generated: '2026-07-25' method: searched source: https://evari.tech/trust also_derived_from: openapi/evari-quotes-api-openapi.yml standards: - id: openapi conforms: partial evidence: Swagger 2.0 (not OpenAPI 3.x) generated by typescript-rest-swagger and published in the evari-quotes-api npm tarball; 49 paths, 56 operations, 70 definitions, unique operationIds on every operation. - id: swagger-2.0 conforms: true evidence: openapi/evari-quotes-api-openapi.yml declares swagger "2.0". - id: oauth2 conforms: false evidence: securityDefinitions declares a single apiKey scheme in the Authorization header; no oauth2 flows anywhere in the spec, and auth.cloudstream.evari.tech exposes no anonymous discovery. - id: openid-connect conforms: false evidence: /.well-known/openid-configuration returns the marketing homepage (catch-all), not a discovery document. - id: rfc8414-oauth-metadata conforms: false evidence: /.well-known/oauth-authorization-server returns the catch-all homepage. - id: rfc9457-problem-details conforms: false evidence: No 4xx/5xx responses and no application/problem+json media type appear in the spec. - id: rfc9116-security-txt conforms: true evidence: https://evari.tech/.well-known/security.txt returns a valid RFC 9116 document with Contact, Expires, Preferred-Languages and Canonical fields. - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returns the catch-all homepage. - id: rfc8594-sunset-header conforms: false evidence: No deprecation or sunset signalling documented or present in the spec. - id: json-schema-draft-07 conforms: true evidence: json-schema/evari-contracts-types.json declares $schema http://json-schema.org/draft-07/schema# with 369 definitions. - id: pagination conforms: true evidence: Consistent offset/limit/sort/order query parameters across 8 collection operations, with {items,total} list envelopes. - id: idempotency conforms: false evidence: No Idempotency-Key parameter, header or documented retry contract. - id: json-api conforms: false - id: odata conforms: false - id: asyncapi conforms: false evidence: No event, streaming or webhook surface is published. "Webhook" appears in the site corpus only as an action an AI assistant may be permitted to call on a customer's system. - id: acord conforms: false evidence: | Zero case-insensitive matches for ACORD, AL3 or IVANS across the full 418,510-byte evari.tech site corpus (llms.txt), and no ACORD element naming anywhere in the 70 quote definitions or the 369 @evari/contracts definitions. Notable for an insurance core-systems vendor: the entity model (Quote, Cover, CoverLimit, InterestedParty, Endorsement, ReferredQuote) is proprietary, not ACORD-aligned. - id: fhir conforms: false note: not applicable (general insurance, not health) - id: pci-dss conforms: not-applicable evidence: Trust Center states card data is handled exclusively by Stripe and never touches Evari servers. compliance_program: published: true url: https://evari.tech/trust certifications: - {name: ISO/IEC 27001, status: certified, verification: independently audited annually by an accredited certification body, scope: 'design, development and operation of the Evari platform'} - {name: GDPR (UK and EU), status: compliant, note: 'Evari Services UK Ltd; DPA available to all customers and part of standard Terms of Service; 72-hour breach notification; RoPA maintained; SCCs cover international transfers'} - {name: SOC 2, status: claimed-only, evidence: 'Asserted once in the pricing-page FAQ ("Evari is SOC 2 compliant"). The Trust Center itself lists only ISO 27001 and GDPR — no SOC 2 report, type or auditor is named anywhere. Recorded as an unverified marketing claim, not a certification.'} controls: encryption: AES-256 at rest, TLS 1.2+ in transit, keys in Google Cloud KMS, HSTS preloading claimed access: RBAC, MFA enforced for staff, least privilege, quarterly access reviews testing: dependency scanning on every merge, regular third-party penetration testing, responsible disclosure programme development: mandatory code review, OWASP Top 10 considered in design and review, infrastructure-as-code with change control data_residency: trust_center: Primary infrastructure on Google Cloud Platform, primary data in EU/UK GCP regions (Evari Services UK Ltd) help_centre: AU/NZ customers on AWS ap-southeast-2, UK eu-west-2, US us-east-1 note: The Trust Center (GCP, EU/UK) and the help centre (AWS, per-region) describe different infrastructure. Recorded as published — the discrepancy is the finding, most likely the CloudStream-era AWS estate versus the current QuivaWorks-era GCP estate. sub_processors: - {name: Anthropic (Claude), purpose: AI model processing, location: United States} - {name: Google (Gemini), purpose: AI model processing, location: United States} - {name: Google Cloud Platform, purpose: infrastructure, location: United Kingdom} - {name: Stripe, purpose: payments and subscription billing, location: United States} - {name: Google Analytics, purpose: website analytics, location: United States}