API reference
The Veritas Cyber v1 API lets you score an Essential Eight self-assessment and generate the document pack from your own systems. It's built for broker platforms, MSP tools and other integrations. You get back an indicative, self-assessed maturity result, and every document carries the standard self-assessment disclaimer. It is not a certification, audit or insurance-outcome service.
Authentication
Create an API key on your Developer page and send it as a bearer token. Treat it like a password and keep it secret.
Authorization: Bearer vk_live_your_key_herePOST /api/v1/score
Scores a set of answers against a framework (default essential-eight). It's stateless, so nothing is stored. Rate limit: 60 requests a minute per key.
curl -X POST https://veritas-cyber.com/api/v1/score \
-H "Authorization: Bearer $VK_KEY" \
-H "Content-Type: application/json" \
-d '{
"framework": "essential-eight",
"answers": [
{ "questionId": "mfa-org-online-services", "value": "yes" },
{ "questionId": "backups-performed", "value": "no" }
]
}'Returns the scored result:
{
"result": {
"frameworkId": "essential-eight",
"overall": 0,
"targetLevel": 2,
"maxLevel": 3,
"perControl": [ { "control": "mfa", "level": 1, "applicable": true, ... } ]
}
}POST /api/v1/documents
Generates one PDF document from the answers plus an organisation profile. You need an active subscription on your account (the Privacy Act and AI documents need the Pro plan). Calls without one get a 402. Rate limit: 20 requests a minute per key. Pass org.brand to put your own name in the header. The Veritas Cyber attribution and self-assessment disclaimer always stay on the document.
curl -X POST https://veritas-cyber.com/api/v1/documents \
-H "Authorization: Bearer $VK_KEY" \
-H "Content-Type: application/json" \
-o evidence-pack.pdf \
-d '{
"kind": "evidence_pack",
"org": { "name": "Blue Gum Dental", "industry": "Healthcare", "hasMsOffice": true, "brand": "Acme Brokers" },
"answers": [ { "questionId": "mfa-org-online-services", "value": "yes" } ]
}'Document kinds: evidence_pack, roadmap, information_security_policy, access_control_policy, patch_management_policy, backup_recovery_policy, acceptable_use_policy, incident_response_plan, privacy_reasonable_steps, data_breach_response_plan, data_inventory_starter, ai_use_policy.
Errors
401: the API key is missing or invalid.402: generating documents needs an active subscription (Pro for the Privacy Act and AI documents).400: the payload is invalid (the response body says why).429: you've hit the rate limit (check theRetry-Afterheader).
Questions
Building an integration? Get in touch at hello@veritas-cyber.com.