Create Compliance Check
curl --request POST \
--url https://api.truthlocks.com/v1/compliance/check \
--header 'Content-Type: application/json' \
--header 'X-API-Key: <api-key>' \
--data '
{
"agent_id": "550e8400-e29b-41d4-a716-446655440000",
"framework": "soc2",
"scope": {
"controls": [
"CC6.1",
"CC6.2",
"CC6.3"
]
}
}
'import requests
url = "https://api.truthlocks.com/v1/compliance/check"
payload = {
"agent_id": "550e8400-e29b-41d4-a716-446655440000",
"framework": "soc2",
"scope": { "controls": ["CC6.1", "CC6.2", "CC6.3"] }
}
headers = {
"X-API-Key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-API-Key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
agent_id: '550e8400-e29b-41d4-a716-446655440000',
framework: 'soc2',
scope: {controls: ['CC6.1', 'CC6.2', 'CC6.3']}
})
};
fetch('https://api.truthlocks.com/v1/compliance/check', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.truthlocks.com/v1/compliance/check",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'agent_id' => '550e8400-e29b-41d4-a716-446655440000',
'framework' => 'soc2',
'scope' => [
'controls' => [
'CC6.1',
'CC6.2',
'CC6.3'
]
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.truthlocks.com/v1/compliance/check"
payload := strings.NewReader("{\n \"agent_id\": \"550e8400-e29b-41d4-a716-446655440000\",\n \"framework\": \"soc2\",\n \"scope\": {\n \"controls\": [\n \"CC6.1\",\n \"CC6.2\",\n \"CC6.3\"\n ]\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-API-Key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.truthlocks.com/v1/compliance/check")
.header("X-API-Key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"agent_id\": \"550e8400-e29b-41d4-a716-446655440000\",\n \"framework\": \"soc2\",\n \"scope\": {\n \"controls\": [\n \"CC6.1\",\n \"CC6.2\",\n \"CC6.3\"\n ]\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.truthlocks.com/v1/compliance/check")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-Key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"agent_id\": \"550e8400-e29b-41d4-a716-446655440000\",\n \"framework\": \"soc2\",\n \"scope\": {\n \"controls\": [\n \"CC6.1\",\n \"CC6.2\",\n \"CC6.3\"\n ]\n }\n}"
response = http.request(request)
puts response.read_body{
"check_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"agent_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"framework": "soc2",
"scope": {},
"status": "pending",
"findings": [
{
"finding_id": "<string>",
"severity": "low",
"title": "<string>",
"description": "<string>"
}
],
"created_at": "2023-11-07T05:31:56Z"
}{
"code": "AUTH_REQUIRED",
"message": "Authentication required",
"http_status": 401
}{
"code": "AUTH_REQUIRED",
"message": "Authentication required",
"http_status": 401
}{
"code": "AUTH_REQUIRED",
"message": "Authentication required",
"http_status": 401
}Compliance & Anomalies
Create Compliance Check
Run an automated compliance check against a regulation for an entity
POST
/
v1
/
compliance
/
check
Create Compliance Check
curl --request POST \
--url https://api.truthlocks.com/v1/compliance/check \
--header 'Content-Type: application/json' \
--header 'X-API-Key: <api-key>' \
--data '
{
"agent_id": "550e8400-e29b-41d4-a716-446655440000",
"framework": "soc2",
"scope": {
"controls": [
"CC6.1",
"CC6.2",
"CC6.3"
]
}
}
'import requests
url = "https://api.truthlocks.com/v1/compliance/check"
payload = {
"agent_id": "550e8400-e29b-41d4-a716-446655440000",
"framework": "soc2",
"scope": { "controls": ["CC6.1", "CC6.2", "CC6.3"] }
}
headers = {
"X-API-Key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-API-Key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
agent_id: '550e8400-e29b-41d4-a716-446655440000',
framework: 'soc2',
scope: {controls: ['CC6.1', 'CC6.2', 'CC6.3']}
})
};
fetch('https://api.truthlocks.com/v1/compliance/check', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.truthlocks.com/v1/compliance/check",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'agent_id' => '550e8400-e29b-41d4-a716-446655440000',
'framework' => 'soc2',
'scope' => [
'controls' => [
'CC6.1',
'CC6.2',
'CC6.3'
]
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.truthlocks.com/v1/compliance/check"
payload := strings.NewReader("{\n \"agent_id\": \"550e8400-e29b-41d4-a716-446655440000\",\n \"framework\": \"soc2\",\n \"scope\": {\n \"controls\": [\n \"CC6.1\",\n \"CC6.2\",\n \"CC6.3\"\n ]\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-API-Key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.truthlocks.com/v1/compliance/check")
