Security
Security posture, disclosure, and compliance for the Sylvia API.
Security posture
- API keys authenticate every request via the
X-API-KEYheader; keys are stored hashed. - Keys can carry an optional expiry date and a USD budget cap.
- All endpoints are read-only; there is no write or mutation surface.
- Transport is TLS-only.
Vulnerability disclosure
If you find a security issue, report it responsibly to [email protected]. We respond within 5 business days.
See also /.well-known/security.txt.
Data handling
Sylvia is a read-only passthrough for public Reddit data. See the privacy policy and terms of service.