> ## Documentation Index
> Fetch the complete documentation index at: https://docs.valiqor.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Run Security Audit

> Run security audit on a dataset

Evaluates each item in the dataset for safety violations (S1-S23).
Creates a batch with all items and returns aggregate statistics.

**Request Body:**
```json
{
  "project_id": "uuid",
  "dataset": [
    {
      "input": "User prompt",
      "output": "Model response"
    }
  ],
  "batch_name": "Optional batch name",
  "config": {
    "check_categories": ["S1", "S2", "S3"]
  }
}
```



## OpenAPI

````yaml openapi.json post /v2/security/audit
openapi: 3.1.0
info:
  title: Valiqor API
  description: >-
    The Valiqor API provides programmatic access to AI application testing,
    evaluation, failure analysis, and security auditing.


    ## Authentication


    All API requests require an API key passed as a Bearer token in the
    `Authorization` header:


    ```

    Authorization: Bearer vq-xxxxxxxxxxxxxxxxxxxx

    ```


    Get your API key from the [Valiqor Dashboard](https://app.valiqor.com) or
    via `valiqor login` CLI command.


    ## Base URL


    ```

    https://api.valiqor.com

    ```
  version: 2.0.0
  contact:
    name: Valiqor Support
    url: https://valiqor.com
    email: support@valiqor.com
servers:
  - url: https://api.valiqor.com
    description: Production
security: []
tags:
  - name: Authentication
    description: >-
      API key validation, user management, device authorization flow, and CLI
      authentication. All SDK requests require a valid API key passed as a
      Bearer token.
  - name: Evaluation
    description: >-
      Run quality evaluations on datasets or traces. Compute metrics like
      faithfulness, relevance, coherence, and more. Compare runs and track
      trends over time.
  - name: Security
    description: >-
      Security audits (S1-S23 safety categories) and red team simulations.
      Detect prompt injection, harmful content, data leakage, and other
      vulnerabilities.
  - name: Failure Analysis
    description: >-
      Analyze AI app failures with root cause detection, severity scoring, and
      actionable fix suggestions. Supports both trace-based (full) and
      dataset-based (minimal) analysis modes.
  - name: Tracing
    description: >-
      Upload and query execution traces from AI applications. Traces capture
      messages, spans, tool calls, retrievals, and LLM interactions for
      debugging and evaluation.
  - name: Scanner
    description: >-
      Upload code scans to detect AI app features, workflows, and prompts.
      Generates evaluation configurations automatically from your codebase.
  - name: Projects
    description: >-
      Create and manage projects. Projects are containers that organize
      evaluation runs, security audits, traces, and failure analysis results.
paths:
  /v2/security/audit:
    post:
      tags:
        - Security
      summary: Run Security Audit
      description: |-
        Run security audit on a dataset

        Evaluates each item in the dataset for safety violations (S1-S23).
        Creates a batch with all items and returns aggregate statistics.

        **Request Body:**
        ```json
        {
          "project_id": "uuid",
          "dataset": [
            {
              "input": "User prompt",
              "output": "Model response"
            }
          ],
          "batch_name": "Optional batch name",
          "config": {
            "check_categories": ["S1", "S2", "S3"]
          }
        }
        ```
      operationId: run_security_audit_v2_security_audit
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SecurityAuditRequest'
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema: {}
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
      security:
        - APIKeyAuth: []
components:
  schemas:
    SecurityAuditRequest:
      properties:
        project_name:
          type: string
          title: Project Name
          description: Project name (will be created if doesn't exist)
        dataset:
          items:
            additionalProperties: true
            type: object
          type: array
          title: Dataset
          description: Dataset items with input/output
        batch_name:
          anyOf:
            - type: string
            - type: 'null'
          title: Batch Name
          description: Optional batch name
        config:
          anyOf:
            - additionalProperties: true
              type: object
            - type: 'null'
          title: Config
          description: Optional configuration
        openai_api_key:
          anyOf:
            - type: string
            - type: 'null'
          title: Openai Api Key
          description: Optional OpenAI key override
      type: object
      required:
        - project_name
        - dataset
      title: SecurityAuditRequest
      description: Request to run security audit
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError
  securitySchemes:
    APIKeyAuth:
      type: http
      scheme: bearer
      description: >-
        Valiqor API key. Pass as Bearer token: `Authorization: Bearer
        vq-xxxxxxxxxxxxxxxxxxxx`

````