get
https://staging.ankatech.co/api/v3/admin/platform/policies/templates
Retrieves all available policy templates that can be used as
base configurations for tenant policies.
Available template types and their seeded templates. Each description below is the
template's own stored description; the authoritative set is the seeded
policy_templates catalogue returned by this endpoint.
• ALGORITHM_AVAILABILITY (29 templates): Controls which cryptographic algorithms are allowed
- DEFAULT: Default algorithm availability - all algorithms allowed (CLASSICAL + POST_QUANTUM + HYBRID)
- CLASSICAL: Classical algorithms only. Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- POST_QUANTUM: Post-quantum algorithms only. Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- NIST_APPROVED: NIST approved algorithms (FIPS + PQC finalists). Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- HIGH_SECURITY: High security algorithms (Level 3+). Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- EU_COMPLIANT: European Union compliance (ENISA recommended algorithms) - GDPR, NIS2, eIDAS 2.0. Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- CHINA_GMT_COMPLIANT: Chinese GM/T cryptographic standards (SM2, SM3, SM4) - Mandatory for China operations
- JAPAN_CRYPTREC: Japan CRYPTREC e-Government Recommended Ciphers List (May 2024 revision). Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- GLOBAL_ISO_COMPLIANT: ISO/IEC international standards for global interoperability and compliance. Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- SAUDI_NCA_COMPLIANT: Saudi Arabia NCA-NCS-1:2020 approved algorithms for critical infrastructure. Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- MALAYSIA_MYSEAL: Malaysia MySEAL 2.0 Approved Algorithms for government and critical infrastructure. Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- KOREA_KCMVP: South Korea KCMVP (KISA) plus ISO/IEC-approved algorithms for government systems. Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- US_NSA_CNSA: NSA CNSA 2.0 (Sep 2022) - explicit allow-list, currently AES-GCM-256 and AES-CCM-256 only
- PQC_TRANSITION: Classical and post-quantum for the quantum transition period - algorithms approved by NIST or ENISA, Level 3 minimum. Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- FINANCE_COMPLIANT: Financial services compliance (PCI-DSS, SOC2, ISO 27001) - algorithms approved by NIST or ISO, Level 3 minimum. Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- BSI_COMPLIANT: German BSI TR-02102-1 approved algorithms for federal contracts. Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- ETSI_QSC: ETSI TS 103 744 Quantum-Safe Cryptography for telecommunications. Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- GOST_COMPLIANT: Russian GOST algorithms plus ISO/IEC-approved international ciphers for state information systems. Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- ANSSI_COMPLIANT: French ANSSI cryptographic recommendations for defense and critical infrastructure. Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- IETF_RFC: IETF RFC standardized algorithms for Internet protocols (TLS, VPN, SSH). Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- NCSC_UK_PQC: UK NCSC PQC recommendations - NIST and ENISA aligned for government and critical infrastructure. Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- CCN_CERT_ENS: Spanish CCN-CERT / ENS compliance - ENISA and NIST aligned for critical infrastructure. Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- ACN_ITALY_PQC: Italian ACN quantum-safe cryptography - ENISA, NIST, and ISO aligned for national security. Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- BSI_HYBRID_ENFORCED: German BSI TR-02102-1 with mandatory hybrid enforcement - Level 3 minimum. Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- ANSSI_HYBRID_ENFORCED: French ANSSI with mandatory hybridization - Level 3 minimum, HKDF-SHA256 only. Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- ETSI_HYBRID_ENFORCED: ETSI TS 103 744 Quantum-Safe Hybrid Key Exchanges with CatKDF/CasKDF. Composite (hybrid) algorithms bypass these restrictions and the declared composite mode, and are admitted at create
- EU_UNIFIED_HYBRID: Broadest EU template - admits algorithms approved by BSI, ANSSI or ETSI (any one), Level 3 minimum, hybrid enforced. Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- NIST_HYBRID_OPTIONAL: NIST SP 800-227 hybrid recommended but not required. Composite (hybrid) algorithms bypass these restrictions and are admitted at create
- ENISA_RISK_BASED: ENISA risk-based approach - Hybrid recommended for high-risk systems. Composite (hybrid) algorithms bypass these restrictions and are admitted at create
• ALGORITHM_ROTATION (6 templates): Rules for algorithm transitions during key rotation
- DEFAULT: Default rotation policy - secure transitions
- NO_PQC_TO_CLASSICAL: Prevent downgrade from PQC to classical
- STRICT_SECURITY: Strict no-downgrade with same family requirement
- FLEXIBLE: Flexible transitions allowing all changes
- NIST_COMPLIANT: Requires NIST compliance throughout rotation
- SAME_FAMILY_ONLY: Only allows transitions within same algorithm family
Optionally filter by template type: ALGORITHM_AVAILABILITY or ALGORITHM_ROTATION.
Total available: 35 policy templates (29 availability + 6 rotation)
Recent Requests
Log in to see full request history
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||
Loading…