generated: '2026-07-25' method: derived source: >- review.yml (2026-07-25 developer-surface review) + live probes of www.gooseinsurance.com, api.gooseinsurance.com and the 125-URL sitemap note: >- Conformance is asserted against a company that publishes no machine-readable API contract of any kind. Every `conforms: false` below is a probed or searched negative, not an untested assumption. No published certification program (SOC 2, ISO 27001, PCI DSS, HIPAA) was found, so this file intentionally carries NO `Compliance` pointer in apis.yml. standards: - id: openapi conforms: false evidence: >- No OpenAPI or Swagger document at any probed path on api.gooseinsurance.com or www.gooseinsurance.com (/openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api/openapi.json, /v2/openapi.json, /api-docs, /api-docs.json, /docs, /redoc, /rapidoc, /spec — all 404). - id: graphql conforms: false evidence: >- POST introspection to /graphql, /api/graphql and /v1/graphql on both hosts returned 404. No SDL to introspect. - id: asyncapi conforms: false evidence: No event catalog, streaming surface, webhook documentation or AsyncAPI document published. - id: mcp conforms: false evidence: >- tools/list POST to api.gooseinsurance.com/mcp and www.gooseinsurance.com/mcp returned 404; mcp.gooseinsurance.com does not resolve. - id: oauth2 conforms: false evidence: >- No /.well-known/oauth-authorization-server (RFC 8414) and no /.well-known/oauth-protected-resource on any host. No OAuth documentation exists. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on www and api hosts. - id: rfc9457-problem-details conforms: false evidence: No API responses are documented; api host returns bare text/html 404 bodies. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt and /security.txt return 404 on every host. - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404 on every host. - id: acord-al3 conforms: false evidence: >- No occurrence of ACORD, AL3, ACORD XML, NGDS, IVANS, Applied Epic or Vertafore anywhere on gooseinsurance.com — product pages, partners, licensing, claims, terms of use or privacy policy. Goose is a direct-to-consumer app, not an agency-management-system participant, so the ACORD/IVANS download rail does not touch it. - id: acord-xml conforms: false evidence: Same sitemap-wide search as acord-al3; no ACORD XML reference published. - id: open-insurance-canada conforms: not-applicable evidence: >- Canada has no open-insurance mandate. Consumer-Driven Banking (the Canadian open-banking framework) explicitly excludes insurance, so no regulation obliges Goose to expose quote, bind, issue or FNOL as an API. - id: tls-1.3 conforms: true evidence: >- www, api and support hosts all negotiate TLSv1.3 — see security/goose-insurance-domain-security.yml. - id: hsts conforms: partial evidence: >- www.gooseinsurance.com sets max-age=63072000 and support sets max-age=259200, but api.gooseinsurance.com returns no Strict-Transport-Security header. - id: dnssec conforms: false evidence: gooseinsurance.com is not DNSSEC-signed; no CAA records are published. - id: dmarc conforms: partial evidence: SPF and DMARC records exist for gooseinsurance.com, but the DMARC policy is p=none (monitor only). regulatory: regime: Canadian provincial market-conduct supervision (no open-insurance mandate) note: >- OSFI supervises federally-regulated insurers prudentially; provinces own market conduct (FSRA Ontario, AMF Quebec). Goose sits on the market-conduct side as a licensed distributor, not a carrier. licences: british_columbia: LIC-2018-0008799-R01 (general), LIC-2019-0015533-R01 (life & A&S) ontario: 1076M (general), 36825M (life & A&S) quebec: AMF firm registration 603913 other: Alberta, Saskatchewan, Manitoba, New Brunswick, Nova Scotia source: https://www.gooseinsurance.com/en-ca/licensing