Your carrier wants security documents. You don’t have a security team.
Answer 22 plain-English questions about your business. Coverwright assembles a written information security program, an incident response plan carrying your state’s notification duties, and more — written for your setup, ready for the cyber insurance application or the client security review.
From one real 10-minute intake — the sample shown here and at /sample.
No AI in the decision path
A rules engine selects your clauses from a fixed library — never a model improvising prose. The same 22 answers always produce the same documents.
Every line traces to a source
Clause references in the margin point back to the rule that included them, built on published NIST, CISA, and FTC small-business guidance — not invented from scratch.
Judge it before you pay
A real generated document set, and a real sample set built from a fixed persona, are both visible before checkout — nothing about the output is a surprise at the price point.
Coverwright does not guarantee insurance acceptance, claim outcomes, or regulatory compliance. How this is built, what is reviewed, and what happens to your answers.
The four reasons someone asks you for this.
Your cyber insurance is up for renewal
Applications now ask for a written policy, an incident response plan, MFA, tested backups, and training — and carriers verify at claim time. Documents that overstate what you have are worse than none.
A client sent you a security questionnaire
Bigger customers push their own security requirements down to their vendors. The vendor matrix answers the “who manages this?” rows directly.
You prepare taxes, keep books, or advise on money
The FTC Safeguards Rule expects firms like yours to hold a written information security program, with a named person responsible for it.
You handle patient information
HIPAA applies whether you treat patients directly or handle records for someone who does — and the two roles carry different duties. Your documents say which one you are.
Coverwright produces the documentation these ask for. It does not make you compliant with any of them on its own — where a rule wants something beyond a document, your set names it and says who owns it.
Rules, not guesswork.
The same answers always produce the same documents, and every paragraph can point at the answer that put it there.
- 01
Answer 22 questions
Plain-English questions about your business: what you use, what data you handle, what’s already in place, and which state you’re in. Ten minutes, no jargon, no uploads — everything you answer feeds straight into the next step.
- 02
Rules select your clauses
A deterministic rules engine — not an AI improvising — selects every clause from a curated library based on your answers. Same answers, same documents, every time, for a traceable reason.
- 03
Download your document set
A one-page security summary for whoever you forward it to, a written information security program, an incident response plan built around US notification deadlines, and — on Complete — an acceptable use policy, continuity plan, and vendor matrix. Plus a plain-English readiness summary and a ranked plan for your gaps.
This is what lands in your inbox.
Not a template with your name dropped in. A prepared document, typeset, with a reference against every clause pointing back to the answer that selected it.
Written Information Security Program
Information security policy for Harborview Accounting LLC
1. Purpose & scope
This program sets out how Harborview Accounting LLC protects its information, systems, and the data entrusted to it by customers and partners. It applies to everyone who works in or with the business — employees, contractors, and temporary staff — and to every device and service used for business purposes.
The controls in this program are proportionate to the size and nature of the business. They exist to keep the business operating, to meet the expectations of customers and insurance carriers, and to satisfy legal obligations around the data the business handles.
Because Harborview Accounting LLC handles personal information, this program also supports the business’s legal obligations for protecting it — the specific regimes that apply are set out under “Legal & regulatory obligations” below. Questions that go beyond day-to-day security practice are escalated to the owner, who takes advice where the answer isn’t obvious.
2. Roles & responsibilities
The business owner (or managing director) is accountable for this policy. A named security lead is responsible for day-to-day operation: managing accounts, checking that controls remain in place, and acting as the first point of contact for concerns. The current security lead is recorded alongside this policy.
Every member of staff is responsible for following this policy, for reporting anything suspicious promptly, and for asking before working around a control. No one is expected to diagnose a security problem — only to report it.
Five documents. Yours, not a template’s.
Written Information Security Program (WISP)
The document a cyber insurance application, a client security review, and the FTC Safeguards Rule all ask for — under three different names. States what your business actually does, and where you’re still rolling a control out, says so honestly with a remediation clause instead of a false claim.
Incident Response Plan
Who does what when something goes wrong — phishing, a hacked account, ransomware. Tailored to your actual stack, and to the notification clocks that apply to you: state breach-notification deadlines, the 60-day HIPAA timetable, the FTC’s 30-day rule.
