---
title: "List platform breach records"
description: "\n\n### Quire permissions\n\nRequired capability: `platform/breaches_view`.\n\nCredential scopes: `privacy:read`.\n\nThe acting subject must also be allowed to perform this action in the organisation."
image: "https://docs.quirelms.com/og.png"
---

> Documentation Index
> Fetch the complete documentation index at: https://docs.quirelms.com/llms.txt
> Use this file to discover all available pages before exploring further.

Path: Quire API › privacy

`GET /platform/breaches`

\### Quire permissions

Required capability: `platform/breaches_view`.

Credential scopes: `privacy:read`.

The acting subject must also be allowed to perform this action in the organisation.

## Authentication

Requires one of the following:

- `apiKey`, http, header `Authorization`, scopes: `privacy:read`
- `oauth2`, oauth2, scopes: `privacy:read`

## Header parameters

- `listPlatformBreaches.header.Quire-Version` (string, optional) — The dated API revision to serve this request at. Omitted, the request is served at the revision the credential was issued against. The response echoes the revision actually applied.
  - format `date`

## Code samples

### cURL

```curl
curl --request GET \
  --url https://your-organisation.quirelms.com/api/v1/platform/breaches \
  --header 'Authorization: Bearer <token>'
```

### TypeScript

```typescript
const url = 'https://your-organisation.quirelms.com/api/v1/platform/breaches';
const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};

fetch(url, options)
  .then(res => res.json())
  .then(json => console.log(json))
  .catch(err => console.error(err));
```

### Python

```python
import requests

url = "https://your-organisation.quirelms.com/api/v1/platform/breaches"

headers = {"Authorization": "Bearer <token>"}

response = requests.get(url, headers=headers)

print(response.text)
```

## Responses

### 200

Success.

#### Example

```json
{
  "data": [
    {
      "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
      "reference": "string",
      "quire_role": "controller",
      "detected_at": "2019-08-24T14:15:22Z",
      "became_aware_at": "2019-08-24T14:15:22Z",
      "awareness_note": "string",
      "occurred_from": "2019-08-24T14:15:22Z",
      "occurred_to": "2019-08-24T14:15:22Z",
      "nature": "confidentiality",
      "nature_detail": "string",
      "data_categories": [
        "string"
      ],
      "subjects_estimate": 9007199254740991,
      "records_estimate": 9007199254740991,
      "severity": "low",
      "risk_assessment": "string",
      "containment": "string",
      "authority_required": true,
      "authority_rationale": "string",
      "authority_name": "string",
      "authority_due_at": "2019-08-24T14:15:22Z",
      "authority_notified_at": "2019-08-24T14:15:22Z",
      "authority_reference": "string",
      "authority_delay_reason": "string",
      "subjects_required": true,
      "subjects_rationale": "string",
      "subjects_method": "string",
      "subjects_notified_at": "2019-08-24T14:15:22Z",
      "status": "open",
      "escalation_stage": -9007199254740991,
      "closed_at": "2019-08-24T14:15:22Z",
      "hours_since_awareness": -9007199254740991,
      "authority_overdue": true,
      "tenants": [
        {
          "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",
          "tenant_name": "string",
          "notified_at": "2019-08-24T14:15:22Z",
          "acknowledged_at": "2019-08-24T14:15:22Z",
          "tenant_decision": "string"
        }
      ],
      "timeline": [
        {
          "at": "2019-08-24T14:15:22Z",
          "action": "string",
          "note": "string"
        }
      ]
    }
  ]
}
```

