SB StartupBasket
All ideas
77 /100 GO Medium complexity

AttestTrail — cyber-attestation ledger for MSPs

Proves the security controls you swore to your cyber insurer stayed on every day of the policy year.

— views
Evaluation Scores
77/100

GO

Overall Score

17
Problem
13
Demand
11
Build
13
Distrib.
12
Revenue
8
Time
6
Defense

AttestTrail

1. One-liner

Proves the security controls you swore to your cyber insurer stayed on every day of the policy year.

2. Trend signal — why now?

Cyber underwriting stopped being a checkbox exercise in 2026. It became an evidence exercise — and nobody sells the evidence.

Three things changed at once:

Carriers moved from questionnaires to forensic proof. Per Barracuda’s SmarterMSP, the old flow was “a client would complete an insurance form, answer ‘yes’ when asked about MFA, and be issued a policy.” Not anymore. Stanislav Kazanov of Innowise, quoted in the same piece: “today if there’s any type of breach through a service account that was forgotten about and used by an employee, or through a legacy VPN that wasn’t required to have MFA implemented, the insurance company will deny the claim because the client did not accurately represent what measures were in place for their security posture.”

The denial rate is now the story, not the premium. More than 40% of cyber insurance claims filed in 2024–2025 received no payout, and the most common reason was failure to maintain the controls the business attested to. Application denial rates have climbed to ~45% as carriers tighten underwriting, even as premium increases have cooled to single digits. One MSP-focused source puts SMB assessment failure at 73% in 2026, mostly from documentation, not from missing tools.

Case law made rescission cheap for the carrier. In Travelers v. International Control Services, the insured attested to MFA; Travelers’ investigation found MFA protected only the firewall and not the ransomed server. Travelers sought rescission and got it — the policy was declared void from inception, and the $1M claim went unpaid. The misrepresentation being unintentional did not matter. Some courts don’t even require a causal link between the misstatement and the loss.

And the liability is now flowing to the IT provider. In Ace American Insurance Co. v. Congruity 360 and Trustwave Holdings, the carrier paid roughly $500,000 on a ransomware claim at CoWorx Staffing, then turned around and sued the client’s IT provider and MSSP for failing MFA enforcement and timely detection. MSP Channel Insights states it plainly: “While business owners sign insurance applications, MSPs understand what security controls are in place, and when attestations are inaccurate, MSPs are often named in downstream errors and omissions claims.”

So the MSP is now personally exposed to a document they don’t sign, about a control state they can’t currently prove, on a date twelve months in the past.

Provenance:

3. The opportunity

Every vendor in this market sells the score. Nobody sells the proof.

Guardz — the MSP security platform aimed squarely at this problem — generates a “Client Security Report”: a shareable PDF with security score, threats contained, high-risk users, executive insight, plus CSV exports of issue-level detections. Their own guidance concedes the limit: the report does not replace insurer-requested configuration records, device inventories, backup test results, training records, or incident response documentation. That sentence is the product spec for AttestTrail.

Vanta and Drata solve an adjacent problem for a different buyer at a different price. Vanta starts around $7,500–$12,000/year, Drata’s foundation plan around $15,000/year for up to 50 FTEs. They exist to get a startup through SOC 2 so it can sell to enterprise. A 40-person plumbing contractor paying $3,200/year for a $1M cyber policy is not buying a $12,000/year GRC platform to protect it. That’s a 4× inversion — the tool costs more than the risk transfer it protects.

The gap is specific and structural:

  • Posture tools answer “are you secure today?” The carrier’s forensic examiner asks “was MFA enforced on the account that got popped, on 14 March, nine months ago?”
  • Attestation is a point-in-time act with a twelve-month tail. You sign in January. The exception you granted the CFO in April, the service account the new sysadmin excluded in June, the EDR agent that fell off six laptops in a hardware refresh in August — each one silently converts your signed application into a material misrepresentation. Nobody watches that drift against the specific sentences you signed.
  • The evidence must be contemporaneous to be worth anything. You cannot reconstruct “MFA was enforced in March” in December. Screenshots taken after the breach prove nothing. The record has to have been written before the loss.

