If a CVE not on the FIRE list causes your financial loss breach, we reimburse the loss. Up to $5 million, underwritten by Cysurance.
We put our money where our mouth is.
Cybersecurity is the only enterprise category where the vendor walks away scot-free when the product fails. The rest of your budget comes with performance terms. Vulnerability management hasn't had them, because no vendor's findings have been grounded in data they'd put real money behind.
The FIRE list changes everything. Built from actual cyber incidents and loss data, it's the only list in the world that covers every CVE known to have cost money. We scan your perimeter against it daily, and stand behind the result when we miss.
Mythos finds vulnerabilities.
Evidence finds liabilities.
Mythos will keep surfacing new vulnerabilities: some exploitable, but many that are impossible or impractical to use in a real-world context. Attackers will keep exploiting a very small number of CVEs.
Evidence tracks the CVEs with a documented history of causing financial loss. Our proprietary FIRE list is built from insurance claims and DFIR forensics, and it grows as new loss data emerges (including from attacks that use Mythos).
Think of our warranty as a bet, up to $5 million, that a CVE we have never seen won't be the one that costs you money.
If it costs you money, we cover it.
Evidence Warranty covers the direct financial costs of a qualifying breach.
Ransomware
Payment, recovery, and direct expenses.
Data loss
Exfiltration and destruction costs.
Compliance fines
HIPAA, PCI, SEC, FTC, GDPR, and similar frameworks.
Legal
Initial counsel engagement covering disclosure obligations and litigation exposure.
Emergency response
Containment, forensics, and immediate operational costs.
Tiers
Renewed every 12 months. Purchased separately from the Evidence Platform subscription. Ask your Evidence rep for a full quote.
What the warranty doesn't cover.
The warranty covers what the scanner is built to find. The rest stays with your cyber policy. Claims will not be paid for:
Non-CVE compromise
Phishing, credential stuffing, brute force, malicious email, drive-by downloads, lost laptops.
FIREs we already disclosed
If we told you about a FIRE vuln in your environment and attackers use it when you already knew it could cause financial loss.
Third-party systems
CRMs, HRIS, SaaS you don't control.
Unidentifiable initial access
No entry vector found means no claim validation.