generated: '2026-09-05' method: searched source: >- https://zendrive-root.bitbucket.io/ios/docs/latest/Enums/ZendriveRegion.html ; https://zendrive-root.bitbucket.io/ios/docs/latest/Classes/ZendriveInsurance.html ; well-known/zendrive-well-known.yml name: Zendrive conformance description: >- Zendrive published no machine-readable contract and no compliance program that is still reachable, so nearly every cross-cutting standard is honestly negative. The two positives are read out of the SDK reference itself rather than a marketing claim: a first-class EU/US data-residency selector, and an insurance-period model (Period 1/2/3) that implements the rideshare/TNC commercial-auto coverage-period convention used across US usage-based auto insurance. No certification (SOC 2, ISO 27001, PCI, HIPAA, FedRAMP) can be evidenced — the trust and security pages lived on zendrive.com, which no longer resolves — so no Compliance pointer is emitted. conformance: - id: oauth2 conforms: false evidence: >- No OAuth surface. /.well-known/oauth-authorization-server returned 403 (Cloudflare 1014) on docs.zendrive.com and 404 on zendrive-root.bitbucket.io; the SDK authenticates with an opaque application key. - id: oidc conforms: false evidence: /.well-known/openid-configuration missed on every probed host. - id: rfc9457 conforms: false evidence: >- Errors are delivered as NSError in kZendriveErrorDomain through SDK completion handlers, not as application/problem+json. See errors/zendrive-error-codes.yml. - id: openapi conforms: false evidence: >- No OpenAPI or Swagger document is served on any known host. See the contract_discovery block in well-known/zendrive-well-known.yml. - id: asyncapi conforms: false evidence: >- No event or webhook surface is published. The SDK's event model is in-process delegate callbacks (ZendriveDelegateProtocol), not an HTTP webhook. - id: pagination conforms: true evidence: >- Zendrive's Analytics REST API documented cursor-style pagination on list endpoints using offset and limit parameters (docs.zendrive.com/en/latest/api/list_endpoints). RECORDED AS HISTORICAL: the documentation host is now a dangling Cloudflare CNAME returning 403, so this cannot be re-verified first-hand today. confidence: low - id: idempotency conforms: false evidence: >- No idempotency key or replay-protection mechanism is documented for either the SDK or the REST API. - id: eu-data-residency conforms: true evidence: >- ZendriveConfiguration.region accepts ZendriveRegionUS (0, default) and ZendriveRegionEU (1), documented as "Dictates the region where user's data will reside". Region is fixed at setup and cannot be switched without wipeOut; an application not provisioned for a region receives kZendriveErrorRegionUnsupported (109). url: https://zendrive-root.bitbucket.io/ios/docs/latest/Enums/ZendriveRegion.html note: >- A data-residency capability, not a GDPR certification. No DPA, SCC or privacy attestation is reachable. domain_standards: - id: usage-based-insurance-coverage-periods market: auto insurance / rideshare telematics conforms: true evidence: >- The SDK implements the standard US commercial-auto / TNC coverage-period model directly in its contract: ZendriveInsurance exposes startDriveWithPeriod1, startDriveWithPeriod2 and startDriveWithPeriod3, and ZendriveInsurancePeriod enumerates NoPeriod/Period1/Period2/ Period3 with "Each drive belongs to exactly one of these insurance periods", guarded by kZendriveErrorInsurancePeriodSame (104) on a no-op transition. Period 1/2/3 is the rideshare/TNC industry's shared vocabulary for which policy attaches when, so an insurer already speaking it needs no bespoke mapping. Zendrive's reference names and numbers the periods but does not itself define their coverage semantics — that reading is the industry convention, not a Zendrive statement. url: https://zendrive-root.bitbucket.io/ios/docs/latest/Classes/ZendriveInsurance.html confidence: medium note: >- Reward-only signal read from the contract surface itself (the SDK class + enum), not from a marketing claim. It is a convention, not a chartered specification body. certifications: published: [] note: >- None evidenced. trust.zendrive.com and zendrive.com/security do not resolve; no trust center, certification list or audit report is reachable. No Compliance or TrustCenter pointer is emitted.