That’s the wedge. Not a security product — a defensibility record. Bind the exact attested statements from the client’s application to a daily-verified evidence stream, and produce a sealed, timestamped ledger that a coverage lawyer can hand to an adjuster.

The AI is load-bearing at the front door: a broker’s questionnaire is an unstructured PDF, different for every carrier, written in insurance English. Turning “Is MFA enforced for all remote access, including VPN and RDP, and for all privileged and service accounts?” into a set of machine-checkable assertions against Entra, Okta, Google Workspace, and an RMM — automatically, for 40 different carrier forms — is the thing that was not cheaply doable two years ago.

4. Target market

  • Primary customer: Owner/vCISO at a managed service provider with 15–120 SMB clients, US/UK/AU/CA, $1M–$15M revenue. They sit in the E&O blast radius of every client attestation and currently assemble renewal packets by hand.
  • Secondary customer: Direct-buy SMB in the $3K–$8K premium band — professional services, healthcare practices, specialty contractors, 25–200 employees — with internal IT and no MSP.
  • Why they buy (in their words): From MSP Channel Insights — “when attestations are inaccurate, MSPs are often named in downstream errors and omissions claims.” And from the same source, the winning behaviour they’re being told to adopt: “MSPs winning renewal conversations in 2026 are producing attestation evidence before brokers ask. They deliver annual documentation packets mapped directly to common cyber insurance application questions.” That packet is currently built in Word, by hand, once a year, at 2am the week before renewal.
  • Rough TAM reasoning: ~40,000 MSPs in North America alone, the large majority serving SMBs and nearly all of them now touching client cyber renewals. Capturing 400 of them — 1% — at $600/mo average is $2.9M ARR. Direct SMB is upside, not the plan.
  • Why now for them: Two forcing functions landed in the same 18 months. Carriers stopped accepting self-attestation, and carriers started suing MSPs. Before 2024 the MSP could shrug at the client’s insurance form. After Ace American, they can’t.

5. Product sketch (MVP)

  • Application ingest. Upload the carrier’s renewal application or broker questionnaire (PDF or portal export). It’s parsed into a structured list of atomic, machine-checkable assertions — “MFA enforced on all admin accounts”, “EDR deployed on 100% of endpoints”, “backups tested within last 30 days”, “annual security awareness training completed by all staff”.
  • Assertion binding. Each assertion is mapped to a live evidence source: Microsoft Entra / Okta / Google Workspace conditional-access policy, EDR console coverage report, backup product’s restore-test log, training platform completion export, RMM patch state.
  • Daily verification with a dated trail. Every assertion is re-checked daily and written to an append-only, timestamped record. The output isn’t a score — it’s “MFA enforcement on admin accounts: TRUE, verified daily 2026-01-14 through 2026-08-29, two exceptions logged with dates and business justification.”
  • Drift alerts tied to the signed sentence. When an exclusion, an exemption, or an uninstalled agent breaks an assertion the client signed, the alert names the application question it just falsified — not a generic security warning.
  • Exception register. Time-bound, justified, owner-assigned exceptions. Brokers can work with a declared, dated gap; a silent gap behind a “yes” is what kills the claim.
  • Renewal packet, one click. The annual documentation packet, mapped question-by-question to the carrier’s form, with per-assertion evidence appendices and coverage dates.
  • Claim-mode export. Given an incident date, produce the sealed evidence bundle for exactly that date — what was enforced, on which accounts, with what verification history — formatted for an adjuster or coverage counsel.
  • MSP multi-tenant view. All clients, all assertions, ranked by renewal date and by which client is currently sitting on a falsified attestation.

6. AI angle — what’s load-bearing

Two places, both real.

Questionnaire → assertion extraction. There is no standard cyber application. Every carrier and every broker writes their own, they change annually, and they’re compound and weaselly: one question routinely bundles five separate technical conditions. Hand-mapping each new form to checkable assertions is exactly the work that stops a two-person team from serving 400 MSPs across 40 carriers. An LLM decomposing compound insurance prose into atomic, source-bound assertions is the scaling mechanism. Remove it and this becomes a consultancy, not a product.

