generated: '2026-07-25' method: searched source: >- https://apollocover.com/security (published security posture page) plus derivation from openapi/apollo-insurance-affiliates.yml, openapi/apollo-insurance-affiliates-legacy.yml and openapi/apollo-insurance-covertrack.yml note: >- APOLLO conforms to almost none of the cross-cutting API standards, and — unusually for an insurance company — to none of the insurance industry data standards. No ACORD, AL3, IVANS, or agency-management-system reference appears anywhere in its public site, its developer portal or its OpenAPI definitions. Canada has no open-insurance mandate: OSFI supervises prudentially, the provinces (FSRA in Ontario, AMF in Quebec) supervise market conduct, and Consumer-Driven Banking excludes insurance, so nothing standardises this surface. standards: - id: openapi-3.0 conforms: true evidence: openapi/apollo-insurance-affiliates.yml and -affiliates-legacy.yml declare openapi 3.0.0 - id: openapi-3.1 conforms: true evidence: openapi/apollo-insurance-covertrack.yml declares openapi 3.1.0 - id: asyncapi conforms: false evidence: >- No AsyncAPI document is published. The one event surface (a partner-destination policy callback) is modelled as an ordinary OpenAPI path, explicitly annotated "this is not an actual endpoint, just the specification for the callback", rather than as an OpenAPI callback object or an AsyncAPI channel. - id: oauth2 conforms: false evidence: no oauth2 securityScheme in any spec; authentication is a static x-api-key header - id: oidc conforms: false evidence: no openIdConnect securityScheme; /.well-known/openid-configuration 404 on every host - id: rfc8414-authorization-server-metadata conforms: false evidence: /.well-known/oauth-authorization-server 404/403 on every host - id: rfc9457-problem-details conforms: false evidence: >- Validation errors return a proprietary Joi/celebrate envelope under a `message` object; no application/problem+json media type appears in any spec - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt 404/403 on every host - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog 404/403 on every host - id: rfc8594-sunset-header conforms: false evidence: no Sunset or Deprecation response header declared; no deprecation policy published - id: json-api conforms: false evidence: responses use a bare `data` wrapper, not the JSON:API media type or document structure - id: idempotency-key-header conforms: false partial: true evidence: >- No Idempotency-Key header. A client-supplied `externalId` body field on application creation is documented as preventing duplicate applications — a deduplication key, not the IETF idempotency-key draft. See conventions/apollo-insurance-conventions.yml. - id: pagination conforms: false evidence: >- GET /compliance/{partnerId}/{propertyId} returns an unbounded array with no cursor, offset, limit or page parameter - id: scim conforms: false evidence: no /Users or /Groups paths - id: odata conforms: false evidence: no $filter/$select/$expand query conventions - id: fhir-r4 conforms: false evidence: not a healthcare API - id: fapi conforms: false evidence: no FAPI security profile; no mTLS, no PAR, no sender-constrained tokens - id: psd2 conforms: false evidence: not a payments API and not in scope of EU payment regulation - id: acord conforms: false evidence: >- No ACORD standard (AL3, ACORD XML, ACORD Reference Architecture) is referenced anywhere in the public surface. The tenant question set is an APOLLO-proprietary schema (TenantInsuranceQuestions / TenantInsuranceQuoteQuestions). - id: ivans conforms: false evidence: no IVANS Download / IVANS Exchange reference anywhere in the public surface - id: openinsurance-mandate conforms: false evidence: >- Canada has no open-insurance mandate. Consumer-Driven Banking (Canada's open-banking framework) explicitly excludes insurance. APOLLO published this surface as a distribution strategy, not to satisfy a regulator. compliance_program: published: true url: https://apollocover.com/security detail: security/apollo-insurance-trust-center.yml certifications_named: - {name: SOC 2 Type 2, held_by: AWS data centres and Stripe, apollo_held: false} - {name: ISO 27001, held_by: AWS, apollo_held: false} - {name: PCI DSS, held_by: Stripe, apollo_held: false} apollo_operated_controls: - annual third-party penetration testing of infrastructure, web applications and APIs - internal vulnerability-management SLA with severity classification - mandatory peer code review via pull request, plus automatic static code analysis and dependency scanning - 24/7 threat monitoring (AWS GuardDuty, DataDome, third-party SOC) - AES-256 encryption at rest (AWS KMS), TLS v1.2 minimum in transit - documented incident response plan with customer, regulator and law-enforcement notification - enforced MFA across AWS and source control; security awareness training for staff and contractors caveat: >- Every named certification is inherited from an infrastructure or payment vendor. APOLLO does not claim a SOC 2, ISO 27001 or PCI DSS certification of its own, and publishes no audit report, no trust-portal and no certificate. regulatory: jurisdiction: Canada entity: APOLLO Insurance Agency Ltd. (o/a APOLLO Brokerage in Ontario); APOLLO Insurance Solutions Ltd. licensing: >- Licensed retail brokerage maintaining corporate licensing in provinces across Canada; availability of products depends on provincial licensing. conduct_disclosures: - {name: RIBO Conduct fact sheet, url: 'https://3917439.fs1.hubspotusercontent-na1.net/hubfs/3917439/apollocover%20website/RIBO_Conduct_Sheet_040622-fact_sheet.pdf'} - {name: RIBO Conduct guidance, url: 'https://3917439.fs1.hubspotusercontent-na1.net/hubfs/3917439/apollocover%20website/RIBO_Conduct_Sheet_040622-guidance.pdf'} - {name: Disclosure Statement, url: 'https://platform-assets.apollocover.com/apollocover/Disclosure-Statement.pdf'} underwriting: >- APOLLO does not underwrite; it distributes on commission on behalf of A+ to A- rated Canadian carriers.