{
  "openapi": "3.1.0",
  "info": {
    "title": "BitScore — Indian Cyber Regulation Register",
    "version": "1.0.0",
    "description": "Read-only answers from BitScore Cybertech LLP’s Indian cyber regulation register: which instruments bind an entity, incident-reporting deadlines in India, the US and the EU, SEBI CSCRF categories, and aggregate Indian threat activity. Every instrument read at source. Indicative, not legal advice.",
    "contact": {
      "name": "BitScore Cybertech LLP",
      "url": "https://www.bitscore.in/data/connector"
    },
    "license": {
      "name": "CC BY 4.0",
      "url": "https://creativecommons.org/licenses/by/4.0/"
    }
  },
  "servers": [
    {
      "url": "https://www.bitscore.in"
    }
  ],
  "paths": {
    "/api/connector/search_instruments": {
      "post": {
        "operationId": "searchInstruments",
        "summary": "Search the Indian cyber regulation register",
        "description": "Search every cyber and data-protection instrument binding Indian regulated entities (RBI, SEBI, IRDAI, IFSCA, CERT-In, MeitY/DPDP): reference number, issue date, status, who it binds and the deadlines it sets. Filter by free text, issuer or status. Returns summaries; use get_instrument for one…",
        "x-openai-isConsequential": false,
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "query": {
                    "type": "string",
                    "description": "Words to match against the name, reference number and who it binds, e.g. \"outsourcing\", \"NBFC\", \"2024/113\".",
                    "maxLength": 200
                  },
                  "issuer": {
                    "type": "string",
                    "description": "Only instruments from this issuer.",
                    "enum": [
                      "RBI",
                      "SEBI",
                      "IRDAI",
                      "IFSCA",
                      "CERT-In",
                      "MeitY"
                    ]
                  },
                  "status": {
                    "type": "string",
                    "description": "Only instruments with this status.",
                    "enum": [
                      "in-force",
                      "partly-in-force",
                      "superseded"
                    ]
                  },
                  "limit": {
                    "type": "integer",
                    "description": "Maximum results, 1–50. Default 20.",
                    "minimum": 1,
                    "maximum": 50
                  }
                },
                "additionalProperties": false
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "The answer: prose to quote, and the same facts as structured data.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "text": {
                      "type": "string",
                      "description": "Answer with source and verification date. Quote it; do not paraphrase deadlines."
                    },
                    "data": {
                      "type": "object",
                      "description": "The same facts, structured."
                    }
                  },
                  "required": [
                    "text",
                    "data"
                  ]
                }
              }
            }
          },
          "400": {
            "description": "Invalid arguments; the message says which and how to fix it."
          }
        }
      }
    },
    "/api/connector/get_instrument": {
      "post": {
        "operationId": "getInstrument",
        "summary": "Get one instrument from the register",
        "description": "Full register entry for one instrument by its id (from search_instruments): formal name, reference, issue date, status, who it binds, every dated deadline it sets, the regulator’s own URL and the date it was last re-read there.",
        "x-openai-isConsequential": false,
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "id": {
                    "type": "string",
                    "description": "Register id, e.g. \"rbi-cyber-2026-nbfc\" or \"sebi-cscrf\".",
                    "maxLength": 100
                  }
                },
                "required": [
                  "id"
                ],
                "additionalProperties": false
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "The answer: prose to quote, and the same facts as structured data.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "text": {
                      "type": "string",
                      "description": "Answer with source and verification date. Quote it; do not paraphrase deadlines."
                    },
                    "data": {
                      "type": "object",
                      "description": "The same facts, structured."
                    }
                  },
                  "required": [
                    "text",
                    "data"
                  ]
                }
              }
            }
          },
          "400": {
            "description": "Invalid arguments; the message says which and how to fix it."