- `listPlatformBreaches.response.200.data` (array<object>, required)
  - `listPlatformBreaches.response.200.data.id` (string, required)
    - format `uuid`; pattern `^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$`
  - `listPlatformBreaches.response.200.data.reference` (string, required)
  - `listPlatformBreaches.response.200.data.quire_role` (string, required)
    - one of `"controller"`, `"processor"`
  - `listPlatformBreaches.response.200.data.detected_at` (string, required)
    - format `date-time`; pattern `^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d+)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$`
  - `listPlatformBreaches.response.200.data.became_aware_at` (string, required)
    - format `date-time`; pattern `^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d+)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$`
  - `listPlatformBreaches.response.200.data.awareness_note` (string | null, required)
  - `listPlatformBreaches.response.200.data.occurred_from` (any of, required)
    - any of: `string`, `null`
  - `listPlatformBreaches.response.200.data.occurred_to` (any of, required)
    - any of: `string`, `null`
  - `listPlatformBreaches.response.200.data.nature` (string, required)
    - one of `"confidentiality"`, `"integrity"`, `"availability"`
  - `listPlatformBreaches.response.200.data.nature_detail` (string, required)
  - `listPlatformBreaches.response.200.data.data_categories` (array<string>, required)
  - `listPlatformBreaches.response.200.data.subjects_estimate` (any of, required)
    - any of: `integer`, `null`
  - `listPlatformBreaches.response.200.data.records_estimate` (any of, required)
    - any of: `integer`, `null`
  - `listPlatformBreaches.response.200.data.severity` (string, required)
    - one of `"low"`, `"medium"`, `"high"`, `"critical"`
  - `listPlatformBreaches.response.200.data.risk_assessment` (string, required)
  - `listPlatformBreaches.response.200.data.containment` (string | null, required)
  - `listPlatformBreaches.response.200.data.authority_required` (boolean | null, required)
  - `listPlatformBreaches.response.200.data.authority_rationale` (string | null, required)
  - `listPlatformBreaches.response.200.data.authority_name` (string | null, required)
  - `listPlatformBreaches.response.200.data.authority_due_at` (string, required)
    - format `date-time`; pattern `^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d+)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$`
  - `listPlatformBreaches.response.200.data.authority_notified_at` (any of, required)
    - any of: `string`, `null`
  - `listPlatformBreaches.response.200.data.authority_reference` (string | null, required)
  - `listPlatformBreaches.response.200.data.authority_delay_reason` (string | null, required)
  - `listPlatformBreaches.response.200.data.subjects_required` (boolean | null, required)
  - `listPlatformBreaches.response.200.data.subjects_rationale` (string, required)
  - `listPlatformBreaches.response.200.data.subjects_method` (string | null, required)
  - `listPlatformBreaches.response.200.data.subjects_notified_at` (any of, required)
    - any of: `string`, `null`
  - `listPlatformBreaches.response.200.data.status` (string, required)
    - one of `"open"`, `"assessing"`, `"notified"`, `"closed"`
  - `listPlatformBreaches.response.200.data.escalation_stage` (integer, required)
    - min -9007199254740991; max 9007199254740991
  - `listPlatformBreaches.response.200.data.closed_at` (any of, required)
    - any of: `string`, `null`
  - `listPlatformBreaches.response.200.data.hours_since_awareness` (integer, required)
    - min -9007199254740991; max 9007199254740991
  - `listPlatformBreaches.response.200.data.authority_overdue` (boolean, required)
  - `listPlatformBreaches.response.200.data.tenants` (array<object>, required)
    - `listPlatformBreaches.response.200.data.tenants.tenant_id` (string, required)
      - format `uuid`; pattern `^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$`
    - `listPlatformBreaches.response.200.data.tenants.tenant_name` (string, required)
    - `listPlatformBreaches.response.200.data.tenants.notified_at` (any of, required)
      - any of: `string`, `null`
    - `listPlatformBreaches.response.200.data.tenants.acknowledged_at` (any of, required)
      - any of: `string`, `null`
    - `listPlatformBreaches.response.200.data.tenants.tenant_decision` (string | null, required)
  - `listPlatformBreaches.response.200.data.timeline` (array<object>, required)
    - `listPlatformBreaches.response.200.data.timeline.at` (string, required)
      - format `date-time`; pattern `^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d+)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$`
    - `listPlatformBreaches.response.200.data.timeline.action` (string, required)
    - `listPlatformBreaches.response.200.data.timeline.note` (string | null, required)

### 401

The credential is missing, malformed, expired or revoked.

