Skip to content
GET/api/v1/compliance/soc2/evidence

Raw SOC 2 evidence row export (auditor-facing)

Auditor-grade row dump from soc2_control_evidence — paginated, filterable by control / evidence_type / date range. Each row includes the canonical JSON payload + payload_hash so the auditor can recompute SHA-256 and verify tamper-detection. Rate-limited tighter than dashboard summary (5/min).

Authentication

Send Authorization: Bearer YOUR_API_KEY on every request. Generate API keys at /dashboard/settings/api-keys.

Parameters

orgId in queryrequired
string
controlId in query
string
evidenceType in query
string
from in query
string
to in query
string
limit in query
integer
offset in query
integer
format in query

Set to 'csv' to receive an RFC-4180 attachment download instead of JSON.

string

Response

200 example

{
  "success": true
}

All status codes

200Rows + total + pagination cursors (JSON), or RFC-4180 CSV attachment when format=csv.
400Invalid params.
401Unauthorized — no valid credential was presented (AUTH_REQUIRED).
403Forbidden — the credential is valid but lacks the API-key scope, member role, or plan entitlement this operation requires.
429Too Many Requests — the per-key or per-organization rate limit was exceeded. Honour the Retry-After header.
500Internal Server Error — DB_ERROR.

Code samples

cURL

curl -X GET \
  https://evalguard.ai/api/v1/compliance/soc2/evidence \
  -H "Authorization: Bearer $EVALGUARD_API_KEY"

TypeScript

// The TypeScript SDK (@evalguard/sdk) exposes TYPED methods — runEval,
// getEval, runSecurityScan, checkFirewall, … — not a generic request().
// For an arbitrary endpoint, call it directly:

const res = await fetch("https://evalguard.ai/api/v1/compliance/soc2/evidence", {
  method: "GET",
  headers: { Authorization: `Bearer ${process.env.EVALGUARD_API_KEY}` },
});
console.log(res.status, await res.json());

Python

# The Python SDK (pip install evalguardai) exposes TYPED methods on
# EvalGuardClient — run_eval, get_eval, … — not a generic request().
# For an arbitrary endpoint, call it directly:

import os
import requests

headers = {"Authorization": f"Bearer {os.environ['EVALGUARD_API_KEY']}"}

response = requests.request("GET", "https://evalguard.ai/api/v1/compliance/soc2/evidence", headers=headers)
print(response.status_code, response.json())

Go

package main

import (
	"context"
	"fmt"
	"net/http"
	"os"
)

func main() {
	req, _ := http.NewRequestWithContext(context.Background(), "GET", "https://evalguard.ai/api/v1/compliance/soc2/evidence", nil)
	req.Header.Set("Authorization", "Bearer "+os.Getenv("EVALGUARD_API_KEY"))
	resp, err := http.DefaultClient.Do(req)
	if err != nil { panic(err) }
	defer resp.Body.Close()
	fmt.Println(resp.Status)
}

Errors

400401403429500

Other Compliance endpoints