merged without public disclosure — you receive an alert within 48 hours. Not 48 hours after an advisory is published. 48 hours after the fix is merged, before any disclosure exists.
Each alert includes the affected protocol, the commit containing the fix, the vulnerability class, a severity rating, and whether the fix has been pulled into the downstream deployment you are covering. Your actuarial team can integrate alerts directly into your risk model via API, or review them through a web dashboard.
The feed also tracks concealment patterns over time. A protocol whose upstream dependencies have silently patched 14 critical vulnerabilities in the past year — with zero CVEs — is a fundamentally different risk profile than one with consistent public disclosure. That pattern history is priced into every alert we deliver.
What You Receive
Continuous silent patch detection across your full coverage book. 48-hour detection-to-alert SLA. Severity ratings per finding (CVSS-aligned). Protocol-level exposure mapping. Concealment pattern histories per upstream project. API integration for actuarial model ingestion. Dashboard with portfolio filtering and export.
The Portfolio Assessment is a one-time audit of every protocol in your current coverage book against our silent patch database. We identify every security fix that was merged without public disclosure in every upstream dependency of every protocol you cover, and map the resulting exposure back to your specific policy positions.
The output tells you which policies are covering protocols with unpatched silent vulnerabilities, which upstream dependencies carry the highest concealment risk, and where your current premiums are most likely underpriced relative to the actual vulnerability surface.
The report is structured for actuarial consumption: per-protocol risk rankings, severity distributions, concealment pattern scores, and a comparison of public posture versus actual patch status for each covered protocol. Includes premium repricing recommendations calibrated to the gap between disclosed and actual vulnerability counts.
What You Receive
Full portfolio exposure analysis against our silent patch database. Per-protocol risk report with severity breakdown. Public posture versus actual patch status comparison. Upstream dependency mapping per covered protocol. Concealment pattern scores. Premium repricing recommendations. Structured data appendix for model ingestion.
Underwriting Intelligence is the full service. It includes everything in the Risk Intelligence Feed, plus pre-binding coverage assessments for new applications, real-time exposure change alerts when a covered protocol’s risk profile shifts, quarterly underwriting briefings, and dedicated analyst support.
Pre-binding assessments run a full silent patch analysis on any protocol before you write the policy. You see the actual upstream vulnerability surface — not the public record — before you set the premium. Applications that look clean on paper frequently carry significant unpatched exposure in upstream dependencies that public audits never reviewed.
When a silent patch is detected in a covered protocol after binding, you receive an immediate exposure change alert: what changed, how it affects the risk profile, and whether it triggers a mid-term review right under your policy terms. Your team does not find out at claim time.
What You Receive
Everything in the Risk Intelligence Feed, plus: pre-binding silent patch assessments for new applications. Real-time exposure change alerts for covered protocols. Quarterly underwriting briefings with portfolio-level trend analysis. Dedicated analyst for your coverage book. Custom SLAs and reporting cadence. Mid-term review triggers on material risk changes.
One prevented claim pays for the service for over a decade.
At 8 basis points on $300M in coverage volume, the Risk Intelligence Feed costs $240,000 per year. The average exploit loss in the lending protocol fork chain documented above was $7.9 million per incident. A single prevented claim represents 33x the annual cost of the feed. Three of four documented incidents in that chain were preventable with upstream patch intelligence.
The more important number is what systematic underpricing costs across a book. If your premiums are calibrated against public CVE data and the actual vulnerability rate is 227x higher, the expected loss embedded in your book is orders of magnitude larger than your model suggests. That is not a pricing variance. It is a structural model failure — one that compounds with every new policy written against incomplete data.
The Risk Intelligence Feed does not just prevent individual claims. It corrects the input data your pricing model depends on. Protocols with high concealment scores get repriced. Protocols with clean upstream disclosure histories get priced more competitively. The book becomes more accurately differentiated, which is the only durable source of underwriting advantage.
Audits are point-in-time. Silent patches happen after the audit closes.
70% of 2024 crypto exploits hit audited contracts. This is not because audits are poorly executed. It is because an audit reviews a codebase at a specific moment. The moment the audit closes, upstream dependencies begin accumulating new silent patches that no audit ever reviewed and no CVE database will ever record.
