This is the thinnest evidence base in the dossier, and the page should say so before it says anything else. Every figure below is generic technology insurance data from US brokers. Not one number describes an offensive-security firm, an AI data vendor, or anything closer to this business than "a software company." Use them to know the order of magnitude of the category, and to know which questions to take to a broker — not to build a model.
What a firm doing offensive work carries
The standard stack for a penetration testing business, per two US brokers (TechInsurance; Insureon):
| Cover | What it is for |
|---|---|
| Technology E&O | The core policy: claims from poor methodology, insufficient due diligence, incomplete remediation, damage caused during testing |
| Cyber liability | The firm's own breach — notification, investigation, downtime |
| General liability | Routinely required by client contracts |
| Fidelity bond | Employee theft or fraud, specifically including "unauthorized access of a client's data" by an employee |
| Workers' compensation / commercial auto | Where employees and vehicles exist |
The only real market figures available. US small-business averages, from TechInsurance customer data (the page does not date the sample [WEAK]): general liability $30/month, errors and omissions $67/month, cyber insurance $148/month.
A 2026 tech E&O cost guide gives revenue-banded annual figures (insura.ai) [WEAK — a commercial content site, not a broker filing]:
| Profile | Annual tech E&O |
|---|---|
| Solo IT consultant, $100K revenue | $1,200–$1,800 |
| Solo, $500K revenue | $2,000–$3,000 |
| Software dev firm, $1M | $3,000–$5,000 |
| SaaS, $1M | $3,500–$6,000 |
| Tech services, $5M | $6,000–$12,000 |
Typical structure is $1M per occurrence / $2M aggregate with a $5,000–$10,000 deductible; stepping to $2M/$4M or $5M/$10M adds 40–80% per tier. Named carriers: Hartford (competitive under $5M revenue), Chubb (higher limits, $5M+).
At seed stage this is a four-figure annual line item, possibly low five figures once cyber limits rise to match the exposure. It is not a business-model question. Everything on this page that is a business-model question is unpriced.
The three questions that matter more than the premium
1. No offensive-security-specific pricing exists publicly. A specific search for penetration-testing surcharges, declinations or specialist wordings found nothing. UK-specific ethical-hacking professional-indemnity quotes could not be established at usable detail either. The absence is consistent with this being a specialty-underwritten, individually-rated class — meaning the price comes from a conversation with an underwriter, not from a table, and the conversation will be about the controls in The corpus is the target rather than about revenue.
2. Whether downstream buyer misuse is a covered wrongful act is unknown. If a corpus is exfiltrated, or a vetted buyer misuses it and harm results, is that a covered wrongful act in the professional services? Almost certainly a coverage dispute, because no standard wording was written with this fact pattern in mind. The practical instruction is blunt: ask for an explicit affirmative grant or an explicit exclusion, so you know which one you have before you need to know.
A related exposure sits alongside it. If contractors deliver material derived in breach of an employer's IP terms, a bounty platform licence, or a range's acceptable use policy — the Hack The Box problem — the resulting claim is contractual and IP, which tech E&O may cover in part and may exclude. The provenance warranty in Copy Daybreak's architecture is the control that keeps that claim from arising.
3. Criminal defence costs are explicitly not covered. Insureon's FAQ states that tech E&O covers authorised testing mishaps but "won't provide criminal defense coverage if you intentionally cause harm." That is the exposure that matters most for a Europe-based company: the §202c and Modern Solution risk is not a claim, it is a prosecution. A separate legal-expenses or criminal-defence-costs wording would be needed, and whether such cover is available for §202c-type exposure in the German market could not be established.
The insurance market sells cover for the risk a pentest firm has — breaking a client's system. This company's largest realistic downside is a criminal investigation of a contractor in an unreformed jurisdiction, or a catastrophic theft of the corpus itself. Neither is what the standard stack is for. That mismatch is worth naming to a broker in the first meeting, because it changes which product they reach for.
Is a pure data business a different risk class?
The argument is yes, and materially better — on the traditional axis. Almost all tech E&O loss experience in this class comes from touching the client's systems: an outage caused during a test, data destroyed, a scope overrun, a missed vulnerability later exploited. A business that never tests a customer's infrastructure removes that entire loss vector.
That is an argument to make at renewal, and it should be worth a substantial discount. It is also, to be clear, an argument and not a sourced fact [UNVERIFIED — how underwriters actually price this could not be established]. Present it that way internally, because a plan that has already booked the discount is a plan that will be surprised.
