Cyber Liability Insurance
Bestis, Inc. (a Delaware corporation) treats the security of our members’ and partners’ data as fundamental to the Bestis Service. As part of our risk-management program, we maintain cyber liability insurance and follow industry-standard security practices. This statement summarizes that coverage and how partners can request supporting documentation.
1. Coverage
Bestis maintains a cyber liability (technology errors & omissions and data breach) insurance policy with a licensed carrier. The policy is designed to respond to covered events such as:
- data breaches and unauthorized access to, or disclosure of, personal information;
- network security failures and related third-party liability;
- breach-response costs, including notification, forensics, and credit monitoring where applicable;
- business interruption arising from covered security incidents; and
- regulatory defense costs, subject to policy terms.
Specific carrier, policy number, coverage limits, and effective dates are set out in our current policy and are available to partners on request under a Certificate of Insurance (see below).
2. Security practices
Our insurance complements — it does not replace — our security controls. These include encryption of data in transit, hashed credentials, secure httpOnly session cookies, least-privilege access controls, network segmentation, logging and monitoring, dependency and vulnerability management, and secure development practices. Further detail is available in our Privacy Policy and Data Processing Agreement.
3. Incident response
In the event of a security incident affecting personal data, Bestis follows a defined incident-response process and will notify affected parties and, where required, regulators without undue delay, consistent with applicable law and our contractual commitments.
4. Requesting a Certificate of Insurance
Business partners and enterprise customers may request a Certificate of Insurance (COI) evidencing our current cyber liability coverage. Please contact [email protected] or [email protected] with your organization’s details and the reason for the request.
5. No third-party rights
This statement is provided for information only. It does not create any coverage for, or confer any rights on, any third party, is not a substitute for the policy itself, and is subject to the actual terms, conditions, limits, and exclusions of the applicable insurance policy, which controls in all respects.
6. Contact
Security and insurance inquiries: [email protected].
