/api/v1/compliance/frameworksDiscovery — list available compliance frameworks + endpoints
Returns the list of compliance frameworks EvalGuard exposes — SOC 2, EU AI Act, ISO 42001, NIST AI RMF, OWASP LLM Top 10, OWASP Agentic AI Top 10, HIPAA, FedRAMP, PCI-DSS, India DPDP, Singapore IMDA Agentic AI, India RBI, India SEBI, India IRDAI, Vietnam Law 134/2025 — each with its `status` (evidence-engine vs control-mappings), a `legalStatus` + `legalStatusNote` pair on EVERY entry, and the endpoints customers can call for it. `status` and `legalStatus` answer different questions and are never collapsed: `status` is how far EvalGuard's own implementation has got, `legalStatus` is the standing of the INSTRUMENT itself. `legalStatus` is always a member of the `FrameworkLegalStatus` union exported by `@evalguard/core` — `in-force`, `enacted-not-yet-applicable`, `proposed`, `voluntary`, `superseded`, `not-assessed` — and it fails CLOSED: a framework whose standing has not been established against a primary source resolves to `not-assessed`, never to `in-force`. `not-assessed` is NOT a synonym for `voluntary`; it means unverified, and such a framework may well be binding law. Every entry that is not `in-force` carries a `legalStatusNote` qualifying it, which a consumer must render alongside any score derived from that framework. Earlier revisions of this response published two additional labels that were never members of the union; both have been withdrawn. Also returns a `meta` block of cross-cutting endpoints (posture, gaps, export, model-cards, audit-bundle, verify, health) and `schemaVersion`. Used by SDK consumers and audit tooling that needs to enumerate available attestation generators. Public reference data, no per-org context, cached 1h at the edge. Authentication: none. This is a public endpoint and no credential is read. The empty `security` is a deliberate statement rather than an omission — nothing on this path resolves a caller, so no API-key scope is evaluated and an `eg_` key sent anyway is ignored.
Authentication
Public endpoint. No credential is read — send the request without an Authorization header. This is a deliberate statement, not a missing one.
Response
200 example
{
"success": true
}All status codes
Code samples
cURL
curl -X GET \ https://evalguard.ai/api/v1/compliance/frameworks \ -H "Authorization: Bearer $EVALGUARD_API_KEY"
TypeScript
// The TypeScript SDK (@evalguard/sdk) exposes TYPED methods — runEval,
// getEval, runSecurityScan, checkFirewall, … — not a generic request().
// For an arbitrary endpoint, call it directly:
const res = await fetch("https://evalguard.ai/api/v1/compliance/frameworks", {
method: "GET",
headers: { Authorization: `Bearer ${process.env.EVALGUARD_API_KEY}` },
});
console.log(res.status, await res.json());Python
# The Python SDK (pip install evalguardai) exposes TYPED methods on
# EvalGuardClient — run_eval, get_eval, … — not a generic request().
# For an arbitrary endpoint, call it directly:
import os
import requests
headers = {"Authorization": f"Bearer {os.environ['EVALGUARD_API_KEY']}"}
response = requests.request("GET", "https://evalguard.ai/api/v1/compliance/frameworks", headers=headers)
print(response.status_code, response.json())Go
package main
import (
"context"
"fmt"
"net/http"
"os"
)
func main() {
req, _ := http.NewRequestWithContext(context.Background(), "GET", "https://evalguard.ai/api/v1/compliance/frameworks", nil)
req.Header.Set("Authorization", "Bearer "+os.Getenv("EVALGUARD_API_KEY"))
resp, err := http.DefaultClient.Do(req)
if err != nil { panic(err) }
defer resp.Body.Close()
fmt.Println(resp.Status)
}