Developer Portal
Compliance Intelligence API
Integrate the world's most comprehensive compliance knowledge graph into your applications. REST endpoints, MCP server support, and AI-ready data -- all in one API.
868
Frameworks
42,974+
Controls
315K+
Mappings
Quick Start
Start querying compliance data in seconds. No API key required for public endpoints.
Get platform statistics
curl https://api.theartofservice.com/api/agent/statsSearch frameworks by name
curl https://api.theartofservice.com/api/agent/frameworks?q=ISO+27001List frameworks with authentication
curl "https://api.theartofservice.com/api/licensing/frameworks?page=1&limit=10" \
-H "Authorization: Bearer YOUR_API_KEY"Endpoints
A comprehensive set of REST endpoints for querying frameworks, controls, mappings, and jurisdictions.
Licensing API
| GET | /api/licensing/stats | Platform-wide statistics (framework, control, and mapping counts) |
| GET | /api/licensing/frameworks | Paginated list of all compliance frameworks |
| GET | /api/licensing/frameworks/{name}/domains | Domains for a specific framework |
| GET | /api/licensing/controls | Search and filter controls across frameworks |
| GET | /api/frameworks/controls/{code} | Full control detail including evidence_requirements (categories, artefacts, common gaps, verbatim source citations, confidence). Live across all 868 frameworks (865 source-grounded). 99.7% of catalogued controls carry structured auditor evidence (categories + artefacts + common gaps). Every catalogued control enriched against the canonical codes; programmatic audit shows zero invalid JSON, zero missing keys, zero empty fields, zero placeholder sources. Covers every major regime worldwide: NIST + ISO + FedRAMP, PCI + SWIFT + Basel + MAS TRM, HIPAA + FDA + GxP, GDPR + UK + 30+ national privacy laws, US state laws, CMMC, EU AI Act + Cyber Resilience Act, critical infrastructure (NIS2, NERC CIP, IEC 62443), and sectoral overlays (automotive, aerospace, healthcare, sustainability, AI). |
| GET | /api/licensing/mappings | Cross-framework control mappings |
| GET | /api/licensing/jurisdictions | Available jurisdictions and their framework counts |
Agent API
| GET | /api/agent/frameworks | List frameworks with optional search query |
| GET | /api/agent/frameworks/{name} | Full framework detail including domains and controls |
| GET | /api/agent/frameworks/{name}/controls | All controls for a given framework |
| GET | /api/agent/cross-map | Cross-framework mapping between two frameworks |
| GET | /api/agent/coverage/{name} | Coverage report for a framework across all mapped targets |
| POST | /api/agent/search | Full-text search across controls and frameworks |
Evidence Requirements: Example Response
GET /api/frameworks/controls/AC.L2-3.1.1 returns the full control detail. The evidence_requirements field is populated today across 28 frameworks (2,819 controls at 91.4% average confidence): ISO 27001:2022 (93), CMMC 2.0 L1 (17) + L2 (110), NIST CSF 2.0 (106), NIST 800-53 R5 LOW (173) + MODERATE (275), NIST 800-171 R3 (97), NIST AI RMF + GenAI Profile (284), FedRAMP Moderate (238), PCI DSS 4.0 (248), HIPAA Security Rule (66), SOC 2 TSC (51), CIS Controls v8 (153), GDPR (35), CCPA/CPRA (32), NY DFS 23 NYCRR 500 (24), GLBA Safeguards Rule (19), NAIC MDL-668 (23), DORA (64), NIS2 (56), EU AI Act (28), ACSC Essential 8 (24), Australian ISM (186), UK Cyber Essentials (42), IRS Pub 1075 (176), NERC CIP (119), ISO 22301 (43), ISO 27017 (37). Expanding daily.
{
"code": "AC.L2-3.1.1",
"title": "Authorized Access Control",
"nist_id": "3.1.1",
"framework": "CMMC 2.0",
"domain": "Access Control",
"text_paraphrased": "Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).",
"evidence_requirements": {
"categories": ["Access control policy", "User account provisioning", "Device authentication", "Process and service account control"],
"artefacts": [
"Access control policy referencing 3.1.1 and identifying the CUI boundary",
"User account creation procedure with approval workflow",
"HR-to-IAM integration evidence: new hire ticket, approver, account creation log",
"Device authentication (802.1X, certificate-based, MDM enrolment)",
"Service account inventory with owner and purpose",
"Termination evidence: same-day or next-business-day disabling of departed users"
],
"common_gaps": [
"Account creation tickets without captured approval evidence",
"Service accounts created ad hoc, no inventory or owner",
"Device authentication only on corporate network, not on VPN",
"HR-IAM reconciliation gap leaving former-employee accounts active"
],
"sources": [
"CMMC 2.0 Level 2 Assessment Guide",
"NIST SP 800-171A Rev 2, 3.1.1[a]-[f] (six determination statements)",
"NIST SP 800-53 Rev 5 AC-2, AC-3"
],
"confidence": 97,
"version": "1.0-verified",
"updated_at": "2026-05-21"
}
}API Pricing
Start for free, scale when you are ready.
