Noctelle
Cyber-Insurance Claim Evidence

Every control representation, measured against the technical record.

When a cyber claim turns on what was represented at underwriting versus what the evidence actually shows, that comparison is done by hand — slowly, and one matter at a time. Noctelle produces it as a deterministic, source-cited dossier: neutral, reproducible, and built to withstand scrutiny.

Request a conversation
The Gap

An attestation is not proof.

Cyber policies are underwritten on representations: the insured attests to multi-factor authentication, endpoint protection, patch cadence, backups. Those attestations are true for the moment they're made — everything after is drift.

When a loss occurs, coverage turns on a single question: does the technical record match what was represented? Answering it means reading forensic findings, application materials, and control evidence against one another, line by line, under deadline.

Today that work is manual, unstandardized, and difficult to reproduce. Two reviewers can reach two answers. Noctelle makes the comparison deterministic and the reasoning traceable to its sources.

The question is not "did they attest to the control?" — it is "does the evidence support the representation?"
The Framework

Five dispositions. One is assigned to every representation.

An extraction layer proposes structured candidates from the claim record; a deterministic engine decides. The model proposes, the engine decides — and characterization stops where legal judgment begins.

Two axes, resolved deterministically. Their intersection places every representation in exactly one of five frozen statuses — the same result on every run, for every reviewer.

Temporal alignment

Was the control in force at the moment the record turns on — not merely at some point in the policy period?

Scope alignment

Did it cover the systems, accounts, and data the representation actually claims — not a subset that happens to match?

Contradicted
The technical record affirmatively conflicts with the representation — the control was not in place as attested, on both the timing and the scope the record requires.
Insufficient
The evidence cannot resolve the representation without answering a named construction question — the scope-discipline hold that flags exactly what remains unresolved, rather than guessing.
Supported
The record corroborates the representation on both temporal and scope alignment — the attested control is evidenced where and when it needed to be.
Not Addressed
The reviewed sources are silent on the representation — no evidence speaks to it either way within the record as produced.
Additional Source Required
Resolution is possible, but only with source material not present in the current record — the dossier names precisely what is needed.

No status carries a legal conclusion. Noctelle does not render coverage determinations, severity verdicts, or opinions on materiality — those remain with counsel. The dossier establishes the factual predicate; the judgment stays where it belongs.

The Discipline

Built to be reproduced, not just read.

01

Deterministic by construction

The same record produces the same dossier, every run. Extraction candidates are frozen and hashed at intake; the engine's dispositions never vary between reviewers or between runs.

02

Source-cited throughout

Every disposition traces to the specific evidence behind it. Nothing is asserted that isn't anchored to a source in the record, and the ledger of those sources travels with the dossier.

03

Chain of custody, sealed

A SHA-256 chain binds the record from intake to output, so the dossier's integrity is verifiable after the fact — the same property the evidence itself is held to.

The Deliverable

One artifact: the Noctelle Dossier.

Nine sections, in the order they appear — this is the dossier's own table of contents.

01Matter Profile

The one-page briefing: sources reviewed, pipeline posture, and a findings preview linked to the Matter Matrix.

02Principal Review

Disposition counts by status, plus a plain-language account of every open item and what would resolve it.

03Chronology

The technical record and the claim record, set on parallel timelines and read against each other.

04Matter Matrix

The representation register — disposition, evidentiary basis, and citation for every representation tested.

05Open Questions

Every unresolved representation, with the specific construction question or missing source that would close it.

06Source Ledger

The full source corpus — classification, party attribution, and integrity hash for every document reviewed.

07Matter Scope

The analytical boundary stated plainly: representations tested, sources reviewed, and what falls outside either.

08Trace Record

The evidentiary basis for each disposition, source by source.

09Record Integrity

A SHA-256 hash for every artifact, chained to one canonical proof record for independent verification.

Runs where the evidence lives. Client-installed, with a local deterministic proof engine — no Noctelle servers, no data retention, air-gap capable.

Maps the record; never argues from it. No conclusions of law, coverage determinations, severity scores, or recommended actions — the judgment stays with counsel.

Who It's For

The people who have to answer the coverage question.

Carrier Coverage & Claims

Leadership assessing representation-versus-evidence at claim time, across a portfolio of matters, on a defensible and consistent basis.

Coverage Counsel

Insurer-side counsel who need the factual predicate assembled and traceable before the questions of materiality and reliance are argued.

Monitoring & Program Managers

MGAs and program managers who need a repeatable, neutral index of control representations against the record as claims develop.

A Note on Neutrality

Noctelle indexes what the record shows. It does not advocate, does not decide coverage, and does not render the verdict — it establishes what the evidence supports, and leaves the conclusions to the parties whose role it is to draw them.

Request a conversation.

Noctelle is opening conversations with a small number of design partners. If your practice touches cyber-claim coverage, we'll walk you through a live dossier and where it fits your workflow.

Or write directly — dante@noctelle.ai

Sent straight to our team — we typically reply within a business day.