          }
        }
      }
    },
    "/api/connector/find_applicable_regulations": {
      "post": {
        "operationId": "findApplicableRegulations",
        "summary": "Which Indian cyber regulations apply to an entity",
        "description": "Given an Indian entity class, whether it is listed and whether it handles personal data, returns the cyber and data-protection instruments that bind it, why each applies, a caution where one is commonly misapplied, and its next dated deadline. RBI classes each map to their own 2026 Directions;…",
        "x-openai-isConsequential": false,
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "entity_class": {
                    "type": "string",
                    "description": "The entity’s class.",
                    "enum": [
                      "commercial-bank",
                      "sfb",
                      "payments-bank",
                      "ucb",
                      "aifi",
                      "nbfc",
                      "cic",
                      "rrb",
                      "lab",
                      "sebi-re",
                      "insurer",
                      "ifsca-re",
                      "other"
                    ]
                  },
                  "listed": {
                    "type": "boolean",
                    "description": "Listed on an Indian stock exchange (brings SEBI LODR disclosure)."
                  },
                  "handles_personal_data": {
                    "type": "boolean",
                    "description": "Processes digital personal data of individuals in India (brings DPDP)."
                  }
                },
                "required": [
                  "entity_class",
                  "listed",
                  "handles_personal_data"
                ],
                "additionalProperties": false
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "The answer: prose to quote, and the same facts as structured data.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "text": {
                      "type": "string",
                      "description": "Answer with source and verification date. Quote it; do not paraphrase deadlines."
                    },
                    "data": {
                      "type": "object",
                      "description": "The same facts, structured."
                    }
                  },
                  "required": [
                    "text",
                    "data"
                  ]
                }
              }
            }
          },
          "400": {
            "description": "Invalid arguments; the message says which and how to fix it."
          }
        }
      }
    },
    "/api/connector/india_incident_reporting_deadlines": {
      "post": {
        "operationId": "indiaIncidentReportingDeadlines",
        "summary": "Indian cyber incident reporting deadlines",
        "description": "Every incident-reporting clock an Indian entity owes — CERT-In six hours, the sectoral regulator (RBI, SEBI, IRDAI, IFSCA), SEBI LODR, NCIIPC, DPDP — each with its trigger, recipient, channel and source clause. Give noticed_at to get wall-clock IST due times. Clocks run in parallel; none…",
        "x-openai-isConsequential": false,
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "sector": {
                    "type": "string",
                    "description": "Sectoral regulator, or \"none\".",
                    "enum": [
                      "rbi",
                      "sebi",
                      "irdai",
                      "ifsca",
                      "none"
                    ]
                  },
                  "rbi_class": {
                    "type": "string",
                    "description": "Required when sector is \"rbi\".",
                    "enum": [
                      "commercial-bank",
                      "sfb",
                      "payments-bank",
                      "ucb",
                      "aifi",
                      "nbfc",
                      "cic"
                    ]
                  },
                  "nbfc_layer": {
                    "type": "string",
                    "description": "For an NBFC: its layer under Scale-Based Regulation.",
                    "enum": [
                      "base-below-500",
                      "base-500-plus",
                      "middle-upper-top"
                    ]
                  },
                  "sebi_broker_or_dp": {
                    "type": "boolean",
                    "description": "SEBI stock broker or depository participant (adds a six-hour leg to the exchanges/depositories)."
                  },
                  "ifsca_exempt": {
                    "type": "boolean",
                    "description": "IFSCA RE inside either exemption tier of the 2025 Guidelines."
                  },
                  "ifsca_mii": {
                    "type": "boolean",
                    "description": "IFSC market infrastructure institution (stock exchange, clearing corporation, depository)."
                  },
                  "listed": {
                    "type": "boolean",
                    "description": "Listed on an Indian stock exchange."
                  },
                  "protected_system": {
                    "type": "boolean",
                    "description": "Operates a notified Protected System (brings NCIIPC)."
                  },
                  "personal_data": {
                    "type": "boolean",
                    "description": "The incident involves digital personal data."
