Exports & compliance
Every run can be exported; every organisation can produce a compliance report for a date range. Both are secret-free by construction and the compliance report is tamper-evident.
Run exports
GET /v1/test-runs/{id}/export?format=json|csv|pdf any key or session. JSON: run, scenarios, attempts, expected vs observed, checks, guardrail hits, cost. CSV: one row per attempt, RFC 4180, BOM, formula injection neutralised. PDF: the readable report your client can read.
Compliance report
GET /v1/compliance/export?from=…&to=…&project_id=…&format=json|pdf any key or session — requires the compliance capability. Production scope. Default range: last 30 days.
- Contents: decisions (with reasons and policy version), executed actions and their provider ids, approvals (who, when, digest), guardrail hits, verifications, incidents.
- Every evidence record is ordered by its chain position and hashed; the report prints the chain head and its own SHA-256 digest on page 1. Recompute the digest from the JSON to prove nothing was altered.
- POST
/v1/compliance/emailsends the PDF to an address (Resend), useful for a monthly auditor delivery.
Retention
Sandbox worlds and test artefacts are removed by a 30-day retention job. Evidence and usage records are append-only for the life of the organisation. Deleting an organisation removes everything after a 30-day grace period.