MetricStream website screenshot

MetricStream

MetricStream is a San Jose, California based enterprise software company and a market leader in integrated Governance, Risk, and Compliance (GRC) management, serving large regulated organizations across banking and financial services, insurance, healthcare, life sciences, energy, utilities, telecom, technology and manufacturing. Its AI-first Connected GRC platform unifies enterprise and operational risk, regulatory and corporate compliance, policy and document management, internal audit and SOX, IT and cyber risk, third-party and vendor risk, operational resilience and business continuity, ESG, and case and incident management on one data core. MetricStream publishes a public API developer portal describing its Business REST APIs — a family of OpenAPI-derived REST modules covering GRC Foundation objects, Issues, Loss Event Management, Metrics, Risk Assessments, Regulatory Engagements, Surveys and Self Assessment & Testing — that customers, partners and internal developers use to move GRC data in and out of a MetricStream instance over HTTPS.

MetricStream publishes 8 APIs on the APIs.io network. Tagged areas include Company, Governance, Risk, Compliance, and GRC.

MetricStream’s developer surface includes API reference, documentation, engineering blog, support, signup flow, authentication, changelog, and 18 more developer resources.

29.9/100 thin ▬ flat Agent 9/100 agent aware saas Full breakdown ↓
scored 2026-09-02 · rubric v0.18.0
AccessOpen
8 APIs
CompanyGovernanceRiskComplianceGRCAuditEnterprise SoftwareRegulatory TechnologyCyber RiskThird-Party RiskOperational ResilienceESG

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-02 · rubric v0.18.0
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/metricstream: open an issue to ask a question, or submit a pull request to add artifacts. Submit an artifact on GitHub — free → Manage your own listing — the Influence plan, $499/mo →

APIs 8

Individual APIs this provider publishes, each with its own machine-readable definition.

MetricStream GRC Foundation APIs

Business REST APIs over the GRC Foundation object model — Area of Compliance, Asset, Asset Class, Control, Evidence, Exception, Financial Accounts, Function, Framework/Model Ref...

MetricStream Issues APIs

Business REST APIs for the Issues module — reporting issues and viewing issue details, so first-line users and upstream systems can flag weaknesses, gaps in internal controls an...

MetricStream Loss Event Management APIs

Business REST APIs for operational loss data — internal and external loss events, impacts, approval (loss) rules, default currency configuration and risk/regulatory event type m...

MetricStream Metrics APIs

Business REST APIs for KRI/KPI metric definitions and metric data entry — create and maintain metric definitions and post metric data points into the GRC platform.

MetricStream Risk Assessments APIs

Business REST APIs for risk assessment tasks and the setup of risk aggregation weights used when rolling assessment scores up a risk hierarchy.

MetricStream Regulatory Engagements APIs

Business REST APIs for the Regulatory Engagement module — engagements with regulators and the tasks raised under them.

MetricStream Surveys APIs

Business REST APIs for the Survey/Questionnaire module — creating questionnaires and initiating survey, scorecard and certification campaigns.

MetricStream Self Assessment & Testing APIs

Business REST APIs for the Compliance module's test and self-assessment plans — creating and maintaining the plans that drive control testing cycles.

Scroll for all 8

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Metricstream Rate Limits

0 limits

RATE LIMITS

Security Posture 4

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Metricstream Authentication

0 schemes

SECURITY

Metricstream Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Metricstream Trust Center

