generated: '2026-08-22' method: searched source: >- https://www.iboss.com/.well-known/brand-facts.json (provider-published), https://www.iboss.com/llms.txt (provider-published), https://www.okta.com/integrations/iboss/ (Okta Integration Network listing) note: >- iboss publishes NO machine-readable contract (no OpenAPI, AsyncAPI, GraphQL SDL, WSDL or .proto — see the discovery log in lifecycle/iboss-lifecycle.yml). Every entry below is therefore graded from provider-published prose or a vendor-certified integration directory, NOT from a contract, and each entry says which. No conformance has been asserted from a contract that was never inspected. standards: - id: scim2 name: SCIM 2.0 (System for Cross-domain Identity Management, RFC 7643/7644) conforms: true evidence: source: https://www.okta.com/integrations/iboss/ detail: >- The Okta Integration Network listing for iboss publishes SCIM provisioning features: Create, Update, Attribute Sourcing, Deactivate, Sync Password, Group Push, Group Linking, Schema Discovery, Attribute Writeback. contract_inspected: false note: >- The SCIM schema URNs (urn:ietf:params:scim:schemas:*) could NOT be read, because the SCIM endpoint is customer-tenant-scoped and iboss publishes no reference for it. Recorded as a directory-evidenced conformance, not a contract-verified one. confidence: medium - id: saml2 name: SAML 2.0 Web Browser SSO conforms: true evidence: source: https://www.okta.com/integrations/iboss/ detail: iboss is listed in the Okta Integration Network with SAML SSO support. contract_inspected: false confidence: medium - id: oidc name: OpenID Connect conforms: true evidence: source: https://www.okta.com/integrations/iboss/ detail: >- The Okta listing names OIDC among supported federation protocols. No OIDC discovery document is served on any iboss host — /.well-known/openid-configuration returns the marketing-site SPA shell on www.iboss.com and 404 on the gateway hosts. contract_inspected: false confidence: low - id: oauth2 name: OAuth 2.0 conforms: false evidence: detail: >- No OAuth 2.0 authorization-server metadata (RFC 8414) or protected-resource metadata is served on any iboss host, and no OAuth flow is publicly documented. The observed API surface uses session cookies plus a double-submit XSRF token. source: authentication/iboss-authentication.yml confidence: high - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: detail: >- The anonymous 401 from /ibcloud/web/users returns Content-Length 0 with no application/problem+json body. No error catalog is published. source: https://api.ibosscloud.com/ibcloud/web/users confidence: medium - id: rfc9116 name: RFC 9116 security.txt conforms: false evidence: detail: No security.txt is served on any iboss host — see well-known/iboss-well-known.yml. source: well-known/iboss-well-known.yml confidence: high - id: llmstxt name: llms.txt (llmstxt.org) conforms: true evidence: source: https://www.iboss.com/llms.txt detail: >- A real 5,264-byte llms.txt is served, correctly shaped (H1, blockquote summary, H2 sections of annotated links), with a companion /llms-full.txt that names the llmstxt.org specification in its own header. Saved verbatim to llms/iboss-llms.txt. contract_inspected: true confidence: high compliance: published: true page: https://www.iboss.com/compliance machine_readable: https://www.iboss.com/.well-known/brand-facts.json detail: security/iboss-trust-center.yml certifications: - SOC 1 Type II - SOC 2 Type II - ISO 27001 - ISO 9001 - FedRAMP Authorized - StateRAMP Authorized - CJIS - CSA STAR Level 1 - CSA STAR Level 2 - Cyber Essentials - CMMC 2.0 (125 controls mapped) - FIPS 140-2 - HIPAA - FERPA - GDPR note: >- Union of the certifications published on /compliance and those in the provider's own /.well-known/brand-facts.json; the two lists disagree and neither is a superset. See security/iboss-trust-center.yml for the per-item source and the discrepancy note. Recorded as published by iboss and NOT independently audited by API Evangelist. domain_standard: market: Cybersecurity / Zero Trust SASE / identity-adjacent access control candidate: SCIM 2.0 contract_declared: false note: >- The 0.12.0 domain_standard_conformance check reads a DECLARED standard inside the contract (a SCIM schema URN, an OData $metadata surface, and so on). iboss ships no contract for that check to read, so this slot is recorded as undeterminable rather than credited. The SCIM evidence above is directory-level and deliberately does not claim the contract signature.