An audit that passed six months ago tells you the code was clean six months ago. It says nothing about the 47 silent upstream patches that may have been merged to the protocol’s dependencies since then — each one representing a vulnerability that exists in the current deployment but appears nowhere in the public record.
Requiring an audit as a condition of coverage is necessary. It is not sufficient. The audit gives you a baseline. Our feed tells you what has changed since the baseline was set — the silent patch delta that accumulates between every audit cycle and every renewal date.
Our lab has documented this pattern across nine ecosystems with a combined 0.44% disclosure rate. For every vulnerability your current risk model can see, there are 227 it cannot.
Get out your calculator.
Every rate is published. Type your coverage volume. The math is instant.
Risk Intelligence Feed
- Continuous silent patch detection
- Protocol-level exposure mapping
- CVSS-aligned severity ratings
- Concealment pattern histories
- API for actuarial model integration
- 48-hour detection SLA
Portfolio Assessment
- Full portfolio exposure analysis
- Per-protocol risk report
- Public posture vs. actual patch status
- Upstream dependency mapping
- Premium repricing recommendations
- Structured data appendix
Underwriting Intelligence
- Everything in Risk Intelligence Feed
- Pre-binding coverage assessments
- Real-time exposure change alerts
- Quarterly underwriting briefings
- Mid-term review triggers
- Dedicated analyst
Annual — coverage volume locked at signing. Book growth mid-contract doesn’t change your rate until renewal.
Dependency Scan
- Full upstream dependency map
- Silent patch exposure report
- Severity breakdown per finding
- Downstream fork impact analysis
Upstream Watch
- Everything in Dependency Scan
- Continuous silent patch feed
- 48-hour detection SLA
- API integration for CI/CD
- Concealment pattern histories
Full Advisory
- Everything in Upstream Watch
- Dedicated analyst
- Remediation guidance
- Quarterly security reviews
- Investor-ready reporting
Annual — TVL locked at signing.
Silent Patch Access
- Full silent patch database
- Search by project, ecosystem, CWE
- Supplement audit findings
- Historical concealment data
Audit Overlay
- Targeted scan for audit target
- Upstream dependency exposure
- Client-ready findings appendix
- Silent patch delta report
Integrated Feed
- Everything in Dataset Access
- API for workflow integration
- White-label capability
- Dedicated analyst
- Priority SLA
Pre-Launch Scan
- Dependency exposure report
- Silent patches in your stack
- Risk profile before launch
- Board-ready summary
Continuous Monitor
- Everything in Pre-Launch Scan
- Ongoing silent patch alerts
- 48-hour detection SLA
- API access
Full Advisory
- Everything in Continuous Monitor
- Quarterly security reviews
- Investor-ready risk reports
- Insurance-readiness assessment
Portfolio Screen
- Exposure scan across holdings
- Per-protocol risk breakdown
- Silent patch count per position
- LP-ready summary
Due Diligence Feed
- Everything in Portfolio Screen
- Continuous monitoring of holdings
- Pre-investment protocol scans
- Real-time exposure alerts
Full Intelligence
- Everything in Due Diligence Feed
- Quarterly portfolio briefings
- IC-ready risk reports
- Dedicated analyst
Public interest. No charge.
Investigative support. No charge.
- Concealment timelines with commit-level precision
- Evidence of knowledge prior to exploit events
- Downstream exposure mapping for affected parties
- Expert consultation on technical findings
- Chain-of-custody-ready documentation
What you get. What we don’t do.
What You Get
- Silent patch detections across your full coverage book
- Pre-binding assessments for new coverage applications
- Concealment pattern scoring per upstream project
- Mid-term exposure change alerts for covered protocols
- Premium repricing recommendations calibrated to actual risk
- 48-hour detection-to-delivery SLA
What We Don’t Do
- Perform penetration testing or active exploitation
- Provide legal advice or regulatory representation
- Replace audit requirements as a condition of coverage
- Disclose raw vulnerability details to non-subscribers
- Guarantee specific loss ratios or pricing outcomes
- Accept protocol payment to suppress risk findings
Price risk with complete data.
Start with a Portfolio Assessment to see the gap between your current risk model and the actual upstream vulnerability surface. Or move straight to continuous monitoring. Either way, you stop pricing against a dataset that is missing 99.56% of actual security fixes.
Initial consultation free · All prices published · No sales theater
