# INSTANDA > INSTANDA is a London-headquartered no-code insurance core-systems vendor (legal entity F2X Group Limited, England and Wales no. 05236974), selling a cloud-native policy administration and digital distribution platform to carriers, MGAs and brokers across the UK, EMEA, North America, Japan and Australia. It markets itself as API-first and the platform does generate per-product REST and SOAP interfaces described with Swagger or WSDL definitions, plus Event Webhooks for real-time customer event notifications — but none of that contract is published. There is no public developer portal, no downloadable OpenAPI, and every integration route runs through a licensed tenant or a partner engagement. ## What an agent should know first - **There is no public, self-serve API.** `api.instanda.com` is live and answers anonymous requests with a bare `403` and no `WWW-Authenticate` challenge. No documentation path under it resolves. - **The Swagger surface exists but is gated.** `https://design.instanda.com/swagger/index.html` is a registered route on the tenant configuration application — a `HEAD` returns `302 → /Account/LogOn?ReturnUrl=%2fswagger%2findex.html`, while unknown paths on the same host hard-404. The Swagger UI is real; it is behind forms authentication. - **Contracts are per-tenant, per-product.** INSTANDA generates the REST/SOAP interface for each configured insurance product inside the customer's tenant, so there is no single global API version to reference. - **Webhooks are the one event surface named in public.** No catalog, no payload schemas, no signature scheme, no retry policy. - **Do not expect ACORD.** No ACORD, AL3, NGDS, IVANS or agency-download conformance is claimed anywhere. ## Public surfaces - [Website](https://instanda.com/): company and platform marketing. - [Cloud / integration model](https://instanda.com/cloud): the first-party statement of how integration works — "You can connect through REST or SOAP services using Swagger or WSDL definitions, while WebHooks handle real-time customer event notifications." - [Platform security](https://instanda.com/platform-security): certifications and security controls. - [Trust centre](https://app.trustero.com/trust/instanda): third-party hosted, JavaScript-rendered. - [Status page](https://status.instanda.com/): public, component-level, no login. Four regions (AU, EMEA, JP, NA). - [Support portal](https://support.instanda.com/): Freshdesk knowledge base behind a login wall — customers only. - [Partners](https://instanda.com/partners): integration directory (identity, data, payments, broker systems, reinsurance). - [Blog](https://instanda.com/blog) · [News](https://instanda.com/news) - [GitHub organisation](https://github.com/instanda): exists, zero public repositories. ## Platform capability surface (from the public status page) Published as monitored components, so these are real platform services rather than marketing claims: - Quote Engine, Referrals, Renewals, MTAs, Endorsements, Multi Items, Claims, Reports - Emails: New Business Emails, Quote Emails, Referral Emails - Online Payments (AU, EMEA, NA) - Design, Production sites, ODS (per region) - **Event Webhooks** — "Event Webhooks allow Instanda to send information to another system. When an event happens, such as an update to a policy, Instanda will HTTP POST the information to a URL of your choice." ## Compliance ISO 27001:2022 · SOC 2 · Cyber Essentials · PCI DSS SAQ A. Hosted on Microsoft Azure, geo-replicated per region, AES-256 at rest and in transit. No published security contact, no vulnerability disclosure policy, no `security.txt`. ## Artifacts in this record - [apis.yml](apis.yml) — the APIs.json record for INSTANDA. - [review.yml](review.yml) — the full API Evangelist review, with every probe and its HTTP status. - [lifecycle/instanda-lifecycle.yml](lifecycle/instanda-lifecycle.yml) — status page, regions, components, versioning and SLA posture. - [asyncapi/instanda-webhooks.yml](asyncapi/instanda-webhooks.yml) — the Event Webhooks surface as published. - [conformance/instanda-conformance.yml](conformance/instanda-conformance.yml) — standards and certifications, each with its evidence. - [security/instanda-domain-security.yml](security/instanda-domain-security.yml) — TLS, HSTS, DNSSEC, CAA, SPF, DMARC probe. - [security/instanda-trust-center.yml](security/instanda-trust-center.yml) — trust centre and published controls. - [well-known/instanda-well-known.yml](well-known/instanda-well-known.yml) — the negative /.well-known/ probe record. ## Not available No OpenAPI or Swagger document · no WSDL · no GraphQL · no gRPC/protobuf · no AsyncAPI · no MCP server · no SDKs or packages on npm, PyPI, NuGet, RubyGems, Packagist or crates.io · no CLI · no first-party Postman workspace · no public changelog, roadmap, pricing page or SLA · no sandbox or test credentials. Every one of these was probed on 2026-07-25 and missed. ## Contact - [Contact INSTANDA](https://instanda.com/contact-us) · [Request a demo](https://instanda.com/demo-request) - This record is maintained by API Evangelist — kin@apievangelist.com