#### Example

```json
{
  "type": "http://example.com",
  "title": "string",
  "status": 0,
  "code": "string",
  "category": "validation",
  "detail": "string",
  "request_id": "string",
  "errors": [
    {
      "path": "string",
      "code": "string",
      "detail": "string"
    }
  ],
  "retry_after": 0,
  "docs_url": "http://example.com"
}
```

- `listPlatformBreaches.response.401.type` (string, required)
  - format `uri`
- `listPlatformBreaches.response.401.title` (string, required)
- `listPlatformBreaches.response.401.status` (integer, required)
- `listPlatformBreaches.response.401.code` (string, required)
- `listPlatformBreaches.response.401.category` (string, required)
  - one of `"validation"`, `"authentication"`, `"authorization"`, `"not_found"`, `"conflict"`, `"precondition"`, `"quota"`, `"rate_limit"`, `"upstream"`, `"internal"`
- `listPlatformBreaches.response.401.detail` (string, required)
- `listPlatformBreaches.response.401.request_id` (string, required)
- `listPlatformBreaches.response.401.docs_url` (string, required)
  - format `uri`
- `listPlatformBreaches.response.401.errors` (array<object>, optional)
  - `listPlatformBreaches.response.401.errors.path` (string, required) — RFC 6901 JSON Pointer into the request body.
  - `listPlatformBreaches.response.401.errors.code` (string, required)
  - `listPlatformBreaches.response.401.errors.detail` (string, required)
- `listPlatformBreaches.response.401.retry_after` (integer | null, optional)

### 403

The credential lacks the scope this operation requires, or the acting subject lacks the capability.

#### Example

```json
{
  "type": "http://example.com",
  "title": "string",
  "status": 0,
  "code": "string",
  "category": "validation",
  "detail": "string",
  "request_id": "string",
  "errors": [
    {
      "path": "string",
      "code": "string",
      "detail": "string"
    }
  ],
  "retry_after": 0,
  "docs_url": "http://example.com"
}
```

- `listPlatformBreaches.response.403.type` (string, required)
  - format `uri`
- `listPlatformBreaches.response.403.title` (string, required)
- `listPlatformBreaches.response.403.status` (integer, required)
- `listPlatformBreaches.response.403.code` (string, required)
- `listPlatformBreaches.response.403.category` (string, required)
  - one of `"validation"`, `"authentication"`, `"authorization"`, `"not_found"`, `"conflict"`, `"precondition"`, `"quota"`, `"rate_limit"`, `"upstream"`, `"internal"`
- `listPlatformBreaches.response.403.detail` (string, required)
- `listPlatformBreaches.response.403.request_id` (string, required)
- `listPlatformBreaches.response.403.docs_url` (string, required)
  - format `uri`
- `listPlatformBreaches.response.403.errors` (array<object>, optional)
  - `listPlatformBreaches.response.403.errors.path` (string, required) — RFC 6901 JSON Pointer into the request body.
  - `listPlatformBreaches.response.403.errors.code` (string, required)
  - `listPlatformBreaches.response.403.errors.detail` (string, required)
- `listPlatformBreaches.response.403.retry_after` (integer | null, optional)

### 422

The request was understood and its content is not valid. `errors` names each field.

#### Example

```json
{
  "type": "http://example.com",
  "title": "string",
  "status": 0,
  "code": "string",
  "category": "validation",
  "detail": "string",
  "request_id": "string",
  "errors": [
    {
      "path": "string",
      "code": "string",
      "detail": "string"
    }
  ],
  "retry_after": 0,
  "docs_url": "http://example.com"
}
```

