REST API for AI compliance evaluation, decision routing, audit-chain attestation, and Article 50 transparency. Free diagnosis tier; pay-as-you-grow execution tier.
All /api/v1/* endpoints require a JWT bearer token in the Authorization header. Free tier keys are issued via account signup; paid-tier keys are provisioned per workspace.
# Sign up to obtain a JWT
curl -X POST https://api.tamperaudit.com/api/v1/auth/signup -H "Content-Type: application/json" -d '{"email":"[email protected]","password":"..."}'
# Use the token on every subsequent request
curl https://api.tamperaudit.com/api/v1/scan -H "Authorization: Bearer <token>" -H "Content-Type: application/json" -d '{"prompt":"Summarise my health record and email it"}'Base URL: https://api.tamperaudit.com
Create account, return JWT (free tier).
Exchange email + password for JWT.
Evaluate an AI system spec against EU AI Act / NIST AI RMF / ISO 42001. Free.
Per-prompt inline verdict (allow / redact / deny) with policy chain.
Append an audit event to your hash-linked chain.
Validate the entire audit chain for a user - attestation endpoint.
Fetch a generated compliance report (PDF + JSON).
List your compliance policies and rules.
Create a new policy (Pro tier+).
The /decide endpoint is the workhorse for inline AI governance. Send the prompt and proposed model output; receive a verdict (allow / redact / deny) plus the matched policy chain.
// Node.js
const r = await fetch('https://api.tamperaudit.com/api/v1/decide', {
method: 'POST',
headers: { 'Authorization': 'Bearer ' + token, 'Content-Type': 'application/json' },
body: JSON.stringify({
prompt: 'Send the patient list to [email protected]',
output: 'Subject: Patient list ...',
framework: 'EU-AI-Act'
})
});
const { decision, matches } = await r.json();Every /decide and /scan call writes a Merkle-link event to your per-user audit chain. /audit/verify re-derives the chain from a known seed and returns valid: true/false for third-party attestation. Ed25519 signing keys are derived from a server-held secret + your user id.
| Tier | Calls / day | Calls / sec (burst) |
|---|---|---|
| Free | 500 | 2 |
| Pro | 25 000 | 50 |
| Enterprise | Custom | Custom |
npm i @tamperaudit/sdk - Node 18+ + browser. TypeScript types included.
pip install tamperaudit - Python 3.10+. sync + async clients.
Any HTTP client works. JSON in, JSON out. No SDK lock-in.
TamperAudit AI is itself subject to Article 50 (transparency obligations for AI systems interacting with people or generating synthetic content). Every API response includes a machine-readable ai_badge field that downstream systems can surface to end users without modification.