---
title: "Upload compliance certificate"
method: POST
path: "/v1/trust-portal/compliance-resources/upload"
tags: ["Trust Portal"]
---

# Upload compliance certificate

`POST /v1/trust-portal/compliance-resources/upload`

Upload or replace a compliance certificate PDF such as SOC 2, ISO 27001, HIPAA, or GDPR evidence for Trust Center sharing.

## Request body

- UploadComplianceResourceDto
  - `organizationId` string, required — Organization ID that owns the compliance resource
  - `framework` 'iso_27001' | 'iso_42001' | 'gdpr' | 'hipaa' | 'soc2_type1' | 'soc2_type2' | 'soc3' | 'pci_dss' | 'nen_7510' | 'iso_9001' | 'pipeda' | 'ccpa', required — Compliance framework identifier
  - `fileName` string, required — Original file name (PDF only)
  - `fileType` string, required — MIME type of the file
  - `fileData` string, required — Base64 encoded PDF content

## Response `201`

Compliance certificate uploaded successfully

- ComplianceResourceResponseDto
  - `framework` 'iso_27001' | 'iso_42001' | 'gdpr' | 'hipaa' | 'soc2_type1' | 'soc2_type2' | 'soc3' | 'pci_dss' | 'nen_7510' | 'iso_9001' | 'pipeda' | 'ccpa', required
  - `fileName` string, required
  - `fileSize` number, required — File size in bytes
  - `updatedAt` string, required — ISO timestamp when the certificate was last updated

## Other responses

- `400` — Framework not compliant, PDF validation failed, or organization mismatch

## Changes

- **2026-05-08** `4c7c42b20b90` — 2 warning, 2 info
  - added the new `ccpa` enum value to the `framework` response property for the response status `201`
  - added the new `pipeda` enum value to the `framework` response property for the response status `201`
  - added the new `ccpa` enum value to the request property `framework`
  - added the new `pipeda` enum value to the request property `framework`
- **2026-04-29** `ef13f9ae48ef` — 1 warning, 1 info
  - added the new `soc3` enum value to the `framework` response property for the response status `201`
  - added the new `soc3` enum value to the request property `framework`
- **2026-04-29** `36253e8a5c1b` — 1 breaking, 1 info
  - removed the enum value `soc3` of the request property `framework`
  - removed the `soc3` enum value from the `framework` response property for the response status `201`
- **2026-04-29** `2dadf65e24a1` — 1 warning, 1 info
  - added the new `soc3` enum value to the `framework` response property for the response status `201`
  - added the new `soc3` enum value to the request property `framework`
- **2026-03-05** `946edaa856a9` — 1 warning
  - deleted the `header` request parameter `X-Organization-Id`

[Change history](https://skmtc.dev/om-network/apis/betayum-api/changes/v1/trust-portal/compliance-resources/upload/post.md)

---

[API](https://skmtc.dev/om-network/apis/betayum-api.md) · [All operations](https://skmtc.dev/om-network/apis/betayum-api/llms.txt) · [OpenAPI document](https://skmtc.dev/om-network/apis/betayum-api/revisions/95679a9aa625?raw)
