generated: '2026-09-05' method: searched source: >- docs.ixhello.com iX Hello Customer v2 API + MCP pages, and the Azure AD B2C discovery document saved at well-known/concentrix-openid-configuration.json note: >- Concentrix publishes no OpenAPI, so nothing here is derived from a spec — every entry cites a documented statement or a document actually fetched. Negative entries are recorded on purpose: they are the measurement, not an omission. standards: - id: oauth2 conforms: true role: provider evidence: >- Azure AD B2C tenant ixadminprodk5 exposes authorization_endpoint / token_endpoint / end_session_endpoint for the b2c_1a_signup_signin user flow; response_types include code and the implicit forms. See well-known/concentrix-openid-configuration.json. - id: oidc conforms: true role: provider evidence: >- OpenID Connect discovery document served at https://ixadminprodk5.b2clogin.com/2c95ae7b-5bab-49e0-a483-62a3cd3867ba/b2c_1a_signup_signin/v2.0/.well-known/openid-configuration (HTTP 200, 2026-09-05) with issuer, jwks_uri, userinfo_endpoint, RS256 id_token signing and pairwise subject identifiers. - id: rfc6750-bearer-token conforms: true evidence: 'iX Hello Customer v2 APIs require "Authorization: Bearer " on every endpoint.' - id: rfc2104-hmac conforms: true evidence: Webhook callbacks carry X-Signature; sha256= computed as HMAC-SHA256(webhookAuth, rawRequestBody). - id: e164 conforms: true evidence: 'destinationNumber must be an E.164 PSTN number; a non-conforming value returns 400 INVALID_DESTINATION.' - id: sip conforms: true evidence: 'Outbound Calling API accepts a SIP address (sip:user@domain.com) as destinationNumber, and documents SIP/PSTN trunk interoperability.' - id: mcp conforms: true role: client evidence: >- iX Hello Customer v2 implements an MCP client — an MCP connection type on the Integrations page, server discovery via https://registry.modelcontextprotocol.io/, OAuth against the selected server, and auto-generated List Tools / Execute Tool methods bound to a Flow Designer Tools node. Concentrix does NOT publish an MCP server; see mcp/concentrix-mcp.yml. docs: https://docs.ixhello.com/ixhc2/integrations/mcp - id: llms-txt conforms: true evidence: >- Two real llms.txt documents served — https://www.concentrix.com/llms.txt (a crawler-policy variant using Allow/Disallow/Attribution/Contact rather than the link-list format) and https://docs.ixhello.com/llms.txt (a GitBook-generated 459-entry documentation index, with a companion llms-full.txt). - id: openapi conforms: false evidence: >- No OpenAPI/Swagger document at any probed location on www.concentrix.com, docs.ixhello.com, www.ixhello.com, api.vnext.ixhello.com or api.demo.vnext.ixhello.com (2026-09-05). The APIs are documented in prose tables only. - id: asyncapi conforms: false evidence: No AsyncAPI document published; the webhook surface is documented in prose (asyncapi/concentrix-ix-hello-webhooks.yml). - id: rfc9457-problem-details conforms: false evidence: 'Errors use a vendor envelope {"error": {"code", "message"}}, not application/problem+json.' - id: rfc8594-sunset-header conforms: false evidence: No deprecation policy and no Sunset/Deprecation header support is documented. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on every Concentrix-controlled host probed. - id: apis-json conforms: false evidence: /apis.json, /apis.yml and /.well-known/apis.json miss on every host probed. - id: a2a-agent-card conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json 404 on all ten hosts probed. - id: idempotency-key conforms: false evidence: No idempotency key or replay-protection mechanism on either write surface (conventions/concentrix-conventions.yml). domain_standard: market: conversational AI / CCaaS / outbound voice declared: false note: >- The contract declares no market-specific data standard. The closest thing to a domain standard this platform speaks is MCP, and it speaks it as a consumer of other vendors' servers rather than as a publisher, so it is recorded above with role client rather than claimed here. compliance_program: published: false trust_center: null certifications: [] evidence: - {url: 'https://trust.concentrix.com/', status: 'DNS does not resolve'} - {url: 'https://security.concentrix.com/', status: 'DNS does not resolve'} - {url: 'https://www.concentrix.com/legal/', status: 200, finding: 'legal hub lists privacy, ESG, modern-slavery and governance documents; no SOC 2 / ISO 27001 / PCI / HIPAA / FedRAMP attestation is published'} - {url: 'https://www.concentrix.com/legal/disclosure/', status: 200, finding: 'SEC merger disclosure (SYNNEX/Convergys), not a security disclosure policy'} note: >- No trust center, no named certification, and no vulnerability-disclosure policy was found for a company whose own service lines include Cybersecurity, Trust & Safety and Financial Crime & Compliance. Recorded as an absence rather than inferred from the services they sell.