> ## Documentation Index
> Fetch the complete documentation index at: https://docs.useanima.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# Compliance Reporting

> Generate compliance reports, handle DSAR requests, and monitor compliance posture through dashboards and templates.

# Compliance Reporting

Anima provides built-in reporting tools for compliance workflows including SOC 2 audit preparation, DSAR (Data Subject Access Request) fulfillment, and executive compliance dashboards.

<Note>
  These are tools for preparing **your** audit. They do not constitute an
  attestation of Anima's own compliance posture, and generating a report here is
  not evidence that Anima has been audited.
</Note>

## Report Templates

Generate pre-built reports for common compliance needs:

<Tabs items={["Node.js", "Python", "Go"]}>
  <Tab value="Node.js">
    ```ts theme={null}
    import { Anima } from "@anima-labs/sdk";

    const anima = new Anima({ apiKey: "mk_..." });

    // Generate a SOC 2 summary. Compliance calls are org-scoped: the org id
    // is the first argument, not a field on the body.
    const report = await anima.compliance.generateReport(orgId, {
      type: "SOC2_SUMMARY",
      periodStart: "2026-01-01",
      periodEnd: "2026-03-31",
    });

    console.log(`Report: ${report.id}`);
    console.log(`Status: ${report.status}`);  // PENDING | GENERATING | COMPLETED | FAILED

    // Once it completes, export it. The bytes come back inline — there is no
    // signed download URL.
    const exported = await anima.compliance.exportReport(orgId, report.id, { format: "PDF" });
    console.log(`${exported.filename} (${exported.contentType})`);
    ```
  </Tab>

  <Tab value="Python">
    ```python theme={null}
    from anima import Anima

    anima = Anima(api_key="mk_...")

    report = anima.compliance.generate_report(
        org_id=org_id,
        type="SOC2_SUMMARY",
        period_start="2026-01-01",
        period_end="2026-03-31",
    )

    print(f"Report: {report.id}")
    print(f"Status: {report.status}")

    exported = anima.compliance.export_report(org_id=org_id, report_id=report.id, format="PDF")
    print(f"{exported.filename} ({exported.content_type})")
    ```
  </Tab>

  <Tab value="Go">
    ```go theme={null}
    import "github.com/anima-labs-ai/go"

    client := anima.NewClient("mk_...")

    report, err := client.Compliance.GenerateReport(ctx, orgID, anima.GenerateReportInput{
        Type:        anima.ComplianceReportTypeSOC2Summary,
        PeriodStart: "2026-01-01",
        PeriodEnd:   "2026-03-31",
    })
    ```
  </Tab>
</Tabs>

### Available Templates

Template identifiers are the uppercase values below. `GET /v1/orgs/{orgId}/compliance/templates` returns the live list.

| Template | Description |
| - | - |
| `SOC2_SUMMARY` | Control status and collected evidence, for your own audit prep |
| `ACTIVITY_REPORT` | Agent activity across channels over the period |
| `ACCESS_REVIEW` | API keys, permission changes, and access grants |
| `AUDIT_EXPORT` | Raw audit-log export for the period |
| `GDPR_DSAR` | The data-subject bundle backing a DSAR response |

## DSAR (Data Subject Access Requests)

Handle GDPR and CCPA data subject access requests.

<Warning>
  Published SDK releases up to and including Node 0.6.0, Python 0.7.0 and the
  current Go tag send `requestType` with lowercase values here, which the API
  rejects. The fix is merged but unreleased. On those versions, call the DSAR
  routes directly as below — the field is `type` and the values are uppercase.
</Warning>

```bash theme={null}
curl -X POST https://api.useanima.sh/v1/orgs/{orgId}/compliance/dsars \
  -H "Authorization: Bearer mk_..." \
  -H "Content-Type: application/json" \
  -d '{
    "type": "ACCESS",
    "subjectEmail": "user@example.com",
    "description": "GDPR Article 15 request received via support ticket #4521",
    "dueInDays": 30
  }'
```

Then poll it:

```bash theme={null}
curl https://api.useanima.sh/v1/orgs/{orgId}/compliance/dsars/{dsarId} \
  -H "Authorization: Bearer mk_..."
```

### Request types

| Value | Meaning |
| - | - |
| `ACCESS` | Article 15 — give the subject their data |
| `DELETE` | Article 17 — erase the subject's data |
| `RECTIFY` | Article 16 — correct inaccurate data |
| `PORTABILITY` | Article 20 — export in a portable format |
| `RESTRICT` | Article 18 — restrict processing |

### Status values

`RECEIVED` → `VERIFIED` → `IN_PROGRESS` → `COMPLETED`, or `DENIED`. A request
past its due date reports `OVERDUE`. `dueInDays` accepts 1–90 and defaults to
30, the GDPR response window.

## Compliance Dashboard

Get a real-time view of your compliance posture:

The dashboard has three sections: `reports`, `dsars`, and `compliance`.

```ts theme={null}
const dashboard = await anima.compliance.getDashboard(orgId);

console.log(`Overall progress: ${dashboard.compliance.overallProgress}%`);
for (const fw of dashboard.compliance.frameworkSummaries) {
  console.log(`${fw.framework}: ${fw.implementedCount}/${fw.totalControls} (${fw.progress}%)`);
}

// `overdue` is the number that matters — those are blown GDPR deadlines.
console.log(`DSARs: ${dashboard.dsars.total} total, ${dashboard.dsars.overdue} overdue`);
console.log(`Average resolution: ${dashboard.dsars.averageResolutionDays ?? "n/a"} days`);

console.log(`Reports: ${dashboard.reports.total}`);
for (const report of dashboard.reports.recentReports) {
  console.log(`  ${report.type} — ${report.status} — ${report.createdAt}`);
}
```

## API Reference

Every compliance route is org-scoped and lives under `/v1`. Base URL `https://api.useanima.sh`.

| Endpoint | Method | Description |
| - | - | - |
| `/v1/orgs/{orgId}/compliance/reports` | POST | Generate a report |
| `/v1/orgs/{orgId}/compliance/reports` | GET | List generated reports |
| `/v1/orgs/{orgId}/compliance/reports/{reportId}` | GET | Get report status and download URL |
| `/v1/orgs/{orgId}/compliance/reports/{reportId}/export` | POST | Export a generated report |
| `/v1/orgs/{orgId}/compliance/reports/{reportId}` | DELETE | Delete a report |
| `/v1/orgs/{orgId}/compliance/templates` | GET | List available report templates |
| `/v1/orgs/{orgId}/compliance/dsars` | POST | Create a DSAR request |
| `/v1/orgs/{orgId}/compliance/dsars` | GET | List DSARs |
| `/v1/orgs/{orgId}/compliance/dsars/{dsarId}` | GET | Get DSAR status and results |
| `/v1/orgs/{orgId}/compliance/dsars/{dsarId}` | PATCH | Update a DSAR |
| `/v1/orgs/{orgId}/compliance/dashboard` | GET | Get compliance dashboard |

These routes require a master key (`mk_*`).

## Next Steps

* [Audit Log](/security/audit-log) -- Underlying data for reports
* [Anomaly Detection](/security/anomaly-detection) -- Security posture data


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.