> ## Documentation Index
> Fetch the complete documentation index at: https://docs.wistx.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Get Compliance Analysis

> Get aggregated compliance analysis for an indexed repository

> Get aggregated compliance analysis from knowledge articles for an indexed repository

<CodeGroup>
  ```bash cURL theme={null}
  curl --request GET \
    --url 'https://api.wistx.ai/v1/indexing/resources/res_abc123/compliance-analysis?standards=PCI-DSS&standards=HIPAA&refresh=false' \
    --header 'Authorization: Bearer YOUR_API_KEY'
  ```

  ```python Python theme={null}
  import requests

  api_key = "YOUR_API_KEY"
  resource_id = "res_abc123"

  response = requests.get(
      f"https://api.wistx.ai/v1/indexing/resources/{resource_id}/compliance-analysis",
      headers={"Authorization": f"Bearer {api_key}"},
      params={
          "standards": ["PCI-DSS", "HIPAA"],
          "refresh": False
      }
  )

  analysis = response.json()
  print(f"Compliance analysis for: {analysis['repository_url']}")
  ```

  ```javascript JavaScript theme={null}
  const apiKey = "YOUR_API_KEY";
  const resourceId = "res_abc123";

  const params = new URLSearchParams({
    standards: "PCI-DSS",
    standards: "HIPAA",
    refresh: "false"
  });

  const response = await fetch(
    `https://api.wistx.ai/v1/indexing/resources/${resourceId}/compliance-analysis?${params}`,
    {
      headers: {
        Authorization: `Bearer ${apiKey}`
      }
    }
  );

  const analysis = await response.json();
  console.log(`Compliance analysis for: ${analysis.repository_url}`);
  ```

  ```go Go theme={null}
  package main

  import (
      "encoding/json"
      "fmt"
      "net/http"
      "net/url"
  )

  func main() {
      apiKey := "YOUR_API_KEY"
      resourceID := "res_abc123"
      baseURL := fmt.Sprintf("https://api.wistx.ai/v1/indexing/resources/%s/compliance-analysis", resourceID)
      
      params := url.Values{}
      params.Add("standards", "PCI-DSS")
      params.Add("standards", "HIPAA")
      params.Add("refresh", "false")
      fullURL := baseURL + "?" + params.Encode()

      req, _ := http.NewRequest("GET", fullURL, nil)
      req.Header.Set("Authorization", fmt.Sprintf("Bearer %s", apiKey))

      client := &http.Client{}
      resp, _ := client.Do(req)
      defer resp.Body.Close()

      var analysis map[string]interface{}
      json.NewDecoder(resp.Body).Decode(&analysis)
      fmt.Printf("Compliance analysis for: %v\n", analysis["repository_url"])
  }
  ```

  ```ruby Ruby theme={null}
  require 'net/http'
  require 'json'
  require 'uri'

  api_key = "YOUR_API_KEY"
  resource_id = "res_abc123"
  url = URI("https://api.wistx.ai/v1/indexing/resources/#{resource_id}/compliance-analysis")
  params = {
    standards: ["PCI-DSS", "HIPAA"],
    refresh: false
  }
  url.query = URI.encode_www_form(params)

  http = Net::HTTP.new(url.host, url.port)
  http.use_ssl = true

  request = Net::HTTP::Get.new(url)
  request["Authorization"] = "Bearer #{api_key}"

  response = http.request(request)
  analysis = JSON.parse(response.body)
  puts "Compliance analysis for: #{analysis['repository_url']}"
  ```

  ```php PHP theme={null}
  <?php

  $apiKey = "YOUR_API_KEY";
  $resourceId = "res_abc123";
  $url = "https://api.wistx.ai/v1/indexing/resources/" . $resourceId . "/compliance-analysis?" . http_build_query([
      "standards" => ["PCI-DSS", "HIPAA"],
      "refresh" => false
  ]);

  $ch = curl_init($url);
  curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  curl_setopt($ch, CURLOPT_HTTPHEADER, [
      "Authorization: Bearer " . $apiKey
  ]);

  $response = curl_exec($ch);
  curl_close($ch);

  $analysis = json_decode($response, true);
  echo "Compliance analysis for: " . $analysis['repository_url'];
  ```

  ```java Java theme={null}
  import java.net.HttpURLConnection;
  import java.net.URL;
  import java.io.BufferedReader;
  import java.io.InputStreamReader;
  import com.google.gson.Gson;
  import com.google.gson.JsonObject;

  public class GetComplianceAnalysis {
      public static void main(String[] args) throws Exception {
          String apiKey = "YOUR_API_KEY";
          String resourceId = "res_abc123";
          URL url = new URL("https://api.wistx.ai/v1/indexing/resources/" + resourceId + "/compliance-analysis?standards=PCI-DSS&standards=HIPAA&refresh=false");
          
          HttpURLConnection conn = (HttpURLConnection) url.openConnection();
          conn.setRequestMethod("GET");
          conn.setRequestProperty("Authorization", "Bearer " + apiKey);
          
          BufferedReader br = new BufferedReader(new InputStreamReader(conn.getInputStream(), "utf-8"));
          StringBuilder response = new StringBuilder();
          String responseLine;
          while ((responseLine = br.readLine()) != null) {
              response.append(responseLine.trim());
          }
          
          Gson gson = new Gson();
          JsonObject analysis = gson.fromJson(response.toString(), JsonObject.class);
          System.out.println("Compliance analysis for: " + analysis.get("repository_url"));
      }
  }
  ```
</CodeGroup>

## Path Parameters

<ParamField path="resource_id" type="string" required>
  Resource ID of the indexed repository.
</ParamField>

## Query Parameters

<ParamField query="standards" type="array[string]">
  Filter by compliance standards (e.g., `["PCI-DSS", "HIPAA", "SOC2"]`).
</ParamField>

<ParamField query="refresh" type="boolean">
  Force recalculation of compliance analysis.

  **Default:** `false`
</ParamField>

## Response

<ResponseExample>
  ```json 200 Success theme={null}
  {
    "resource_id": "res_abc123",
    "repository_url": "https://github.com/owner/repo",
    "environment_name": "production",
    "compliance_analysis": {
      "overall_score": 0.85,
      "by_standard": {
        "PCI-DSS": {
          "score": 0.90,
          "total_controls": 50,
          "passed_controls": 45,
          "failed_controls": 5
        },
        "HIPAA": {
          "score": 0.80,
          "total_controls": 30,
          "passed_controls": 24,
          "failed_controls": 6
        }
      },
      "critical_issues": [
        {
          "control_id": "PCI-3.4",
          "standard": "PCI-DSS",
          "severity": "CRITICAL",
          "description": "Encryption key management not properly configured"
        }
      ],
      "recommendations": [
        {
          "priority": "HIGH",
          "action": "Enable encryption at rest for S3 buckets",
          "impact": "Will improve PCI-DSS compliance score"
        }
      ]
    }
  }
  ```

  ```json 401 Unauthorized theme={null}
  {
    "detail": "User ID not found"
  }
  ```

  ```json 404 Not Found theme={null}
  {
    "detail": "Resource not found or access denied"
  }
  ```

  ```json 500 Internal Server Error theme={null}
  {
    "detail": "Failed to get compliance analysis"
  }
  ```
</ResponseExample>

## Related Endpoints

* [Get Cost Analysis](/api-reference/indexing/cost-analysis) - Get cost analysis
* [Get Resource Status](/api-reference/indexing/resource-status) - Check resource status
* [Compliance Requirements](/api-reference/compliance) - Get compliance requirements


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.