.header("X-API-Key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"agent_id\": \"550e8400-e29b-41d4-a716-446655440000\",\n \"framework\": \"soc2\",\n \"scope\": {\n \"controls\": [\n \"CC6.1\",\n \"CC6.2\",\n \"CC6.3\"\n ]\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.truthlocks.com/v1/compliance/check")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-Key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"agent_id\": \"550e8400-e29b-41d4-a716-446655440000\",\n \"framework\": \"soc2\",\n \"scope\": {\n \"controls\": [\n \"CC6.1\",\n \"CC6.2\",\n \"CC6.3\"\n ]\n }\n}"
response = http.request(request)
puts response.read_body{
"check_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"agent_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"framework": "soc2",
"scope": {},
"status": "pending",
"findings": [
{
"finding_id": "<string>",
"severity": "low",
"title": "<string>",
"description": "<string>"
}
],
"created_at": "2023-11-07T05:31:56Z"
}{
"code": "AUTH_REQUIRED",
"message": "Authentication required",
"http_status": 401
}{
"code": "AUTH_REQUIRED",
"message": "Authentication required",
"http_status": 401
}{
"code": "AUTH_REQUIRED",
"message": "Authentication required",
"http_status": 401
}Executes an automated compliance assessment for a specific entity (agent, model, dataset, or workflow) against a supported regulation. The check evaluates the entity’s configuration, access patterns, data handling, and audit trail against the regulation’s requirements and produces a compliance determination with detailed findings.
Compliance checks are idempotent for the same entity-regulation pair within a 24-hour window. Repeated calls within that window return the cached result.
Authentication
RequiresX-API-Key header or Bearer JWT token. Tenant-scoped via X-Tenant-ID.
Request Body
string
required
The type of entity to assess. One of: -
agent — a registered machine agentmodel— an AI/ML model -dataset— a data asset or training dataset -workflow— an automated workflow or pipeline
string
required
The unique identifier of the entity to assess. Must exist within the tenant.
string
required
The regulation or framework to assess against. Supported values: -
SOC2 —
SOC 2 Type II controls - ISO27001 — ISO 27001 information security
management - GDPR — EU General Data Protection Regulation - HIPAA — US
Health Insurance Portability and Accountability Act - EU_AI_ACT — EU
Artificial Intelligence Actstring
Optional scope qualifier to narrow the assessment. For example,
access-control to assess only access-control-related controls, or
data-handling for data processing controls. If omitted, a full-scope
assessment is performed.Response
string
Unique identifier for the compliance check record. Format:
maip-cc:ULID.string
The type of entity that was assessed.
string
The identifier of the assessed entity.
string
The regulation that was assessed.
string
The scope of the assessment.
full if no scope was specified.string
The compliance determination. One of: -
compliant — entity meets all
assessed requirements - non_compliant — entity fails one or more critical
requirements - partial — entity meets some but not all requirementsobject[]
Detailed list of individual findings from the assessment.
Show Finding fields
Show Finding fields
string
The control identifier within the regulation (e.g.,
CC6.1 for SOC2, A.9.1.1 for ISO27001).string
Human-readable name of the control.
string
Status of this specific control:
pass, fail, partial, not_applicable.string
Severity of the finding if not passing:
critical, high, medium, low.string
Detailed description of the finding and remediation guidance.
string
The MAIP receipt minted for this compliance check, providing an immutable
audit record.
string
ISO 8601 timestamp of when the assessment was performed.
Supported Regulations
| Regulation | Controls Assessed | Typical Duration |
|---|---|---|
SOC2 | Trust Service Criteria (CC1-CC9) | 2-5 seconds |
ISO27001 | Annex A controls (A.5-A.18) | 2-5 seconds |
GDPR | Articles 5, 6, 12-22, 25, 32-34 | 3-8 seconds |
HIPAA | Administrative, Physical, Technical Safeguards | 3-8 seconds |
EU_AI_ACT | Risk classification, transparency, human oversight | 5-10 seconds |
Authorizations
API key for machine-to-machine authentication
Body
application/json