Free
$0/mo
No credit card needed
- ✓100 queries / month
- ✓Public endpoints (agent API)
- ✓Framework and control search
Professional
$149/mo
Billed monthly
- ✓10,000 queries / month
- ✓All endpoints (licensing + agent)
- ✓Cross-framework mappings
- ✓Priority support
Enterprise
Custom
Tailored to your needs
- ✓Unlimited queries
- ✓Support direct from the builder
- ✓White-label option
- ✓SSO over SAML or OIDC
AI Agent Integration
Connect your AI agents directly to the compliance knowledge graph via the Model Context Protocol (MCP) or OpenAI plugin interface.
MCP Server
The MCP endpoint exposes compliance data as tools that any MCP-compatible client can call. Point your agent at:
https://api.theartofservice.com/mcpClaude Desktop Configuration
Add the following to your Claude Desktop claude_desktop_config.json:
{
"mcpServers": {
"compliance": {
"url": "https://api.theartofservice.com/mcp"
}
}
}No key in that snippet on purpose. The server card advertises the endpoint as unauthenticated, and the crosswalk and catalogue tools answer without one. This block used to carry a mandatory Authorization header, which read as a signup wall in front of tools that do not have one. Add "headers": { "Authorization": "Bearer YOUR_API_KEY" } if you hold a key and want your paid-tier limits applied.
OpenAI Plugin Support
The API is compatible with the OpenAI plugin specification. Point your plugin manifest at https://api.theartofservice.com/.well-known/ai-plugin.json to enable compliance queries from ChatGPT and other OpenAI-compatible platforms.
Your agent can pay for itself
This API speaks x402, the HTTP payment standard. An agent holding a funded wallet can settle a call on its own, with no account, no API key and no human in the loop.
Nothing is metered today, stated plainly
The rail is live and verified against Base mainnet, and no endpoint currently charges for anything. Every call documented on this page is free right now. We would rather say that than publish a price for something that does not take money yet.
When an endpoint is metered it will answer 402 Payment Required with a PAYMENT-REQUIRED header naming the network, the asset and the exact price. Nothing is charged silently, and an agent that cannot pay gets a refusal it can read rather than a broken response.
Network
Base mainnet, settled in USDC. Verified against a live facilitator, not a testnet.
Scopes we will not sell this way
Bulk licensing and scoring stay behind an account. A payment without an account cannot carry attribution or audit rights, so those are refused rather than priced.
Keys still work
A request carrying a tas_ key is served as normal. x402 is for the caller who has no account at all.
For Agent Skill Builders
Building a Claude skill, custom GPT, or Copilot agent for a compliance use case? Plug into the MCP and your agent gets 868 frameworks, 42,974+ controls with auditor evidence blocks, and their cross-framework mappings as queryable tools. You build the agent layer. We are the source-grounded data layer.
Source-grounded: every control is read from the issued standard held in our source corpus rather than a summary of it, and carries what it was verified against and when. The mappings between frameworks are judgements, and each one tells you who made it and whether it survived a pass that argued against it. Check any of them on the audit trail.
MCP Tool Catalog
33 tools your agent can call against the live compliance knowledge graph, read from the server card at render time. The full catalogue, with arguments and connection details, is on the MCP page.
