> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developer.fortresstech.io/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.fortresstech.io/_mcp/server.

# Compliance Documents Overview

> Overview of the Compliance Documents API, the application bundle used by the CORA document-review agent

The Compliance Documents API gives the document-review agent everything it needs to review one application in a single read: the application's requirement slots, the document types each slot accepts with their definitions, and the documents uploaded with their status, extracted fields and review result.

> **Note**
>
> Status: **Defined, not yet published**. The route below is specified for the CORA integration and is not delivered yet. Authenticate with the `x-api-key` header, as for every other route.

## Key Concepts

### The bundle

One read returns `Application → Requirements → Document Types → Documents → Extracted fields → Review result`. It lists every requirement of the application, including slots with no upload yet (empty `documents`). Definitions (fields, mappings, rules) are the versions pinned for the application when it was signed; a document type with no approved definition has `definitionVersion: null` and empty fields, mappings and rules.

### Requirement status

Fortress derives each requirement's `status` from the statuses of its documents: `AWAITING_UPLOAD`, `UPLOADED`, `IN_REVIEW`, `WAITING_FOR_APPLICANT`, `WAITING_FOR_COMPLIANCE` or `VALIDATED`. A `REJECTED` document stays in the bundle as history only and never counts, so a requirement without the non-rejected documents it needs is `AWAITING_UPLOAD`. It is never written by the agent. The agent writes document statuses through [`POST /documents/{documentId}/results`](/api-reference/documents/post-document-results), and Fortress recomputes the requirement status after each write.

### Trimming the response

* `exclude` leaves out parts of the bundle (comma-separated paths). Excluded properties are **absent**, never returned empty: an empty array means "no definition".
* `hideDocumentTypesOnValidatedRequirement=true` returns `VALIDATED` requirements without their `documentTypes`, so the reader sees only what still needs work.

### When to read it

On [`application.signed`](/webhooks/webhook-events/webhooks/application-signed) and on every [`requirement.upload_received`](/webhooks/webhook-events/webhooks/requirement-upload-received) and [`requirement.upload_removed`](/webhooks/webhook-events/webhooks/requirement-upload-removed).

## Available Endpoints

| Endpoint                                                                                                                  | Summary                                             | Method |
| ------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------- | :----: |
| [`/compliance-documents/applications/{applicationId}/bundle`](/api-reference/compliance-documents/get-application-bundle) | Get Application Bundle (defined, not yet published) |   GET  |