generated: '2026-07-25' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts hosts: - host: www.zensurance.com https: true tls_version: TLSv1.3 cert_expires: Oct 13 05:47:10 2026 GMT hsts: true hsts_max_age: 31536000 - host: api.zensurance.com https: true tls_version: TLSv1.2 tls13_supported: false cert_expires: Oct 26 23:59:59 2026 GMT hsts: true hsts_max_age: 15552000 hsts_include_subdomains: true headers: x_content_type_options: nosniff x_frame_options: SAMEORIGIN note: Undocumented first-party backend. Probed manually because it is not carried in apis.yml apis[] (it is not a published product API). Negotiates TLS 1.2 only — an explicit TLS 1.3 handshake is refused. - host: app.zensurance.com https: true tls_version: TLSv1.2 tls13_supported: false cert_expires: Oct 26 23:59:59 2026 GMT hsts: true hsts_max_age: 31536000 hsts_include_subdomains: true hsts_preload: true server: AmazonS3 headers: x_content_type_options: nosniff note: Customer application (S3-fronted SPA). TLS 1.2 only. domains: - domain: zensurance.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: quarantine