Acceptable Use Policy
The one your staff actually read, written at them rather than about them. Covers accounts, phishing, devices, and what may and may not be pasted into a public AI assistant — the question every small business now has and few policies answer.
Business Continuity Plan
A one-pager, deliberately: what gets restored first, how long you can work without it, and how you keep invoicing while it’s down. Recovery targets are written as decisions you record — never as a capability you didn’t tell us you had.
Vendor Responsibility Matrix
For each service you rely on: what the vendor secures, what’s on you. The exact answer to a client questionnaire’s “who manages X?” rows — built from the tools you told us you use.
Content built on published small-business security guidance from US government sources (NIST, CISA, FTC), adapted to your answers.
What a business like yours generates.
Answer a few questions here and watch the same rules engine assemble a set — live. The real thing runs on all 22 answers; this is a taste of how your setup drives the output.
Change an answer on the left and the clauses it selects appear here, by reference. Same answers in, same clauses out — every time.
- —Multi-factor authentication: stated with a remediation clause, never a false claim.
What this work costs the usual way.
Or low five figures as a one-off policy project, at $150–$500 an hour.
No retainer, no hourly billing — pay once, renew for $99 a year. The price you see is the price charged; nothing is added at checkout.
Typical published US ranges as of 2026-07-18. Content drawn from NIST, CISA, and FTC small-business guidance.
Pay once. Renew when your insurance does.
The core set — what the application asks for.
- ✓One-page security summary, for whoever you forward it to
- ✓Written Information Security Program (WISP)
- ✓Incident Response Plan with your state’s notification duties
- ✓Readiness summary and a ranked action plan for your gaps
- ✓PDF and editable Word, both included
Two documents. See yours before you pay.
The full set — everything a client security review asks for too.
- ✓Everything in Standard
- ✓Acceptable Use Policy, including AI-tool rules
- ✓Business Continuity Plan
- ✓Vendor Responsibility Matrix for your actual tools
- ✓Renewal reminder timed to your insurance date
Five documents. See yours before you pay.
Annual refresh — re-answer what changed, regenerate everything — $99. No subscription.
Prices in USD. The price shown is the price charged — any tax that applies is already included, not added at the last step.
The things worth asking before you buy.
Is this generated by AI?
No. Clause selection is a rules engine over a curated clause library — deterministic and auditable. A document your insurance depends on shouldn’t come from a model’s best guess.
How is this different from a template pack?
A template says [COMPANY NAME] and lists controls you may not have. Coverwright’s documents are assembled from your answers: your tools by name, your working setup, your state’s notification duties, and honest remediation clauses where a control isn’t in place yet — which is what an underwriter actually wants to see.
What is a WISP, and is that what I need?
A Written Information Security Program is the same document an insurance application calls an information security policy and a client questionnaire calls a security policy. If you prepare taxes, keep books, advise on finances, or arrange financing, the FTC Safeguards Rule expects you to have one in writing. Coverwright generates it under both names so you can hand it to whoever asked.
Does this make me HIPAA or FTC compliant?
No, and anyone selling you that is overselling. Documentation is one requirement among several — HIPAA also requires a written security risk analysis and signed business associate agreements; the Safeguards Rule requires a named responsible individual and a risk assessment. Your documents name those obligations and who owns them, so you can see what’s still outstanding rather than assuming a PDF covered it.
What is the content based on?
The clause library is built on published US government and industry guidance for small-business security — NIST, CISA, and FTC small-business guidance, including NIST’s incident-handling lifecycle — adapted into plain English.
Why a renewal, not a subscription?
You need these documents when insurance renews or a client asks — roughly once a year, not monthly. So you pay once to generate, and $99 each year to re-answer what’s changed and regenerate.
Why is this so much cheaper than hiring someone?
A security consultant or virtual CISO doing this same work typically charges $3,500–$15,000 a month as an ongoing retainer, or low five figures as a one-off policy project, at $150–$500 an hour. Coverwright runs the same underlying task — turning your answers into policy — through a rules engine instead of billed hours, so the price reflects that, not a discount on what’s in the documents.
Ten minutes now, or a scramble at renewal.
Answer the 22 questions and read your own document set in full before you decide whether to pay for it. Nothing is sent anywhere until you do.
No account needed to see your documents · no sales call, ever