generated: '2026-07-25' method: derived source: review.yml plus live probes of the Direct Line Group estate on 2026-07-25 scope: >- Direct Line Group publishes no machine-readable API contract, so nothing here is derived from an OpenAPI, AsyncAPI or GraphQL document. Every entry is an honest statement about what the group's public surface does and does not evidence. The two positives are transport-layer facts observed directly on the group's gated API hosts; everything else is a recorded absence, not a failure to look. standards: - id: openapi conforms: false evidence: No OpenAPI or Swagger document served on any brand host, the group API host (api.directlinegroup.co.uk), the brand API host (api.bymiles.co.uk) or the docs host. /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs and /redoc all miss. - id: asyncapi conforms: false evidence: No event, streaming or webhook catalog published anywhere on the estate. - id: graphql conforms: false evidence: No /graphql surface found on any group or brand host. - id: grpc conforms: false evidence: No published .proto and no gRPC endpoint; the group GitHub organization has zero public repositories. - id: oauth2 conforms: false evidence: No /.well-known/oauth-authorization-server on any host (all 404 or soft-404). - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any host (all 404 or soft-404). - id: rfc9116-security-txt conforms: false evidence: No /.well-known/security.txt on any of the eight brand, group, API or docs hosts probed. - id: rfc8414-api-catalog conforms: false evidence: No /.well-known/api-catalog on any host. - id: rfc9457-problem-details conforms: false evidence: No public error contract is documented; the only observable error bodies are an nginx 403 page (api.directlinegroup.co.uk) and Amazon API Gateway's {"message":"Forbidden"} envelope (api.bymiles.co.uk), neither of which is application/problem+json. - id: mutual-tls conforms: true evidence: api.directlinegroup.co.uk sends a TLS CertificateRequest during the handshake — the MuleSoft Anypoint gateway requires a client certificate from partner and internal consumers. This is a private integration control, not a published standard the group claims. - id: tls-1-3 conforms: true evidence: Ten of eleven reachable hosts negotiate TLSv1.3; docs.directline.com is the lone TLSv1.2 host. See security/direct-line-group-domain-security.yml. - id: acord conforms: false evidence: No mention of ACORD, ACORD XML, AL3, ACORD certification or NGDS anywhere in the group's public material or on any brand property. Consistent with the UK personal-lines market and with the group's 2023 exit from brokered commercial lines (NIG/FarmWeb sold to RSA). - id: polaris-imarket conforms: false evidence: No Polaris Standards or imarket reference found. Polaris/imarket is the UK broker-insurer data-exchange seam; Direct Line Group is a direct writer with no broker channel, so it does not sit on that seam. - id: uk-open-banking conforms: partial evidence: The By Miles brand was reported as FCA-authorised under the Open Banking regulations in 2020 (used to verify credit and payment history during quote), but no Open Banking API is published by the group and no supporting document is served on bymiles.co.uk. Recorded as a reported consumer-side use of a third-party Open Banking API, not a Direct Line Group conformance claim. - id: uk-open-finance conforms: false evidence: The UK has no open-insurance obligation. The FCA's Open Finance work remains consultation rather than rule, so there is no regime requiring Direct Line Group to expose quote, bind, issue or FNOL as an API. - id: blueprint-two-london-market conforms: false evidence: Blueprint Two, PPL, Whitespace and Ki are the UK's market-wide API modernization programmes, but they serve the Lloyd's subscription market of brokers and syndicates. Direct Line Group does not participate in that market. regulatory: - regime: FCA jurisdiction: United Kingdom role: Conduct regulator for the group's insurance activity. api_obligation: none - regime: PRA jurisdiction: United Kingdom role: Prudential regulator for the group's underwriting entities. api_obligation: none - regime: UK GDPR / Data Protection Act 2018 jurisdiction: United Kingdom role: Data-protection regime covering the group's processing. evidence: https://www.brandsprivacypolicy.co.uk/policy — the U K Insurance Limited privacy notice covering the Direct Line, Churchill, Privilege, Darwin and Green Flag brands. api_obligation: none summary: machine_readable_contracts: 0 standards_conformed: 3 standards_not_conformed: 12 compliance_program_published: false note: No Compliance pointer is wired into apis.yml — the group publishes no trust center, no certification list (SOC 2, ISO 27001, PCI DSS) and no security policy page, so there is nothing to point at.