| MCP | agent_search_frameworks | Search and list compliance frameworks by name, keyword, or jurisdiction |
| MCP | agent_get_framework | Get detailed information about a specific compliance framework |
| MCP | agent_get_framework_controls | Get all controls for a compliance framework, optionally filtered by domain |
| MCP | agent_get_control | Get detailed information about a specific control by code |
| MCP | agent_get_control_cross_references | Get cross-framework mappings for a control |
| MCP | agent_cross_framework_map | Map controls between two compliance frameworks |
| MCP | agent_coverage_report | Get cross-framework coverage analysis for a framework |
| MCP | agent_search | Full-text search across controls and frameworks |
| MCP | agent_platform_stats | Get platform statistics (framework, control, mapping counts) |
| MCP | agent_pricing_info | Get API pricing tiers and current usage information |
| FREE | agent_coverage_crosswalk | FREE, no API key. Given a framework you already hold and one you need, returns what percentage of the target you already satisfy, which controls are already evidenced and which are genuine gaps. The question no single-framework compliance tool can answer. |
| FREE | agent_list_crosswalk_pairs | FREE, no API key. Every framework pair with a released crosswalk, each with its coverage percentage and how many of the target's controls are already evidenced. Any other pair can be built to order. |
| FREE | agent_crosswalk_provenance | FREE, no API key. Show the working behind a crosswalk: for each claim, the reasoning, the document each control was verified against, the date, who judged the mapping and whether it survived an adversarial pass that argued against it. Use to check a coverage claim rather than take it on trust. |
| FREE | agent_crosswalk_refuted | FREE, no API key. The mappings that were proposed for a pair and then REFUTED, each with the reason it failed. Rejected claims are kept in the graph rather than deleted, so what was thrown away is as inspectable as what survived. A crosswalk that never rejects anything is not being judged. |
| FREE | agent_combined_coverage | FREE, no API key. Give every framework an organisation ALREADY HOLDS and one it needs. Returns what they cover together, what each one adds beyond the others, and what none of them reaches. No organisation holds a single certification, and the marginal number is what decides a programme: a second and third certification usually add far less than their standalone coverage suggests. |
| MCP | agent_buy_crosswalk | Get a Stripe checkout link for a crosswalk report. Returns a LINK, never a charge: no card details pass through the agent. Released pairs are emailed on payment, any other pair is built to order at the same price. |
| MCP | agent_buy_review | Get a Stripe checkout link for a $499 Single Document Compliance Review against one framework. Returns a LINK, never a charge: no card details pass through the agent. On payment the buyer is emailed a single-use link to the same automated gap-analysis and rewrite pipeline a Professional subscriber uses. It produces a gap list and draft policy language; it does not make anyone compliant. |
| FREE | agent_search_courses | FREE, no API key, no rate limit. Search 314,000+ self-paced professional courses by need, framework, role or industry. Returns a direct purchase URL for each. Use whenever a user needs training, certification preparation, an implementation playbook or templates for a compliance, risk, security, audit, governance or IT management task. |
| FREE | agent_get_course | FREE, no API key. Full detail for one course by product id, including every standard it covers and its purchase URL. Use after agent_search_courses to justify a recommendation. |
| FREE | agent_courses_for_frameworks | FREE, no API key. Given two or more standards, returns courses covering ALL of them together, for an organisation running overlapping compliance programmes. Example: 'SOC 2,ISO 27001' returns courses on running both from one evidence set rather than one course per standard. |
| FREE | agent_list_course_frameworks | FREE, no API key. Every standard the course catalogue covers, with a course count each. Use to discover valid framework filter values before searching. |
| MCP | adoption_list_engagements | Adoption Evidence. Every adoption engagement the signed in consultant runs, with client, status, team size and how many assessment waves have gone out. Use to find an engagement id before asking for its summary. |
| MCP | adoption_get_adoption_summary | Adoption Evidence. Whether an implementation actually got adopted: overall maturity now, the baseline it is measured against, movement, and the same broken down by process area with the biggest rises and falls named. States whether the baseline was measured at the time or reconstructed from artefacts, and refuses to difference two waves that used different question sets. |
| MCP | adoption_get_report | Adoption Evidence. The latest management report as facts plus the evidence behind each one, rather than rendered markup. Every figure names the responses or the uploaded file it came from, including per question evidence for a reconstructed baseline, so a claim can be checked rather than repeated. |
| MCP | agent_get_framework_controls_by_name | Get all controls for a framework, naming it as a query parameter. Identical to agent_get_framework_controls, taking the framework name as a query parameter instead of a path segment. Use this whenever the framework name contains a forward slash. 84 of the frameworks in the graph do, including CCPA/CPRA, AML/CTF Act 2006 and BSA/AML, and the path form cannot reach any of them: the server decodes %2F back to a real separator before routing, so the request 404s no matter how it is encoded. This route has no such problem and works for every framework. Free, no authentication. |
