generated: '2026-08-22' method: searched source: https://hubsync.com/solution/ai summary: >- HubSync publishes no machine-readable contract, so every entry below is judged against the provider's own prose claims rather than against a specification document. Nothing here is derived from a spec because there is no spec to derive from. domain_standard_conformance is deliberately NOT asserted: HubSync operates in a market with real domain standards (IRS Modernized e-File, IRS Form 8879 e-signature rules) and its product plainly touches them, but the rubric reads the CONTRACT for that check and HubSync publishes no contract to read. standards: - id: mcp name: Model Context Protocol conforms: true evidence: url: https://hubsync.com/hubfs/llms.txt status: 200 quote: >- "MCP Connectivity: Native support for Model Context Protocol, allowing users to interact with HubSync resources via Co-pilot, ChatGPT, and Claude." note: >- First-party claim, corroborated on https://hubsync.com/solution/ai. Protocol version and tool schemas are not published and could not be introspected — the server is tenant-gated. - id: llmstxt name: llms.txt conforms: true evidence: url: https://hubsync.com/llms.txt status: 301 note: >- Redirects to https://hubsync.com/hubfs/llms.txt (200), which is a well-formed llms.txt with an H1, a blockquote summary and linked sections. Saved verbatim to llms/hubsync-llms.txt. Six of its 24 hubsync.com links are dead (see that artifact's companion note in lifecycle/hubsync-lifecycle.yml). - id: oauth2 name: OAuth 2.0 conforms: unknown evidence: note: >- HubSync describes permission- and login-scoped access for MCP clients, which implies an authorization handshake, but publishes no authorization-server metadata. RFC 8414 (/.well-known/oauth-authorization-server) and RFC 9728 (/.well-known/oauth-protected-resource) both miss on every host. url: https://hubsync.com/.well-known/oauth-authorization-server status: 404 - id: oidc name: OpenID Connect Discovery conforms: false evidence: url: https://hubsync.com/.well-known/openid-configuration status: 404 - id: rfc9116 name: security.txt (RFC 9116) conforms: false evidence: url: https://hubsync.com/.well-known/security.txt status: 404 - id: rfc9457 name: Problem Details for HTTP APIs (RFC 9457) conforms: unknown evidence: note: No public contract or error reference exists to evaluate. - id: openapi name: OpenAPI conforms: false evidence: note: >- No OpenAPI/Swagger document found on any HubSync host after probing /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api/openapi.json, /api-docs and /redoc against hubsync.com, docs.hubsync.com and app.hubsync.com. url: https://hubsync.com/openapi.json status: 404 - id: asyncapi name: AsyncAPI conforms: false evidence: note: No event, streaming or webhook specification is published. - id: graphql name: GraphQL conforms: false evidence: url: https://app.hubsync.com/graphql status: 200 note: soft-404 SPA shell (1,573 bytes), not a GraphQL endpoint; introspection not attempted against a non-endpoint. compliance: - id: soc2-type-1 name: SOC 2 Type 1 status: announced year: 2022 auditor_platform: Laika evidence: url: https://www.prnewswire.com/news-releases/hubsync-completes-soc-2-type-1-certification-with-laika-301593991.html status: 200 note: >- HubSync's own press release (July 2022) announcing completion of a SOC 2 Type 1 examination. This is the ONLY compliance attestation found. HubSync serves no trust center and no security page: trust.hubsync.com and status.hubsync.com do not resolve, and https://hubsync.com/security and https://hubsync.com/trust both return 404. No SOC 2 Type 2, ISO 27001, PCI or HIPAA claim was found anywhere on the public surface. domain_standard_conformance: asserted: false reason: >- Reward-only check, deliberately left unasserted. HubSync's market (US tax preparation) has genuine domain standards — IRS Modernized e-File (MeF) schemas and IRS Form 8879 e-signature requirements — and HubSync's e-File, batch-extension and 8879 e-sign modules necessarily speak them. But the check reads a declared standard inside a published contract, and HubSync publishes no contract. Claiming conformance from marketing copy would invent the signal the check exists to measure.