INSTANDA website screenshot

INSTANDA

INSTANDA is a London-headquartered no-code insurance core-systems vendor, trading as F2X Group Limited (England and Wales no. 05236974) from 70 Gracechurch Street in the City of London, a few streets from Lloyd's. Founded in 2015 by Tim Hardcastle (CEO) and Derek Hill (Group CRO), it sells a cloud-native policy administration and digital distribution platform to insurance carriers, MGAs and brokers, letting business users configure products, rating, rules, documents, agent/broker portals and direct-to-consumer journeys without writing code. Its footprint spans property and casualty, life and health, and specialty lines across the UK, EMEA, North America and APAC, and it is architected on Microsoft Azure. INSTANDA markets itself as "API-first" and its platform does generate per-product REST/SOAP interfaces described with Swagger or WSDL definitions, plus Event Webhooks that HTTP POST customer event notifications to a subscriber-supplied URL - but none of that contract is public. There is no first-party developer portal: developer, developers, docs and api-docs subdomains all return 404, api.instanda.com resolves but answers anonymous requests with a bare 403, and support.instanda.com is a Freshdesk login wall. The Swagger surface has been located and it is gated - design.instanda.com/swagger/index.html is a registered route that redirects to the platform log-on page, while unknown paths on the same host hard-404. What INSTANDA does publish openly is a component-level status page at status.instanda.com covering four hosting regions, and a certification set of ISO 27001:2022, SOC 2, Cyber Essentials and PCI DSS SAQ A. Quote, bind, issue and FNOL all exist as platform capabilities - the status page names Quote Engine, Referrals, Renewals, MTAs, Endorsements and Claims as monitored services - but every one of them is reachable only through a licensed tenant or a partner integration. The honest finding is a partner-gated insurance core system with no public self-serve API.

INSTANDA is profiled on the APIs.io network. Tagged areas include Insurance, United Kingdom, Insurtech, Policy Administration, and Underwriting.

The INSTANDA catalog on APIs.io includes 1 event-driven AsyncAPI specification.

INSTANDA’s developer surface includes engineering blog, product news, support, and 19 more developer resources.

33.4/100 thin ▬ flat Agent 21/100 agent aware Full breakdown ↓
scored 2026-08-20 · rubric v0.12.0
0 APIs
InsuranceUnited KingdomInsurtechPolicy AdministrationUnderwritingClaimsProperty and CasualtyLife InsuranceHealth InsuranceDigital DistributionNo-CodeCore SystemsMGABrokersWebhookMicrosoft AzureEmbedded Insurance

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-08-20 · rubric v0.12.0
Composite quality — 33.4/100 · thin
Contract Quality 9.6 / 21
Developer Ergonomics 0.8 / 17
Access Clarity 6.0 / 17
Operational Transparency 4.1 / 11
Contract Governance 1.9 / 10
Discoverability 4.9 / 9
Regulatory Posture 5.5 / 15
Agent readiness — 21/100 · agent aware
Machine-Readable Contract 18 / 18
Agentic Access Contract 0 / 10
Documented Reversibility 0 / 6
MCP Server 0 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 6 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Regulatory Posture applies to this provider. Its tags matched the Insurance regime, so Regulatory Posture carries 15 points of the composite. If this regime is wrong for your business, say so on your provider repo — the applicability map is public and we will correct it.
The six quality facets above are damped to 85 points between them, because the conditional facet above carries the other 15. That is why each facet's contribution is shown against a damped maximum: raising a quality facet moves the composite by 85% of its nominal weight, not 100%. The full arithmetic is at apis.io/rating/.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/instanda: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

Event Specifications 1

AsyncAPI definitions for this provider's event-driven and streaming APIs.