- `listPlatformBreaches.response.422.type` (string, required)
  - format `uri`
- `listPlatformBreaches.response.422.title` (string, required)
- `listPlatformBreaches.response.422.status` (integer, required)
- `listPlatformBreaches.response.422.code` (string, required)
- `listPlatformBreaches.response.422.category` (string, required)
  - one of `"validation"`, `"authentication"`, `"authorization"`, `"not_found"`, `"conflict"`, `"precondition"`, `"quota"`, `"rate_limit"`, `"upstream"`, `"internal"`
- `listPlatformBreaches.response.422.detail` (string, required)
- `listPlatformBreaches.response.422.request_id` (string, required)
- `listPlatformBreaches.response.422.docs_url` (string, required)
  - format `uri`
- `listPlatformBreaches.response.422.errors` (array<object>, optional)
  - `listPlatformBreaches.response.422.errors.path` (string, required) — RFC 6901 JSON Pointer into the request body.
  - `listPlatformBreaches.response.422.errors.code` (string, required)
  - `listPlatformBreaches.response.422.errors.detail` (string, required)
- `listPlatformBreaches.response.422.retry_after` (integer | null, optional)

### 429

A rate limit or a concurrency cap was reached. `Retry-After` says when to try again.

#### Example

```json
{
  "type": "http://example.com",
  "title": "string",
  "status": 0,
  "code": "string",
  "category": "validation",
  "detail": "string",
  "request_id": "string",
  "errors": [
    {
      "path": "string",
      "code": "string",
      "detail": "string"
    }
  ],
  "retry_after": 0,
  "docs_url": "http://example.com"
}
```

- `listPlatformBreaches.response.429.type` (string, required)
  - format `uri`
- `listPlatformBreaches.response.429.title` (string, required)
- `listPlatformBreaches.response.429.status` (integer, required)
- `listPlatformBreaches.response.429.code` (string, required)
- `listPlatformBreaches.response.429.category` (string, required)
  - one of `"validation"`, `"authentication"`, `"authorization"`, `"not_found"`, `"conflict"`, `"precondition"`, `"quota"`, `"rate_limit"`, `"upstream"`, `"internal"`
- `listPlatformBreaches.response.429.detail` (string, required)
- `listPlatformBreaches.response.429.request_id` (string, required)
- `listPlatformBreaches.response.429.docs_url` (string, required)
  - format `uri`
- `listPlatformBreaches.response.429.errors` (array<object>, optional)
  - `listPlatformBreaches.response.429.errors.path` (string, required) — RFC 6901 JSON Pointer into the request body.
  - `listPlatformBreaches.response.429.errors.code` (string, required)
  - `listPlatformBreaches.response.429.errors.detail` (string, required)
- `listPlatformBreaches.response.429.retry_after` (integer | null, optional)

### 500

Something failed at our end. Quote `request_id` when reporting it.

#### Example

```json
{
  "type": "http://example.com",
  "title": "string",
  "status": 0,
  "code": "string",
  "category": "validation",
  "detail": "string",
  "request_id": "string",
  "errors": [
    {
      "path": "string",
      "code": "string",
      "detail": "string"
    }
  ],
  "retry_after": 0,
  "docs_url": "http://example.com"
}
```

- `listPlatformBreaches.response.500.type` (string, required)
  - format `uri`
- `listPlatformBreaches.response.500.title` (string, required)
- `listPlatformBreaches.response.500.status` (integer, required)
- `listPlatformBreaches.response.500.code` (string, required)
- `listPlatformBreaches.response.500.category` (string, required)
  - one of `"validation"`, `"authentication"`, `"authorization"`, `"not_found"`, `"conflict"`, `"precondition"`, `"quota"`, `"rate_limit"`, `"upstream"`, `"internal"`
- `listPlatformBreaches.response.500.detail` (string, required)
- `listPlatformBreaches.response.500.request_id` (string, required)
- `listPlatformBreaches.response.500.docs_url` (string, required)
  - format `uri`
- `listPlatformBreaches.response.500.errors` (array<object>, optional)
  - `listPlatformBreaches.response.500.errors.path` (string, required) — RFC 6901 JSON Pointer into the request body.
  - `listPlatformBreaches.response.500.errors.code` (string, required)
  - `listPlatformBreaches.response.500.errors.detail` (string, required)
- `listPlatformBreaches.response.500.retry_after` (integer | null, optional)


Source: https://docs.quirelms.com/api/privacy/listPlatformBreaches/index.md