                  },
                  "noticed_at": {
                    "type": "string",
                    "description": "Optional. When the incident was noticed or brought to notice, ISO 8601 with offset, e.g. 2026-10-01T14:30:00+05:30.",
                    "maxLength": 40
                  }
                },
                "required": [
                  "sector",
                  "listed",
                  "protected_system",
                  "personal_data"
                ],
                "additionalProperties": false
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "The answer: prose to quote, and the same facts as structured data.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "text": {
                      "type": "string",
                      "description": "Answer with source and verification date. Quote it; do not paraphrase deadlines."
                    },
                    "data": {
                      "type": "object",
                      "description": "The same facts, structured."
                    }
                  },
                  "required": [
                    "text",
                    "data"
                  ]
                }
              }
            }
          },
          "400": {
            "description": "Invalid arguments; the message says which and how to fix it."
          }
        }
      }
    },
    "/api/connector/us_eu_incident_reporting_deadlines": {
      "post": {
        "operationId": "usEuIncidentReportingDeadlines",
        "summary": "US and EU cyber incident reporting deadlines",
        "description": "Incident-reporting clocks under SEC Form 8-K/6-K, NYDFS Part 500, the US bank 36-hour rule, HIPAA, the FTC Safeguards Rule, NIS2, DORA, GDPR and the EU Cyber Resilience Act, each from its own trigger. Give aware_at (and decided_at for materiality/classification clocks) for wall-clock due times.",
        "x-openai-isConsequential": false,
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "sec": {
                    "type": "string",
                    "description": "SEC status.",
                    "enum": [
                      "none",
                      "domestic",
                      "fpi"
                    ]
                  },
                  "nydfs": {
                    "type": "boolean",
                    "description": "Regulated by the New York DFS (23 NYCRR 500)."
                  },
                  "us_bank": {
                    "type": "boolean",
                    "description": "A US banking organisation under the 36-hour computer-security incident rule."
                  },
                  "bank_service_provider": {
                    "type": "boolean",
                    "description": "A bank service provider under the same rule."
                  },
                  "hipaa": {
                    "type": "string",
                    "description": "HIPAA role.",
                    "enum": [
                      "none",
                      "covered-entity",
                      "business-associate"
                    ]
                  },
                  "ftc_safeguards": {
                    "type": "boolean",
                    "description": "A non-bank financial institution under the FTC Safeguards Rule."
                  },
                  "nis2": {
                    "type": "boolean",
                    "description": "An essential or important entity under NIS2."
                  },
                  "dora": {
                    "type": "string",
                    "description": "DORA status.",
                    "enum": [
                      "none",
                      "financial-entity",
                      "no-weekend-relief"
                    ]
                  },
                  "gdpr": {
                    "type": "string",
                    "description": "GDPR role for the personal data involved.",
                    "enum": [
                      "none",
                      "controller",
                      "processor"
                    ]
                  },
                  "cra_manufacturer": {
                    "type": "boolean",
                    "description": "A manufacturer of products with digital elements under the EU CRA."
                  },
                  "aware_at": {
                    "type": "string",
                    "description": "Optional. When the entity became aware, ISO 8601 with offset.",
                    "maxLength": 40
                  },
                  "decided_at": {
                    "type": "string",
                    "description": "Optional. When materiality/reportability/major classification was determined, ISO 8601 with offset.",
                    "maxLength": 40
                  }
                },
                "required": [
                  "sec",
                  "nydfs",
                  "us_bank",
                  "bank_service_provider",
                  "hipaa",
                  "ftc_safeguards",
                  "nis2",
                  "dora",
                  "gdpr",
                  "cra_manufacturer"
                ],
                "additionalProperties": false
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "The answer: prose to quote, and the same facts as structured data.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "text": {
                      "type": "string",
                      "description": "Answer with source and verification date. Quote it; do not paraphrase deadlines."
