A company that is indemnifying their customers for security lapses perhaps?
Or a company that is handling HIPAA, GDPR or other sensitive data and is certifying that they are following policies around employee training, data sovereignty and document handling?