You are looking directly into your policyholder's systems right now. No audit. No questionnaire. No trust required.
When a control fails, you know in seconds — not at renewal. Your risk is math, not hope.
Policyholder probe active — Acme Corp AI Claims System — 44 HATS rules + 6 warranty conditions monitored across 3 environments — ML-DSA-65 + FALCON-512 + SLH-DSA
MFA (all privileged accounts) IN FORCE
EDR (CrowdStrike / SentinelOne) IN FORCE
Encrypted Backups (AES-256) IN FORCE
FHE Data Protection (BFV N=4096) IN FORCE
Patch Cadence (≤ 30 days critical) IN FORCE
AI Governance Policy (HATS REQ-1.1) IN FORCE
COVERAGE STATUS: ACTIVE — All warranted controls verified in force
Tier 2
PQ Readiness Level
HNDL Window2027–2029 (3yr horizon)
Data-at-restFHE-protected (BFV)
ML-DSA-65 (Dilithium)Active · NIST Level 3
FALCON-512Active · NIST Level 1
SLH-DSA-SHA2-128fActive · Stateless hash
H33-74 Substrate74B attestation · Patent pending
Classical crypto exposureNone detected
95
HATS Certification Score
< 70: Partial
< 50: Full Claim
0RevokedWarningActive100
On violation, a cryptographically-anchored forensic evidence packet is generated. RFC 3161 timestamped. HSM-anchored. Multi-party witness delivery to carrier, policyholder, and reinsurer. Court-ready provenance for recovering claim payouts from the vendor whose pipeline failed.
SUBROGATION EVIDENCE PACKET
Incident ID:
Violation:
Timestamp:
Score at incident:
Warranty lapsed:
H33-74 Hash:
RFC 3161 Timestamp:
HSM Anchor:
Witness Delivery:
Merkle Root:
Signatures: ML-DSA-65 + FALCON-512 + SLH-DSA-SHA2-128f
Evidence chain:
Download Forensic Packet
Standing by. Webhooks fire on warranty lapse — press Trigger Violation.
Active (98.8%)
Warning (1.2%)
Suspended (0%)
Concentration risk: No systemic event detected. Largest single-sector exposure: Financial Services (34%). HATS proofs covering $2.1B aggregate cyber limit.
ML-DSA+FALCON+SLH-DSA
3 PQ Families
Demo data. The dashboard above is a live interactive demonstration. The Acme Corp policyholder, the 247-insured portfolio, the hashes, and the proof stream are illustrative sample values generated in your browser to show the shape of the evidence — not a real insured's telemetry. The evidence record format, the three post-quantum signature families, and the verifier path are the production shapes; the numbers are simulated.
What this surface is
Cyber-insurance continuous monitoring is the HATS surface that RECORDS and MONITORS whether an insured's warranted controls stayed in force over the policy period — MFA, EDR, encrypted backups, FHE data protection, patch cadence, and the AI governance policy — emitting a signed, replayable evidence record so protection is provably true, not attested once and trusted. It records the evidence; it does not underwrite, price, verify, or pay the claim.
Why this surface exists
A cyber policy has historically rested on a questionnaire taken once at bind and trusted until renewal. Between those points a warranted control — a condition precedent to coverage — can lapse silently, and neither carrier nor insured knows until a claim forces a forensic reconstruction. HATS exists to remove that blind window: it replaces the periodic snapshot with a continuous, replayable evidence record, so “the control was in force” is reproduced from receipts, and a lapse is recorded the moment it happens. That is why H33 keeps monitoring as a distinct component: recording operational evidence over time is a different job from scoring, verdicts, and decisions.
When to use HATS here — and when not
- ›Use HATS when the requirement is continuous operational evidence that insured controls stayed in force over time — the answer to “was the warranty held on the day of the incident?” reproduced from receipts, not argued.
- ›Use Verification when the requirement is an independent verdict on an existing artifact — the subrogation packet and every receipt are checked by the external verifier. Do not treat HATS monitoring as its own independent verification.
- ›Use HICS when you want a maturity score of the insured's code or controls — how good they are — rather than operational evidence that they ran. The parametric score here rates control state over time, not code maturity.
- ›Use Agent-008 when the need is to govern an AI decision under attested authority; HATS only records that the governed controls held.
Parent standard: the HATS standard — which defines the evidence record this surface writes and RECORDS operational evidence against. Related surfaces: HATS hub · Insurer surface · Broker quote engine · Claims evidence · verify a receipt independently at the public verifier.
Frequently asked
What does HATS continuous monitoring record for cyber insurance?
It RECORDS and MONITORS the operational evidence that warranted controls stayed in force — MFA, EDR, encrypted backups, FHE data protection, patch cadence, and the AI governance policy — as signed, portable receipts, so a carrier sees continuous state rather than a renewal-time snapshot. HATS records this evidence; it does not underwrite, price, or pay the claim.
Why does this surface exist?
Because a once-a-year questionnaire lets a warranted control lapse silently between renewals. HATS makes the lapse a recorded, timestamped event instead of a claim-time dispute — coverage state and subrogation follow from evidence.
When should a carrier use HATS versus independent Verification?
Use HATS for continuous operational evidence over time. Use Verification for an independent verdict on an existing artifact — the subrogation packet is checked by the external verifier. HATS monitoring is not itself verification.
When should I use HICS or Agent-008 instead?
Use HICS for a maturity score of the insured's code or controls; use Agent-008 to govern an AI decision under attested authority. HATS records that governed controls held; it neither scores maturity nor makes the decision.
What does the carrier actually see when a warranty lapses?
A signed record of the lapse — which control failed, the timestamp, the score transition — plus a subrogation evidence packet with an H33-74 hash, RFC 3161 timestamp, HSM anchor, Merkle root, and three-family post-quantum signatures, delivered to carrier, policyholder, and reinsurer. Any party can verify it independently.
Is the data shown on this page real policyholder data?
No. It is a live interactive demo. Acme Corp, the 247-insured portfolio, the hashes, and the proof stream are illustrative sample values generated in the browser to show the shape of the evidence. The record format, signature families, and verifier path are production shapes; the values are simulated.