generated: '2026-08-22' method: searched source: https://www.horizon.auto/en/legal/security name: Horizon Robotics Product Security / Vulnerability Disclosure Policy published: true program_type: coordinated-disclosure # no bug bounty; no HackerOne/Bugcrowd/Intigriti program found bounty: false contact: email: report_vulnerability@horizon.auto encryption: pgp_advertised: true pgp_key_url: null note: >- The policy tells reporters to encrypt with Horizon Robotics' public PGP key and renders the literal placeholders "[pgp-public-key.asc]" and "(insert key link)". No .asc file is actually linked or served — probed https://www.horizon.auto/pgp-public-key.asc (404) and https://www.horizon.auto/en/legal/pgp-public-key.asc (404). An encrypted report cannot currently be sent as instructed. security_txt: served: false probed: - url: https://www.horizon.auto/.well-known/security.txt status: 404 - url: https://developer.horizon.auto/.well-known/security.txt status: 200 note: SPA catch-all HTML shell, not an RFC 9116 document report_requirements: - affected product or driver, including version or release - vulnerability type (code execution, denial of service, buffer overflow, ...) - steps to reproduce - proof of concept or exploit code - potential impact and how an attacker could exploit it scope: products: - Horizon Journey™ Series / Journey™ 6 Series - Horizon Mono™ - Horizon SuperDrive™ - Horizon OpenExplorer™ - Horizon Matrix™ - Horizon QoHo™ - Horizon AIDI™ - Horizon TogetheROS™ - BPU™ websites: - https://www.horizon.auto - https://www.horizon.auto/en - https://auto-developer.horizon.cc repositories: - https://github.com/HorizonRDK - https://github.com/HorizonRobotics-Platform gaps: - >- The in-scope website https://auto-developer.horizon.cc now 301s to https://developer.horizon.auto/, which is not itself named in the policy. - >- The two in-scope GitHub orgs are HorizonRDK (renamed to D-Robotics, the 2024 spin-off) and HorizonRobotics-Platform (0 public repos). The active github.com/HorizonRobotics org — 44 public repos including OE-Skills — is not listed in scope. - >- The hosted MCP server at https://mcp.oe.horizon.auto/mcp is not named in scope, even though it is an anonymously reachable production endpoint. prohibited: - social engineering, credential phishing, cookie theft - resource exhaustion (SMS/email bombing over 1,000 messages) - downloading or accessing internal materials, source code or non-public data - denial-of-service attacks against web services - internal network penetration, lateral movement, backdoor implantation - unauthorized access to internal servers (OA, internal Git) - supply chain attacks via distributors or partners disclosure: advisories_published: true advisory_contents: - affected products and versions - Horizon Robotics vulnerability identifier - description and potential impact - CVSS severity rating (https://www.first.org/cvss/user-guide.html) - remediation details / mitigations - reporter acknowledgement advisory_feed_url: null note: >- The policy commits to publishing security advisories but names no advisory index, RSS feed, CVE namespace or CNA registration; none was found on the site. timelines: in_vehicle_report_window_hours: 168 in_vehicle_report_window_note: Vulnerabilities affecting in-vehicle functions must be reported within 168 hours (7 days) of identification. vendor_response_sla: null safe_harbor: offered: true text: >- Horizon Robotics will not initiate legal action or request law enforcement investigation of reporters who follow the stated responsible-disclosure guidelines, subject to applicable national law. certifications_named: [] x-evidence: fetched: '2026-08-22' urls: - url: https://www.horizon.auto/en/legal/security status: 200 - url: https://www.horizon.auto/legal/security status: 200 - url: https://www.horizon.auto/pgp-public-key.asc status: 404 - url: https://www.horizon.auto/en/legal/pgp-public-key.asc status: 404 - url: https://www.horizon.auto/.well-known/security.txt status: 404