Security

Security is part of the mission system

Darkstar treats security, capture denial, auditability, and human authorization as core operating requirements rather than after-market controls.

Security overview

Darkstar systems are designed for contested environments where RF is denied, hardware may be captured, and every decision must be explainable after the mission. This public page summarizes our website and product security posture at a high level.

Report a vulnerability

Send security reports to security@darkstarinc.com. Include affected URL or component, reproduction steps, impact, and contact information for follow-up.

Safe harbor

Good-faith research that avoids privacy harm, service disruption, data destruction, and unauthorized persistence will be reviewed constructively. Do not test live operational systems without written authorization.

Response process

We triage reports, validate impact, prioritize remediation, and coordinate disclosure timing when appropriate. Critical issues affecting safety, authorization, or data exposure receive priority handling.

Assurance posture

Human authorizationEngagement decisions require human authorization; recommendations and evidence traces are separate from final authority.
Capture denialCaptured hardware is designed to reveal no model, no mission data, and no coordination keys.
Deterministic replayMission behavior can be recorded, replayed, branched, diffed, and audited.
Enclave boundariesOperational materials, demos, and procurement data are separated by authorization context and need-to-know access.
Website securityPublic web properties use security headers, static builds, dependency checks, and minimal data collection.

Do not submit classified data

Public website channels are not approved for classified, controlled, mission-sensitive, or export-restricted submissions. Contact us first to establish an approved process.

Operational testing

Testing against drones, enclaves, field systems, or simulation infrastructure requires written authorization, scoped rules of engagement, and designated safety contacts.