RegScale
RegScale is a Continuous Controls Monitoring (CCM) and compliance-automation company whose cloud-native, OSCAL-native GRC platform keeps organizations continuously audit-ready by turning compliance documentation into living, machine-readable data. The platform ships as a customer-tenanted deployment (SaaS, hybrid, or on-premises) and exposes its data through three programmable surfaces: a JWT-authenticated REST API under /api, a HotChocolate-style GraphQL endpoint at /graphql, and a published gRPC contract library (rs-data) covering asset, issue and vulnerability ingestion. RegScale also publishes a first-party Python CLI/SDK (regscale-cli) that doubles as an integration framework for 70+ scanners, cloud providers and ITSM tools, and holds FedRAMP High, SOC 2 Type 2, ISO 27001:2022, TX-RAMP Level 2 and CSA STAR credentials.
RegScale publishes 3 APIs on the APIs.io network. Tagged areas include Company, Compliance, Governance Risk and Compliance, Continuous Controls Monitoring, and Security.
The RegScale catalog on APIs.io includes 1 event-driven AsyncAPI specification.
RegScale’s developer surface includes documentation, getting-started guide, support, API reference, engineering blog, changelog, CLI, and 25 more developer resources.
Kin Score
APIs 3
Individual APIs this provider publishes, each with its own machine-readable definition.
RegScale REST API
The RegScale REST API is the primary programmable surface of the RegScale platform. It is served from each customer's own RegScale tenant under the /api path, authenticated with...
RegScale GraphQL API
RegScale exposes a GraphQL endpoint at /graphql on each customer tenant, used by the first-party RegScale CLI for high-volume paginated reads. Queries follow the HotChocolate co...
RegScale gRPC Ingestion Services
RegScale publishes a gRPC contract library, rs-data, covering three high-volume ingestion services: AssetIngestionService, IssueIngestionService and VulnIngestionService. Each s...
Pricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
Regscale Rate Limits
RATE LIMITSEvent Specifications 1
AsyncAPI definitions for this provider's event-driven and streaming APIs.
Regscale Webhooks
ASYNCAPISecurity Posture 4
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Regscale Trust Center
FedRAMP High, SOC 2 Type 2, ISO 27001:2022, TX-RAMP Level 2, CSA STAR Level 1, CSA STAR Valid-AI-ted, DoD IL5 (in process), HIPAA, GDPR
SECURITYResources
Get Started 2
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 6
Pagination, idempotency, versioning, errors, and events
Build 4
SDKs, sample code, and the tooling you integrate with
Access & Security 7
Authentication, authorization, and security posture
Scroll for all 7
Operate 4
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API
Other 1
Properties that don't map to a standard resource type
Source (apis.yml)
Work with this as data
Every provider here is available over the APIs.io API and to AI agents over MCP.