PlatformControlSight API

Embed the Control Fabric in your platform.

The ControlSight API delivers UC's 14,000+ Intelligent Controls, mapped to 4,100+ authority documents, directly into your GRC platform. One API. One Rosetta Stone. Every framework your customers need.

Built for OEMs and Platform Partners

Ship the Gold Standard. Faster.

Whether you're building a GRC platform, a cyber risk product, a governance tool, or a vertical compliance solution — the ControlSight API gives your customers UC's continuously maintained fabric without asking you to become a compliance research firm.

01 / Reach

Every framework your customers ask for

4,100+ authority documents — laws, regulations, standards, and directives — harmonized into the same model. When your customer asks for CMMC, DORA, the EU AI Act, or the latest state privacy law, the answer is yes.

02 / Speed

Months of research, in an API call

Building a compliance framework from scratch takes a team of analysts and years of work. With ControlSight, your roadmap ships framework coverage in days — while UC's team does the harmonization behind the scenes.

03 / Depth

Defensible mapping, not surface tagging

UC's patented harmonization process produces mappings that auditors actually accept. Citation-level traceability, expert-reviewed relationships, and 15 years of institutional knowledge behind every control in the response.

04 / Currency

Always up to date. Automatically.

UC monitors every authority document continuously. When a regulation changes, your API responses reflect the change — your customers stay current without your team touching a line of code.

05 / Extension

Your customers weave in their own content

With ControlFoundry integrated into the API, your customers can submit their internal policies and custom frameworks — and receive them back mapped into the same Intelligent Controls that already power your platform.

06 / Scale

Enterprise-grade infrastructure

REST and GraphQL endpoints, webhooks for regulatory changes, SDKs in the languages your team writes in, and SLA-backed uptime. Trusted in production by the leading GRC platforms on the market.

The Rosetta Stone, Extended

The same translation layer — now bilingual for your customer's content.

For 15 years, the ControlSight API has been the Rosetta Stone that lets OEM platforms deliver UC's harmonized controls. With ControlFoundry now integrated, that translation layer speaks a new language: your customer's own policies, mapped into the same fabric your platform already runs on.

How it flows
Unified Compliance
The Control Fabric
14,000+ Intelligent Controls · 4,100+ authority documents · patented harmonization
ControlSight API
Your Platform
Your GRC Product
Your interface. Your workflows. Powered by UC's fabric.
Your UI
Your Customer
Every Framework, Covered
CCPA · HIPAA · NIST · ISO · SOC 2 · DORA · and the framework they're about to ask for.
↑ And with ControlFoundry — the flow runs the other way, too ↑
Your customer uploads their own policies and custom controls through your platform. The API passes them to ControlFoundry, which maps them into the same Intelligent Controls — and returns them to your customer's view of the fabric. Their content. Your platform. UC's model.
Core Endpoints

A clean REST API. No surprises.

GET/v2/controls
GET/v2/authority-documents
GET/v2/mandates
POST/v2/foundry/estimate
POST/v2/foundry/submit
// Request: Get all controls for an authority document
GET https://api.unifiedcompliance.com/v2/controls
 ?authority_doc="nist-800-53-r5"
 &impact_zone="identity-access"
 &control_type="preventative"

// Response
{
 "total": 284,
 "controls": [
   {

     "id": "07.01.14",
     "title": "Enforce multi-factor authentication for privileged accounts",
     "type": "preventative",
     "impact_zone": "identity-access",
     "mandates_satisfied": 23,
     "citations": [
       {
"doc": "NIST 800-53 r5", "ref": "IA-2(1)" },
       {
"doc": "ISO 27001:2022", "ref": "A.8.5" }
     ],

     "last_updated": "2026-04-14T09:22:00Z"
   }
 ]
}
From Kickoff to Production

Live in your platform in weeks.

Most OEM partners are calling the ControlSight API in a developer environment within days, and shipping it in their product within a few weeks. UC provides hands-on onboarding — our Partner Engineering team walks yours through the integration.

Existing API 1.0 partners have a guided migration path to v2 that preserves your current integration and opts you into the new ControlFoundry capabilities when you're ready.

Week 1
Access & credentials
Partner Engineering kickoff call. API keys issued. Postman collection and SDK setup. Your team is making their first calls against sandbox data by end of week.
Week 2–3
Integration development
Build against the core endpoints: controls, authority documents, mandates. UC Partner Engineering is on Slack for technical questions — typical response time under an hour.
Week 3–4
Customer UX & ControlFoundry
Design how the fabric appears in your product. If ControlFoundry is in scope, wire up the document upload flow and the estimate-review UI inside your platform.
Week 4+
Production launch
Switch from sandbox to production credentials. Monitoring in place. Go live for customers. UC stays hands-on through first-month operational review.
Who Uses the ControlSight API

The fabric behind the fabric — in your customers' favorite products.

GRC Platforms

Power your compliance module

Offer your customers every regulatory framework in one model — without building a compliance research team. UC maintains it. Your platform delivers it.

Cyber Risk Platforms

Link risk to controls to regulation

Connect your risk findings to the exact Intelligent Controls and underlying mandates. Give your customers a defensible line from risk posture to regulatory coverage.

Audit & Advisory Firms

Standardize your engagement model

Use the same harmonized control model across every client engagement. Reduce delivery time. Increase margin. Plug UC's fabric into your own methodology.

Vertical SaaS

Add compliance as a feature

Healthcare, financial services, defense, critical infrastructure — embed the controls relevant to your vertical without building them yourself. Launch faster. Compete on value.

Become an API Partner

Put the Gold Standard
in your product.

Let's talk about the integration. Our Partner Engineering team will walk yours through the API, the roadmap, and the commercial model.