# RegScale

**Canonical:** https://apis.io/providers/regscale/  
**Website:** https://regscale.com/  
**APIs profiled:** 3

RegScale is a Continuous Controls Monitoring (CCM) and compliance-automation company whose cloud-native, OSCAL-native GRC platform keeps organizations continuously audit-ready by turning compliance documentation into living, machine-readable data. The platform ships as a customer-tenanted deployment (SaaS, hybrid, or on-premises) and exposes its data through three programmable surfaces: a JWT-authenticated REST API under /api, a HotChocolate-style GraphQL endpoint at /graphql, and a published gRPC contract library (rs-data) covering asset, issue and vulnerability ingestion. RegScale also publishes a first-party Python CLI/SDK (regscale-cli) that doubles as an integration framework for 70+ scanners, cloud providers and ITSM tools, and holds FedRAMP High, SOC 2 Type 2, ISO 27001:2022, TX-RAMP Level 2 and CSA STAR credentials.

## Kin Score — 51.2 / 100 (developing)

Scored 2026-09-01 under rubric 0.17.2. Trend: flat (+0.0 from 51.2).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 42.7 |
| Governance | 18.2 |
| Contract Governance | 18.2 |
| Operational Transparency | 36.8 |
| Developer Ergonomics | 64.3 |
| Commercial Clarity | 28.9 |
| Access Clarity | 28.9 |

Regulatory layer — **Government & Public Sector**: 66.7 (matched via tags).

## Agent readiness — 25.5 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | bearer |
| Idempotency | documented |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | yes |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## APIs (3)

- **RegScale REST API** — The RegScale REST API is the primary programmable surface of the RegScale platform. It is served from each customer's own RegScale tenant under the /api path, authenticated with...
- **RegScale GraphQL API** — RegScale exposes a GraphQL endpoint at /graphql on each customer tenant, used by the first-party RegScale CLI for high-volume paginated reads. Queries follow the HotChocolate co...
- **RegScale gRPC Ingestion Services** — RegScale publishes a gRPC contract library, rs-data, covering three high-volume ingestion services: AssetIngestionService, IssueIngestionService and VulnIngestionService. Each s...

## Security (4)

- **Regscale Authentication** — http/oauth2/openIdConnect/saml · 4 schemes
- **Regscale Domain Security** — TLSv1.3 · HSTS · DMARC
- **Regscale Vulnerability Disclosure** — Hackerone
- **Regscale Trust Center** — FedRAMP High, SOC 2 Type 2, ISO 27001:2022, TX-RAMP Level 2, CSA STAR Level 1, CSA STAR Valid-AI-ted, DoD IL5 (in process), HIPAA, GDPR

## Plans (1)

- **Regscale Plans Pricing**

## Tags

Company, Compliance, Governance Risk and Compliance, Continuous Controls Monitoring, Security, FedRAMP, OSCAL, Risk Management, Audit, Compliance as Code, Vulnerability Management, Government

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/regscale/). Scores are computed from the provider's own public artifacts under a published rubric.
