Skip to content

We'll bet $5 million we found the CVEs that matter.

We put our money where our mouth is: Evidence Scan finds every vulnerability that could cause financial loss. And we'll stand behind that with up to $5 million in coverage.

Underwritten by Cysurance · One Benefit Usage per 12-month term · T&Cs apply

The $5M question

The $5 Million Question: Why does every other product in your budget come with performance terms except the one where failure costs the most?

Answer: Because no vendor has had findings they'd bet on... Until now.

No vendor has ever had findings they'd bet on.

We built the FIRE list from real losses at real companies. That's evidence you can put money behind, so we did: up to $5M.

We put money behind catching what actually costs money.

Our warranty is the ultimate guarantee that the FIRE list stays the world's most up-to-date, comprehensive list of CVEs leading to financial loss.

Skip the security translation: say it in dollars.

Your CFO won't learn CVSS, and the board won't read the dashboard. Everyone understands the universal language.

Your board wants a number. Give them two.

First, tell them you're warrantied up to $5M. Then, show them what the unfixed FIREs would cost, and let them approve the budget themselves.

Tiers

Foundation
up to
$1M
coverage
Best for SME · $0-$10M revenue
Standard
up to
$3M
coverage
Best for Middle Market · $11M-$499M revenue
Maximum
up to
$5M
coverage
Best for Large · $500M+ revenue

Sold only with Evidence Platform. Ask your Evidence rep for a full quote.

If it costs you money, we cover it.

Mythos Warranty covers the direct financial costs of a qualifying breach.

Losses above $5,000 qualify. The benefit may be used once per 12-month term.

Ransomware

Payment, recovery, and direct expenses

Data loss

Exfiltration and destruction costs

Compliance fines

HIPAA, PCI, SEC, FTC, GDPR, and similar frameworks

Legal

Initial counsel engagement covering disclosure obligations and litigation exposure

Emergency response

Containment, forensics, and immediate operational costs

What the warranty doesn't cover.

The warranty covers what the scanner is built to find. Benefit Usage will not be granted for:

Non-CVE compromise

Phishing, credential stuffing, brute force, malicious email, drive-by downloads, lost laptops

FIREs we already disclosed

If we told you about a FIRE vuln in your environment and attackers use it when you already knew it could cause financial loss

Third-party systems

CRMs, HRIS, SaaS you don't control

Unidentifiable initial access

No entry vector found means no Benefit Usage validation

Nobody bets $5M on a scan with holes in it.

We built our EASM from a live map of the whole public internet, so nothing on your perimeter is news to us. Our FIRE list covers every CVE that has cost someone money. Underwriters back it all.

What Stakeholders See:

CFO

Up to $5M against a loss you'd otherwise absorb to offset deductible or use directly.

Board

Underwriters put money behind this vulnerability program.

Auditor

Every CVE with a loss history, closed and documented.

Carrier

Daily scanning against the vulnerabilities that generate claims.

What You Get

Underwriter Backed / Mythos Ready / No Questionnaire Required

01

Underwriter-Tested. CFO-Approved.

The Mythos Warranty is underwritten by a specialist cyber warranty carrier backed by a licensed reinsurer. You see more assets, know exactly which CVEs cause breaches, and communicate better with every stakeholder. Your CFO gets up to $5M in coverage, with risk priced and modeled with the backing of a leading insurer.

02

Mythos finds vulnerabilities. Evidence finds liabilities.

Frontier models will keep surfacing new CVEs. Adversaries will keep exploiting the small proportion that work. We track the ones with a documented loss history, using a list that grows when new loss data emerges.

03

Keep your policy. Add a warranty.

We certify our findings and pay out on them directly, with no underwriting questionnaire. In the event of a valid Benefit Usage, customers may apply the payout to their deductible or use it to reduce what they claim.

Our CEO has raised the industry's warranty ceiling three times since 2014.

Jeremiah Grossman put the first real warranty on web application security at WhiteHat, then broke new ground again on endpoint at SentinelOne. Vulnerability management and EASM had never been warrantied by anyone, so he founded Root Evidence to raise the standard.

Jeremiah Grossman, founder and CEO of Root Evidence

No other vendor backs their findings with money. We back ours with $5M.

We'll show you every vuln that has ever cost a real organization money, plus an average of 40% more assets than your EASM tool.
Sound hard to believe? We're ready to prove it to you.

Book a Demo