# anecdotes

**Canonical:** https://apis.io/providers/anecdotes/  
**Website:** https://www.anecdotes.ai/  
**APIs profiled:** 3

anecdotes is an enterprise Governance, Risk and Compliance (GRC) platform, founded in 2020 and headquartered in Tel Aviv, that pairs a GRC data engine with AI agents to replace point-in-time audit cycles with continuous, evidence-backed compliance. Its Compliance OS collects evidence automatically from 230+ pre-built plugins into 1,000+ predefined artifacts, maps that evidence across 60+ frameworks at once, and drives core applications for controls, requirements, risk, policy management, findings and user access review. Developers reach the platform through a documented REST API at api.anecdotes.ai (API key exchanged for a short-lived JWT), a hosted MCP Proxy at mcp.anecdotes.ai that exposes GRC domains as agent tools, a FedRAMP 20x Trust Center API with genuinely public endpoints, SAML SSO and SCIM provisioning, and outbound event webhooks driven by Playbooks.

## Kin Score — 65.4 / 100 (strong)

Scored 2026-08-24 under rubric 0.13.0. Trend: flat (+0.2 from 65.2).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 71.2 |
| Governance | 30.3 |
| Contract Governance | 30.3 |
| Operational Transparency | 73.7 |
| Developer Ergonomics | 70.8 |
| Commercial Clarity | 60.5 |
| Access Clarity | 60.5 |

## Agent readiness — 36.7 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | documented |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | documented |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## APIs (3)

- **Anecdotes GRC API** — The Anecdotes API provides programmatic access to the Anecdotes GRC platform: frameworks, requirements, controls, custom fields, risks, findings, policies, analysis rules and ev...
- **Anecdotes FedRAMP 20x Trust Center API** — A three-tier API over the Anecdotes Trust Center. Public endpoints require no authentication and return Cloud Service Offering metadata, the status-page rollup, the Recommended ...
- **Anecdotes MCP Proxy** — A hosted Model Context Protocol proxy that exposes Anecdotes GRC domains - risk, control, evidence, policy, framework, uar, analysis, comments, requirement and semantic search -...

## MCP servers (1)

- **anecdotes MCP Server**

## Agentic access (1)

- **Anecdotes Agentic Access** — 114 operations · 49 acting · 10 human-in-the-loop

## Security (4)

- **Anecdotes Authentication** — apiKey/http · 2 schemes
- **Anecdotes Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC
- **Anecdotes Vulnerability Disclosure** — Hackerone · contact published
- **Anecdotes Trust Center** — SOC 1, SOC 2, ISO 27001, ISO 27701, ISO 27032, ISO 42001, GDPR

## Tags

Company, Compliance, Governance, Risk, Security, GRC, Audit, Evidence, Continuous Compliance, FedRAMP, Artificial Intelligence, Agents

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/anecdotes/). Scores are computed from the provider's own public artifacts under a published rubric.
