> ## Documentation Index
> Fetch the complete documentation index at: https://docs.wistx.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Compliance Requirements

> Get compliance requirements for infrastructure resources

> Get compliance requirements for infrastructure resources (PCI-DSS, HIPAA, CIS, SOC2, NIST, ISO 27001)

<Info>
  **Base URL:** `https://api.wistx.ai`\
  The API playground will use this base URL by default. You can switch to `http://localhost:8000` for local development using the server selector above.
</Info>

## Endpoint

<CodeGroup>
  ```bash cURL theme={null}
  curl --request POST \
    --url https://api.wistx.ai/v1/compliance/requirements \
    --header 'Authorization: Bearer YOUR_API_KEY' \
    --header 'Content-Type: application/json' \
    --data '{
      "resource_types": ["RDS", "S3"],
      "standards": ["PCI-DSS", "HIPAA"],
      "severity": "HIGH",
      "include_remediation": true,
      "include_verification": true
    }'
  ```

  ```python Python theme={null}
  import requests

  api_key = "YOUR_API_KEY"
  url = "https://api.wistx.ai/v1/compliance/requirements"

  response = requests.post(
      url,
      headers={
          "Authorization": f"Bearer {api_key}",
          "Content-Type": "application/json"
      },
      json={
          "resource_types": ["RDS", "S3"],
          "standards": ["PCI-DSS", "HIPAA"],
          "severity": "HIGH",
          "include_remediation": True,
          "include_verification": True
      }
  )

  data = response.json()
  print(data)
  ```

  ```javascript JavaScript theme={null}
  const apiKey = "YOUR_API_KEY";
  const url = "https://api.wistx.ai/v1/compliance/requirements";

  const response = await fetch(url, {
    method: "POST",
    headers: {
      "Authorization": `Bearer ${apiKey}`,
      "Content-Type": "application/json"
    },
    body: JSON.stringify({
      resource_types: ["RDS", "S3"],
      standards: ["PCI-DSS", "HIPAA"],
      severity: "HIGH",
      include_remediation: true,
      include_verification: true
    })
  });

  const data = await response.json();
  console.log(data);
  ```

  ```go Go theme={null}
  package main

  import (
      "bytes"
      "encoding/json"
      "fmt"
      "net/http"
  )

  func main() {
      apiKey := "YOUR_API_KEY"
      url := "https://api.wistx.ai/v1/compliance/requirements"

      payload := map[string]interface{}{
          "resource_types": []string{"RDS", "S3"},
          "standards":      []string{"PCI-DSS", "HIPAA"},
          "severity":       "HIGH",
          "include_remediation": true,
          "include_verification": true,
      }

      jsonData, _ := json.Marshal(payload)
      req, _ := http.NewRequest("POST", url, bytes.NewBuffer(jsonData))
      req.Header.Set("Authorization", fmt.Sprintf("Bearer %s", apiKey))
      req.Header.Set("Content-Type", "application/json")

      client := &http.Client{}
      resp, _ := client.Do(req)
      defer resp.Body.Close()

      var result map[string]interface{}
      json.NewDecoder(resp.Body).Decode(&result)
      fmt.Printf("%+v\n", result)
  }
  ```

  ```ruby Ruby theme={null}
  require 'net/http'
  require 'json'
  require 'uri'

  api_key = "YOUR_API_KEY"
  url = URI("https://api.wistx.ai/v1/compliance/requirements")

  http = Net::HTTP.new(url.host, url.port)
  http.use_ssl = true

  request = Net::HTTP::Post.new(url)
  request["Authorization"] = "Bearer #{api_key}"
  request["Content-Type"] = "application/json"
  request.body = {
    resource_types: ["RDS", "S3"],
    standards: ["PCI-DSS", "HIPAA"],
    severity: "HIGH",
    include_remediation: true,
    include_verification: true
  }.to_json

  response = http.request(request)
  puts JSON.parse(response.body)
  ```

  ```php PHP theme={null}
  <?php

  $apiKey = "YOUR_API_KEY";
  $url = "https://api.wistx.ai/v1/compliance/requirements";

  $data = [
      "resource_types" => ["RDS", "S3"],
      "standards" => ["PCI-DSS", "HIPAA"],
      "severity" => "HIGH",
      "include_remediation" => true,
      "include_verification" => true
  ];

  $ch = curl_init($url);
  curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  curl_setopt($ch, CURLOPT_POST, true);
  curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode($data));
  curl_setopt($ch, CURLOPT_HTTPHEADER, [
      "Authorization: Bearer " . $apiKey,
      "Content-Type: application/json"
  ]);

  $response = curl_exec($ch);
  curl_close($ch);

  echo $response;
  ```

  ```java Java theme={null}
  import java.net.HttpURLConnection;
  import java.net.URL;
  import java.io.OutputStream;
  import java.io.BufferedReader;
  import java.io.InputStreamReader;
  import com.google.gson.Gson;
  import com.google.gson.JsonObject;

  public class ComplianceRequest {
      public static void main(String[] args) throws Exception {
          String apiKey = "YOUR_API_KEY";
          URL url = new URL("https://api.wistx.ai/v1/compliance/requirements");
          
          HttpURLConnection conn = (HttpURLConnection) url.openConnection();
          conn.setRequestMethod("POST");
          conn.setRequestProperty("Authorization", "Bearer " + apiKey);
          conn.setRequestProperty("Content-Type", "application/json");
          conn.setDoOutput(true);
          
          JsonObject payload = new JsonObject();
          payload.addProperty("severity", "HIGH");
          payload.addProperty("include_remediation", true);
          payload.addProperty("include_verification", true);
          
          // Add arrays using Gson
          Gson gson = new Gson();
          String[] resourceTypes = {"RDS", "S3"};
          String[] standards = {"PCI-DSS", "HIPAA"};
          payload.add("resource_types", gson.toJsonTree(resourceTypes));
          payload.add("standards", gson.toJsonTree(standards));
          
          try (OutputStream os = conn.getOutputStream()) {
              byte[] input = gson.toJson(payload).getBytes("utf-8");
              os.write(input, 0, input.length);
          }
          
          BufferedReader br = new BufferedReader(new InputStreamReader(conn.getInputStream(), "utf-8"));
          StringBuilder response = new StringBuilder();
          String responseLine;
          while ((responseLine = br.readLine()) != null) {
              response.append(responseLine.trim());
          }
          System.out.println(response.toString());
      }
  }
  ```
</CodeGroup>

