Skip to main content
For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
Third-party risk teams are asked to diligence Coverbase the way they diligence everyone else. This page answers the contractual questions that normally arrive as a redline, so you can get through them before the negotiation rather than during it.
Your executed agreement governs. This page describes the standard Coverbase positions and the operational reality behind them; it is not the contract, and enterprise terms are negotiated.

Incident and breach notification

Coverbase maintains a documented incident-response plan with defined severity levels, named roles and a timed escalation path. See Security governance for the process and Support, service levels and escalation for the response and update clocks. On notification specifically:
  • We notify affected customers of incidents affecting their data, in line with our contractual and regulatory obligations, through the named contacts on your account.
  • Notification windows are contractual and we negotiate on them. Coverbase contracts with supervised financial institutions, and we are used to notification clauses drawn to a specific regulatory window rather than to a vague “without undue delay”. If your institution must notify its primary federal regulator within 36 hours of determining that a notification incident has occurred (12 CFR 53, 12 CFR 225 subpart N, or 12 CFR 304 subpart C, depending on your supervisor), your service-provider notification clause needs to leave you time to make that call. Bring the language you need; take it to your Coverbase account team and legal contact early, and it is a negotiation rather than a surprise.
  • What we commit to operationally. Security and platform monitoring surface anomalous activity for triage; on-call responders contain and remediate by severity; customer-affecting events are published to status.coverbase.com once impact is confirmed, without waiting for the incident to be formally classified; and every material incident is followed by a post-incident review, with a root-cause analysis provided for a P0.
  • Report an incident to us at security@coverbase.ai. We acknowledge within one business day.

Data return and destruction on exit

Get your data out, any time

Nothing about exit depends on Coverbase’s cooperation. Throughout the engagement you can pull vendor, assessment, evaluation, control, finding, obligation and contract data through the Export API, download every document in bulk as an archive, and generate a complete due-diligence file per third party.

Deletion on termination

On termination, customer data is deleted in line with the agreed terms. Deletion cascades to dependent artifacts rather than leaving orphans, and extends to personal data held at a screening provider on your instruction. Deleted data ages out of backups on the backup-retention schedule.

Certification of destruction

Written confirmation of deletion is available on request at the end of an engagement. Ask your account team, or security@coverbase.ai.

Export is not a paid service

Export is a standard product capability available to any admin, not a paid professional-services engagement and not something that has to be requested. That is deliberate: a system of record that is hard to leave is a concentration risk in its own right.
Run your exit test before you need it. Pull a full export and a due-diligence package for one vendor during your evaluation, and you will know exactly what an exit looks like rather than taking anyone’s word for it, ours included.

Term, renewal and notice

Subscription term, renewal mechanics and notice periods are set in your order form. Coverbase’s standard position is a stated term with a defined notice period rather than an automatic renewal that turns over silently, and we are comfortable with clauses requiring advance written notice of renewal and of any price change. Two practical notes:
  • We use our own product on our own paper. Coverbase tracks contract dates, notice windows and renewal deadlines as first-class obligations, which is exactly the capability that stops a renewal from surprising anyone. Load your Coverbase agreement into your own tenant and it reminds you before your notice window closes.
  • Ask early. Term, renewal, notice, liability, indemnity and incident notification are the six clauses that take longest to settle. Raise them with your account team at the start of an evaluation rather than at signature.

Subprocessors

Subprocessors that process customer data are assessed for security and privacy posture before they touch customer data, and reassessed on a recurring basis. We use Coverbase to do it. A current subprocessor list is available on request, and material changes are communicated in line with your agreement.

Diligence package

Everything a third-party risk team normally asks for, available to customers and prospects under a mutual NDA from security@coverbase.ai:

Support, service levels and escalation

Severity ladder, response clocks, escalation path and the uptime commitment.

Regulatory alignment

How Coverbase maps to the guidance your examiner cites.

Data protection

Encryption, residency, retention and deletion in technical detail.

Working with Coverbase

Company profile, roadmap transparency and how customers shape what gets built.