generated: '2026-07-25' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts hosts: - host: www.honeyinsurance.com https: true tls_version: TLSv1.3 cert_expires: Jan 14 23:59:59 2027 GMT hsts: true hsts_max_age: 63072000 - host: auth.honeyinsurance.com https: true tls_version: TLSv1.3 cert_expires: Sep 19 16:58:24 2026 GMT hsts: true hsts_max_age: 31536000 hsts_include_subdomains: true note: Auth0 custom-domain tenant serving anonymous OIDC discovery and JWKS. - host: api.honeyinsurance.com https: true tls_version: TLSv1.3 cert_expires: Jan 17 23:59:59 2027 GMT hsts: false note: >- Private AWS API Gateway backing Honey's own quote funnel and account app. Every anonymous path returns HTTP 403 {"message":"Forbidden"}; no HSTS header is sent on the deny response. domains: - domain: honeyinsurance.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: reject