## Authorization

<ParamField header="Authorization" type="string" required>
  Bearer token for API authentication. Format: `Bearer YOUR_API_KEY`
</ParamField>

## Request Body

<ParamField body="resource_types" type="array[string]" required>
  List of resource types to check compliance for. Examples: `RDS`, `S3`, `EC2`, `Lambda`, `EKS`, `GKE`, `AKS`, etc.

  **Minimum:** 1 item\
  **Maximum:** 50 items
</ParamField>

<ParamField body="standards" type="array[string]">
  Compliance standards to check. Supported standards:

  * `PCI-DSS` - Payment Card Industry Data Security Standard
  * `HIPAA` - Health Insurance Portability and Accountability Act
  * `CIS` - Center for Internet Security Benchmarks
  * `SOC2` - Service Organization Control 2
  * `NIST-800-53` - NIST Cybersecurity Framework
  * `ISO-27001` - ISO/IEC 27001 Information Security Management
  * `GDPR` - General Data Protection Regulation
  * `FedRAMP` - Federal Risk and Authorization Management Program

  **Default:** `[]` (all standards)\
  **Maximum:** 20 items
</ParamField>

<ParamField body="severity" type="string">
  Filter results by severity level.

  **Options:** `CRITICAL`, `HIGH`, `MEDIUM`, `LOW`\
  **Default:** `null` (all severities)
</ParamField>

<ParamField body="include_remediation" type="boolean">
  Include remediation guidance and code snippets in the response.

  **Default:** `true`
</ParamField>

<ParamField body="include_verification" type="boolean">
  Include verification procedures in the response.

