Monitor vendor security, privacy, subprocessor, certification and SLA evidence, and map changes to controls and risk.
Production API: https://vendorevidence-api.com
Get a free API key · Documentation · Pricing · Status
Free tier: 150 evidence checks/month. No card required. Paid plans from $499/month.
Request a key. The token arrives by email; exchange it for the key, which is shown once.
curl -X POST https://vendorevidence-api.com/v1/keys \
-H 'content-type: application/json' \
-d '{"email": "you@example.com"}'Then call the API:
curl -X POST https://vendorevidence-api.com/v1/checks \
-H "Authorization: Bearer $KEY" \
-H 'content-type: application/json' \
-d '{"check":{
"vendorId":"vnd-northwind",
"previous":{"capturedAt":"2026-02-01",
"certifications":[{"framework":"soc2_type2","issuedAt":"2025-02-15",
"expiresAt":"2026-02-14",
"scope":["security","availability","confidentiality"]}],
"subprocessors":[{"name":"Cloudmail","country":"US"}],
"slas":[{"metric":"uptime","uptimeBasisPoints":9995}]},
"current":{"capturedAt":"2026-08-01",
"certifications":[{"framework":"soc2_type2","issuedAt":"2026-02-15",
"expiresAt":"2027-02-14",
"scope":["security","confidentiality"]}],
"subprocessors":[{"name":"Cloudmail","country":"US"},
{"name":"Supportly","country":"BR"}],
"slas":[{"metric":"uptime","uptimeBasisPoints":9990}]}}}\'Every endpoint below has a runnable playground on the documentation page.
| Endpoint | Auth | Description |
|---|---|---|
GET /health |
public | Liveness and deployed version |
GET / |
public | Service index — endpoints, auth and error format |
POST /v1/checks |
API key | Compare two evidence snapshots and return drift, controls and risk |
POST /v1/demo/check |
public | Public demo — compare one pair of snapshots without a key |
GET /v1/drift-types |
public | Every drift code, severity, control mapping and scoring constant |
POST /v1/checkout |
public | Start a hosted Square checkout for a paid tier |
POST /v1/keys |
public | Request a free sandbox API key (sends a verification email) |
GET /v1/keys |
API key | List your API keys for this API |
POST /v1/keys/claim |
public | Exchange an emailed claim token for the API key |
POST /v1/keys/{id}/revoke |
API key | Revoke one of your API keys |
POST /v1/keys/{id}/rotate |
API key | Replace one of your API keys with a new secret |
GET /v1/usage |
API key | Your consumption and remaining allowance for this period |
GET /v1/subscription |
API key | Your current plan, billing window and available changes (dashboard session required) |
POST /v1/subscription/plan |
API key | Upgrade or downgrade to another plan (dashboard session required) |
POST /v1/subscription/cancel |
API key | Cancel this plan and end metered access (dashboard session required) |
GET /v1/invoices |
API key | Every invoice issued against this account, newest first (dashboard session required) |
GET /v1/payments |
API key | Every payment attempted against this account and how it went (dashboard session required) |
The full machine-readable contract is openapi.json, generated
from the deployed route table rather than maintained by hand. A
Postman collection is included.
Python — sdk/python
from vendor_evidence_drift import VendorEvidenceDrift
client = VendorEvidenceDrift() # reads VENDOR_EVIDENCE_DRIFT_API_KEY
res = client.check({
"vendorId": "vnd-northwind",
"previous": {
"capturedAt": "2026-02-01",
"certifications": [{"framework": "soc2_type2", "issuedAt": "2025-02-15",
"expiresAt": "2026-02-14",
"scope": ["security", "availability", "confidentiality"]}],
"subprocessors": [{"name": "Cloudmail", "country": "US"}],
"slas": [{"metric": "uptime", "uptimeBasisPoints": 9995}],
},
"current": {
"capturedAt": "2026-08-01",
"certifications": [{"framework": "soc2_type2", "issuedAt": "2026-02-15",
"expiresAt": "2027-02-14",
"scope": ["security", "confidentiality"]}],
"subprocessors": [{"name": "Cloudmail", "country": "US"},
{"name": "Supportly", "country": "BR"}],
"slas": [{"metric": "uptime", "uptimeBasisPoints": 9990}],
},
})
report = res["reports"][0]
# The certification is current and covers less than it did. Branch on the code,
# never on the detail text.
for f in report["findings"]:
if f["material"]:
open_review(f["code"], f["subject"], f["detail"], f["controls"])
print(report["risk"]["score"], report["risk"]["band"])
for line in report["risk"]["derivation"]:
print(line) # the arithmetic, reproducible by hand
for w in report["warnings"]:
print("could not check:", w)TypeScript — sdk/typescript
import { VendorEvidenceDrift } from './vendor-evidence-drift.js'
const client = new VendorEvidenceDrift() // reads VENDOR_EVIDENCE_DRIFT_API_KEY
const { reports } = await client.check({
vendorId: 'vnd-northwind',
previous: {
capturedAt: '2026-02-01',
certifications: [{ framework: 'soc2_type2', issuedAt: '2025-02-15',
expiresAt: '2026-02-14',
scope: ['security', 'availability', 'confidentiality'] }],
subprocessors: [{ name: 'Cloudmail', country: 'US' }],
slas: [{ metric: 'uptime', uptimeBasisPoints: 9995 }],
},
current: {
capturedAt: '2026-08-01',
certifications: [{ framework: 'soc2_type2', issuedAt: '2026-02-15',
expiresAt: '2027-02-14',
scope: ['security', 'confidentiality'] }],
subprocessors: [{ name: 'Cloudmail', country: 'US' },
{ name: 'Supportly', country: 'BR' }],
slas: [{ metric: 'uptime', uptimeBasisPoints: 9990 }],
},
})
const report = reports[0]
// The certification is current and covers less than it did. Branch on the
// code, never on the detail text.
for (const f of report.findings) {
if (f.material) openReview(f.code, f.subject, f.detail, f.controls)
}
console.log(report.risk.score, report.risk.band)
report.risk.derivation.forEach((line) => console.log(line))
for (const w of report.warnings) console.log('could not check:', w)Every failure returns the same shape. Branch on code, which is a stable enum;
message is for humans and may change.
{"error": {"code": "invalid_api_key", "message": "...", "requestId": "0f3c8b12-…"}}requestId appears on every response and in the x-request-id header. Quote it
in any support request.
Open an issue in this repository, or see the contact route at https://vendorevidence-api.com/docs.

