Skip to content

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Vendor Evidence Drift API

Monitor vendor security, privacy, subprocessor, certification and SLA evidence, and map changes to controls and risk.

Vendor Evidence Drift landing page

Production API: https://vendorevidence-api.com

Get a free API key · Documentation · Pricing · Status

Free tier: 150 evidence checks/month. No card required. Paid plans from $499/month.

Quickstart

Request a key. The token arrives by email; exchange it for the key, which is shown once.

curl -X POST https://vendorevidence-api.com/v1/keys \
  -H 'content-type: application/json' \
  -d '{"email": "you@example.com"}'

Then call the API:

curl -X POST https://vendorevidence-api.com/v1/checks \
  -H "Authorization: Bearer $KEY" \
  -H 'content-type: application/json' \
  -d '{"check":{
        "vendorId":"vnd-northwind",
        "previous":{"capturedAt":"2026-02-01",
          "certifications":[{"framework":"soc2_type2","issuedAt":"2025-02-15",
            "expiresAt":"2026-02-14",
            "scope":["security","availability","confidentiality"]}],
          "subprocessors":[{"name":"Cloudmail","country":"US"}],
          "slas":[{"metric":"uptime","uptimeBasisPoints":9995}]},
        "current":{"capturedAt":"2026-08-01",
          "certifications":[{"framework":"soc2_type2","issuedAt":"2026-02-15",
            "expiresAt":"2027-02-14",
            "scope":["security","confidentiality"]}],
          "subprocessors":[{"name":"Cloudmail","country":"US"},
                           {"name":"Supportly","country":"BR"}],
          "slas":[{"metric":"uptime","uptimeBasisPoints":9990}]}}}\'

Endpoints

Vendor Evidence Drift API reference, with a live playground for every endpoint

Every endpoint below has a runnable playground on the documentation page.

Endpoint Auth Description
GET /health public Liveness and deployed version
GET / public Service index — endpoints, auth and error format
POST /v1/checks API key Compare two evidence snapshots and return drift, controls and risk
POST /v1/demo/check public Public demo — compare one pair of snapshots without a key
GET /v1/drift-types public Every drift code, severity, control mapping and scoring constant
POST /v1/checkout public Start a hosted Square checkout for a paid tier
POST /v1/keys public Request a free sandbox API key (sends a verification email)
GET /v1/keys API key List your API keys for this API
POST /v1/keys/claim public Exchange an emailed claim token for the API key
POST /v1/keys/{id}/revoke API key Revoke one of your API keys
POST /v1/keys/{id}/rotate API key Replace one of your API keys with a new secret
GET /v1/usage API key Your consumption and remaining allowance for this period
GET /v1/subscription API key Your current plan, billing window and available changes (dashboard session required)
POST /v1/subscription/plan API key Upgrade or downgrade to another plan (dashboard session required)
POST /v1/subscription/cancel API key Cancel this plan and end metered access (dashboard session required)
GET /v1/invoices API key Every invoice issued against this account, newest first (dashboard session required)
GET /v1/payments API key Every payment attempted against this account and how it went (dashboard session required)

The full machine-readable contract is openapi.json, generated from the deployed route table rather than maintained by hand. A Postman collection is included.

SDKs

Python — sdk/python

from vendor_evidence_drift import VendorEvidenceDrift

client = VendorEvidenceDrift()          # reads VENDOR_EVIDENCE_DRIFT_API_KEY

res = client.check({
    "vendorId": "vnd-northwind",
    "previous": {
        "capturedAt": "2026-02-01",
        "certifications": [{"framework": "soc2_type2", "issuedAt": "2025-02-15",
                            "expiresAt": "2026-02-14",
                            "scope": ["security", "availability", "confidentiality"]}],
        "subprocessors": [{"name": "Cloudmail", "country": "US"}],
        "slas": [{"metric": "uptime", "uptimeBasisPoints": 9995}],
    },
    "current": {
        "capturedAt": "2026-08-01",
        "certifications": [{"framework": "soc2_type2", "issuedAt": "2026-02-15",
                            "expiresAt": "2027-02-14",
                            "scope": ["security", "confidentiality"]}],
        "subprocessors": [{"name": "Cloudmail", "country": "US"},
                          {"name": "Supportly", "country": "BR"}],
        "slas": [{"metric": "uptime", "uptimeBasisPoints": 9990}],
    },
})

report = res["reports"][0]

# The certification is current and covers less than it did. Branch on the code,
# never on the detail text.
for f in report["findings"]:
    if f["material"]:
        open_review(f["code"], f["subject"], f["detail"], f["controls"])

print(report["risk"]["score"], report["risk"]["band"])
for line in report["risk"]["derivation"]:
    print(line)          # the arithmetic, reproducible by hand

for w in report["warnings"]:
    print("could not check:", w)

TypeScript — sdk/typescript

import { VendorEvidenceDrift } from './vendor-evidence-drift.js'

const client = new VendorEvidenceDrift()  // reads VENDOR_EVIDENCE_DRIFT_API_KEY

const { reports } = await client.check({
  vendorId: 'vnd-northwind',
  previous: {
    capturedAt: '2026-02-01',
    certifications: [{ framework: 'soc2_type2', issuedAt: '2025-02-15',
                       expiresAt: '2026-02-14',
                       scope: ['security', 'availability', 'confidentiality'] }],
    subprocessors: [{ name: 'Cloudmail', country: 'US' }],
    slas: [{ metric: 'uptime', uptimeBasisPoints: 9995 }],
  },
  current: {
    capturedAt: '2026-08-01',
    certifications: [{ framework: 'soc2_type2', issuedAt: '2026-02-15',
                       expiresAt: '2027-02-14',
                       scope: ['security', 'confidentiality'] }],
    subprocessors: [{ name: 'Cloudmail', country: 'US' },
                    { name: 'Supportly', country: 'BR' }],
    slas: [{ metric: 'uptime', uptimeBasisPoints: 9990 }],
  },
})

const report = reports[0]

// The certification is current and covers less than it did. Branch on the
// code, never on the detail text.
for (const f of report.findings) {
  if (f.material) openReview(f.code, f.subject, f.detail, f.controls)
}

console.log(report.risk.score, report.risk.band)
report.risk.derivation.forEach((line) => console.log(line))

for (const w of report.warnings) console.log('could not check:', w)

Errors

Every failure returns the same shape. Branch on code, which is a stable enum; message is for humans and may change.

{"error": {"code": "invalid_api_key", "message": "...", "requestId": "0f3c8b12-…"}}

requestId appears on every response and in the x-request-id header. Quote it in any support request.

Support

Open an issue in this repository, or see the contact route at https://vendorevidence-api.com/docs.

About

Monitor vendor security, privacy, subprocessor, certification and SLA evidence, and map changes to controls and risk.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages