For Underwriters · Risk Intelligence

Your premiums are priced against incomplete data.

The CVE database covers less than 1% of actual security fixes in the protocols you insure. The other 99% are silent. When they get exploited, your book takes the loss.

Underwriting Risk Signal
Data Gap>99% Silent Patches
Ecosystems9+ Monitored
Disclosure Rate0.44% Observed
OutputAPI + Portfolio Reports
PricingPublished Below
MetricBasis Points of Coverage

You are pricing risk using a dataset that is missing 99.56% of the actual vulnerability surface.

Every DeFi underwriting model we have seen prices protocol risk against public CVE data, disclosed audits, and bug bounty records. These sources share one structural flaw: they only capture what maintainers chose to disclose. According to Chainguard’s 2024 analysis, more than 50% of open-source security fixes are never publicly disclosed. Our own pipeline, analyzing 4,121 patches across 9 ecosystems, found a disclosure rate of just 0.44%.

That means for every vulnerability that appears in the data your underwriting model uses, there are approximately 227 that do not. Those 227 silent patches represent real, exploitable weaknesses in the protocols you are covering. They are not hypothetical risk. They are the risk your book is actually carrying, priced as if they do not exist.

The result is systematic underpricing. Not because your models are wrong, but because the input data is structurally incomplete. No public source can fix this. The only solution is independent monitoring of upstream commit behavior — finding fixes that maintainers never announced.

The patch existed months before the exploit. The insurer had no idea.

██████████‘s exchange rate manipulation vulnerability was fixed upstream and never disclosed. Four forks of the same codebase were exploited over thirteen months. Total losses across the fork chain: $31.6 million. At least three of those claims were insurable events that occurred after the upstream fix was available — fix that the downstream protocols never received because no disclosure was ever made.

From an underwriting standpoint, this is the key fact: the patch that would have prevented the claim was merged to the upstream repository months before the exploit. The protocol’s maintainers didn’t pull it because they didn’t know it existed. The underwriter had no way to know it existed either. The claim was paid against a risk that had a known fix sitting in a public commit history.

This is not an isolated case. Our pipeline has identified this pattern — known fix, no disclosure, downstream exposure, eventual exploit — across every category of DeFi infrastructure we monitor.

Claim Pattern: Lending Protocol Fork Chain
Root Protocol██████████
VulnerabilityExchange rate manipulation — silently patched upstream, never disclosed
Affected Forks████████ · ██████ · ████████████
Claim Window13 months across 4 separate exploit events
Total Losses$31.6 million across downstream deployments
Fix Status at ClaimUpstream patch existed — downstream protocols unaware
Preventable Claims3 of 4 with upstream patch intelligence
Claim Pattern: Consensus Engine — Fork Detection Bypass
Engine████████
VulnerabilityLight client verification bypass — CVSS 9.3 — enabling undetected chain forks
Downstream Exposure12+ chains running forked versions, none notified of upstream fix
Fix StatusPatched without disclosure. Third-party researcher notified downstream chains independently.
Underwriting ImpactAny policy covering these chains carried unmodeled CVSS 9.3 exposure for the full window
Claim Pattern: Authentication Platform — Session Bypass
Platform██████████████
VulnerabilityAuthentication bypass affecting session validation — 13 related findings in a single cycle
Downstream ExposureApplications using platform for user auth running vulnerable versions, no notification issued
Underwriting ImpactPolicies covering dependent applications priced without knowledge of 13 active authentication vulnerabilities
1
Risk Intelligence Feed
TypeContinuous
DeliveryAPI + Dashboard
Price8 bps of coverage
A protocol you cover patches a critical vulnerability at 2 AM on a Saturday. No CVE. No disclosure. No advisory. You find out when the claim comes in six months later.

The Risk Intelligence Feed is continuous monitoring of every protocol in your coverage book. When our pipeline detects a silent security patch — a fix merged without public disclosure — you receive an alert within 48 hours. Not 48 hours after an advisory is published. 48 hours after the fix is merged, before any disclosure exists.

Each alert includes the affected protocol, the commit containing the fix, the vulnerability class, a severity rating, and whether the fix has been pulled into the downstream deployment you are covering. Your actuarial team can integrate alerts directly into your risk model via API, or review them through a web dashboard.

The feed also tracks concealment patterns over time. A protocol whose upstream dependencies have silently patched 14 critical vulnerabilities in the past year — with zero CVEs — is a fundamentally different risk profile than one with consistent public disclosure. That pattern history is priced into every alert we deliver.

What You Receive

Continuous silent patch detection across your full coverage book. 48-hour detection-to-alert SLA. Severity ratings per finding (CVSS-aligned). Protocol-level exposure mapping. Concealment pattern histories per upstream project. API integration for actuarial model ingestion. Dashboard with portfolio filtering and export.

2
Portfolio Assessment
TypeOne-Time
DeliveryStructured Report
Price3 bps of coverage
You want to know what your book looks like right now — not what the public record says, but what the actual upstream patch history reveals about the protocols you are currently covering.

