Move from declarations to evidence.
Use cases:
Risk selection: support Accept / Refer / Decline with contextual evidence, not CVSS alone
Risk engineering: show insureds which remediation may reduce the most financial exposure
One evidence layer across the policy lifecycle.
Policy-to-control engine
Turn policy conditions into testable controls.
Conditions, warranties and security requirements become mapped controls the insured assigns, tests, evidences and attests. A view of compliance during the policy period, not just at binding.
Example: one policy condition
Policy requirement: MFA required for remote privileged access
Mapped control: privileged remote access requires MFA — tested Pass / Partial / Fail
Evidence: configuration evidence, endpoint evidence and attestation
Monitor: exceptions surface during the policy period, before renewal or a claim
Underwriting example
Move beyond CVSS.
A critical vulnerability on a revenue-critical application holding sensitive customer records is a different risk from the same CVE on a test server. Astragar connects finding → asset → data → loss scenario → modelled exposure → control strength → residual exposure, so the underwriting decision rests on context, not severity scores.










