{"q":"config","count":10,"hits":[{"title":"Configure US frameworks","url":"https://docs.heygrc.com/docs/us-frameworks","mdUrl":"https://docs.heygrc.com/docs/us-frameworks.md","description":"Select SOC 2, HIPAA, CCPA, and other US catalog IDs on an existing heyGRC org. GET the current config, merge IDs, PUT the full state, then read back.","score":9,"snippet":"iew runs when `CCPA` is selected in org config. A bare (unconfigured) install uses **ISO 27001, SOC 2, and GDPR**. There is no install-time picker. **Suggest re"},{"title":"API reference","url":"https://docs.heygrc.com/docs/api-reference","mdUrl":"https://docs.heygrc.com/docs/api-reference.md","description":"heyGRC public API: endpoints for frameworks and review configuration, with request and response shapes.","score":4,"snippet":" App installation) and carries scopes (`config:read`, `config:write`). Send the key in the header only - keys passed in the URL are rejected (`400`), to avoid l"},{"title":"What does heyGRC look for?","url":"https://docs.heygrc.com/docs/faq-what-heygrc-looks-for","mdUrl":"https://docs.heygrc.com/docs/faq-what-heygrc-looks-for.md","description":"Not a fixed checklist. heyGRC reads the pull request for compliance-relevant changes against the frameworks you configured, and cites the clause.","score":4,"snippet":"ng - Secrets and credentials in code or config - Vendors and third parties: new SDKs, subprocessors, outbound data flows - Retention and deletion rules - Audit "},{"title":"For AI agents","url":"https://docs.heygrc.com/docs/for-ai-agents","mdUrl":"https://docs.heygrc.com/docs/for-ai-agents.md","description":"How coding agents should read heyGRC docs and configure the product as code without browser scraping.","score":4,"snippet":"Hosting region is a choice the customer configures, not a reason to skip US buyers. ## Security model (read this) **READ open / EXECUTE locked.** - Public do"},{"title":"Set up with your agent","url":"https://docs.heygrc.com/docs/setup-with-an-agent","mdUrl":"https://docs.heygrc.com/docs/setup-with-an-agent.md","description":"Point your AI coding agent at the heyGRC docs to install the GitHub App, connect your org, and configure frameworks.","score":4,"snippet":", and many other frameworks. heyGRC is configured **as code** through a small REST API, so you can do the whole setup by asking your coding agent (Claude Code,"},{"title":"Console and API keys","url":"https://docs.heygrc.com/docs/console-and-api-keys","mdUrl":"https://docs.heygrc.com/docs/console-and-api-keys.md","description":"Use app.heygrc.com to manage API keys, review modes, and org settings for heyGRC.","score":1,"snippet":"I for the same control plane your agent configures via the API. ## Sign in and org Sign in at [app.heygrc.com](https://app.heygrc.com) with GitHub, Google, Mi"},{"title":"EU inference","url":"https://docs.heygrc.com/docs/eu-inference","mdUrl":"https://docs.heygrc.com/docs/eu-inference.md","description":"Optional org setting that sends heyGRC compliance reviews to Mistral on the EU regional endpoint, with no silent fallback to the default global path.","score":1,"snippet":" return to the default global path. ## Configure it as code `eu_inference` is a sticky field on `GET` / `PUT /v1/config`. Omitting it on `PUT` leaves the curr"},{"title":"GitHub App permissions","url":"https://docs.heygrc.com/docs/github-app-permissions","mdUrl":"https://docs.heygrc.com/docs/github-app-permissions.md","description":"What the heyGRC GitHub App can read and write, and what it never does to your source.","score":1,"snippet":"and read the optional `.heygrc.md` repo config | | **Metadata** | Read-only (mandatory) | Repository and installation metadata | | **Checks** | Read and write |"},{"title":"Overview","url":"https://docs.heygrc.com/docs","mdUrl":"https://docs.heygrc.com/docs.md","description":"heyGRC reviews every pull request against your compliance frameworks and posts control-grounded findings as a GitHub check.","score":1,"snippet":"s you choose to require the check. You configure company context and frameworks **as code** through a small REST API (or the console). Your coding agent can do"},{"title":"Pricing and plans","url":"https://docs.heygrc.com/docs/pricing-and-plans","mdUrl":"https://docs.heygrc.com/docs/pricing-and-plans.md","description":"heyGRC Free, Starter, Pro, and Business plans. Included private reviews hard-stop unless you enable on-demand at $0.49 each. Public repos always free.","score":1,"snippet":"me product surface as paid: frameworks, config API, PR reviews If Free private reviews are exhausted for the month, upgrade or wait for the next month. Public-"}],"note":"English public docs only. Prefer hit.mdUrl for clean body text."}