Security Disclosure

Daktronics is committed to maintaining the security and resilience of our products, services, and digital platforms. We value the collaboration of security researchers and responsible members of the cybersecurity community who help us identify and address potential vulnerabilities. If you believe you have discovered a security issue affecting a Daktronics product, service, or website, we encourage you to report it through the process outlined below.

ATTENTION: If you are experiencing an active exploit, please call Daktronics

Contact Us


Product Vulnerabilities

Report a vulnerability specific to a Daktronics product with our Vulnerability Reporting Form or email us at SSIRT@Daktronics.com**.

Learn more about our Vulnerability Disclosure Policy.

Non-product Vulnerabilities

Report any other (non-product) vulnerability involving Daktronics (i.e. vulnerabilities affecting Daktronics.com)

Submit a Non-Product Related Vulnerability by emailing ITSecurity@daktronics.com.

**Daktronics does not support PGP-encrypted email communications. Please do not include sensitive or confidential information in your vulnerability report or email correspondence. If your report contains sensitive information, indicate this in your submission, and a Daktronics representative will contact you to establish a secure method for information sharing.

Responsible Disclosure Program Guidelines

Daktronics is committed to the principles of Coordinated Vulnerability Disclosure (CVD). When we receive a report of a potential security vulnerability, our Solution Security Incident Response Team (SSIRT) works to promptly investigate, validate, and address the issue. When appropriate, we develop and make security updates, mitigations, or guidance available to affected customers to help protect their systems and operations.

We value the partnership of the security reporting community and ask that potential vulnerabilities be reported privately to Daktronics. By providing us a reasonable opportunity to investigate and remediate vulnerabilities before public disclosure, reporters help us better protect our customers, products, services, and infrastructure.

Please review and follow the guidelines below when submitting a vulnerability report:

Rules of Engagement

Reporting Parties Must:

  • Make every effort to avoid impacting product availability.

  • Test only what is necessary to confirm the existence of a vulnerability.

  • Immediately stop testing if sensitive customer information is encountered.

  • Report vulnerabilities promptly.

  • Maintain confidentiality until coordinated disclosure has been completed.

Reporting Parties Must NOT:

  • Access, modify, or delete data for which you are not authorized.

  • Access or modify equipment for which you are not authorized.

  • Attempt denial-of-service testing.

  • Conduct physical intrusion activities.

  • Use social engineering, phishing, or impersonation techniques.

  • Install malware or persistent software.

  • Exploit vulnerabilities beyond what is required for verification.

  • Publicly disclose vulnerabilities before coordination with Daktronics.

Accepted Web Vulnerabilities:

  • OWASP Top 10 vulnerability categories

  • Other vulnerabilities with demonstrated impact

Out of Scope Web Vulnerabilities:

  • Theoretical vulnerabilities

  • Self XSS (user defined payload)

Out of Scope Activities

  • Physical security testing

  • Disclosure of previously known vulnerabilities without additional findings

  • Findings that require unrealistic attack preconditions

  • Vulnerabilities in third-party products not controlled by Daktronics

Reporters should report third-party vulnerabilities directly to the appropriate vendor.

Daktronics currently does not offer financial compensation or bug bounty rewards.