CYBORA API — your compliance and monitoring data, in your tools
A REST API over everything CYBORA operates for you: Agentic GRC evidence, compliance posture, risk registers, and HybridSOC alerts. Start free in the sandbox, scale into production as your integration grows.

Core endpoints
Versioned REST endpoints, JSON responses, API-key authentication over TLS, and an OpenAPI specification for code generation. Webhooks for anything that shouldn't wait for a poll.
GET /v1/compliance/status
Live compliance posture per framework (DORA, MiCA, NIS2, ISO 27001) — control coverage, gaps, and trend.
GET /v1/evidence
Continuously collected, timestamped GRC evidence — exportable for auditors or your own reporting.
GET /v1/alerts
HybridSOC detections and incidents with severity, status, and response timeline.
POST /v1/webhooks
Push alerts and compliance-drift events into Slack, Teams, SIEM, or any HTTPS endpoint the moment they happen.
GET /v1/risks
Risk register entries with owners, scores, and mitigation status — keep your board pack always current.
GET /v1/reports
Generated audit and board reports as PDF/JSON, ready to file or forward.
curl https://api.cybora.tech/v1/compliance/status \
-H "Authorization: Bearer $CYBORA_API_KEY" \
-H "Accept: application/json"
{
"framework": "DORA",
"coverage": 0.94,
"open_gaps": 3,
"last_evidence_at": "2026-07-08T06:42:11Z"
}Sandbox first, production when you're ready
Get a free sandbox key
1,000 calls a month against read-only endpoints with realistic test data — enough to validate your whole integration.
Build against OpenAPI
Generate typed clients from the spec, subscribe to webhooks, and wire alerts into the tools your team already lives in.
Go live on Growth or Enterprise
Production keys, higher rate limits, read/write endpoints, SLAs, and a private on-perimeter deployment option for regulated workloads.
CYBORA API
Pull Agentic GRC evidence and HybridSOC alerts directly into your own tools. Start free in the sandbox, scale as your integration grows.
Explore the API and validate your integration before going live.
- 1,000 API calls / month
- 30 requests per minute
- Read-only Agentic GRC endpoints
- Sandbox environment & test data
- Community & docs support
For production integrations pulling live compliance and monitoring data.
- 50,000 API calls / month
- 300 requests per minute
- Full Agentic GRC read/write endpoints
- HybridSOC alert webhooks included
- Evidence & audit-log export
- Email support
A plan built around your traffic, jurisdictions, and compliance scope.
- Unlimited API calls
- Custom rate limits
- Uptime SLA
- Private / on-perimeter deployment option
- 24/7 support via email, chat, and phone
- Dedicated technical account manager
Billed monthly or annually. Volume discounts and longer commitments are available on request. Unused calls do not roll over to the next billing period.
Sehen Sie es in Ihrem eigenen Perimeter
Tell us where you are today. A CYBORA engineer — not a salesperson — will come back with what actually applies to your situation.
- Reply within one business day
- Scoped to your regulatory frameworks
- No obligation, no sales pitch
Take control of your perimeter
Register for a pilot demonstration of the CYBORA GRC and HybridSOC platform. One team, accountable for your full cyber security lifecycle.