You are already carrying generative AI risk. The question is whether you can price it.
AI-enabled social engineering losses are landing on crime, cyber and fidelity policies with almost no way to distinguish a well-controlled insured from a poorly controlled one. Proveniro turns that distinction into evidence: attested AI controls at underwriting, and replayable per-decision model records at claim.
- underwriting
- control attestation
- claims
- replayable evidence
- record
- tamper-evident
- export
- signed bundle
Three problems that show up on the loss run before they show up in the wording.
Generative AI does not create a new peril so much as it collapses the assumptions inside existing ones.
Undifferentiated risk selection
Two insureds with identical revenue and identical questionnaire answers can have completely different exposure, and nothing in the submission tells you which is which.
Unprovable claims
After a voice-cloned transfer, the insured's account of what was checked is reconstructed from memory and email. Coverage turns on facts nobody recorded.
Silent accumulation
One widely adopted AI cloning model and one widely shared control gap can drive correlated losses across an entire portfolio in a single quarter.
Evidence at underwriting, evidence at claim, and a view across the portfolio.
Proveniro is deployed by the insured; you receive the assurance artefacts, scoped and consented.
AI control attestation
A signed statement of which AI controls were live, on which channels, at which model thresholds, over a stated period.
Claims-grade records
Per-decision evidence with inputs, AI model versions and timings — replayable to the moment of the loss.
Independent verification
Exported bundles verify against published checkpoints without needing Proveniro to be in the loop.
Portfolio signals
Anonymised, aggregated AI attack-pattern telemetry to inform pricing, wordings and accumulation views.
Risk-improvement pathway
A concrete remediation an underwriter can require and then verify, rather than a questionnaire answer.
Consent-bounded sharing
Insureds control exactly what is shared with a carrier or broker, and for how long.
Into the process you already run.
- 01
Submission
The insured attaches an AI control attestation covering callbacks, contact centre, agent traffic and onboarding.
quote stage
- 02
Pricing
Verified controls become a rating factor rather than a claim on a questionnaire.
bind
- 03
In force
Continuous attestation shows whether controls stayed live and at what threshold.
policy period
- 04
Claim
The adjuster receives a sealed, replayable record of exactly what was checked and when.
notification
AI provenance designed for people whose job is to doubt it.
The value of an evidence record is entirely a function of how hard it is to fabricate after the fact. That constraint shaped the design.
This is not an AI fraud score for underwriting, and it does not tell you whether a specific claim is fraudulent. It tells you, with cryptographic support, which AI controls were operating and what they concluded at the moment in question — which is usually the fact everyone is arguing about.
- record structure
- Append-only, hash-linked, per-tenant isolated, with periodic signed checkpoints
- independence
- Exports verify offline against published keys and checkpoint proofs
- attestation scope
- Channels covered, model thresholds in force, coverage percentage, gaps and downtime disclosed
- claims export
- Signed bundle: records, keys, checkpoints and a standalone verifier binary
- privacy
- Hashes and manifests by default; raw media only where the insured explicitly retains it
- portfolio data
- Aggregated and anonymised; never attributable to a named insured without consent
Turn a control you cannot see into one you can price.
We work with carriers and MGAs on attestation formats, claims workflows and portfolio telemetry. Early participants shape the standard.
soc 2 type ii in progress · eu & uk data residency · no ai training on your data