Compliance Reports
Generate Annex IV-oriented PDF documentation in one call.
Compliance reports bundle the evidence an auditor expects — project metadata, compliance score, agent inventory, policy catalogue, trace statistics, blockchain anchoring configuration, retention posture — into a single PDF.
Generate a report
curl https://gateway.palveron.com/api/v1/compliance/report \
-H "Authorization: Bearer pv_live_..." \
-G --data-urlencode "from=2026-01-01" --data-urlencode "to=2026-03-31" \
-o compliance-report.pdf| Query | Default | Values |
|---|---|---|
from | — (optional) | ISO 8601 date — start of the trace date range |
to | — (optional) | ISO 8601 date — end of the trace date range |
The report always covers all frameworks active on the project; there is no per-framework or per-agent filter. from/to scope the trace statistics — omit both for an all-time report. Invalid dates return 400 (never a silently widened scope). The endpoint requires the compliance_report_pdf feature (403 with error.code forbidden otherwise) and streams application/pdf.
Contents
The PDF has 15 fixed sections, in this order:
| Section | Contents |
|---|---|
| 1. Executive Summary | Project metadata and the weighted compliance score with its breakdown |
| 2. Regulatory Timeline & Applicability | EU AI Act obligations already in force vs. scheduled |
| 3. System Description & Intended Purpose | Description and purpose of the AI system |
| 4. Risk Management System | The project's risk management |
| 5. Data & Data Governance | Data and data governance |
| 6. Monitoring, Functioning & Control | Monitoring, operation, and control |
| 7. Transparency & Information Provision | Transparency and information obligations |
| 8. Human Oversight Measures | Human oversight, including the approval decisions on the MCP path |
| 9. Accuracy, Robustness & Cybersecurity | Accuracy, robustness, and security |
| 10. AI System Registry | Registered agents with type and risk classification |
| 11. Policy Inventory & Attestation | Active policies |
| 12. Blockchain Verification Evidence | Merkle proofs and transaction hashes of anchored records |
| 13. Audit Trail (Recent Samples) | Latest governance decisions with provenance |
| 14. Compliance Matrix | The controls matrix from the live catalog |
| 15. Declaration & Signatures | Declaration and signatures |
The trace statistics in sections 1 and 13 are scoped by from/to.
Every statement in the report is backed by the deployed code or the live database — regulatory dates come from the sourced regulatory timeline, retention from the same resolution the retention worker enforces, and the score from the dashboard's calculation. Nothing is hand-maintained.
Incident reports are filed and listed via the Compliance API (POST /api/v1/compliance/incidents); for exportable audit evidence beyond the PDF, see GET /api/v1/compliance/evidence-package and the CSV export in the Traces API.