Skip to content
GET/api/v1/compliance/sla

Operational SLA evidence for SOC 2 CC7.x + EU AI Act Art 15

Returns uptime% + latency p50/p95/p99/max + error rate for the org's gateway traffic over a configurable window (`from`/`to`, defaulting to the last 90 days), plus a controlMapping block (SOC 2 CC7.1-CC7.4/CC8.1, EU AI Act Article 15). Sourced from `gateway_logs` scoped to the org's own project ids — rows written by ORG-scoped API keys leave project_id NULL and are deliberately excluded rather than risk counting another tenant's traffic. Capped at 50,000 log rows per window. Empty windows return zeros (uptime 100, null latencies), never 500.

Authentication

Send Authorization: Bearer YOUR_API_KEY on every request. Generate API keys at /dashboard/settings/api-keys.

Parameters

orgId in queryrequired
string
from in query

Defaults to now - 90 days.

string
to in query

Defaults to now.

string

Response

200 example

{
  "success": true
}

All status codes

200Totals + latency percentiles + control mapping.
400Invalid params.
401Unauthorized — no valid credential was presented (AUTH_REQUIRED).
403Forbidden — the credential is valid but lacks the API-key scope, member role, or plan entitlement this operation requires.
429Too Many Requests — the per-key or per-organization rate limit was exceeded. Honour the Retry-After header.
500Internal Server Error — an unhandled error was converted to the standard error envelope (INTERNAL_ERROR).

Code samples

cURL

curl -X GET \
  https://evalguard.ai/api/v1/compliance/sla \
  -H "Authorization: Bearer $EVALGUARD_API_KEY"

TypeScript

// The TypeScript SDK (@evalguard/sdk) exposes TYPED methods — runEval,
// getEval, runSecurityScan, checkFirewall, … — not a generic request().
// For an arbitrary endpoint, call it directly:

const res = await fetch("https://evalguard.ai/api/v1/compliance/sla", {
  method: "GET",
  headers: { Authorization: `Bearer ${process.env.EVALGUARD_API_KEY}` },
});
console.log(res.status, await res.json());

Python

# The Python SDK (pip install evalguardai) exposes TYPED methods on
# EvalGuardClient — run_eval, get_eval, … — not a generic request().
# For an arbitrary endpoint, call it directly:

import os
import requests

headers = {"Authorization": f"Bearer {os.environ['EVALGUARD_API_KEY']}"}

response = requests.request("GET", "https://evalguard.ai/api/v1/compliance/sla", headers=headers)
print(response.status_code, response.json())

Go

package main

import (
	"context"
	"fmt"
	"net/http"
	"os"
)

func main() {
	req, _ := http.NewRequestWithContext(context.Background(), "GET", "https://evalguard.ai/api/v1/compliance/sla", nil)
	req.Header.Set("Authorization", "Bearer "+os.Getenv("EVALGUARD_API_KEY"))
	resp, err := http.DefaultClient.Do(req)
	if err != nil { panic(err) }
	defer resp.Body.Close()
	fmt.Println(resp.Status)
}

Errors

400401403429500

Other Compliance endpoints