  **Default:** `true`
</ParamField>

## Response

<ResponseExample>
  ```json 200 Success theme={null}
  {
    "data": {
      "controls": [
        {
          "control_id": "PCI-DSS-3.4",
          "standard": "PCI-DSS",
          "title": "Render PAN unreadable anywhere it is stored",
          "description": "Render primary account numbers (PAN) unreadable anywhere they are stored...",
          "severity": "CRITICAL",
          "category": "Data Protection",
          "subcategory": "Encryption",
          "applies_to": ["RDS", "S3", "EC2"],
          "remediation": {
            "guidance": "Use encryption at rest for all databases storing PAN data...",
            "code_examples": [
              {
                "language": "terraform",
                "code": "resource \"aws_db_instance\" \"rds\" {\n  storage_encrypted = true\n  kms_key_id = \"arn:aws:kms:...\"\n}"
              }
            ]
          },
          "verification": {
            "procedures": [
              "Check database encryption settings",
              "Verify KMS key configuration",
              "Review encryption logs"
            ]
          },
          "references": [
            {
              "title": "PCI-DSS Requirements",
              "url": "https://www.pcisecuritystandards.org/..."
            }
          ],
          "source_url": "https://www.pcisecuritystandards.org/..."
        }
      ],
      "summary": {
        "total": 45,
        "by_severity": {
          "CRITICAL": 12,
          "HIGH": 18,
          "MEDIUM": 10,
          "LOW": 5
        },
        "by_standard": {
          "PCI-DSS": 25,
          "HIPAA": 20
        }
      },
      "metadata": {
        "query_time_ms": 234,
        "filters_applied": {
          "resource_types": ["RDS", "S3"],
          "standards": ["PCI-DSS", "HIPAA"],
          "severity": "HIGH"
        }
      }
    },
    "metadata": {
      "request_id": "req_abc123",
      "timestamp": 1704067200.0,
      "query_time_ms": 234
    }
  }
  ```

  ```json 400 Bad Request theme={null}
  {
    "error": {
      "code": "VALIDATION_ERROR",
      "message": "Invalid request parameters",
      "details": "At least one resource type is required"
    },
    "metadata": {
      "request_id": "req_abc123",
      "timestamp": 1704067200.0
    }
  }
  ```

  ```json 401 Unauthorized theme={null}
  {
    "detail": "Invalid authorization header. Expected 'Bearer {api_key}'"
  }
  ```

  ```json 401 Unauthorized theme={null}
  {
    "detail": "Invalid or expired token"
  }
  ```

  ```json 429 Too Many Requests theme={null}
  {
    "error": {
      "code": "QUOTA_EXCEEDED",
      "message": "Query quota exceeded",
      "details": {
        "limit_type": "queries_per_month",
        "current": 50,
        "limit": 50
      }
    },
    "metadata": {
      "request_id": "req_abc123",
      "timestamp": 1704067200.0
    }
  }
  ```

  ```json 500 Internal Server Error theme={null}
  {
    "error": {
      "code": "INTERNAL_ERROR",
      "message": "An unexpected error occurred",
      "details": null
    },
    "metadata": {
      "request_id": "req_abc123",
      "timestamp": 1704067200.0
    }
  }
  ```

  ```json 503 Service Unavailable theme={null}
  {
    "error": {
      "code": "DATABASE_ERROR",
      "message": "Database connection failed",
      "details": "Connection timeout"
    },
    "metadata": {
      "request_id": "req_abc123",
      "timestamp": 1704067200.0
    }
  }
  ```
</ResponseExample>

### Response Fields

<ResponseField name="data" type="object" required>
  Response data containing compliance controls and summary.

  <Expandable title="Data properties">
    <ResponseField name="controls" type="array[object]" required>
      List of compliance controls matching the query criteria.

      <Expandable title="Control object properties">
        <ResponseField name="control_id" type="string" required>
          Unique identifier for the compliance control (e.g., `PCI-DSS-3.4`).
        </ResponseField>

        <ResponseField name="standard" type="string" required>
          Compliance standard name (e.g., `PCI-DSS`, `HIPAA`).
        </ResponseField>

        <ResponseField name="title" type="string" required>
          Human-readable title of the control.
        </ResponseField>

        <ResponseField name="description" type="string" required>
          Detailed description of the control requirement.
        </ResponseField>

        <ResponseField name="severity" type="string" required>
          Severity level: `CRITICAL`, `HIGH`, `MEDIUM`, or `LOW`.
        </ResponseField>

        <ResponseField name="category" type="string">
          Control category (e.g., `Data Protection`, `Access Control`).
        </ResponseField>

        <ResponseField name="subcategory" type="string">
          Control subcategory for more specific classification.
        </ResponseField>

        <ResponseField name="applies_to" type="array[string]" required>
          List of resource types this control applies to (e.g., `["RDS", "S3"]`).
        </ResponseField>

        <ResponseField name="remediation" type="object">
          Remediation guidance and code examples (included if `include_remediation` is `true`).

          <Expandable title="Remediation properties">
            <ResponseField name="guidance" type="string">
              Text guidance on how to remediate the control.
            </ResponseField>

            <ResponseField name="code_examples" type="array[object]">
              Code examples in various formats (Terraform, CloudFormation, etc.).

              <Expandable title="Code example properties">
                <ResponseField name="language" type="string">
                  Programming language or format (e.g., `terraform`, `cloudformation`).
                </ResponseField>

                <ResponseField name="code" type="string">
                  Code snippet demonstrating the remediation.
                </ResponseField>
              </Expandable>
            </ResponseField>
          </Expandable>
        </ResponseField>

        <ResponseField name="verification" type="object">
          Verification procedures (included if `include_verification` is `true`).

          <Expandable title="Verification properties">
            <ResponseField name="procedures" type="array[string]">
              List of steps to verify compliance with the control.
            </ResponseField>
          </Expandable>
        </ResponseField>

        <ResponseField name="references" type="array[object]">
          External references and documentation links.