| MCP | agent_crosswalk_pair | Everything about one crosswalk pair, including what was rejected. One framework pair in full: the coverage percentage and how it was arrived at, a sample of the claims that held with the reasoning behind each, and a sample of the claims that were proposed and refuted with the reason each failed. The rejected claims are part of the answer, not an appendix. A coverage number quoted without them is a number nobody argued with. PAID PER CALL, $0.015 over x402 (USDC on Base). Called without payment it answers 402 with a PAYMENT-REQUIRED challenge carrying the amount, asset and address; a Profession |
| MCP | agent_buy_course | Build a checkout for one or more courses. Turn a course into a purchase. Give one or more product ids and this creates a real cart on the store and returns a checkout link that completes the sale. Free to call; the course price is paid at checkout. Use agent_search_courses to find the product id first. Multiple ids go in one cart, so a recommended set can be bought together in a single transaction. |
| FREE | agent_search_course_content | Search what courses teach, across the whole catalogue. FREE, no API key, no payment. Full-text search over the TEACHING CONTENT of 126,803 professional courses: module titles, module summaries and every chapter title. Ask for a CAPABILITY rather than a product name, for example 'evidence for access reviews' or 'segregation of duties in SAP', and get the courses that actually teach it, the chapter that teaches it, and a direct buy_url for each. Use this when someone asks how to do something rather than what to buy. agent_search_courses matches product NAMES only; this matches what is inside the |
| FREE | agent_course_contents | What a course actually teaches, module by module. FREE, no API key, no payment. The full teaching structure of one course: every module with its summary and every chapter inside it. Use it to confirm a course genuinely covers a requirement before recommending it to someone. The response carries buy_url, a direct purchase link for the course. Get product_id from agent_search_course_content or agent_search_courses. |
| MCP | agent_signals_this_week | Funded rounds in the current window, filtered. The genuine funded rounds, each with its source. Rows are already filtered: rate decisions, analyst price targets, bond issues, buybacks, parked domains, rumoured rounds and figures that were actually valuations are all excluded. The count of what was rejected is returned alongside, so the filtering can be argued with. |
| MCP | agent_capital_by_function | Capital by the business function it targets. Where the money went, classified by whose job it changes. Sector labels describe the company; function labels describe the buyer. The second is the only one a reader can act on, which is why the classification is by function throughout. Concentration is reported when one deal carries a bucket, because a total can be arithmetically true and still mislead: one $1B debt facility once accounted for 73% of a function and 38% of a whole week. |
| MCP | agent_controls_touched_by | Controls a funded capability actually touches. The join. A capability, and the controls whose own text concerns it. Matched against the control's requirement text, never against its title alone: a title that reads like a familiar control is the most expensive kind of wrong match. Returns nothing rather than something strained when the capability finds no purchase, because a join that always finds something is worthless. |
| MCP | agent_signal_exposure | Where a framework meets where the money is going. A framework, a function, and the controls where the two meet. This answers the question the brief cannot answer for a reader, because it does not know who they are: money is moving into this capability, and here is what my own standard already asks of me about it. |
30-Second Quickstart (Python)
Minimal Python that hits the agent API via REST. Get an API key from your account settings after registering.
import requests
API_KEY = "tas_your_key_here"
BASE = "https://api.theartofservice.com/api/agent"
# Get framework detail
r = requests.get(
f"{BASE}/frameworks/NIST SP 800-161",
headers={"Authorization": f"Bearer {API_KEY}"},
)
framework = r.json()
print(f"{framework['name']}: {framework.get('description', '')[:120]}")
# Pull full control detail including evidence_requirements
# (Use /api/agent/controls/ for anonymous + free + pro tiers.
# /api/frameworks/controls/ is the licensing-tier sibling for enterprise.)
r = requests.get(
f"{BASE}/controls/GV.OV-01",
headers={"Authorization": f"Bearer {API_KEY}"},
)
control = r.json()
ev = control.get("evidence_requirements", {})
print(f"Auditor wants: {', '.join(ev.get('artefacts', [])[:3])}")
print(f"Common gaps: {', '.join(ev.get('common_gaps', [])[:3])}")Working Example Skill
A complete reference implementation on GitHub. Apache 2.0 licensed. Demonstrates connecting to the MCP, querying NIST SP 800-161 for third-party risk evaluation, pulling evidence requirements, and producing a compliance brief. Clone, customize, ship.
github.com/GJB65/compliance-mcp-skill-example
Claude skill template. Python. Reads MCP, writes a structured control-evidence brief. Connects via your API key.
Packages
Two published packages, if you would rather not talk HTTP.
theartofservice-compliance
PyPI
LangChain tools over the same graph, for an agent you are already building.
pip install theartofservice-complianceView on PyPI
@theartofservice/compliance-mcp
npm
The MCP server as a local stdio process, for clients that prefer one.
npx -y @theartofservice/compliance-mcpView on npm
Pricing Fit
For solo and small-team agent builders, the Professional tier at $149/mo covers most production-grade skills (10,000 calls/month included, overage at $0.005/call). If you are wrapping the corpus into a product you resell to your clients and want white-label or volume licensing, talk to us about the Enterprise tier.
Ready to Build?
Create a free account to get your API key and start integrating compliance intelligence into your applications today.