Evidence normalisation. “MFA enforced” means five different shapes across Entra conditional access, Okta policies, Google Workspace enforcement, and an RMM’s inference. Reconciling heterogeneous config exports into a single defensible truth claim — including catching the partial-deployment pattern that sank Travelers v. ICS — is judgment work, not a schema mapping.

What is not AI: the ledger itself. That must be boring, deterministic, and append-only. A hallucinated evidence record is worse than no record — it’s a fresh misrepresentation. AI reads the form and interprets the config; it never writes the proof.

7. Localization angle

N/A — this is a global play, launched English-first.

The duty comes from a policy warranty, not a statute, so there’s no jurisdiction to localise to. The rescission doctrine that gives this teeth is common-law and travels across the US, UK, Canada, and Australia. Practically: launch US MSP channel, expand to UK/AU where the same carriers write the same forms in the same language. A German or Japanese version needs different carrier forms and is a year-two question, not a wedge.

8. Business model — path to $1M–$5M ARR

  • Pricing: MSP tiers — $299/mo up to 10 client tenants, $699/mo up to 30, $1,499/mo up to 80, custom above. Direct SMB: $199/mo single tenant. Claim-mode export included; no per-incident gouging (charging a customer extra during a breach is how you lose a channel).
  • ACV: ~$7,200 blended for MSPs, ~$2,400 direct SMB. Assume 80/20 mix → ~$6,200 blended.
  • To $1M ARR: 135 MSPs at the $699 tier, or a realistic mix of ~90 MSPs plus ~120 direct SMBs. That’s a reachable number from a channel of 40,000 North American MSPs.
  • To $5M ARR: ~650 MSP accounts with the tier mix skewing up as they add tenants, plus a carrier or broker distribution deal (a broker or MGA white-labelling the packet for their book is the step-change; that’s a year-two conversation, not a launch dependency).
  • Expansion path: Grows automatically with the MSP’s client count — the best kind of expansion, because they don’t have to decide to spend more. Then upsells: multi-carrier comparison at renewal, E&O-defence bundle for the MSP’s own policy, and a broker-facing seat.

Cost side is friendly. Daily API polls against Entra/Okta/EDR/backup consoles are cheap; the LLM cost is concentrated in one-time form parsing per carrier per year, amortised across every customer on that carrier. Gross margin should sit comfortably north of 85%.

9. Go-to-market wedge — first 100 customers

  • The subrogation fear-drop, targeted. Ace American v. Congruity 360 is public, named, and terrifying to exactly the buyer. Build a one-page teardown of that case plus Travelers v. ICS, and run it into r/msp (200K+ members, where this is an active recurring topic), the MSP Geek Slack, and Tech Tribe. Not a pitch — a case teardown that ends with “here’s a free tool that tells you which of your clients is currently sitting on a falsified attestation.” Expect the post to do the work; this crowd shares liability news aggressively.
  • Free “attestation drift check.” Single-tenant, read-only, connect Entra or Google Workspace, upload last year’s signed application, get back a list of assertions that are no longer true. This is the entire acquisition engine. An MSP who runs it once on their worst client converts on the spot, because the output is a list of live liabilities with their name on it. Run it free for the MSP’s own tenant first — self-interest before altruism.
  • Peer-group and community sponsorship. MSP peer groups (Evolve, Taylor Business Group, ASCII) meet quarterly and pass vendor recommendations by word of mouth. One 20-minute slot presenting the Ace American teardown to a 25-MSP peer group is a better conversion channel than any ad. Target 6 groups in the first two quarters.
  • Cyber brokers as referrers. Brokers hate incomplete applications — it slows their bind and exposes them to E&O too. Approach 30 SMB-focused cyber brokers with a co-branded renewal packet: their client submits a complete, evidenced application, the broker looks good, the broker refers the MSP. Referral, not revenue-share, to keep it simple.
  • Renewal-date timing. Cyber renewals cluster around January and July. Time outreach 90 days ahead of those — the guidance MSPs are already receiving says starting 14 days out means scrambling. Arrive when the pain is calendared.

