# Digital Shadows > Digital Shadows is a London-founded digital risk protection (DRP) company whose SearchLight platform monitors the open, deep and dark web for data leakage, exposed credentials, brand impersonation, exposed infrastructure and threat-actor activity affecting a customer's organization. ReliaQuest acquired Digital Shadows in July 2022; the entity now trades as ReliaQuest UK Limited and SearchLight is delivered as ReliaQuest GreyMatter Digital Risk Protection. The SearchLight Portal API remains live, but its reference is published only inside the authenticated customer portal. Generated by API Evangelist from the public Digital Shadows surface. No /llms.txt is served by the provider on any of its hosts, so this file is generated, not harvested. ## Status of this profile - The API is real and live: `https://portal-digitalshadows.com/api/` returns a JSON 401 to anonymous callers. - There is **no public OpenAPI, Swagger, GraphQL SDL, AsyncAPI or Postman collection**. Every discovery path was probed and missed. - The API reference lives inside the portal under *Stored Objects > Portal > SearchLight API doc* and requires an active tenant. - Everything documented here is derived from Digital Shadows' own **published client source code** on GitHub and from anonymous live probes. ## APIs - [SearchLight Portal API](https://portal-digitalshadows.com/): REST API over incidents, intelligence incidents, threat records, data breaches and breach records, breach-username rollups, exposed ports, SSL issues, vulnerability exposure, DNS/WHOIS lookups, and cross-entity search. Base URL `https://portal-digitalshadows.com/api/`. ## Authentication - HTTP Basic — `Authorization: Basic base64(:)`. The key and secret are issued self-service inside the SearchLight portal. - No OAuth 2.0, no OpenID Connect, no mTLS, no scopes. - Credential check: `GET /api/session-user`. ## Conventions - Collection reads are `POST /find` with a JSON "view" body: `{filter, sort:{property,direction}, pagination:{offset,size}}`. - Offset pagination; responses carry `currentPage:{offset,size}` and `total`. Default client page size 500. - Versioning travels in a vendor media type: `application/vnd.polaris-v38+json`. - Error envelope is `{code, status, message}` (vendor JSON, not RFC 9457). Observed: `PS491` on 401. - Rate limiting: HTTP 429 on exhaustion; the provider's own client backs off 1 second and resumes the scroll. No published quota. - No idempotency contract. ## Client libraries - [shadowline](https://github.com/digitalshadows/shadowline-api): first-party Python library + CLI. Source-only (not on PyPI), version 0.0.1, last commit 2021-04-06. - [splunk-soar-digitalshadows](https://github.com/digitalshadows/splunk-soar-digitalshadows): first-party Splunk SOAR connector bundling the reusable `dsapi` client package. Repo tag 2.0.0; Splunkbase app 6008 at 2.2.4. ## Operational surfaces - Status page: https://status.digitalshadows.com/ (StatusIQ; email + RSS, no machine-readable status API) - Support contact for API auth failures: drpsupport@reliaquest.com - GitHub organization: https://github.com/digitalshadows - Privacy policy (explicitly covers Digital Shadows SearchLight): https://reliaquest.com/privacy-policy/ - Successor product page: https://reliaquest.com/solution/digital-shadows/ ## Not published - No `/.well-known/` documents on any host (security.txt, openid-configuration, oauth-authorization-server, api-catalog, ai-plugin.json, agent-card.json all miss). - No A2A agent card. No MCP server. No webhooks or event/streaming surface. - No public pricing, no published rate limits, no changelog, no deprecation policy, no trust center or certification page. - `digitalshadows.com` no longer resolves to an address. ## API Evangelist artifacts - apis.yml: https://raw.githubusercontent.com/api-evangelist/digital-shadows/refs/heads/main/apis.yml - Authentication: authentication/digital-shadows-authentication.yml - Conventions: conventions/digital-shadows-conventions.yml - Data model: data-model/digital-shadows-data-model.yml - Errors: errors/digital-shadows-problem-types.yml - Lifecycle: lifecycle/digital-shadows-lifecycle.yml - Packages: packages/digital-shadows-packages.yml - CLI: cli/digital-shadows-cli.yml - Conformance: conformance/digital-shadows-conformance.yml - Rate limits: rate-limits/digital-shadows-rate-limits.yml - Plans: plans/digital-shadows-plans-pricing.yml - Well-known probe: well-known/digital-shadows-well-known.yml - Domain security: security/digital-shadows-domain-security.yml