PalveronPalveronDocs

Compliance Reports

Generate Annex IV-oriented PDF documentation in one call.

Compliance reports bundle the evidence an auditor expects — project metadata, compliance score, agent inventory, policy catalogue, trace statistics, blockchain anchoring configuration, retention posture — into a single PDF.

Generate a report

curl https://gateway.palveron.com/api/v1/compliance/report \
  -H "Authorization: Bearer pv_live_..." \
  -G --data-urlencode "from=2026-01-01" --data-urlencode "to=2026-03-31" \
  -o compliance-report.pdf
QueryDefaultValues
from— (optional)ISO 8601 date — start of the trace date range
to— (optional)ISO 8601 date — end of the trace date range

The report always covers all frameworks active on the project; there is no per-framework or per-agent filter. from/to scope the trace statistics — omit both for an all-time report. Invalid dates return 400 (never a silently widened scope). The endpoint requires the compliance_report_pdf feature (403 with error.code forbidden otherwise) and streams application/pdf.

Contents

The PDF has 15 fixed sections, in this order:

SectionContents
1. Executive SummaryProject metadata and the weighted compliance score with its breakdown
2. Regulatory Timeline & ApplicabilityEU AI Act obligations already in force vs. scheduled
3. System Description & Intended PurposeDescription and purpose of the AI system
4. Risk Management SystemThe project's risk management
5. Data & Data GovernanceData and data governance
6. Monitoring, Functioning & ControlMonitoring, operation, and control
7. Transparency & Information ProvisionTransparency and information obligations
8. Human Oversight MeasuresHuman oversight, including the approval decisions on the MCP path
9. Accuracy, Robustness & CybersecurityAccuracy, robustness, and security
10. AI System RegistryRegistered agents with type and risk classification
11. Policy Inventory & AttestationActive policies
12. Blockchain Verification EvidenceMerkle proofs and transaction hashes of anchored records
13. Audit Trail (Recent Samples)Latest governance decisions with provenance
14. Compliance MatrixThe controls matrix from the live catalog
15. Declaration & SignaturesDeclaration and signatures

The trace statistics in sections 1 and 13 are scoped by from/to.

Every statement in the report is backed by the deployed code or the live database — regulatory dates come from the sourced regulatory timeline, retention from the same resolution the retention worker enforces, and the score from the dashboard's calculation. Nothing is hand-maintained.

Incident reports are filed and listed via the Compliance API (POST /api/v1/compliance/incidents); for exportable audit evidence beyond the PDF, see GET /api/v1/compliance/evidence-package and the CSV export in the Traces API.

On this page