The Portfolio Assessment is a one-time audit of every protocol in your current coverage book against our silent patch database. We identify every security fix that was merged without public disclosure in every upstream dependency of every protocol you cover, and map the resulting exposure back to your specific policy positions.

The output tells you which policies are covering protocols with unpatched silent vulnerabilities, which upstream dependencies carry the highest concealment risk, and where your current premiums are most likely underpriced relative to the actual vulnerability surface.

The report is structured for actuarial consumption: per-protocol risk rankings, severity distributions, concealment pattern scores, and a comparison of public posture versus actual patch status for each covered protocol. Includes premium repricing recommendations calibrated to the gap between disclosed and actual vulnerability counts.

What You Receive

Full portfolio exposure analysis against our silent patch database. Per-protocol risk report with severity breakdown. Public posture versus actual patch status comparison. Upstream dependency mapping per covered protocol. Concealment pattern scores. Premium repricing recommendations. Structured data appendix for model ingestion.

3
Underwriting Intelligence
TypeContinuous + Advisory
DeliveryAPI + Briefings
Price12 bps of coverage
A new protocol applies for coverage. Before you bind, you want to know not just what the audit says — but what the upstream commit history says about every library that protocol depends on.

Underwriting Intelligence is the full service. It includes everything in the Risk Intelligence Feed, plus pre-binding coverage assessments for new applications, real-time exposure change alerts when a covered protocol’s risk profile shifts, quarterly underwriting briefings, and dedicated analyst support.

Pre-binding assessments run a full silent patch analysis on any protocol before you write the policy. You see the actual upstream vulnerability surface — not the public record — before you set the premium. Applications that look clean on paper frequently carry significant unpatched exposure in upstream dependencies that public audits never reviewed.

When a silent patch is detected in a covered protocol after binding, you receive an immediate exposure change alert: what changed, how it affects the risk profile, and whether it triggers a mid-term review right under your policy terms. Your team does not find out at claim time.

What You Receive

Everything in the Risk Intelligence Feed, plus: pre-binding silent patch assessments for new applications. Real-time exposure change alerts for covered protocols. Quarterly underwriting briefings with portfolio-level trend analysis. Dedicated analyst for your coverage book. Custom SLAs and reporting cadence. Mid-term review triggers on material risk changes.

Pricing · Published · Per Audience

Get out your calculator.

Every rate is published. Type your coverage volume. The math is instant.

Coverage Volume
$
Monthly + annual shown below
Continuous

Risk Intelligence Feed

8basis points
0.08%
of coverage volume · recurring
Monthly

Annual (locked)
  • Continuous silent patch detection
  • Protocol-level exposure mapping
  • CVSS-aligned severity ratings
  • Concealment pattern histories
  • API for actuarial model integration
  • 48-hour detection SLA
One-Time

Portfolio Assessment

3basis points
0.03%
of coverage volume · one-time
Your Cost
  • Full portfolio exposure analysis
  • Per-protocol risk report
  • Public posture vs. actual patch status
  • Upstream dependency mapping
  • Premium repricing recommendations
  • Structured data appendix
Full Service

Underwriting Intelligence

12basis points
0.12%
of coverage volume · recurring
Monthly

Annual (locked)
  • Everything in Risk Intelligence Feed
  • Pre-binding coverage assessments
  • Real-time exposure change alerts
  • Quarterly underwriting briefings
  • Mid-term review triggers
  • Dedicated analyst
Monthly — recalculates each billing cycle based on current coverage book.
Annual — coverage volume locked at signing. Book growth mid-contract doesn’t change your rate until renewal.
Minimum engagement: $50,000
Regulatory bodies and law enforcement receive complimentary access to this dataset.
Your TVL
$
Monthly + annual shown below
One-Time

Dependency Scan

1basis point
0.01%
of TVL · one-time
Your Cost
  • Full upstream dependency map
  • Silent patch exposure report
  • Severity breakdown per finding
  • Downstream fork impact analysis
Continuous

Upstream Watch

3basis points
0.03%
of TVL · recurring
Monthly

Annual (locked)
  • Everything in Dependency Scan
  • Continuous silent patch feed
  • 48-hour detection SLA
  • API integration for CI/CD
  • Concealment pattern histories
Full Service

Full Advisory

5basis points
0.05%
of TVL · recurring
Monthly

Annual (locked)
  • Everything in Upstream Watch
  • Dedicated analyst
  • Remediation guidance
  • Quarterly security reviews
  • Investor-ready reporting
Monthly — recalculates each billing cycle based on current TVL.
Annual — TVL locked at signing.
Minimum engagement: $25,000
Regulatory bodies and law enforcement receive complimentary access to this dataset.
Annual Billings
$
Monthly + annual shown below
Dataset

Silent Patch Access

50basis points
0.50%
of annual billings · recurring
Monthly

Annual (locked)
  • Full silent patch database
  • Search by project, ecosystem, CWE
  • Supplement audit findings
  • Historical concealment data
Per-Engagement

