Skip to main content

Data Protection API

These routes use the same X-API-Key and X-Account-ID authentication as the Builder API. Clients must treat the returned effective policy as authoritative; do not reproduce the resolution rule in client code.

Read effective policy​

GET /api/v1/data-protection/effective

Pass either task_exec_id, or both workload_type and workload_id. With no subject parameters, the route returns the authenticated account's effective value. workload_type is inference_endpoint or training_job.

The response includes:

  • effective.node_eligibility and its rank;
  • binding_level, the level that fixed the current value;
  • all three entries in resolution, including undeclared levels;
  • the account ceiling;
  • can_relax_to and can_restrict_to as explicit legal transitions.

Set policy​

PATCH /api/v1/accounts/{account_id}/data-protection
PATCH /api/v1/endpoints/{endpoint_id}/data-protection
PATCH /api/v1/training/jobs/{job_id}/data-protection
Content-Type: application/json

{"node_eligibility":"own_hardware_only"}

Account policy requires owner or admin. Workload policy requires operator. A workload may send null to inherit; account policy cannot inherit.

Placement preflight​

POST /api/v1/data-protection/placement-preflight
{
"workload_type": "inference_endpoint",
"workload_id": "<uuid>",
"node_eligibility": "own_hardware_only",
"model_id": "<optional-uuid>",
"explain": true
}

node_eligibility is an optional hypothetical value and is not persisted. model_id additionally checks physical model fit. A successful result returns would_dispatch: true. No eligible node returns HTTP 422 with blocking_code: "policy_no_eligible_node" and a structured relaxation_hint when a legal relaxation has capacity.

Placement attestation​

GET /api/v1/compliance/placement-attestation?from=<RFC3339>&to=<RFC3339>

The account-scoped report contains the declared account policy and changes in the window, task counts by stamped effective policy, conformance totals, observed destination labels, violation samples, and a deterministic evidence digest.

Stable error and exclusion codes​

CodeHTTPMeaning
policy_exceeds_account_ceiling422Requested policy is more permissive than the account ceiling.
policy_no_eligible_node422 or failed taskNo node satisfies the effective policy.
policy_unresolvable503Required policy data could not be resolved; placement fails closed.
node_is_rented_capacity—Node was excluded as rented capacity.
node_rented_status_unknown—Rental status was not measured and is treated as rented.
node_owned_by_other_account—Node belongs to another account.
node_offline_or_draining—Node is not currently traffic-ready.

Codes are stable and additive. Callers must never interpret an unknown code as permission to dispatch or retry with a more permissive policy.