Independent insurance consulting for technology and IT services companies. We read your contracts, your policies and your exposure — then tell you exactly what to fix. We earn no commission and bind no coverage.
Built for the companies redefining infrastructure
Your risk profile changed.
Your insurance didn't.
Technology companies are underwritten with frameworks built for manufacturers and professional services firms. Meanwhile the market has hardened, carriers have rewritten their AI language, and your customers keep raising the limits they demand. The result is a program that looks complete on a certificate and fails when tested.
forecast cyber rate increase for 2026, after two years of softening.
of cyber insurers now require MFA on remote access and privileged accounts.
in Tech E&O and Cyber limits commonly demanded by enterprise customers.
Market conditions as reported across industry sources, 2026. Figures vary by sector, size and controls.
Three ways to start.
Each one is finite.
Fixed scope, fixed fee, written deliverable. No retainer, no open-ended discovery, no requirement to move your broker. Start with the one that matches the deadline in front of you.
Contract Readiness Review
You signed — or are about to sign — a customer contract with insurance requirements you are not sure you meet.
We read the insurance article of your MSA, DPA or vendor agreement and tell you exactly what is required, what you actually carry, and what has to change before the certificate is issued.
- Clause-by-clause read of the insurance and indemnity articles
- Required limits, additional insured, waiver of subrogation, primary and non-contributory
- Gap list against your policies in force, with what to fix first
- Certificate of insurance checklist your customer will accept
Cyber & Tech E&O Diagnostic
You have coverage in force, but nobody has tested it against how your business actually runs.
Most technology policies are bought once and renewed on autopilot. We read the wording against your architecture, your data flows and your contracts, and position you before the renewal.
- Exclusion, sublimit and definition review across cyber and Tech E&O
- Retroactive date and claims-made continuity check for prior work
- Control readiness against what underwriters now require: MFA, EDR, external scanning
- Renewal positioning ahead of the 2026 rate environment
AI Exposure Review
You shipped AI features, embedded a model, or use AI to deliver client work.
Carriers spent 2025 and 2026 replacing silent AI with explicit language. Some policies now exclude generative AI outright; others grant it back only if you can evidence governance. We find out which one you hold.
- Where AI exclusions and endorsements land across your current program
- Whether affirmative AI cover is available to you, and on what conditions
- Governance evidence underwriters ask for: NIST AI RMF, ISO/IEC 42001
- Downstream liability from model outputs, training data and third-party APIs
Need more than a single review?
Full program architecture covers every line at once — structure, limits, retentions, carrier strategy and wording negotiation — with standing review as you ship, raise and enter new markets. Scoped case by case.
Every line we structure,
and why it exists.
Some lines exist because a customer contract demands them. Others exist because the balance sheet cannot absorb the loss. Knowing which is which is how you avoid paying for cover nobody asked for.
Technology E&O
Failure to perform, defective code, missed SLAs.
Cyber Liability
Breach response, extortion, business interruption.
Commercial General Liability
Bodily injury and property damage. Named in nearly every MSA.
Media & IP Liability
Content, licensing, trademark and infringement claims.
Directors & Officers
Board decisions, investor disputes, governance exposure.
Employment Practices
Hiring, termination, discrimination and wage claims.
Fiduciary Liability
ERISA exposure once you run a 401(k) or benefits plan.
Crime & Fidelity
Funds transfer fraud, social engineering, internal loss.
Business Interruption
Downtime, cloud dependency and revenue protection.
Workers’ Compensation
Statutory in every state you employ. Often overlooked when remote.
Key Person
Concentration risk when the company depends on a few people.
Reps & Warranties
Deal cover for acquisition, merger or exit.
The rules moved.
Your program should have too.
Regulation is what converts a technical incident into a reportable event with a clock attached. These are the obligations we check against when we review a technology company's exposure.
SEC cyber disclosure
Public companies must file Item 1.05 of Form 8-K within four business days of determining an incident is material. Pre-IPO companies are expected to have the process built before they list.
Public and pre-IPO
NYDFS Part 500
The final provisions took effect 1 November 2025, with the first certifications due 15 April 2026. Recent amendments extend personal liability to CEOs and CISOs.
Anyone serving NY financial institutions
State privacy laws
Twenty comprehensive state privacy laws are in effect in 2026, and more have been enacted and are phasing in. Obligations vary by state, and so does the cost of getting it wrong.
Anyone handling consumer data
CIRCIA
CISA is expected to finalise the rule in 2026: 72 hours to report a covered incident, 24 hours to report a ransomware payment, across sixteen critical infrastructure sectors.
Critical infrastructure and their vendors
HIPAA · PCI DSS · FTC Safeguards
Sector rules that decide whether an incident is a contained event or a regulatory action. Each carries its own notification clock and its own penalty structure.
HealthTech, payments, financial services
AI governance frameworks
NIST AI RMF and ISO/IEC 42001 started as good practice. They are now conditions carriers attach to affirmative AI coverage.
Anyone shipping or using AI
Summarised for orientation as of 2026 and subject to change. Cortex.AI is not a law firm and this is not legal advice — we work alongside your counsel, not in place of them.
Risk changes with every sector.
The standard doesn't.
