List Compliance Reports
curl --request GET \
--url https://api.truthlocks.com/v1/compliance/reports \
--header 'X-API-Key: <api-key>'import requests
url = "https://api.truthlocks.com/v1/compliance/reports"
headers = {"X-API-Key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'X-API-Key': '<api-key>'}};
fetch('https://api.truthlocks.com/v1/compliance/reports', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.truthlocks.com/v1/compliance/reports",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.truthlocks.com/v1/compliance/reports"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-API-Key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.truthlocks.com/v1/compliance/reports")
.header("X-API-Key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.truthlocks.com/v1/compliance/reports")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["X-API-Key"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"items": [
{
"check_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"agent_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"framework": "soc2",
"scope": {},
"status": "pending",
"findings": [
{
"finding_id": "<string>",
"severity": "low",
"title": "<string>",
"description": "<string>"
}
],
"created_at": "2023-11-07T05:31:56Z"
}
],
"total": 123
}{
"code": "AUTH_REQUIRED",
"message": "Authentication required",
"http_status": 401
}{
"code": "AUTH_REQUIRED",
"message": "Authentication required",
"http_status": 401
}Compliance & Anomalies
Generate Compliance Report
Generate a comprehensive compliance report for an entity over a time period
GET
/
v1
/
compliance
/
reports
List Compliance Reports
curl --request GET \
--url https://api.truthlocks.com/v1/compliance/reports \
--header 'X-API-Key: <api-key>'import requests
url = "https://api.truthlocks.com/v1/compliance/reports"
headers = {"X-API-Key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'X-API-Key': '<api-key>'}};
fetch('https://api.truthlocks.com/v1/compliance/reports', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.truthlocks.com/v1/compliance/reports",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.truthlocks.com/v1/compliance/reports"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-API-Key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.truthlocks.com/v1/compliance/reports")
.header("X-API-Key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.truthlocks.com/v1/compliance/reports")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["X-API-Key"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"items": [
{
"check_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"agent_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"framework": "soc2",
"scope": {},
"status": "pending",
"findings": [
{
"finding_id": "<string>",
"severity": "low",
"title": "<string>",
"description": "<string>"
}
],
"created_at": "2023-11-07T05:31:56Z"
}
],
"total": 123
}{
"code": "AUTH_REQUIRED",
"message": "Authentication required",
"http_status": 401
}{
"code": "AUTH_REQUIRED",
"message": "Authentication required",
"http_status": 401
}Generates an aggregated compliance report for an entity across all checks performed within a specified time period. Reports provide executive-level summaries, trend analysis, and a consolidated view of all findings — suitable for sharing with auditors, compliance officers, and regulators.
Reports are generated asynchronously for large time ranges. For periods under 30 days, results are typically returned synchronously.
Authentication
RequiresX-API-Key header or Bearer JWT token. Tenant-scoped via X-Tenant-ID.
Request Body
string
required
The type of entity to report on. One of:
agent, model, dataset,
workflow.string
required
The unique identifier of the entity.
string
required
The regulation or framework to report against. Supported values:
SOC2,
ISO27001, GDPR, HIPAA, EU_AI_ACT.string
required
ISO 8601 date for the start of the reporting period (inclusive). Example:
2026-01-01.string
required
ISO 8601 date for the end of the reporting period (inclusive). Example:
2026-03-31.Response
string
Unique identifier for the compliance report. Format:
maip-report:ULID.string
The type of entity reported on.
string
The identifier of the entity reported on.
string
The regulation assessed.
string
Start of the reporting period.
string
End of the reporting period.
string
Report generation status. One of:
generating, ready, failed.object
High-level summary of compliance across the reporting period.
Show Summary fields
Show Summary fields
integer
Total number of compliance checks performed in the period.
integer
Number of checks that returned
compliant.integer
Number of checks that returned
non_compliant.integer
Number of checks that returned
partial.number
Percentage of checks that returned
compliant, as a float between 0.0 and 100.0.string
Compliance trend direction over the period:
improving, stable, degrading.object[]
Aggregated findings across all checks in the period. Deduplicated by control ID with the most recent status.
Show Finding fields
Show Finding fields
string
The control identifier within the regulation.
string
Human-readable name of the control.
string
Most recent status:
pass, fail, partial, not_applicable.string
Severity if not passing:
critical, high, medium, low.string
ISO 8601 timestamp of when this finding first appeared.
string
ISO 8601 timestamp of the most recent check for this control.
string
Detailed description and remediation guidance.
string
ISO 8601 timestamp of when the report was generated.
Authorizations
API key for machine-to-machine authentication
Query Parameters
Filter by agent
Filter by framework
Available options:
soc2, iso27001, hipaa, gdpr Filter by result status
Available options:
pending, passed, failed, partial Required range:
1 <= x <= 100Required range:
x >= 0
