Data Protection API
These routes use the same X-API-Key and X-Account-ID authentication as the Builder API. Clients
must treat the returned effective policy as authoritative; do not reproduce the resolution rule in
client code.
Read effective policy
GET /api/v1/data-protection/effective
Pass either task_exec_id, or both workload_type and workload_id. With no subject parameters,
the route returns the authenticated account's effective value. workload_type is
inference_endpoint or training_job.
The response includes:
effective.node_eligibilityand its rank;binding_level, the level that fixed the current value;- all three entries in
resolution, including undeclared levels; - the account
ceiling; can_relax_toandcan_restrict_toas explicit legal transitions.
Set policy
PATCH /api/v1/accounts/{account_id}/data-protection
PATCH /api/v1/endpoints/{endpoint_id}/data-protection
PATCH /api/v1/training/jobs/{job_id}/data-protection
Content-Type: application/json
{"node_eligibility":"own_hardware_only"}
Account policy requires owner or admin. Workload policy requires operator. A workload may send
null to inherit; account policy cannot inherit.
Placement preflight
POST /api/v1/data-protection/placement-preflight
{
"workload_type": "inference_endpoint",
"workload_id": "<uuid>",
"node_eligibility": "own_hardware_only",
"model_id": "<optional-uuid>",
"explain": true
}
node_eligibility is an optional hypothetical value and is not persisted. model_id additionally
checks physical model fit. A successful result returns would_dispatch: true. No eligible node
returns HTTP 422 with blocking_code: "policy_no_eligible_node" and a structured
relaxation_hint when a legal relaxation has capacity.
Placement attestation
GET /api/v1/compliance/placement-attestation?from=<RFC3339>&to=<RFC3339>
The account-scoped report contains the declared account policy and changes in the window, task counts by stamped effective policy, conformance totals, observed destination labels, violation samples, and a deterministic evidence digest.
Stable error and exclusion codes
| Code | HTTP | Meaning |
|---|---|---|
policy_exceeds_account_ceiling | 422 | Requested policy is more permissive than the account ceiling. |
policy_no_eligible_node | 422 or failed task | No node satisfies the effective policy. |
policy_unresolvable | 503 | Required policy data could not be resolved; placement fails closed. |
node_is_rented_capacity | — | Node was excluded as rented capacity. |
node_rented_status_unknown | — | Rental status was not measured and is treated as rented. |
node_owned_by_other_account | — | Node belongs to another account. |
node_offline_or_draining | — | Node is not currently traffic-ready. |
Codes are stable and additive. Callers must never interpret an unknown code as permission to dispatch or retry with a more permissive policy.