{"q":"config","count":10,"hits":[{"title":"Configure US frameworks","url":"https://docs.heygrc.com/docs/us-frameworks","mdUrl":"https://docs.heygrc.com/docs/us-frameworks.md","description":"Select SOC 2, HIPAA, CCPA, and other US catalog IDs on an existing heyGRC org. GET the current config, merge IDs, PUT the full state, then read back.","score":9,"snippet":"iew runs when `CCPA` is selected in org config. A bare (unconfigured) install uses **ISO 27001, SOC 2, and GDPR**. There is no install-time picker. **Suggest re"},{"title":"Install from your coding agent (plugin)","url":"https://docs.heygrc.com/docs/agent-plugin","mdUrl":"https://docs.heygrc.com/docs/agent-plugin.md","description":"Install the heyGRC setup skill into Claude Code, Codex CLI, GitHub Copilot CLI, Cursor, or Gemini CLI. The agent walks the GitHub App install and configuration with you.","score":4,"snippet":" under Free-plan limits. 2. **Claim and configure:** you sign in at [app.heygrc.com](https://app.heygrc.com) to claim the install (this starts the 14-day tri"},{"title":"API reference","url":"https://docs.heygrc.com/docs/api-reference","mdUrl":"https://docs.heygrc.com/docs/api-reference.md","description":"heyGRC public API: endpoints for frameworks and review configuration, with request and response shapes.","score":4,"snippet":" App installation) and carries scopes (`config:read`, `config:write`). Send the key in the header only - keys passed in the URL are rejected (`400`), to avoid l"},{"title":"What does heyGRC look for?","url":"https://docs.heygrc.com/docs/faq-what-heygrc-looks-for","mdUrl":"https://docs.heygrc.com/docs/faq-what-heygrc-looks-for.md","description":"Not a fixed checklist. heyGRC reads the pull request for compliance-relevant changes against the frameworks you configured, and cites the clause.","score":4,"snippet":"ng - Secrets and credentials in code or config - Vendors and third parties: new SDKs, subprocessors, outbound data flows - Retention and deletion rules - Audit "},{"title":"For AI agents","url":"https://docs.heygrc.com/docs/for-ai-agents","mdUrl":"https://docs.heygrc.com/docs/for-ai-agents.md","description":"How coding agents should read heyGRC docs and configure the product as code without browser scraping.","score":4,"snippet":"Hosting region is a choice the customer configures, not a reason to skip US buyers. ## Security model (read this) **READ open / EXECUTE locked.** - Public do"},{"title":"Set up with your agent","url":"https://docs.heygrc.com/docs/setup-with-an-agent","mdUrl":"https://docs.heygrc.com/docs/setup-with-an-agent.md","description":"Point your AI coding agent at the heyGRC docs to install the GitHub App, connect your org, and configure frameworks.","score":4,"snippet":", and many other frameworks. heyGRC is configured **as code** through a small REST API, so you can do the whole setup by asking your coding agent (Claude Code,"},{"title":"Your implementation commitments","url":"https://docs.heygrc.com/docs/company-commitments","mdUrl":"https://docs.heygrc.com/docs/company-commitments.md","description":"Teach heyGRC how YOUR company implements logging, access, encryption, retention, and subprocessors, and reviews cite your rule instead of a bare control number.","score":1,"snippet":"ctually implements it. With commitments configured, a finding stops saying \"consider ISO 27001 A.8.15 Logging\" and starts saying what your own rule is: > **Hig"},{"title":"Console and API keys","url":"https://docs.heygrc.com/docs/console-and-api-keys","mdUrl":"https://docs.heygrc.com/docs/console-and-api-keys.md","description":"Use app.heygrc.com to manage API keys, review modes, and org settings for heyGRC.","score":1,"snippet":"I for the same control plane your agent configures via the API. ## Sign in and org Sign in at [app.heygrc.com](https://app.heygrc.com) with GitHub, Google, Mi"},{"title":"EU inference","url":"https://docs.heygrc.com/docs/eu-inference","mdUrl":"https://docs.heygrc.com/docs/eu-inference.md","description":"Optional org setting that sends heyGRC compliance reviews to Mistral on the EU regional endpoint, with no silent fallback to the default global path.","score":1,"snippet":" return to the default global path. ## Configure it as code `eu_inference` is a sticky field on `GET` / `PUT /v1/config`. Omitting it on `PUT` leaves the curr"},{"title":"GitHub App permissions","url":"https://docs.heygrc.com/docs/github-app-permissions","mdUrl":"https://docs.heygrc.com/docs/github-app-permissions.md","description":"What the heyGRC GitHub App can read and write, and what it never does to your source.","score":1,"snippet":"and read the optional `.heygrc.md` repo config | | **Metadata** | Read-only (mandatory) | Repository and installation metadata | | **Checks** | Read and write |"}],"note":"English public docs only. Prefer hit.mdUrl for clean body text."}