> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://developer.fortresstech.io/api-reference/compliance-documents/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.fortresstech.io/_mcp/server. # Compliance Documents Overview > Overview of the Compliance Documents API, the application bundle used by the CORA document-review agent The Compliance Documents API gives the document-review agent everything it needs to review one application in a single read: the application's requirement slots, the document types each slot accepts with their definitions, and the documents uploaded with their status, extracted fields and review result. > **Note** > > Status: **Defined, not yet published**. The route below is specified for the CORA integration and is not delivered yet. Authenticate with the `x-api-key` header, as for every other route. ## Key Concepts ### The bundle One read returns `Application → Requirements → Document Types → Documents → Extracted fields → Review result`. It lists every requirement of the application, including slots with no upload yet (empty `documents`). Definitions (fields, mappings, rules) are the versions pinned for the application when it was signed; a document type with no approved definition has `definitionVersion: null` and empty fields, mappings and rules. ### Requirement status Fortress derives each requirement's `status` from the statuses of its documents: `AWAITING_UPLOAD`, `UPLOADED`, `IN_REVIEW`, `WAITING_FOR_APPLICANT`, `WAITING_FOR_COMPLIANCE` or `VALIDATED`. A `REJECTED` document stays in the bundle as history only and never counts, so a requirement without the non-rejected documents it needs is `AWAITING_UPLOAD`. It is never written by the agent. The agent writes document statuses through [`POST /documents/{documentId}/results`](/api-reference/documents/post-document-results), and Fortress recomputes the requirement status after each write. ### Trimming the response * `exclude` leaves out parts of the bundle (comma-separated paths). Excluded properties are **absent**, never returned empty: an empty array means "no definition". * `hideDocumentTypesOnValidatedRequirement=true` returns `VALIDATED` requirements without their `documentTypes`, so the reader sees only what still needs work. ### When to read it On [`application.signed`](/webhooks/webhook-events/webhooks/application-signed) and on every [`requirement.upload_received`](/webhooks/webhook-events/webhooks/requirement-upload-received) and [`requirement.upload_removed`](/webhooks/webhook-events/webhooks/requirement-upload-removed). ## Available Endpoints | Endpoint | Summary | Method | | ------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------- | :----: | | [`/compliance-documents/applications/{applicationId}/bundle`](/api-reference/compliance-documents/get-application-bundle) | Get Application Bundle (defined, not yet published) | GET | > Overview of the Compliance Documents API, the application bundle used by the CORA document-review agent ## API Docs - Compliance Documents [Get Application Bundle](https://developer.fortresstech.io/api-reference/compliance-documents/get-application-bundle.md) ## OpenAPI Specification The raw OpenAPI 3.1 specification for this API is available at: - [OpenAPI JSON](https://developer.fortresstech.io/api-reference/compliance-documents/openapi.json) - [OpenAPI YAML](https://developer.fortresstech.io/api-reference/compliance-documents/openapi.yaml)