ISO 27001, SOC 2 Type II, HIPAA

SECURITY

Resources

Get Started 2

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 2

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 5

Pagination, idempotency, versioning, errors, and events

Build 2

SDKs, sample code, and the tooling you integrate with

Access & Security 4

Authentication, authorization, and security posture

Operate 3

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: metricstream
name: MetricStream
description: MetricStream is a San Jose, California based enterprise software company and a market leader in integrated Governance,
  Risk, and Compliance (GRC) management, serving large regulated organizations across banking and financial services, insurance,
  healthcare, life sciences, energy, utilities, telecom, technology and manufacturing. Its AI-first Connected GRC platform
  unifies enterprise and operational risk, regulatory and corporate compliance, policy and document management, internal audit
  and SOX, IT and cyber risk, third-party and vendor risk, operational resilience and business continuity, ESG, and case and
  incident management on one data core. MetricStream publishes a public API developer portal describing its Business REST
  APIs — a family of OpenAPI-derived REST modules covering GRC Foundation objects, Issues, Loss Event Management, Metrics,
  Risk Assessments, Regulatory Engagements, Surveys and Self Assessment & Testing — that customers, partners and internal
  developers use to move GRC data in and out of a MetricStream instance over HTTPS.
url: https://raw.githubusercontent.com/api-evangelist/metricstream/refs/heads/main/apis.yml
deliveryModel:
  model: saas
  open_source: false
  commercial: true
  callable_host: false
  label: Hosted service · you call their endpoint
  confidence: medium
  source:
  - pricing
  generated: '2026-08-28'
  method: derived
accessModel:
  pricing: unknown
  onboarding: open
  trial: false
  try_now: false
  public: true
  label: Open access
  confidence: medium
  source:
  - authentication
  - rate-limits
  - security
  generated: '2026-09-02'
  method: derived
image: https://www.metricstream.com/sites/default/files/2025-05/metricstream-logo.png
x-type: company
x-source: harvest:secondary-market
specificationVersion: '0.20'
created: '2026-08-25'
modified: '2026-08-25'
tags:
- Company
- Governance
- Risk
- Compliance
- GRC
- Audit
- Enterprise Software
- Regulatory Technology
- Cyber Risk
- Third-Party Risk
- Operational Resilience
- ESG
tags_raw:
- Company
- Governance
- Risk
- Compliance
- GRC
- Audit
- Enterprise Software
- Regulatory Technology
- Cyber Risk
- Third Party Risk
- Operational Resilience
- ESG
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
apis:
- aid: metricstream-grc-foundation
  name: MetricStream GRC Foundation APIs
  description: Business REST APIs over the GRC Foundation object model — Area of Compliance, Asset, Asset Class, Control,
    Evidence, Exception, Financial Accounts, Function, Framework/Model Reference, Objectives, Process, Product, Question &
    Procedure, Reference, Regulatory Body, Requirement, Risk and Standard. Each entity exposes the same six-operation surface
    (single read, single create, single patch, plus bulk collections read, bulk create and bulk patch), for 108 documented
    operations.
  humanURL: https://assets.metricstream.com/pdf/Developer-Portal/GRCF_API/MsGrcGRC%20API%20Overview.html
  baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0
  tags:
  - GRC
  - Risk
  - Compliance
  - Controls
  properties:
  - type: APIReference
    url: https://www.metricstream.com/api-developer-portal.html
  - type: Documentation
    url: https://assets.metricstream.com/pdf/Developer-Portal/GRCF_API/MsGrcGRC%20API%20Overview.html
- aid: metricstream-issues
  name: MetricStream Issues APIs
  description: Business REST APIs for the Issues module — reporting issues and viewing issue details, so first-line users
    and upstream systems can flag weaknesses, gaps in internal controls and process deficiencies into MetricStream.
  humanURL: https://assets.metricstream.com/pdf/Developer-Portal/MsIsmISM-API-Overview.html
  baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0
  tags:
  - Issues
  - Compliance
  properties:
  - type: Documentation
    url: https://assets.metricstream.com/pdf/Developer-Portal/MsIsmISM-API-Overview.html
  - type: APIReference
    url: https://assets.metricstream.com/pdf/Developer-Portal/Issues_API/MsIsmIssue.html
- aid: metricstream-loss-event-management
  name: MetricStream Loss Event Management APIs
  description: Business REST APIs for operational loss data — internal and external loss events, impacts, approval (loss)
    rules, default currency configuration and risk/regulatory event type mapping. 36 documented operations across six resources.
  humanURL: https://assets.metricstream.com/pdf/Developer-Portal/Loss_Event_Managment_API/MslsmLSM%20API%20Overview.html
  baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0
  tags:
  - Operational Risk
  - Loss Events
  properties:
  - type: Documentation
    url: https://assets.metricstream.com/pdf/Developer-Portal/Loss_Event_Managment_API/MslsmLSM%20API%20Overview.html
- aid: metricstream-metrics
  name: MetricStream Metrics APIs
  description: Business REST APIs for KRI/KPI metric definitions and metric data entry — create and maintain metric definitions
    and post metric data points into the GRC platform.
  humanURL: https://assets.metricstream.com/pdf/Developer-Portal/Metric_API/MsMetMET%20API%20Overview.html
  baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0
  tags:
  - Metrics
  - KRI
  properties:
  - type: Documentation
    url: https://assets.metricstream.com/pdf/Developer-Portal/Metric_API/MsMetMET%20API%20Overview.html
- aid: metricstream-risk-assessments
  name: MetricStream Risk Assessments APIs
  description: Business REST APIs for risk assessment tasks and the setup of risk aggregation weights used when rolling assessment
    scores up a risk hierarchy.
  humanURL: https://assets.metricstream.com/pdf/Developer-Portal/Risk_Assemment_API/MsRskRSK%20API%20Overview.html
  baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0
  tags:
  - Risk Assessment
  properties:
  - type: Documentation
    url: https://assets.metricstream.com/pdf/Developer-Portal/Risk_Assemment_API/MsRskRSK%20API%20Overview.html
- aid: metricstream-regulatory-engagements
  name: MetricStream Regulatory Engagements APIs
  description: Business REST APIs for the Regulatory Engagement module — engagements with regulators and the tasks raised
    under them.
  humanURL: https://assets.metricstream.com/pdf/Developer-Portal/Regulatory_Engg_API/MsRenREN%20API%20Overview.html
  baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0
  tags:
  - Regulatory
  - Engagement
  properties:
  - type: Documentation
    url: https://assets.metricstream.com/pdf/Developer-Portal/Regulatory_Engg_API/MsRenREN%20API%20Overview.html
- aid: metricstream-surveys
  name: MetricStream Surveys APIs
  description: Business REST APIs for the Survey/Questionnaire module — creating questionnaires and initiating survey, scorecard
    and certification campaigns.
  humanURL: https://assets.metricstream.com/pdf/Developer-Portal/MsQsmQSM-API-Overview.html
  baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0
  tags:
  - Surveys
  - Questionnaires
  properties:
  - type: Documentation
    url: https://assets.metricstream.com/pdf/Developer-Portal/MsQsmQSM-API-Overview.html
- aid: metricstream-self-assessment-testing
  name: MetricStream Self Assessment & Testing APIs
  description: Business REST APIs for the Compliance module's test and self-assessment plans — creating and maintaining the
    plans that drive control testing cycles.
  humanURL: https://assets.metricstream.com/pdf/Developer-Portal/MsCmpCMP-API-Overview.html
  baseURL: https://{metricstream-instance}/metricstream/b2b/api/7.0
  tags:
  - Controls Testing
  - Self Assessment
  properties:
  - type: Documentation
    url: https://assets.metricstream.com/pdf/Developer-Portal/MsCmpCMP-API-Overview.html
common:
- type: TrustCenter
  url: security/metricstream-trust-center.yml
- type: Website
  url: https://www.metricstream.com/
- type: DeveloperPortal
  url: https://www.metricstream.com/developer-portal.html
- type: APIReference
  url: https://www.metricstream.com/api-developer-portal.html
- type: Documentation
  url: https://www.metricstream.com/platform/apis.htm
- type: Blog
  url: https://www.metricstream.com/blog
- type: GitHubOrganization
  url: https://github.com/MetricStream
- type: Support
  url: https://www.metricstream.com/about-us/lets-talk.html
- type: SignUp
  url: https://www.metricstream.com/about-us/get-started.htm
- type: TermsOfService
  url: https://www.metricstream.com/customer-agreements
- type: PrivacyPolicy
  url: https://www.metricstream.com/about-us/privacy-policy.htm
- type: Compliance
  url: conformance/metricstream-conformance.yml
- type: LLMsTxt
  url: llms/metricstream-llms.txt
- type: Packages
  url: packages/metricstream-packages.yml
- type: Conformance
  url: conformance/metricstream-conformance.yml
- type: ErrorCatalog
  url: errors/metricstream-problem-types.yml
- type: Lifecycle
  url: lifecycle/metricstream-lifecycle.yml
- type: Authentication
  url: authentication/metricstream-authentication.yml
- type: DomainSecurity
  url: security/metricstream-domain-security.yml
- type: Conventions
  url: conventions/metricstream-conventions.yml
- type: DataModel
  url: data-model/metricstream-data-model.yml
- type: Plans
  url: plans/metricstream-plans-pricing.yml
- type: RateLimits
  url: rate-limits/metricstream-rate-limits.yml
- type: AgentSkill
  url: skills/_index.yml
- type: ChangeLog
  url: changelog/metricstream-changelog.yml
x-enrichment:
  date: '2026-08-25'
  status: enriched
  artifacts_added: 21
  pass: local-v1
x-coverage:
  state: covered
  reason: no-machine-readable-spec
  detail: MetricStream publishes a real, public, unauthenticated API reference — 34 swagger-codegen HTML pages under assets.metricstream.com/pdf/Developer-Portal/
    describing 204 operations across 8 API families — but no downloadable OpenAPI/Swagger document exists at any probed location,
    so the catalog holds the API surface as derived artifacts rather than as a contract.
  evidence:
  - url: https://www.metricstream.com/api-developer-portal.html
    status: 200
  - url: https://assets.metricstream.com/pdf/Developer-Portal/GRCF_API/MsGrcRisk.html
    status: 200
  - url: https://www.metricstream.com/openapi.json
    status: 404
  - url: https://assets.metricstream.com/pdf/Developer-Portal/GRCF_API/swagger.json
    status: 404
  - url: https://www.metricstream.com/llms.txt
    status: 200
  checked: '2026-08-25'

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/metricstream"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/metricstream/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/metricstream/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.