Insurance Exchange
The Insurance Exchange lets a cyber-insurance carrier and the organization it insures agree on a set of control obligations, then exchange periodic compliance reports scored from the insured's real records: assessments, evidence, cloud posture findings and deadlines. Neither side ever reads the other's live data. What crosses between the two organizations is a report the insured consented to in advance, evaluated on a schedule both agreed to, and frozen the moment it is produced.
That last part is the point. Today a carrier sends a questionnaire at renewal and takes the answers on faith for a year. Here the carrier states what it needs proven, the insured accepts those terms once, and from then on every report is drawn from the same records that back the insured's audits, with the insured's own justification and the identity of the evidence behind every verdict. Compliance is reported as it is, on a cadence, with the direction of travel since the last report, and the insured can see exactly what the carrier sees before the carrier sees it.
Two sides, two pages
Insurance Exchange (insured). Where a carrier's agreement lands for your review, where your obligations and their deadlines live, where you preview the exact report your carrier will receive, and where every carrier read of your data is recorded. The exchange is a plan add-on; contact SolveGRC to enable it for your organization.
Carrier Portfolio (carrier). Headline positions across every insured, released reports and their downloads, deadlines that need attention, extension requests, release decisions, and a feed of rating-relevant events. Becoming a carrier is not self-service: SolveGRC enables carrier programs after vetting, and the page says so until then.
What crosses, and what never does
What crosses: the agreement itself (terms, obligations, cadence, disclosure scope), and released report snapshots. A snapshot holds a score with its components, a verdict for each obligated control, the insured's written justification and who attested it, and, when the agreement's disclosure level allows, the identity of the supporting evidence: title, date linked, content hash.
What never crosses: the insured's documents, its raw findings, its cloud inventory, its assessments outside the obligated controls, or anything from before the terms were accepted. Files stay in the insured's tenant. What the carrier receives for a document is a hash it can check a copy against, should one ever be handed over.
Reports cross only after they are released. An insured previews a report before release; a carrier sees nothing until release. The carrier can choose to hold releases for a two-person decision, and that choice can only delay or withhold a report, never widen what is in it.
How a relationship runs
- The carrier invites your organization and sends an agreement version. It appears on your Insurance Exchange page with the exact scope: obligations, reporting cadence, grace and notice periods, evidence disclosure level, retention. See Accept an agreement.
- An administrator or compliance officer accepts it in a session protected by two-factor authentication. Acceptance turns the obligations into tracked commitments with due dates. Nothing has left your tenant yet.
- At the end of each reporting period, SolveGRC evaluates the obligated controls overnight from your records and produces a report. You can read it on your page as soon as it exists. See What your carrier sees.
- The report is released to the carrier on the agreed cadence, or after the carrier's own two-person decision if it has asked for manual release. Every read the carrier makes is written to your audit chain.
- Obligations that fall behind enter a grace period with a recorded notice. Extensions can be requested and offered, and the clock never moves without a ledger entry. See Obligations and grace.
Carriers have their own page in this guide: For carriers.
How this connects
The exchange reads what the rest of SolveGRC already knows and adds nothing you have to maintain by hand:
- Frameworks and controls: which controls the obligations name, and how each has been assessed. See Frameworks. A control satisfied through a reviewed crosswalk counts in full; one satisfied only through an unreviewed mapping is marked AI-inferred and counts for less. See Crosswalks.
- Evidence: what is linked to each obligated control, how fresh it is, and whether a person has reviewed it. See Evidence.
- Cloud posture: open failing checks on healthy connectors count against the posture component. See Cloud Posture.
Evaluation runs overnight on your records as they stand at that point, so a control you fix today shows as fixed on the next report, not this one.
The weightings, thresholds and formulas that turn those inputs into a score are not published here, the same way the platform's other scoring models are described by their inputs and their behaviour rather than their arithmetic. Every report states the formula version it was scored under, so two reports scored the same way are comparable and a change in method is visible.
Pages in this guide
- Accept an agreement: reading the terms, what acceptance commits you to, and how versions work.
- What your carrier sees: the report, verdict by verdict, and the preview that shows it before release.
- Obligations and grace: deadlines, extensions, and what a reportable failure means.
- For carriers: the portfolio page, release modes, decisions, and underwriting signals.