Exports & compliance

Every run can be exported; every organisation can produce a compliance report for a date range. Both are secret-free by construction and the compliance report is tamper-evident.

Written from the code · updated 26 Sep 2026 · Something wrong or missing? Tell us

Run exports

GET /v1/test-runs/{id}/export?format=json|csv|pdf any key or session. JSON: run, scenarios, attempts, expected vs observed, checks, guardrail hits, cost. CSV: one row per attempt, RFC 4180, BOM, formula injection neutralised. PDF: the readable report your client can read.

Compliance report

GET /v1/compliance/export?from=…&to=…&project_id=…&format=json|pdf any key or session — requires the compliance capability. Production scope. Default range: last 30 days.

  • Contents: decisions (with reasons and policy version), executed actions and their provider ids, approvals (who, when, digest), guardrail hits, verifications, incidents.
  • Every evidence record is ordered by its chain position and hashed; the report prints the chain head and its own SHA-256 digest on page 1. Recompute the digest from the JSON to prove nothing was altered.
  • POST /v1/compliance/email sends the PDF to an address (Resend), useful for a monthly auditor delivery.

Retention

Sandbox worlds and test artefacts are removed by a 30-day retention job. Evidence and usage records are append-only for the life of the organisation. Deleting an organisation removes everything after a 30-day grace period.

Exports & compliance · Docs · COLVO