                    },
                    "data": {
                      "type": "object",
                      "description": "The same facts, structured."
                    }
                  },
                  "required": [
                    "text",
                    "data"
                  ]
                }
              }
            }
          },
          "400": {
            "description": "Invalid arguments; the message says which and how to fix it."
          }
        }
      }
    },
    "/api/connector/find_global_cyber_regulations": {
      "post": {
        "operationId": "findGlobalCyberRegulations",
        "summary": "Which cyber regulations apply across India, the US and the EU",
        "description": "For an organisation operating across India, the US and the EU, lists the cyber and data-protection regimes that apply, may apply (check) or are pending, with why and a caution for each. All flags default to false and sizes/sectors to none.",
        "x-openai-isConsequential": false,
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "india_operations": {
                    "type": "boolean",
                    "description": "Operates in India."
                  },
                  "india_personal_data": {
                    "type": "boolean",
                    "description": "Processes digital personal data of individuals in India."
                  },
                  "india_listed": {
                    "type": "boolean",
                    "description": "Listed on an Indian stock exchange."
                  },
                  "india_financial_regulated": {
                    "type": "boolean",
                    "description": "Regulated by RBI, SEBI, IRDAI or IFSCA."
                  },
                  "sec": {
                    "type": "string",
                    "description": "SEC status.",
                    "enum": [
                      "none",
                      "domestic",
                      "fpi"
                    ]
                  },
                  "nydfs": {
                    "type": "boolean",
                    "description": "Regulated by the New York DFS."
                  },
                  "us_bank": {
                    "type": "boolean",
                    "description": "US banking organisation."
                  },
                  "ftc_safeguards": {
                    "type": "boolean",
                    "description": "Non-bank financial institution under the FTC Safeguards Rule."
                  },
                  "hipaa": {
                    "type": "boolean",
                    "description": "Covered entity or business associate under HIPAA."
                  },
                  "us_personal_data": {
                    "type": "boolean",
                    "description": "Holds personal data of US residents."
                  },
                  "us_critical_infrastructure": {
                    "type": "boolean",
                    "description": "US critical-infrastructure sector."
                  },
                  "eu_personal_data": {
                    "type": "boolean",
                    "description": "Processes personal data of people in the EU."
                  },
                  "nis2_sector": {
                    "type": "string",
                    "description": "NIS2 sector annex.",
                    "enum": [
                      "none",
                      "annex-i",
                      "annex-ii"
                    ]
                  },
                  "size": {
                    "type": "string",
                    "description": "Enterprise size.",
                    "enum": [
                      "small",
                      "medium",
                      "large"
                    ]
                  },
                  "dora_financial_entity": {
                    "type": "boolean",
                    "description": "EU financial entity under DORA."
                  },
                  "ict_provider_to_eu_finance": {
                    "type": "boolean",
                    "description": "ICT third-party provider to EU financial entities."
                  },
                  "cra_manufacturer": {
                    "type": "boolean",
                    "description": "Manufacturer of products with digital elements sold in the EU."
                  }
                },
                "additionalProperties": false
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "The answer: prose to quote, and the same facts as structured data.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "text": {
                      "type": "string",
                      "description": "Answer with source and verification date. Quote it; do not paraphrase deadlines."
                    },
                    "data": {
                      "type": "object",
                      "description": "The same facts, structured."
                    }
                  },
                  "required": [
                    "text",
                    "data"
                  ]
                }
              }
            }
          },
          "400": {
            "description": "Invalid arguments; the message says which and how to fix it."
