/api/v1/compliance/reportGenerate a framework compliance report
Generates a compliance report for a framework with auto-risk classification (EU AI Act tiers) and gap analysis. Body requires `framework`, `organizationName` and `systemName`; `framework` must be `india-dpdp-act` or `hipaa` (any other value 400s with the valid list — EU AI Act and ISO 42001 have their own registry routes). Optional: `projectId` (pulls the project's org's stored `compliance_assessments` checklist so manual statuses win over automated gap statuses, and enables the declared-vs-classified risk-level mismatch finding and `includeModelCard`), `systemVersion`, `systemDescription`, `assessorName`, `scope`, `useCase` and `dataTypes` (both feed the risk classifier), `scanResults` (gap analysis; defaults to an empty scan), `format` and `includeModelCard`. `format=html` (the default) returns an HTML attachment download; `format=summary` returns inline HTML with no Content-Disposition; `format=json` returns `{report, gapAnalysis, riskClassification}`. Synchronous — no job is queued. Requires `compliance:create`; 10 req/min.
Authentication
Send Authorization: Bearer YOUR_API_KEY on every request. Generate API keys at /dashboard/settings/api-keys.
Request body required
Example
{
"framework": "<india-dpdp-act | hipaa (legacy enhanced->",
"projectId": "00000000-0000-0000-0000-000000000000",
"organizationName": "string",
"systemName": "string",
"systemVersion": "string",
"systemDescription": "string",
"assessorName": "string",
"scope": "string",
"useCase": "<Used for auto-risk classification.>",
"dataTypes": [
"string"
],
"scanResults": {},
"format": "html",
"includeModelCard": false
}Schema
{
"application/json": {
"schema": {
"type": "object",
"properties": {
"framework": {
"type": "string",
"minLength": 1,
"maxLength": 120,
"description": "india-dpdp-act | hipaa (legacy enhanced-shape frameworks)."
},
"projectId": {
"type": "string",
"format": "uuid",
"pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$",
"description": "Pulls stored assessment data for the org."
},
"organizationName": {
"type": "string",
"minLength": 1,
"maxLength": 500
},
"systemName": {
"type": "string",
"minLength": 1,
"maxLength": 500
},
"systemVersion": {
"type": "string",
"maxLength": 120
},
"systemDescription": {
"type": "string",
"maxLength": 20000
},
"assessorName": {
"type": "string",
"maxLength": 500
},
"scope": {
"type": "string",
"maxLength": 2000
},
"useCase": {
"type": "string",
"maxLength": 2000,
"description": "Used for auto-risk classification."
},
"dataTypes": {
"maxItems": 200,
"type": "array",
"items": {
"type": "string",
"maxLength": 200
}
},
"scanResults": {
"type": "object",
"additionalProperties": {},
"description": "Optional SecurityScanResult for gap analysis."
},
"format": {
"type": "string",
"enum": [
"html",
"summary",
"json"
]
},
"includeModelCard": {
"type": "boolean"
}
},
"required": [
"framework",
"organizationName",
"systemName"
],
"additionalProperties": false
}
}
}Response
200 example
{
"success": true
}All status codes
Code samples
cURL
curl -X POST \
https://evalguard.ai/api/v1/compliance/report \
-H "Authorization: Bearer $EVALGUARD_API_KEY" \
-H "Content-Type: application/json" \
-d '{ "framework": "<india-dpdp-act | hipaa (legacy enhanced->", "projectId": "00000000-0000-0000-0000-000000000000", "organizationName": "string", "systemName": "string", "systemVersion": "string", "systemDescription": "string", "assessorName": "string", "scope": "string", "useCase": "<Used for auto-risk classification.>", "dataTypes": [ "string" ], "scanResults": {}, "format": "html", "includeModelCard": false }'TypeScript
// The TypeScript SDK (@evalguard/sdk) exposes TYPED methods — runEval,
// getEval, runSecurityScan, checkFirewall, … — not a generic request().
// For an arbitrary endpoint, call it directly:
const res = await fetch("https://evalguard.ai/api/v1/compliance/report", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.EVALGUARD_API_KEY}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
"framework": "<india-dpdp-act | hipaa (legacy enhanced->",
"projectId": "00000000-0000-0000-0000-000000000000",
"organizationName": "string",
"systemName": "string",
"systemVersion": "string",
"systemDescription": "string",
"assessorName": "string",
"scope": "string",
"useCase": "<Used for auto-risk classification.>",
"dataTypes": [
"string"
],
"scanResults": {},
"format": "html",
"includeModelCard": false
}),
});
console.log(res.status, await res.json());Python
# The Python SDK (pip install evalguardai) exposes TYPED methods on
# EvalGuardClient — run_eval, get_eval, … — not a generic request().
# For an arbitrary endpoint, call it directly:
import os
import requests
headers = {"Authorization": f"Bearer {os.environ['EVALGUARD_API_KEY']}"}
headers["Content-Type"] = "application/json"
response = requests.request(
"POST",
"https://evalguard.ai/api/v1/compliance/report",
headers=headers,
json={
"framework": "<india-dpdp-act | hipaa (legacy enhanced->",
"projectId": "00000000-0000-0000-0000-000000000000",
"organizationName": "string",
"systemName": "string",
"systemVersion": "string",
"systemDescription": "string",
"assessorName": "string",
"scope": "string",
"useCase": "<Used for auto-risk classification.>",
"dataTypes": [
"string"
],
"scanResults": {},
"format": "html",
"includeModelCard": False
},
)
print(response.status_code, response.json())Go
package main
import (
"context"
"fmt"
"net/http"
"os"
"strings"
)
func main() {
body := strings.NewReader(`{"framework":"<india-dpdp-act | hipaa (legacy enhanced->","projectId":"00000000-0000-0000-0000-000000000000","organizationName":"string","systemName":"string","systemVersion":"string","systemDescription":"string","assessorName":"string","scope":"string","useCase":"<Used for auto-risk classification.>","dataTypes":["string"],"scanResults":{},"format":"html","includeModelCard":false}`)
req, _ := http.NewRequestWithContext(context.Background(), "POST", "https://evalguard.ai/api/v1/compliance/report", body)
req.Header.Set("Authorization", "Bearer "+os.Getenv("EVALGUARD_API_KEY"))
req.Header.Set("Content-Type", "application/json")
resp, err := http.DefaultClient.Do(req)
if err != nil { panic(err) }
defer resp.Body.Close()
fmt.Println(resp.Status)
}