One engine, three doors. The intelligence behind the Priventia Workspace is available to your systems and your AI agents: the covered instrument set, obligations with their citations and controls, and deterministic applicability assessment from declared organisation context.
The Priventia API and MCP server are live. Access is provisioned per organisation, and your organisation administrator issues keys directly in the Workspace.
1. Create an accountRegister, confirm your email and set up your organisation. API access belongs to the organisation, not to an individual.
2. Issue a keyYour organisation administrator issues a key in the Workspace under Settings, API Keys, with read or read and assess scope. The full key is shown once.
3. Call the API or connect an agentSend the key as a bearer token to the endpoints below, or add the MCP server to an MCP-compatible client with the same key.
Determination happens once, in one deterministic engine over a governed regulatory ontology. The Workspace, the API and the MCP server are doors into that engine, never separate implementations of it, so an answer is the same answer whichever door asked.
The application: assessments, obligations, controls, evidence and roadmaps, managed over time by your compliance and legal teams.
Read and assess endpoints for the software your organisation builds and runs: GRC platforms, legal operations tooling and internal systems that need regulatory intelligence in place.
A governed tool surface for AI agents, so an assistant can ask Priventia for a determination instead of reconstructing regulation from its own memory.
Version 1 is read and assess only. Requests authenticate with an organisation API key in the Authorization header; keys are created, rotated and revoked by your organisation administrator in the Workspace under Settings.
GET/api/v1/frameworksThe covered instrument set: code, name, category, family and jurisdictions. Coverage is a disclosed subset; instruments outside it are not assessed.
GET/api/v1/obligations?instrument=CODEThe mapped obligations of one covered instrument, each with its citation, label, text, penalty exposure and Observable Governance Controls. Coverage is the mapped canonical subset, and instrument-level indication is not obligation-level applicability; every payload states both.
POST/api/v1/applicability/evaluateDeclared organisation context in, deterministic positions out. Every covered instrument returns indicated, not indicated within the covered set, or undetermined, each with its basis. The assessment is persisted and its id returned.
GET/api/v1/assessments/{id}A previously issued assessment, exactly as stored, with the engine and API versions it was issued under. Assessments are immutable; a rerun is a new assessment.
POST https://priventia.com/api/v1/applicability/evaluate
Authorization: Bearer pv_...
{
"organisation_name": "Example B.V.",
"establishment_jurisdictions": ["NL"],
"markets_served": ["EU"],
"uses_ai_systems": true,
"processes_personal_data": true
}Every response carries its coverage: the instrument set it drew from, stated as a disclosed subset, and any notice that reduces it. Responses are stamped with the engine and API versions they were issued under, and assessments are stored immutably, so a rerun months later can be compared honestly with the original.
Declared facts are recorded and rendered as provided. Priventia does not independently verify them, and applicability that depends on an unestablished fact is reported as undetermined.
Both doors authenticate with the same organisation API keys, sent as a bearer token. Keys are issued, rotated and revoked by your organisation administrator in the Workspace under Settings, and the full key is shown exactly once, at issuance; at rest Priventia stores only its hash.
readRetrieve the covered instrument set, the obligations of an instrument, and assessments the organisation has already been issued.
assessIssue a new applicability assessment from declared organisation context. Assessment results are persisted and retrievable under the read scope.
A key carries the scopes granted when it was issued: read only, or read and assess. An operation the key's scopes do not cover is refused with a 403 and the scope named, on the API and the MCP server alike. Rotation issues a replacement key with the same name and scopes and revokes the original immediately, so a credential can be replaced without reconfiguring what it may do.
Requests are limited to 60 per hour per key, and request bodies to 16 KiB. Failures are described in plain terms with the matching status code, never as raw technical errors:
401The API key is missing, malformed, revoked, or not recognised.
403The key is valid but does not carry the scope the operation requires.
404The instrument is not in the covered set, or no assessment with that id is available to this key.
413The request body exceeds the 16 KiB limit, measured on the bytes received.
429The request limit for the key has been reached. The response carries a Retry-After header; the limit resets within the hour.
503The API is not enabled for this environment.
An applicability evaluation returns one of three positions for every instrument in the covered set. None of them is a grade, and none of them is softened or hidden.
A declared jurisdiction intersects the instrument, and a declared or observed fact engages its family. The basis is returned with the position, so the conclusion can be traced to the facts that produced it.
Evaluated within the covered set and not indicated by the declared facts. This is a statement about the evaluation, never a statement of compliance or safety.
The deciding fact was not declared and is not observable. The response names the fact that would resolve it. Undetermined is a legitimate terminal answer, not an error and not a gap.
The MCP server at /api/mcp exposes the same services as the API to AI agents, over the open Model Context Protocol with the same organisation keys. Four tools in version 1, read and assess only: an agent can retrieve and evaluate, and cannot change your organisation's records.
list_frameworksThe covered instrument set, as the API returns it.
get_obligationsObligations and controls for one instrument code.
assess_applicabilityDeterministic applicability positions from declared context, persisted with an assessment id.
get_assessmentRetrieves a stored assessment by id.
{
"mcpServers": {
"priventia": {
"url": "https://priventia.com/api/mcp",
"headers": { "Authorization": "Bearer pv_..." }
}
}
}MCP-compatible clients, assistants and agents connect over streamable HTTP with the key in the Authorization header; the exact configuration shape depends on the client, and the example above shows the two facts every client needs: the endpoint and the key. The server is stateless, so no session setup is required beyond the standard initialize handshake.
Tool results are determination-layer output: structured positions with their basis, produced by the deterministic engine. No generative step sits between an input and a determination, whichever door asked. Tool availability follows the key's scopes: a read-only key can list, retrieve and fetch stored assessments, and is refused the assessment tool with the scope named.
The API and MCP server are live. Create an account, issue a key in Settings, and make your first call. For an integration or an agent deployment across your organisation, talk to us.