Reporting a vulnerability
Email security@dhstrat.com with a clear description, reproduction steps, potential impact, and contact information. Proof-of-concept material is welcome when it does not expose or modify another person’s data.
What to expect
- Acknowledgment of the report within 48 hours.
- An initial severity assessment within seven days.
- Ongoing coordination for a confirmed vulnerability.
- Coordinated disclosure after an appropriate resolution.
In scope
Vulnerabilities affecting Dark Horse-controlled web applications, APIs, authentication, authorization, session management, server-side behavior, or sensitive information are in scope.
Out of scope
- Social engineering, phishing, and physical attacks.
- Denial-of-service or resource-exhaustion testing.
- Automated scanning without prior written approval.
- Third-party systems not controlled by Dark Horse.
- Issues requiring an obsolete or unsupported browser.
Research guidelines
Do not access data that is not yours, degrade availability, establish persistence, or publicly disclose a vulnerability before it is resolved. Stop testing and report the issue if you encounter sensitive information.
Safe harbor
Dark Horse will not pursue legal action for good-faith research performed in accordance with this policy. If you are unsure whether a test is safe or in scope, contact us before proceeding.
Last updated: July 2026