# Cytora > Cytora is a London-headquartered insurtech (founded 2012, University of Cambridge spinout, acquired by Applied Systems in September 2025) selling a digital risk processing platform to commercial insurers, wholesale brokers, MGAs and reinsurers. It digitises inbound submissions arriving as email, PDF, spreadsheet and broker API payloads, maps them onto pre-built line-of-business schemas, enriches them from ~60 third-party risk-data partners, evaluates appetite and priority rules, and routes them into downstream underwriting and claims systems. **API posture: partner-gated, enterprise-only.** Cytora runs a real production API gateway (api.cytora.com) and a real ReadMe-hosted API reference (docs.cytora.com), but the reference is entirely password-protected and the gateway resets anonymous TLS connections. There is no self-serve developer signup, no public OpenAPI, no public SDK, no public Postman collection, no MCP server and no published webhook or event catalog. Credentials require a contract; the entry point is a sales conversation at https://cytora.com/request-a-demo. Generated by API Evangelist from the public record — this file is not published by Cytora. ## APIs - [Cytora Platform API](https://docs.cytora.com/): production REST gateway at https://api.cytora.com — documentation password-protected, no public specification, TLS reset for anonymous clients - [Cytora Identity (Auth0 OIDC)](https://auth.cytora.com/.well-known/openid-configuration): the only anonymously reachable machine-readable Cytora surface — OAuth 2.0 / OpenID Connect authorization server ## Specs - No OpenAPI, Swagger, AsyncAPI, GraphQL SDL, Protobuf or JSON Schema is publicly retrievable for Cytora (verified 2026-07-25 against the docs host, the API host, the console host and the marketing site) ## Artifacts - [Authentication profile](authentication/cytora-authentication.yml): OAuth 2.0 via Auth0 EU tenant — client_credentials for machine-to-machine, authorization_code + PKCE for the console, private_key_jwt and DPoP (ES256) supported - [OAuth scopes](scopes/cytora-scopes.yml): stock OIDC identity scopes only; no product or resource scopes published - [Well-known discovery index](well-known/cytora-well-known.yml): every /.well-known/ probe and its HTTP status, plus the saved discovery documents - [Conventions](conventions/cytora-conventions.yml): bearer auth, URI-path versioning (v2), X-Request-Id tracing, and the resource path surface observed in the published Risk Console client - [Lifecycle](lifecycle/cytora-lifecycle.yml): Statuspage with five service components; no public deprecation policy, SLA or changelog - [Conformance](conformance/cytora-conformance.yml): OAuth 2.0 / OIDC / RFC 8414 / RFC 7636 / RFC 8628 / RFC 8693 / RFC 9449 confirmed live; no ACORD alignment - [Trust center](security/cytora-trust-center.yml): ISO/IEC 27001:2022 and ISO/IEC 42001:2023 signed certificates, read directly - [Domain security](security/cytora-domain-security.yml): TLS, HSTS, DNSSEC, CAA, SPF and DMARC probe results ## Docs - [Documentation (password wall)](https://docs.cytora.com/) - [Risk Console application (login)](https://uwp.cytora.com) - [Status page](https://status.cytora.com/) - [Trust center](https://trust.cytora.com/) - [Risk Flow Academy — API lesson](https://cytora.com/risk-flow-academy/academy-lessons/api) - [Pre-built schemas (human-readable, no machine-readable download)](https://cytora.com/digital-risk-processing/pre-built-schemas) ## Company - [Website](https://cytora.com/) - [Blog](https://cytora.com/risk-flow-center/blog) - [Customers](https://cytora.com/customers) - [Data ecosystem partners](https://cytora.com/digital-risk-processing/data-ecosystem) - [Privacy policy](https://cytora.com/privacy-policy) - [Contact](https://cytora.com/about-us/contact-us) - [Request a demo](https://cytora.com/request-a-demo) ## Metadata - generated: 2026-07-25 - method: generated - source: apis.yml, review.yml and live probes of cytora.com, docs.cytora.com, api.cytora.com, auth.cytora.com, uwp.cytora.com, status.cytora.com and trust.cytora.com