Last updated: July 18, 2026 · Version 1.0
This page explains how we think about cyber risk - how the product is designed to reduce it, how responsibility is shared, and how insurance fits into an Enterprise engagement. We aim to be precise and honest here rather than to reassure with claims we can’t stand behind.
soul_state. There is no conversation database to breach, ransom, or leak. Insurance covers residual
risk; statelessness removes most of the risk before insurance is ever needed.Risk transfer (insurance) is the last layer. Everything before it is risk reduction, and that is where LEO Soul is strongest:
soul_state are never persisted by us,
so the highest-value target simply isn’t there.Our contracts set out who bears which risk. In plain terms: we are responsible for the security of the Software and the Hosted Service as described on the Security page; you are responsible for your credentials, your team’s access, your Model Provider relationship, human oversight of outputs, and - when you self-host - your own infrastructure. Liability is capped and certain damages are excluded as set out in the Terms of Service and, for Enterprise, the MSA. Data-protection responsibilities are governed by the DPA.
We are an early-stage company and we describe our insurance the way we describe everything else - honestly. As part of our Enterprise-readiness program, cyber-liability and technology errors & omissions (E&O) coverage is addressed in our vendor-risk documentation, and we maintain business insurance commensurate with our size and stage. We do not publish specific policy limits or carrier details on this public page. The relevant point for most customers is upstream of any policy: because we hold no conversation data, the exposure a cyber policy would need to cover is structurally limited.
For an Enterprise engagement, a certificate of insurance (COI) and the coverage details relevant to your procurement can be provided under NDA on reasonable request, as reflected in the MSA’s insurance clause. If your security or procurement team has specific coverage requirements, raise them during the engagement and we’ll address them in the order form.
Insurance is shared responsibility. Depending on your industry and jurisdiction, you may carry your own cyber, technology E&O, or professional-liability coverage, and you remain responsible for your own compliance, controls, and human oversight of AI outputs. Nothing here is a substitute for your own risk assessment. A vendor certificate does not transfer your obligations to your customers or regulators.
This page is an informational description of our approach to cyber risk and insurance. It is not an insurance policy, not a certificate of insurance, not a warranty or guarantee of coverage, and not legal or insurance advice. Coverage, where it exists, is defined solely by the actual policy documents, and contractual risk allocation is defined by the Terms and the MSA. If anything here appears to conflict with those documents, those documents control.
For insurance, security, or procurement questions, contact our team or email support@kadropiclabs.com with “Insurance” in the subject line.