generated: '2026-08-04' method: searched probe: true source: >- live probes of /.well-known/security.txt and the disclosure paths on every Dream Sports host, plus SECURITY.md across the dream-horizon-org repositories policy: - https://github.com/dream-horizon-org/logwise/blob/master/SECURITY.md contact: - kind: email published_at: https://github.com/dream-horizon-org/logwise/blob/master/SECURITY.md note: >- A named individual's @dream11.com address is published in that SECURITY.md. It is deliberately not copied into this artifact — see the enrichment PII guardrail. Read it from the source URL. program: bug_bounty: false platforms_checked: [hackerone.com/dream11, bugcrowd.com/dream11] platforms_result: both HTTP 404 — no public program on either platform rewards: none published safe_harbor: not stated acknowledgement_target: within 24 hours (stated in the logwise SECURITY.md) encrypted_channel: PGP key available on request process: - Report privately by email; do not open a public issue. - Include affected version/commit, reproduction steps or PoC, impact assessment and mitigations. - Dream Sports validates, provides status updates, prioritizes the fix, and notes it in release notes. coverage_gap: >- Exactly one of the 108 public dream-horizon-org repositories publishes a SECURITY.md (logwise). Guardian — the authentication and authorization platform, the single repository where a disclosure route matters most — publishes CONTRIBUTING.md and a MIT license but no security policy. Checkmate, Delivr, Odin, DataGen and odin-mcp publish none either. consumer_program: name: Dream11 Responsible Vulnerability Disclosure Program (RVDP) url: https://www.dream11.com/security/rvdp status: unreachable-at-probe-time observed_http_status: 502 note: >- Dream11 publishes an RVDP covering www.dream11.com and its mobile apps; the page is indexed and titled "RVDP". Every attempt during this pass (four requests, two path variants, browser user-agent) returned HTTP 502 with Dream11's "Server down!" interstitial, so the policy text could not be captured. Recorded as a known-but-unverified policy URL rather than as a confirmed hit. evidence: - source: https://raw.githubusercontent.com/dream-horizon-org/logwise/HEAD/SECURITY.md kind: security-policy http_status: 200 fetched: '2026-08-04' - source: https://www.dream11.com/security/rvdp kind: disclosure-page http_status: 502 fetched: '2026-08-04' - source: https://api.dream11.com/.well-known/security.txt kind: security.txt http_status: 418 fetched: '2026-08-04' - source: https://www.dreamsports.group/.well-known/security.txt kind: security.txt http_status: 404 fetched: '2026-08-04' - source: https://hackerone.com/dream11 kind: bug-bounty http_status: 404 fetched: '2026-08-04' - source: https://bugcrowd.com/dream11 kind: bug-bounty http_status: 404 fetched: '2026-08-04'