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Instanda Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Instanda Trust Center

ISO 27001:2022, SOC 2, Cyber Essentials, PCI DSS SAQ A

SECURITY

Resources

Get Started 1

Portal, sign-up, and the first successful call

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 3

Pagination, idempotency, versioning, errors, and events

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 5

Authentication, authorization, and security posture

Operate 3

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

Company 6

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: instanda
url: https://raw.githubusercontent.com/api-evangelist/instanda/refs/heads/main/apis.yml
name: INSTANDA
kind: company
description: 'INSTANDA is a London-headquartered no-code insurance core-systems vendor, trading as F2X Group Limited (England
  and Wales no. 05236974) from 70 Gracechurch Street in the City of London, a few streets from Lloyd''s. Founded in 2015 by
  Tim Hardcastle (CEO) and Derek Hill (Group CRO), it sells a cloud-native policy administration and digital distribution
  platform to insurance carriers, MGAs and brokers, letting business users configure products, rating, rules, documents, agent/broker
  portals and direct-to-consumer journeys without writing code. Its footprint spans property and casualty, life and health,
  and specialty lines across the UK, EMEA, North America and APAC, and it is architected on Microsoft Azure. INSTANDA markets
  itself as "API-first" and its platform does generate per-product REST/SOAP interfaces described with Swagger or WSDL definitions,
  plus Event Webhooks that HTTP POST customer event notifications to a subscriber-supplied URL - but none of that contract
  is public. There is no first-party developer portal: developer, developers, docs and api-docs subdomains all return 404,
  api.instanda.com resolves but answers anonymous requests with a bare 403, and support.instanda.com is a Freshdesk login
  wall. The Swagger surface has been located and it is gated - design.instanda.com/swagger/index.html is a registered route
  that redirects to the platform log-on page, while unknown paths on the same host hard-404. What INSTANDA does publish openly
  is a component-level status page at status.instanda.com covering four hosting regions, and a certification set of ISO 27001:2022,
  SOC 2, Cyber Essentials and PCI DSS SAQ A. Quote, bind, issue and FNOL all exist as platform capabilities - the status page
  names Quote Engine, Referrals, Renewals, MTAs, Endorsements and Claims as monitored services - but every one of them is
  reachable only through a licensed tenant or a partner integration. The honest finding is a partner-gated insurance core
  system with no public self-serve API.'
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/apis-json-logo.jpg
tags:
- Insurance
- United Kingdom
- Insurtech
- Policy Administration
- Underwriting
- Claims
- Property and Casualty
- Life Insurance
- Health Insurance
- Digital Distribution
- No-Code
- Core Systems
- MGA
- Brokers
- Webhook
- Microsoft Azure
- Embedded Insurance
tags_raw:
- Insurance
- United Kingdom
- Insurtech
- Policy Administration
- Underwriting
- Claims
- Property and Casualty
- Life Insurance
- Health Insurance
- Digital Distribution
- No Code
- Core Systems
- MGA
- Broker
- Webhooks
- Microsoft Azure
- Embedded Insurance
created: '2026-07-25'
modified: '2026-07-25'
specificationVersion: '0.23'
apis: []
common:
- type: DomainSecurity
  url: security/instanda-domain-security.yml
- type: Website
  url: https://instanda.com/
- type: Blog
  url: https://instanda.com/blog
- type: BlogRSS
  url: https://instanda.com/blog/rss.xml
- type: News
  url: https://instanda.com/news
- type: Partners
  url: https://instanda.com/partners
- type: Support
  url: https://support.instanda.com/
- type: StatusPage
  url: https://status.instanda.com/
- type: Lifecycle
  url: lifecycle/instanda-lifecycle.yml
- type: Webhooks
  url: asyncapi/instanda-webhooks.yml
- type: Conformance
  url: conformance/instanda-conformance.yml
- type: Compliance
  url: https://instanda.com/platform-security
- type: TrustCenter
  url: https://app.trustero.com/trust/instanda
- type: TrustCenter
  url: security/instanda-trust-center.yml
- type: Security
  url: https://instanda.com/platform-security
- type: LLMsTxt
  url: llms/instanda-llms.txt
- type: GitHubOrganization
  url: https://github.com/instanda
- type: Login
  url: https://design.instanda.com/Account/LogOn
- type: PrivacyPolicy
  url: https://instanda.com/privacy-policy
- type: TermsOfService
  url: https://instanda.com/terms-and-conditions
- type: ContactUs
  url: https://instanda.com/contact-us
- type: LinkedIn
  url: https://uk.linkedin.com/company/instanda
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com