# Kalepa > Kalepa is a New York–headquartered insurtech (founded 2018 by Paul Monasterio and Daniel Hillman) that builds Copilot, an AI underwriting workbench for commercial property and casualty carriers, MGAs, mutuals and brokers in the United States. Copilot covers submission ingestion, clearance, triage, risk analysis, rating, quote and bind, and portfolio management. Kalepa markets itself as "API-first" and states that it "integrates via API with existing policy, underwriting, and document platforms" — but publishes NO public API: no developer portal, no reference documentation, no machine-readable specification, and no SDK. The production API host api.kalepa.com is live and is monitored as a named component on the public status page, yet every documentation and discovery path on it returns 404, and the Copilot application redirects to a customer login. Integration is negotiated commercially, not self-served. This file is generated by API Evangelist from the public Kalepa surface. Kalepa does not publish an llms.txt of its own (https://kalepa.com/llms.txt returns 404). ## Contract status - No OpenAPI or Swagger document exists at any probed path on api.kalepa.com, kalepa.com, or in github.com/Kalepa. - No GraphQL surface (api.kalepa.com/graphql returns 404). - No gRPC / Protobuf definitions published. - No AsyncAPI, no webhook catalog, no event reference. - No MCP server, no agent skills, no Postman public workspace or collection. - No /.well-known/ discovery document on either host — see well-known/kalepa-well-known.yml. - Auth is an undocumented session login: copilot.kalepa.com 307-redirects to https://api.kalepa.com/auth/login?frontend_redirect_url=... ## Product surface (documentation, human-readable only) - [Platform: Submission Ingestion](https://kalepa.com/platforms/submission-ingestion): Ingests ACORD forms, spreadsheets, handwritten notes, loss runs and supplemental applications via email auto-forwarding, portal integrations or APIs. - [Platform: Clearance](https://kalepa.com/platforms/clearance) - [Platform: Triage](https://kalepa.com/platforms/triage) - [Platform: Risk Analysis](https://kalepa.com/platforms/risk-analysis) - [Platform: Rating](https://kalepa.com/platforms/rating) - [Platform: Quote & Bind](https://kalepa.com/platforms/quote-bind) - [Platform: Portfolio Management](https://kalepa.com/platforms/portfolio-management) - [Solutions: For IT/AI Leaders](https://kalepa.com/solutions/for-it-ai-leaders): The only page carrying technical/compliance posture — "API-first platform", SOC 2 Type II, 4–6 week production deployment. - [Solutions: Carriers](https://kalepa.com/solutions/carriers): "Kalepa integrates via API with existing policy, underwriting, and document platforms." - [Solutions: MGAs](https://kalepa.com/solutions/mgas) - [Solutions: Mutuals](https://kalepa.com/solutions/mutuals) - [Solutions: Brokers](https://kalepa.com/solutions/brokers) ## Operations and security - [Status page](https://status.kalepa.com/): Better Stack. Two components — Kalepa Web App and Kalepa API — both at 99.993% observed uptime. Weekly Sunday maintenance window (6 hours booked, usually under 1 hour). - [Status incident feed](https://status.kalepa.com/feed.rss): dated incidents with written root-cause notes. - [Product Security / responsible disclosure](https://kalepa.com/security): security@kalepa.com; scope kalepa.com, kalepainsurance.com, kalepa.co, kalepa.io and any subdomain; no paid bounty; no security.txt. - [Privacy Policy](https://kalepa.com/privacy-policy): GDPR, UK GDPR and Swiss data protection legal bases. - SOC 2 Type II is the only named certification Kalepa publishes. ## Open source (not API clients) - [safe-init](https://pypi.org/project/safe-init/): AWS Lambda error handling and monitoring for Python. Docs: https://safe-init.readthedocs.io/en/latest/ - [marshmallow-fastoneofschema](https://pypi.org/project/marshmallow-fastoneofschema/): fast marshmallow schema multiplexing. - [kalepa-signxml](https://github.com/Kalepa/kalepa-signxml): fork of the signxml XML Signature / XAdES library (GitHub only). - [Terraform Registry namespace](https://registry.terraform.io/namespaces/Kalepa): 24 first-party AWS/null/external Terraform modules. - [GitHub organization](https://github.com/Kalepa): 29 public repositories, all infrastructure tooling. No API specifications. ## API Evangelist artifacts in this repo - apis.yml — the APIs.json index for Kalepa. - review.yml — the full public-surface probe log behind the "no public API" finding. - conformance/kalepa-conformance.yml — SOC 2 Type II, privacy regimes, and per-standard conformance with evidence. - lifecycle/kalepa-lifecycle.yml — status page, components, uptime, maintenance window, incident history. - packages/kalepa-packages.yml — first-party PyPI and Terraform Registry packages (none are API clients). - security/kalepa-domain-security.yml — TLS/HSTS/DNSSEC/CAA/SPF/DMARC across five hosts and four domains. - security/kalepa-vulnerability-disclosure.yml — the responsible-disclosure program in structured form. - well-known/kalepa-well-known.yml — the /.well-known/ probe record (all 404). ## Notes for agents Do not attempt to call api.kalepa.com. It is a customer-tenant API with no public documentation, no published auth scheme and no self-serve signup. The only public entry point is https://kalepa.com/book-a-demo.