          <Expandable title="Reference properties">
            <ResponseField name="title" type="string">
              Reference title.
            </ResponseField>

            <ResponseField name="url" type="string">
              Reference URL.
            </ResponseField>
          </Expandable>
        </ResponseField>

        <ResponseField name="source_url" type="string">
          Source URL for the control documentation.
        </ResponseField>
      </Expandable>
    </ResponseField>

    <ResponseField name="summary" type="object" required>
      Summary statistics for the compliance requirements.

      <Expandable title="Summary properties">
        <ResponseField name="total" type="integer" required>
          Total number of controls found.
        </ResponseField>

        <ResponseField name="by_severity" type="object" required>
          Count of controls grouped by severity level.
        </ResponseField>

        <ResponseField name="by_standard" type="object" required>
          Count of controls grouped by compliance standard.
        </ResponseField>
      </Expandable>
    </ResponseField>

    <ResponseField name="metadata" type="object">
      Query metadata including filters applied and performance metrics.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="metadata" type="object" required>
  Response metadata including request ID and timestamp.

  <Expandable title="Metadata properties">
    <ResponseField name="request_id" type="string" required>
      Unique request identifier for tracking and debugging.
    </ResponseField>

    <ResponseField name="timestamp" type="number" required>
      Unix timestamp of the response.
    </ResponseField>

    <ResponseField name="query_time_ms" type="integer" required>
      Query execution time in milliseconds.
    </ResponseField>
  </Expandable>
</ResponseField>

## Examples

### Get PCI-DSS Requirements for RDS

<CodeGroup>
  ```bash cURL theme={null}
  curl --request POST \
    --url https://api.wistx.ai/v1/compliance/requirements \
    --header 'Authorization: Bearer YOUR_API_KEY' \
    --header 'Content-Type: application/json' \
    --data '{
      "resource_types": ["RDS"],
      "standards": ["PCI-DSS"],
      "include_remediation": true
    }'
  ```

  ```python Python theme={null}
  import requests

  response = requests.post(
      "https://api.wistx.ai/v1/compliance/requirements",
      headers={"Authorization": f"Bearer {api_key}"},
      json={
          "resource_types": ["RDS"],
          "standards": ["PCI-DSS"],
          "include_remediation": True
      }
  )
  ```

  ```javascript JavaScript theme={null}
  const response = await fetch("https://api.wistx.ai/v1/compliance/requirements", {
    method: "POST",
    headers: {
      "Authorization": `Bearer ${apiKey}`,
      "Content-Type": "application/json"
    },
    body: JSON.stringify({
      resource_types: ["RDS"],
      standards: ["PCI-DSS"],
      include_remediation: true
    })
  });
  ```
</CodeGroup>

### Get Critical HIPAA Controls for S3

<CodeGroup>
  ```bash cURL theme={null}
  curl --request POST \
    --url https://api.wistx.ai/v1/compliance/requirements \
    --header 'Authorization: Bearer YOUR_API_KEY' \
    --header 'Content-Type: application/json' \
    --data '{
      "resource_types": ["S3"],
      "standards": ["HIPAA"],
      "severity": "CRITICAL",
      "include_verification": true
    }'
  ```

  ```python Python theme={null}
  response = requests.post(
      "https://api.wistx.ai/v1/compliance/requirements",
      headers={"Authorization": f"Bearer {api_key}"},
      json={
          "resource_types": ["S3"],
          "standards": ["HIPAA"],
          "severity": "CRITICAL",
          "include_verification": True
      }
  )
  ```

  ```javascript JavaScript theme={null}
  const response = await fetch("https://api.wistx.ai/v1/compliance/requirements", {
    method: "POST",
    headers: {
      "Authorization": `Bearer ${apiKey}`,
      "Content-Type": "application/json"
    },
    body: JSON.stringify({
      resource_types: ["S3"],
      standards: ["HIPAA"],
      severity: "CRITICAL",
      include_verification: true
    })
  });
  ```
</CodeGroup>

## Rate Limits

* **Professional Plan:** 2,000 queries/month
* **Team Plan:** 10,000 queries/month
* **Enterprise Plan:** Unlimited queries/month

Rate limit information is included in response headers:

* `X-RateLimit-Limit`: Maximum requests allowed
* `X-RateLimit-Remaining`: Remaining requests
* `X-RateLimit-Reset`: Unix timestamp when limit resets

## Related Endpoints

* [Knowledge Research](/api-reference/knowledge) - Research DevOps best practices
* [Cost Search](/api-reference/cost-search) - Search infrastructure pricing
* [Indexing](/api-reference/indexing) - Index repositories and documentation


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.