Noctelle
Cyber-Insurance Claim Evidence

Every control representation, measured against the technical record.

When a cyber claim turns on what was represented at underwriting versus what the evidence actually shows, that comparison is done by hand — slowly, and one matter at a time. Noctelle produces it as a deterministic, source-cited dossier: neutral, reproducible, and built to withstand scrutiny.

Request a conversation
The Gap

An attestation is not proof.

Cyber policies are underwritten on representations: the insured attests to multi-factor authentication, endpoint protection, patch cadence, backups. Those attestations are true for the moment they're made — everything after is drift.

When a loss occurs, coverage turns on a single question: does the technical record match what was represented? Answering it means reading forensic findings, application materials, and control evidence against one another, line by line, under deadline.

Today that work is manual, unstandardized, and difficult to reproduce. Two reviewers can reach two answers. Noctelle makes the comparison deterministic and the reasoning traceable to its sources.

The question is not "did they attest to the control?" — it is "does the evidence support the representation?"
The Framework

Five dispositions. One is assigned to every representation.

An extraction layer proposes structured candidates from the claim record; a deterministic engine decides. The model proposes, the engine decides — and characterization stops where legal judgment begins.

Two axes, resolved deterministically. Their intersection places every representation in exactly one of five frozen statuses — the same result on every run, for every reviewer.

Temporal alignment

Was the control in force at the moment the record turns on — not merely at some point in the policy period?

Scope alignment

Did it cover the systems, accounts, and data the representation actually claims — not a subset that happens to match?

Contradicted
The technical record affirmatively conflicts with the representation — the control was not in place as attested, on both the timing and the scope the record requires.
Insufficient
The evidence cannot resolve the representation without answering a named construction question — the scope-discipline hold that flags exactly what remains unresolved, rather than guessing.
Supported
The record corroborates the representation on both temporal and scope alignment — the attested control is evidenced where and when it needed to be.
Not Addressed
The reviewed sources are silent on the representation — no evidence speaks to it either way within the record as produced.
Additional Source Required
Resolution is possible, but only with source material not present in the current record — the dossier names precisely what is needed.

No status carries a legal conclusion. Noctelle does not render coverage determinations, severity verdicts, or opinions on materiality — those remain with counsel. The dossier establishes the factual predicate; the judgment stays where it belongs.

The Discipline

Built to be reproduced, not just read.

01

Deterministic by construction

The same record produces the same dossier, every run. Extraction candidates are frozen and hashed at intake; the engine's dispositions never vary between reviewers or between runs.

02

Source-cited throughout

Every disposition traces to the specific evidence behind it. Nothing is asserted that isn't anchored to a source in the record, and the ledger of those sources travels with the dossier.

03

Chain of custody, sealed

A SHA-256 chain binds the record from intake to output, so the dossier's integrity is verifiable after the fact — the same property the evidence itself is held to.

The Deliverable

One artifact: the Noctelle Dossier.

Nine sections, in the order they appear — this is the dossier's own table of contents.

01Matter Profile

Scope, pipeline posture, and a findings preview at a glance.

02Principal Review

Disposition counts and a plain-language summary of every open item.

03Chronology

The technical and claim timelines, set side by side.

04Matter Matrix

Every representation, its disposition, and the evidence behind it.

05Open Questions

What's unresolved, why, and what would resolve it.

06Source Ledger

Every source reviewed — classified, attributed, and hashed.

07Matter Scope

What was tested, and the boundary of what wasn't.

08Trace Record

The evidentiary observations behind each disposition.

09Record Integrity

Artifact hashes, chained to one canonical proof record.

Runs where the evidence lives. Client-installed, with a local deterministic proof engine — no Noctelle servers, no data retention, air-gap capable.

Maps the record; never argues from it. No conclusions of law, coverage determinations, severity scores, or recommended actions — the judgment stays with counsel.

Who It's For

The people who have to answer the coverage question.

Carrier Coverage & Claims

Leadership assessing representation-versus-evidence at claim time, across a portfolio of matters, on a defensible and consistent basis.

Coverage Counsel

Insurer-side counsel who need the factual predicate assembled and traceable before the questions of materiality and reliance are argued.

Monitoring & Program Managers

MGAs and program managers who need a repeatable, neutral index of control representations against the record as claims develop.

A Note on Neutrality

Noctelle indexes what the record shows. It does not advocate, does not decide coverage, and does not render the verdict — it establishes what the evidence supports, and leaves the conclusions to the parties whose role it is to draw them.

Request a conversation.

Noctelle is opening conversations with a small number of design partners. If your practice touches cyber-claim coverage, we'll walk you through a live dossier and where it fits your workflow.

Or write directly — dante@noctelle.ai

Sent straight to our team — we typically reply within a business day.