Audit Overlay

75basis points
0.75%
of engagement value · per engagement
Per Engagement
  • Targeted scan for audit target
  • Upstream dependency exposure
  • Client-ready findings appendix
  • Silent patch delta report
Full Integration

Integrated Feed

100basis points
1.00%
of annual billings · recurring
Monthly

Annual (locked)
  • Everything in Dataset Access
  • API for workflow integration
  • White-label capability
  • Dedicated analyst
  • Priority SLA
Annual — billings locked at signing.
Minimum engagement: $30,000
Regulatory bodies and law enforcement receive complimentary access to this dataset.
Last Round Raised
$
Monthly + annual shown below
One-Time

Pre-Launch Scan

2basis points
0.02%
of last round · one-time
Your Cost
  • Dependency exposure report
  • Silent patches in your stack
  • Risk profile before launch
  • Board-ready summary
Continuous

Continuous Monitor

4basis points
0.04%
of last round · recurring
Monthly

Annual (locked)
  • Everything in Pre-Launch Scan
  • Ongoing silent patch alerts
  • 48-hour detection SLA
  • API access
Full Service

Full Advisory

6basis points
0.06%
of last round · recurring
Monthly

Annual (locked)
  • Everything in Continuous Monitor
  • Quarterly security reviews
  • Investor-ready risk reports
  • Insurance-readiness assessment
Annual — round size locked at signing.
Minimum engagement: $15,000
Regulatory bodies and law enforcement receive complimentary access to this dataset.
Crypto AUM
$
Monthly + annual shown below
One-Time

Portfolio Screen

2basis points
0.02%
of crypto AUM · one-time
Your Cost
  • Exposure scan across holdings
  • Per-protocol risk breakdown
  • Silent patch count per position
  • LP-ready summary
Continuous

Due Diligence Feed

4basis points
0.04%
of crypto AUM · recurring
Monthly

Annual (locked)
  • Everything in Portfolio Screen
  • Continuous monitoring of holdings
  • Pre-investment protocol scans
  • Real-time exposure alerts
Full Service

Full Intelligence

6basis points
0.06%
of crypto AUM · recurring
Monthly

Annual (locked)
  • Everything in Due Diligence Feed
  • Quarterly portfolio briefings
  • IC-ready risk reports
  • Dedicated analyst
Annual — AUM locked at signing.
Minimum engagement: $25,000
Regulatory bodies and law enforcement receive complimentary access to this dataset.

Public interest. No charge.

Supervisory bodies receive complimentary access to the full silent patch dataset.
Securities regulators, financial supervisory authorities, and government cybersecurity agencies can access the complete risk intelligence feed at no cost. The data exists to make markets transparent. Charging the entities responsible for transparency would defeat the purpose.

Investigative support. No charge.

Law enforcement agencies receive complimentary access for active investigations.
Silent patches are evidence. When a maintainer fixes a critical vulnerability without disclosure and downstream protocols lose funds, the patch history documents the timeline of knowledge. We provide that evidence to law enforcement at no cost.
  • Concealment timelines with commit-level precision
  • Evidence of knowledge prior to exploit events
  • Downstream exposure mapping for affected parties
  • Expert consultation on technical findings
  • Chain-of-custody-ready documentation
Fraud, negligence, breach notification failures, securities violations — when concealment causes losses, the patch record is the evidence. We make sure investigators have it.
Scope

What you get. What we don’t do.

What You Get

  • Silent patch detections across your full coverage book
  • Pre-binding assessments for new coverage applications
  • Concealment pattern scoring per upstream project
  • Mid-term exposure change alerts for covered protocols
  • Premium repricing recommendations calibrated to actual risk
  • 48-hour detection-to-delivery SLA

What We Don’t Do

  • Perform penetration testing or active exploitation
  • Provide legal advice or regulatory representation
  • Replace audit requirements as a condition of coverage
  • Disclose raw vulnerability details to non-subscribers
  • Guarantee specific loss ratios or pricing outcomes
  • Accept protocol payment to suppress risk findings
Disclosure gap: Chainguard, “The Hidden Cost of Silent Patches” (2024). Finding: >50% of open-source security fixes lack public disclosure. Crypto losses: Chainalysis, 2024 Crypto Hacking Report. $2.2B in total crypto losses for 2024. Audited contract exploits: Olympix, “The State of Web3 Security in 2025”. 70% of major exploits targeted previously audited contracts. DeFi insurance market: Research and Markets, Decentralized Insurance Market Report. $3.5B (2025) to $16.94B (2029), 48.4% CAGR. Lending protocol exploit chain: Public incident reports via rekt.news. 4 exploits, 13 months, $31.6M aggregate losses across forked codebases. Internal data: Whitenbaker Labs silent patch detection pipeline. 4,121 patches analyzed, 0.44% disclosure rate across 9 ecosystems.
Get Started

Price risk with complete data.

Start with a Portfolio Assessment to see the gap between your current risk model and the actual upstream vulnerability surface. Or move straight to continuous monitoring. Either way, you stop pricing against a dataset that is missing 99.56% of actual security fixes.

Initial consultation free · All prices published · No sales theater