We work where downtime, data loss and contractual liability are existential — not inconvenient. Each sector gets its own design. The rigour behind it never changes.
Artificial Intelligence
Model outputs, training data and downstream liability now sit inside explicit AI endorsements — or outside coverage entirely.
SaaS
Uptime commitments and contractual indemnities create exposure the policy was never priced for.
Cloud & Infrastructure
One outage cascades to every tenant at once. Business interruption limits have to reflect that.
Cybersecurity
You are held to the standard you sell. Tech E&O has to match the promise in your own MSA.
FinTech
NYDFS, PCI DSS and real-time money movement in one environment. Funds transfer fraud is the live exposure.
HealthTech
HIPAA penalties, PHI volume and clinical decision exposure stack on top of ordinary Tech E&O.
Data Centers
Physical, contractual and continuity risk together — with CIRCIA reporting on the horizon.
MSPs & IT Services
You inherit every client’s risk. One compromised tool reaches all of them at once.
Telecom
Subscriber data and regulatory obligations under continuous pressure across jurisdictions.
Software & Dev Shops
Delivery risk across many clients and contracts, each with its own insurance article.
Six steps.
No black boxes.
Every recommendation traces back to a clause we read, a control we checked or a wording we negotiated. You keep the documentation whether or not the engagement continues.
Scope
A 30-minute call. We confirm which program fits and what deadline you are working against.
Intake
You send contracts, policies and a short questionnaire. No lengthy discovery process.
Analysis
We read the wording against your operation, contracts and regulatory obligations.
Findings
A written deliverable: what you have, what is missing, what to fix in what order.
Execution
We support placement with your broker, or introduce one. Wordings negotiated line by line.
Review
Optional standing review as you ship, raise, hire and enter new markets.
Whoever designs it,
answers for it.
We are engaged by the company, paid by the company, and accountable to the company. That single structural fact changes every recommendation that follows.
Independent by design
We are not paid by carriers. No commission steers the recommendation, so the advice stays yours.
Technology-native
We read your architecture and your MSA. Coverage is designed around how you actually operate.
Built for the board
Documentation, rationale and evidence in the format investors and diligence teams expect.
Quantified, not assumed
Every limit and retention traces back to a modelled scenario, not an industry benchmark.
Wording-level rigour
Claims are won or lost in exclusions. We negotiate the language, not just the price.
Continuous, not annual
Your risk changes every quarter. The program is reviewed on that cadence, not at renewal.
What changes when the advice isn't for sale.
They found three gaps our previous broker had renewed for four years straight. The board noticed immediately.
The first team that read our MSA before recommending a limit. That alone changed the conversation.
Diligence went from a three-week fire drill to a folder we already had ready. That is the real value.
Client identities withheld under confidentiality. References available under NDA during engagement discussions.
Straight answers,
before you call.
Still unresolved? Send it to us directly and you'll get a written response within one business day.
No. Cortex.AI is an independent consulting firm. We are not compensated by carriers, we do not earn commission, and we do not bind coverage. We are engaged and paid directly by the company, so the recommendation is never shaped by who pays the spread. Placement itself is executed by a licensed broker — yours or one we introduce.
Typically Commercial General Liability, Technology E&O and Cyber Liability, with the customer named as additional insured, a waiver of subrogation, and primary and non-contributory wording. Limits scale with the customer: smaller buyers often ask for $1M–$2M, mid-market $2M–$5M, and large enterprises $5M–$10M across Tech E&O and Cyber. The Contract Readiness Review exists precisely to answer this for your specific agreement.
Not necessarily. Through 2025 and 2026 carriers moved to replace silent AI with explicit language, and in January 2026 ISO introduced endorsement forms letting general liability carriers exclude generative AI exposure outright. Some carriers now offer affirmative AI cover instead, usually conditioned on documented governance such as NIST AI RMF or ISO/IEC 42001 alignment. Whether you hold an exclusion or a grant-back is a wording question, and that is what the AI Exposure Review answers.
Cyber and Tech E&O are almost always written on a claims-made basis, meaning the policy responds to claims made during the period — but only for work performed after the retroactive date. Buy coverage late and years of prior delivery sit outside the policy. Change carriers carelessly and you can lose the date entirely. It is one of the most common and most expensive oversights we find.
Our entry programs are built for smaller technology and IT services companies — often under 100 employees, frequently facing their first serious enterprise contract. We also take on full program architecture for companies through Series C and beyond.
Frequently, yes. Many clients keep their broker for placement and engage us for strategy, wording review and renewal positioning. We work alongside whoever is already in place, and we do not need to displace them to be useful.
A fixed professional fee agreed in advance, scoped to the specific work. No commission, no percentage of premium, no contingency. Tell us what you need and the deadline you are working against and we will quote it.
A firmer market than the last two years. Rating forecasts point to meaningful increases, and underwriters have hardened on controls — multi-factor authentication on remote access and privileged accounts, endpoint detection and response, and external vulnerability scanning are now standard conditions rather than preferences. Companies that arrive at renewal unprepared face materially worse terms than those that arrive with evidence.
We quote against scope, not against your revenue. Describe the situation and the deadline you are working to, and you will have a fixed fee and a start date back within 48 hours.
- A fixed fee, not a range
- A start date and a delivery date
- A written note on what we would look at first