Skip to main content

Policy

Security and responsible disclosure.

Dark Horse appreciates good-faith security research that helps protect its public web properties, systems, and users.

Reporting a vulnerability

Email security@dhstrat.com with a clear description, reproduction steps, potential impact, and contact information. Proof-of-concept material is welcome when it does not expose or modify another person’s data.

What to expect

  • Acknowledgment of the report within 48 hours.
  • An initial severity assessment within seven days.
  • Ongoing coordination for a confirmed vulnerability.
  • Coordinated disclosure after an appropriate resolution.

In scope

Vulnerabilities affecting Dark Horse-controlled web applications, APIs, authentication, authorization, session management, server-side behavior, or sensitive information are in scope.

Out of scope

  • Social engineering, phishing, and physical attacks.
  • Denial-of-service or resource-exhaustion testing.
  • Automated scanning without prior written approval.
  • Third-party systems not controlled by Dark Horse.
  • Issues requiring an obsolete or unsupported browser.

Research guidelines

Do not access data that is not yours, degrade availability, establish persistence, or publicly disclose a vulnerability before it is resolved. Stop testing and report the issue if you encounter sensitive information.

Safe harbor

Dark Horse will not pursue legal action for good-faith research performed in accordance with this policy. If you are unsure whether a test is safe or in scope, contact us before proceeding.

Last updated: July 2026