Two new exposures come the other way. The first is downstream misuse, above. The second is that the company's own breach is a catastrophic rather than merely expensive event: a stolen corpus of high-quality attack trajectories is a live weapon, and the July 2026 ExploitGym incident established that the storage location of an answer key is a target. Cyber liability limits appropriate to a $1M-revenue software firm are not appropriate to that scenario, and the underwriter will want to see the release controls before writing it at any limit.
Expect buyer contracts to specify minimum limits — plausibly $2M–$5M [UNVERIFIED — actual lab contract requirements could not be established]. The broker's own framing, that "clients often require this coverage," is the practical driver: procurement, not risk management, is what usually sets the limit. The labs as buyers is where that requirement will first appear in writing.
- What does an offensive-security or exploit-research class actually cost, and who writes it?
- Is downstream misuse by a vetted buyer an affirmative grant, an exclusion, or silence?
- Is criminal-defence-costs cover available in Germany, Belgium or Poland for a §202c-type allegation against a contractor, and can the company buy it for contractors?
- What limits will a frontier lab's procurement require, and does anyone write cyber limits sized to "the corpus itself is stolen"?
None of these could be answered from public sources. All four are answerable in two broker meetings.
What to read in full before committing
Carried across from the underlying research, in the order it recommends.
Read first — these change the business plan
- Hack The Box Acceptable Use Policy, effective 1 April 2026 — the AI-training and commercial-use prohibitions. Then the equivalent for every other range you planned to use.
- DOJ CFAA charging policy, 19 May 2022 — read the "good faith security research" definition and the no-rights-created disclaimer together.
- DOJ CCIPS, "Legal Considerations when Gathering Online Cyber Threat Intelligence and Purchasing Data from Illicit Sources", February 2020 — the closest thing to a rulebook for a company that commissions rather than performs.
- BIS EAR cyber-rule FAQs, revised February 2022 — especially FAQ #24 on exploits.
- Regulation (EU) 2021/821, consolidated — Article 2(2) and (9), Article 5, Annex I 4A005/4D004/4E001, and the General Technology Note with the "in the public domain" definition.
- Commission Guidelines on the export of cyber-surveillance items under Article 5, 15 October 2024 — start with the summary, then the Official Journal text.
Read second — jurisdiction
- Directive 2013/40/EU Article 7, with Articles 2 and 3–6 and Recitals 16–17.
- "Hunting for vulnerabilities: call for European protection of security researchers," Journal of Cybersecurity 12(1) tyag002 — the best comparative survey there is. Pick contractor jurisdictions from its country-by-country section.
- §§ 202a, 202b, 202c StGB in current text, plus the BMJ Referentenentwurf of Oct/Nov 2024 and the Bonn DROPS analysis.
- The Modern Solution judgments (Amtsgericht/Landgericht Jülich, OLG Köln, and the BVerfG order) in German original; background.
- CPS legal guidance on the Computer Misuse Act — the s.3A(2) factors, particularly "closed and vetted list."
- CRA Articles 14 and 16 plus the Commission's CRA reporting page. Note 11 September 2026.
- NIS2 Article 12.
Read third — market and controls
- OpenAI Daybreak Trusted Access overview and the expansion post. Copy the control architecture.
- Anthropic, "Project Glasswing: An initial update", and RSP v3.1.
- The ExploitGym / Hugging Face incident write-up and Hugging Face's own 27 July 2026 technical analysis — before designing any evaluation harness.
- The ExploitBench paper, especially the ethics and release sections, and Cybench.
- HackerOne Finder Terms and the February 2026 AI-policy coverage.
- Mercor's live cyber postings, all of them, as a competitive and pricing benchmark.
- A specialist technology PI/cyber policy wording in full — for example Chubb's Irish tech PI/cyber summary — reading specifically for intentional-acts exclusions, criminal-defence-costs treatment, and whether downstream misuse by a customer is a covered wrongful act.
Six of those twenty change the plan rather than inform it: items 1, 2, 5, 8, 10 and 16. If only one afternoon is available, read those.
The constraints thread runs The terms of service bite first → Exploits are free, uploading is an export → Copy Daybreak's architecture → The corpus is the target → this page, and connects outward to The law is about to arrive on what kind of company this is, Operating from Europe, selling to the US on operating from the EU, and Offensive security on the niche itself.