10. Build complexity — justification

Medium. The integrations are all documented, stable, off-the-shelf admin APIs — Microsoft Graph, Okta, Google Workspace Admin SDK, plus EDR and backup vendor APIs — and multi-tenant MSP access patterns are a solved shape in this ecosystem. The genuinely custom work is the questionnaire→assertion decomposition layer and the append-only evidence store, which must be tamper-evident enough that an adjuster’s lawyer takes it seriously. Call it 14–18 weeks for two people to a credible v1 covering Entra + Google Workspace + two EDR vendors and three carrier form families. The long pole is breadth of integrations, not depth — which is good, because breadth can ship incrementally after first revenue.

11. Gating checklist

GatePass?Note
Legal in target market✅Read-only config telemetry with customer consent. Not insurance advice, not brokering — carefully stay descriptive (“here is what was true”) and never prescriptive about how to answer a carrier.
Ethical — no harm / dark patterns✅The product’s entire function is making attestations more accurate. It surfaces gaps rather than hiding them; the exception register exists to encourage declared gaps over silent ones.
Market exists (evidence above)✅40%+ claim denial rate, named rescission and subrogation cases, MSPs publicly instructed to produce evidence packets.
1–5 person team can build this✅Two people, 14–18 weeks.
Launchable with <$50K / ₹40L✅API costs, a security review, and a coverage attorney’s review of the claim-mode export format. Well under.

12. Feasibility score

AxisWeightScoreNotes
Problem intensity2017/20A rescinded $1M policy is existential for the SMB and an E&O claim for the MSP. Felt acutely at renewal and catastrophically at claim. Docked 3 because the catastrophic moment is rare per-customer — most buy on fear, not on having been burned.
Demand evidence1513/15Named case law, quantified denial rates, MSP trade press instructing the exact behaviour the product automates, and a competitor publicly conceding it doesn’t cover this. Docked 2: no direct verbatim customer quotes obtained — Reddit was inaccessible during research, so the buyer’s own words are second-hand via trade press.
Build feasibility1511/15Standard APIs, but multi-tenant + tamper-evident storage + broad integration surface pushes this past a 6-week solo build. 14–18 weeks for a pair.
Distribution clarity1513/15Named channels (r/msp, peer groups, brokers), a free tool with a genuinely alarming output, and a calendared trigger. Docked 2 because broker referrals are unproven and MSP peer groups gate-keep.
Revenue mechanics1512/15Pricing sits well under the incumbents and well under the risk it protects. Expansion is automatic with tenant count. Docked 3: MSPs are famously price-sensitive on per-tenant tooling and already carry a stack; this has to displace a line item or justify a new one.
Time to first revenue108/10The free drift check produces a paid conversion in the same session for the right prospect. Realistically 6–8 weeks post-launch to first paying MSP.
Defensibility106/10Soft moat, but real: the accumulated corpus of parsed carrier forms is a genuine asset that compounds, and an evidence ledger with 14 months of history is not something a customer switches away from — the history is the product. A funded competitor could reach parity in 9–12 months.
Total10077/100

13. Qualitative modifiers

Founder-fit tags

technical-heavy · domain-expertise-required

You need someone who can build multi-tenant identity integrations, and someone who can talk credibly about coverage rescission to an MSP owner. A security-background founder with a coverage attorney on advisory is the shape. Selling to MSPs without channel credibility is brutal — they can smell a vendor who’s never run a helpdesk.

