# Evari > Evari is an insurance technology company founded in Sydney by Daniel Fogarty (former CEO of Zurich Australia and New Zealand), Robert Jeffery and Brack Norris, now operating as Evari Services UK Ltd. It launched as a digital small-business and trades insurance brand at evari.insure (a Lloyd's coverholder), moved upstream into CloudStream — a cloud-native policy administration platform covering quote, bind and issue through endorsement, renewal and cancellation — and today sells insurance AI operations to brokers, MGAs and insurers as 30-day assistant deployment sprints on the third-party QuivaWorks platform. Evari publishes **no developer portal, no API reference and no self-serve API access**. Every candidate developer host (developer./developers./docs./api. across evari.com, evari.insure and evari.tech) fails DNS, and the paths /developers, /api, /docs, /integrations, /changelog and /roadmap on evari.tech all return the marketing homepage byte-for-byte. Its running API hosts are tenant-scoped: api.cloudstream.evari.tech returns 404 unauthenticated, api.envest.evari.tech returns 502. One real, first-party machine-readable contract does exist. Evari published its Quotes microservice to npm as `evari-quotes-api` (author "Evari Insure", maintainer brack@evari.insure), and the tarball ships a generated **Swagger 2.0 document (49 paths, 56 operations, 70 definitions)** plus a **draft-07 JSON Schema type set with 369 definitions** covering the wider platform contracts. Both are harvested here. This is the only published description of an Evari API anywhere. Generated by the API Evangelist enrichment pipeline, 2026-07-25. Provider surfaces are marked [provider]; everything else is an API Evangelist artifact in this repository (github.com/api-evangelist/evari). ## Specs - [Evari Quotes API — Swagger 2.0](openapi/evari-quotes-api-openapi.yml): Harvested verbatim from dist/swagger.yaml in the evari-quotes-api npm tarball. Quote lifecycle, questions, covers, pricing, endorsements, referrals, attachments, health. Internal surface at /api/quotes/**, customer-facing mirror at /api/quotes/public/**. - [Original Swagger JSON](openapi/_original/evari-quotes-api-swagger.json): The same document as published, unmodified. - [Evari contracts JSON Schema](json-schema/evari-contracts-types.json): draft-07, 369 definitions generated from the private @evari/contracts package — quotes, claims, agents, billing, cancellation, attributes. Most of these entities have no published HTTP surface. - [API Evangelist overlay](overlays/evari-quotes-api-overlay.yaml): Provenance, the inferred host binding, and the internal/public tag split. Records the spec's gaps rather than patching them. ## Artifacts - [Authentication](authentication/evari-authentication.yml): single apiKey scheme in the Authorization header; no OAuth, no scopes. - [Conventions](conventions/evari-conventions.yml): offset/limit/sort/order pagination, PATCH semantics including update-by-internal-key, the public/internal split, and the absence of idempotency and of any documented error contract. - [Data model](data-model/evari-data-model.yml): Product → Quote → Answer/Cover/InterestedParty → price components, plus Endorsement (with a first-class diff model) and ReferredQuote. - [Agentic access](agentic-access/evari-agentic-access.yml): recommended x-agentic-access contracts for all 56 operations (39 read, 17 write). - [MCP (candidate)](mcp/evari-mcp.yml): 56 candidate tools derived from the spec. Evari publishes no MCP server; MCP appears in its help centre only as a QuivaWorks Marketplace capability. - [Agent skills](skills/_index.yml): four packaged flows — public quote to confirmation, broker quote lifecycle, refer to underwriter, price an endorsement. - [Conformance](conformance/evari-conformance.yml): ISO 27001 certified and GDPR compliant; SOC 2 asserted only in a pricing FAQ. **No ACORD, AL3 or IVANS reference anywhere** — the entity model is proprietary. - [Lifecycle](lifecycle/evari-lifecycle.yml): no versioning scheme, no deprecation policy, no status page, no changelog; Uptime SLA named in the platform tiers with no numeric target. - [Plans](plans/evari-plans.yml): fixed-price sprints (A$12k / A$18k / A$35k) plus platform subscriptions banded by daily transaction volume (A$2k / A$4k / A$8k per month). - [Packages](packages/evari-packages.yml): one public npm package (the service itself, not an SDK); the @evari scope is private. - [Well-known](well-known/evari-well-known.yml): a real RFC 9116 security.txt; every other /.well-known/ path is a catch-all serving the homepage. - [Security](security/evari-domain-security.yml): TLS 1.3, SPF and DMARC (p=none) present; no HSTS header observed, no DNSSEC, no CAA. ## Provider surfaces - [Website](https://evari.tech/) [provider] - [Help Centre](https://evari.tech/help-center/) [provider]: the closest thing to documentation — assistants, integrations, security, sprints, platform and billing. - [What systems does Evari integrate with](https://evari.tech/help-center/items/integrations/what-systems-does-evari-integrate-with/) [provider]: Socotra, Vertafore (AMS360, Sagitta), Applied Epic, Guidewire (read access), Salesforce, HubSpot, Dynamics, Microsoft 365, Google Workspace, SharePoint. Evari is a *consumer* of these APIs. - [What is MCP](https://evari.tech/help-center/items/assistants/what-is-mcp-model-context-protocol/) [provider] - [Trust Center](https://evari.tech/trust) [provider]: ISO 27001, GDPR, sub-processor list (Anthropic, Google, GCP, Stripe). - [Pricing](https://evari.tech/pricing) [provider] - [Legal — Terms and Privacy](https://evari.tech/legal) [provider] - [Blog](https://evari.tech/blog/) [provider] · [RSS](https://evari.tech/blog/rss.xml) - [GitHub organisation](https://github.com/myevari) [provider]: 11 public repositories, almost all forks; no specs or SDKs. - [security.txt](https://evari.tech/.well-known/security.txt) [provider] - [Sign up (QuivaWorks)](https://quiva.ai/) [provider]: Evari's help centre directs all account creation to its platform partner. - [llms.txt](https://evari.tech/llms.txt) [provider]: a 418KB full-site content corpus rather than a link index, and disallowed in robots.txt.