          }
        }
      }
    },
    "/api/connector/sebi_cscrf_category": {
      "post": {
        "operationId": "sebiCscrfCategory",
        "summary": "SEBI CSCRF category for a regulated entity",
        "description": "Works out a SEBI regulated entity’s CSCRF category (MII, Qualified, Mid-size, Small-size, Self-certification or Exempt) from the current thresholds, and the obligations that category carries. Call with only entity_type to see which figures it needs. Boundary values the circulars leave…",
        "x-openai-isConsequential": false,
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "entity_type": {
                    "type": "string",
                    "description": "The SEBI entity type.",
                    "enum": [
                      "mii",
                      "stock-broker",
                      "proprietary-stock-broker",
                      "depository-participant",
                      "portfolio-manager",
                      "merchant-banker",
                      "aif-vcf-manager",
                      "mutual-fund-amc",
                      "custodian",
                      "rta",
                      "kra",
                      "investment-adviser",
                      "research-analyst",
                      "ddp",
                      "debenture-trustee",
                      "credit-rating-agency",
                      "collective-investment-scheme",
                      "banker-to-issue",
                      "excluded"
                    ]
                  },
                  "registered_clients": {
                    "type": "number",
                    "description": "Figure for the \"registered-clients\" criterion (see entity_type's required figures). ₹ crore values in crore; counts as plain numbers."
                  },
                  "clientele_trading_volume": {
                    "type": "number",
                    "description": "Figure for the \"clientele-trading-volume\" criterion (see entity_type's required figures). ₹ crore values in crore; counts as plain numbers."
                  },
                  "collateral_with_ccs": {
                    "type": "number",
                    "description": "Figure for the \"collateral-with-ccs\" criterion (see entity_type's required figures). ₹ crore values in crore; counts as plain numbers."
                  },
                  "aum": {
                    "type": "number",
                    "description": "Figure for the \"aum\" criterion (see entity_type's required figures). ₹ crore values in crore; counts as plain numbers."
                  },
                  "corpus": {
                    "type": "number",
                    "description": "Figure for the \"corpus\" criterion (see entity_type's required figures). ₹ crore values in crore; counts as plain numbers."
                  },
                  "auc": {
                    "type": "number",
                    "description": "Figure for the \"auc\" criterion (see entity_type's required figures). ₹ crore values in crore; counts as plain numbers."
                  },
                  "folios": {
                    "type": "number",
                    "description": "Figure for the \"folios\" criterion (see entity_type's required figures). ₹ crore values in crore; counts as plain numbers."
                  }
                },
                "required": [
                  "entity_type"
                ],
                "additionalProperties": false
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "The answer: prose to quote, and the same facts as structured data.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "text": {
                      "type": "string",
                      "description": "Answer with source and verification date. Quote it; do not paraphrase deadlines."
                    },
                    "data": {
                      "type": "object",
                      "description": "The same facts, structured."
                    }
                  },
                  "required": [
                    "text",
                    "data"
                  ]
                }
              }
            }
          },
          "400": {
            "description": "Invalid arguments; the message says which and how to fix it."
          }
        }
      }
    },
    "/api/connector/india_threat_scorecard": {
      "post": {
        "operationId": "indiaThreatScorecard",
        "summary": "India Cyber Threat Scorecard",
        "description": "Aggregate counts of publicly observed cyber threat activity affecting Indian organisations, by industry vertical and category, for one edition (latest by default). Aggregate only: no organisation is named. A vertical the source did not cover is unmeasured, not zero.",
        "x-openai-isConsequential": false,
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "properties": {
                  "edition": {
                    "type": "string",
                    "description": "Edition slug, YYYY-MM. Omit for the latest.",
                    "enum": [
                      "2026-08"
                    ]
                  }
                },
                "additionalProperties": false
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "The answer: prose to quote, and the same facts as structured data.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object",
                  "properties": {
                    "text": {
                      "type": "string",
                      "description": "Answer with source and verification date. Quote it; do not paraphrase deadlines."
                    },
                    "data": {
                      "type": "object",
                      "description": "The same facts, structured."
                    }
                  },
                  "required": [
                    "text",
                    "data"
                  ]
                }
              }
            }
          },
          "400": {
            "description": "Invalid arguments; the message says which and how to fix it."
          }
        }
      }
    }
  }
}