Key assumptions to validate (3–5)

  1. Assumption: MSPs will pay $299–$1,499/mo for a defensibility artefact rather than treating it as a checklist they already do in Word. How to test: Run the free drift check for 20 MSPs on one client tenant each; measure how many ask “can I buy this for all my clients” unprompted. Under 4 of 20 and the pricing thesis is wrong.
  2. Assumption: Carrier applications decompose reliably into machine-checkable assertions at acceptable accuracy. How to test: Collect 25 real applications from 3–4 carriers, run extraction, and have a coverage attorney grade the assertion set. Below 90% and every packet needs human review, which kills the margin.
  3. Assumption: The evidence format is actually persuasive to an adjuster. How to test: Take the claim-mode export to 5 coverage attorneys and 2 public adjusters. Ask the blunt question: would this change your posture in a rescission dispute? A shrug is a fatal answer.
  4. Assumption: Guardz/Huntress won’t ship this as a feature in six months. How to test: Track their roadmap and release notes monthly; talk to 10 MSPs about whether they’d want it from their existing security vendor or from a neutral third party. Neutrality may be the answer — evidence produced by the vendor whose control is being attested has an obvious credibility problem.

Risk flags

  1. Platform dependency: Entra, Okta, Google Workspace, and EDR vendor APIs are the entire evidence supply. A pricing change or admin-API restriction at Microsoft is a direct hit. Mitigate by breadth, not depth.
  2. Incumbent absorption: Guardz, Huntress, or an RMM vendor (ConnectWise, NinjaOne) bolting this on as a feature is the single most likely way this dies. The counter is the carrier-form corpus and the neutrality argument — but it’s a race.
  3. Liability contagion: If AttestTrail’s record is ever wrong in a client’s favour, the product becomes a party to a misrepresentation. Requires conservative defaults (“unverified” not “compliant”), tight contractual language, and its own E&O policy. Non-optional.
  4. Market timing: If carriers standardise their applications — or start pulling telemetry directly from the client’s tenant themselves — the parsing moat evaporates and the carrier owns the evidence layer. Watch for carrier-side continuous-monitoring programs; a couple already supplement questionnaires with external scanning.

14. Structured verdict

Score:                  77/100
Verdict:                GO
Confidence:             Medium
Best-fit builder:       Security-technical founder with MSP channel credibility, plus a coverage attorney on advisory
Time to revenue:        14–18 weeks to v1, first paying MSP 6–8 weeks after launch
Capital to launch:      $15–25K (API costs, security review, attorney review of the claim-mode export)
Top 3 assumptions to validate first:
  1. MSPs pay for defensibility, not just visibility — free drift check on 20 MSPs, count unprompted buying signals
  2. Carrier applications decompose to assertions at >90% accuracy — 25 real forms, graded by a coverage attorney
  3. The claim-mode export persuades an adjuster — put it in front of 5 coverage attorneys and 2 public adjusters
Kill criteria:
  - Abandon if fewer than 4 of 20 MSPs running the free drift check ask to buy it for their full client base
  - Abandon if assertion-extraction accuracy stays under 90% after two iterations — human review per packet destroys the margin
  - Abandon if Guardz, Huntress, or a major RMM ships a dated, claim-grade evidence ledger before v1 launches

15. Next step — 1-week validation sprint

  • Day 1–2: Collect 25 real cyber applications and renewal questionnaires from 3–4 carriers — brokers will hand these over for the price of a coffee, they’re not confidential. Hand-decompose ten of them into atomic assertions. If a human can’t do it unambiguously, an LLM certainly can’t, and the product is dead on the spot.
  • Day 3–4: Build the throwaway drift check — Entra read-only connection, one signed application, a diff. Run it live against 8 MSPs’ own tenants (their own, not their clients’ — no consent friction, and self-interest gets you in the door). Record the reaction verbatim.
  • Day 5: Put the resulting evidence output in front of 3 coverage attorneys and ask one question: in a rescission dispute, does this document change your position?

Go / no-go: Proceed only if ≥5 of 8 MSPs find at least one falsified assertion in their own tenant AND ≥2 of 3 attorneys say the artefact is materially useful in a coverage dispute. If MSPs come back clean, the drift problem is smaller than the trade press implies and there’s no daily job to do — at which point this is a once-a-year packet generator worth maybe $49/mo, and not a business worth building.

Interested in a detailed proposal?

Get a deep-dive with market research, competitive analysis, and implementation roadmap.

Contact us

info@startupbasket.ai