# Insurance Australia Group (IAG) > Insurance Australia Group (ASX: IAG) is the largest general insurance company in Australia and New Zealand, headquartered in Sydney. It underwrites through a portfolio of brands — NRMA Insurance, CGU, WFI, Swann Insurance, SGIO, SGIC and the digital-native ROLLiN' in Australia; State, AMI, NZI and Lumley in New Zealand — across home and contents, motor, commercial, rural and farm, compulsory third party and specialty lines. **IAG publishes no public API.** There is no developer portal, no reference documentation, no OpenAPI/Swagger/AsyncAPI/GraphQL contract, no SDK, no sandbox and no public authorization metadata. An agent cannot integrate with IAG programmatically. This file exists so agents stop hunting: the answer is documented, not missing. This document was generated by the API Evangelist enrichment pipeline from `apis.yml` and the artifacts in this repository. It is not published by IAG. ## What actually exists - A production Apigee Edge API management layer. Four brand virtual hosts resolve to the `iag-prod-production.apigee.net` organisation — `api.iag.com.au` (`https_vhost`), `api.cgu.com.au` (`https_cgu_vhost`), `api.nrma.com.au` (`https_nrma_vhost`) and `api.wfi.com.au` (`https_wfi_vhost`) — plus a publicly resolvable non-production organisation at `test-api.iag.com.au` (`iag-nonprod-test.apigee.net`). Every one returns the Apigee `ApplicationNotFound` fault at the root: proxies exist, none is publicly routable or documented. - A MuleSoft Anypoint API Experience Hub deployment. IAG's head of integration Lloyd Thomas described migrating roughly 600 APIs onto the platform and making them "agent aware" (iTnews, 10 March 2026). The hub itself is not publicly reachable. - `docs.iag.com.au` — an Azure App Service documentation site behind Microsoft Entra ID SSO. Internal, not a developer portal. - `apis.iag.com.au` and `security.iag.com.au` — hosts that exist but return 403 (Akamai) and 401 (IBM Verify Identity Access) respectively. - A HackerOne vulnerability disclosure programme, no paid bounty. ## Artifacts in this repository - [apis.yml](https://raw.githubusercontent.com/api-evangelist/iag/refs/heads/main/apis.yml): APIs.json provider record - [review.yml](https://raw.githubusercontent.com/api-evangelist/iag/refs/heads/main/review.yml): full probe log — every hostname and path tested, with HTTP status - [security/iag-domain-security.yml](https://raw.githubusercontent.com/api-evangelist/iag/refs/heads/main/security/iag-domain-security.yml): TLS, HSTS, DNSSEC, CAA, SPF and DMARC across thirteen hosts and six domains - [security/iag-vulnerability-disclosure.yml](https://raw.githubusercontent.com/api-evangelist/iag/refs/heads/main/security/iag-vulnerability-disclosure.yml): HackerOne programme record and disclosure contacts - [well-known/iag-well-known.yml](https://raw.githubusercontent.com/api-evangelist/iag/refs/heads/main/well-known/iag-well-known.yml): every `/.well-known/` path probed, with the security.txt publication and withdrawal timeline - [well-known/iag-security.txt](https://raw.githubusercontent.com/api-evangelist/iag/refs/heads/main/well-known/iag-security.txt): the last published RFC 9116 security.txt, verbatim (historical — withdrawn mid-2025) - [conformance/iag-conformance.yml](https://raw.githubusercontent.com/api-evangelist/iag/refs/heads/main/conformance/iag-conformance.yml): standards conformance, including what is genuinely unknowable without documentation ## Corporate surfaces - [IAG Limited](https://www.iag.com.au/): corporate website - [Contact us](https://www.iag.com.au/contact-us) - [Codes and policies](https://www.iag.com.au/about-us/corporate-governance/codes-and-policies): corporate governance documents - [Newsroom](https://www.iag.com.au/newsroom) - [Supplier portal](https://www.iag.com.au/supplier-portal) - [Careers](https://careers.iag.com.au/) - [Vulnerability disclosure](https://hackerone.com/iag): HackerOne programme - [GitHub — InsuranceAustraliaGroup](https://github.com/InsuranceAustraliaGroup): one public repository, a fork of Google's AppAuth-iOS - [GitHub — IAG Customer Labs](https://github.com/iagcl): four public repositories of internal platform tooling, mostly unmaintained ## How integration actually happens Not through APIs. Brokers, advisors and partners transact through human-facing platforms: CGU's PolicyPlace quote-and-bind portal, the Ebix Sunrise Exchange and the Steadfast Client Trading Platform. The CGU partner portal directs partners to email a CGU representative for access. Onboarding is request-based, not self-serve. ## Regulatory context General insurance is **not** a designated sector under Australia's Consumer Data Right. The extension flagged for general insurance was paused in favour of banking, non-bank lending and energy. Nothing compels IAG to publish an API, and it does not. ## Optional - [Ebix Sunrise Exchange](https://www.ebix.com.au/): broker-to-carrier trading exchange CGU is connected to - [Steadfast Client Trading Platform](https://www.steadfast.com.au/): broker network trading platform CGU is connected to