generated: '2026-08-14' method: searched source: https://uniphore.us.auth0.com/.well-known/openid-configuration compliance_page: https://trust.uniphore.com/ standards: - id: oauth2 conforms: true evidence: >- RFC 6749 authorization server confirmed live at uniphore.us.auth0.com; authorization, token, revocation and device-code endpoints published. - id: oidc-core conforms: true evidence: >- OIDC discovery document served at https://uniphore.us.auth0.com/.well-known/openid-configuration with issuer, jwks_uri, userinfo_endpoint and id_token_signing_alg_values_supported. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: /.well-known/oauth-authorization-server returns 200 with full metadata. - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported includes S256. - id: rfc8628-device-authorization-grant conforms: true evidence: device_authorization_endpoint published; device_code grant advertised. - id: rfc8693-token-exchange conforms: true evidence: grant_types_supported includes urn:ietf:params:oauth:grant-type:token-exchange. - id: rfc7523-jwt-bearer conforms: true evidence: grant_types_supported includes urn:ietf:params:oauth:grant-type:jwt-bearer. - id: rfc7517-jwks conforms: true evidence: JWKS published; saved to well-known/uniphore-jwks.json. - id: rfc9449-dpop conforms: true evidence: dpop_signing_alg_values_supported present in the discovery document. - id: oidc-backchannel-logout conforms: true evidence: backchannel_logout_supported true. - id: ciba conforms: true evidence: backchannel_authentication_endpoint and backchannel_token_delivery_modes_supported published. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on every Uniphore host probed. - id: rfc8615-well-known-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404 on every Uniphore host probed. - id: openapi conforms: false evidence: >- No OpenAPI/Swagger document found. Re-probed 2026-08-14 across api.uniphore.com (Kong; every path answers "no Route matched with those values"), www.uniphore.com, uniphore.github.io and the newly-found support-rb.uniphore.com docs portal. The U-Capture docs state that individual HTTP request details "are provided within the APIs" — i.e. inside the running deployment — so the wire contract exists but is not published. - id: asyncapi conforms: false evidence: >- No AsyncAPI document is published. Re-checked 2026-08-14 — but a real webhook surface WAS found this round and is captured in asyncapi/uniphore-ucapture-webhooks.yml, so the absence is of the specification, not of the events. - id: webhooks conforms: true evidence: >- U-Capture Health Monitoring "Alert Configurations" deliver alerts to a customer-defined webhook URL (or an SNMP v3 trap receiver), configured through a documented REST API with a test-fire request. Source https://support-rb.uniphore.com/conversa/DevelopConversa/DevelopUCaptureV2.0/UCaptureHealthMonitoringAPIs/API_Overview.htm - id: snmp-v3 conforms: true evidence: >- Health monitoring alerts can be trapped via SNMP v3 using Uniphore's ea_redbox.mib, supplied on request rather than published. - id: saml conforms: true evidence: >- U-Capture Identity Server APIs document external identity provider integration over OpenID Connect, OAuth, WS-Federation and SAML. - id: ws-federation conforms: true evidence: Named alongside OIDC/OAuth/SAML in the U-Capture Identity Server API overview. - id: ldap conforms: true evidence: >- U-Capture ships an LDAP Configuration API covering LDAP server configuration and internal-to-external field mapping. - id: model-context-protocol conforms: false evidence: >- No MCP server, endpoint or package exists. Uniphore's marketing "MCP" expands to Multi-Agent Collaboration Protocol, a different thing — see mcp/uniphore-mcp.yml. - id: rfc9457-problem-details conforms: unknown evidence: No public error reference or spec to inspect. - id: openai-chat-completions-compatibility conforms: true evidence: >- BAIC's pegasus-inference-api exposes an OpenAI-compatible surface at /openai/v1, per the public BAIC Installation Guide. - id: a2a conforms: false evidence: No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host. compliance_programs: - id: soc2-type-2 conforms: true evidence: Named on the Uniphore Trust Center and on https://www.uniphore.com/security/ - id: iso-27001-2022 conforms: true evidence: Named on the Uniphore Trust Center and on https://www.uniphore.com/security/ - id: iso-27017-2015 conforms: true evidence: Named on the Uniphore Trust Center - id: iso-27018-2019 conforms: true evidence: Named on the Uniphore Trust Center - id: iso-27701-2019 conforms: true evidence: Named on the Uniphore Trust Center - id: pci-dss-v4 conforms: true evidence: PCI DSS v4.0.1, Level 1 Service Provider - id: hipaa conforms: true evidence: Named on the Uniphore Trust Center - id: gdpr conforms: true evidence: Trust Center + https://www.uniphore.com/legal/dpa/ - id: fips-140-2 conforms: true evidence: Named on the Uniphore Trust Center - id: fips-140-3 conforms: true evidence: Named on the Uniphore Trust Center - id: casa-tier-2 conforms: true evidence: Named on the Uniphore Trust Center - id: nist-csf conforms: true evidence: Named on the Uniphore Trust Center - id: eu-ai-act conforms: true evidence: Named on the Uniphore Trust Center - id: fedramp conforms: false evidence: Not named on the Uniphore Trust Center. x-evidence: - url: https://uniphore.us.auth0.com/.well-known/openid-configuration http_status: 200 fetched: '2026-08-02' - url: https://support-rb.uniphore.com/conversa/DevelopConversa/DevelopUCaptureV2.0/UCaptureHealthMonitoringAPIs/API_Overview.htm http_status: 200 fetched: '2026-08-14' - url: https://support-rb.uniphore.com/conversa/DevelopConversa/DevelopUCaptureV2.0/UCaptureIdentityServerAPIs/API_Overview.htm http_status: 200 fetched: '2026-08-14' - url: https://api.uniphore.com/openapi.json http_status: 404 fetched: '2026-08-14' - url: https://trust.uniphore.com/ http_status: 403 note: Cloudflare interstitial on curl; content confirmed via rendering fetch. fetched: '2026-08-02' - url: https://www.uniphore.com/security/ http_status: 200 fetched: '2026-08-02'