Legal & Security

Vulnerability Disclosure Policy

Effective date: 23 May 2025  ·  Last updated: 23 May 2025

Legal notice This policy describes how RDD Labs Ltd. ("we", "us", "RDD Labs") handles good-faith security research. It does not create a contract, employment relationship, or compensation obligation of any kind. Nothing in this policy limits or waives any right or remedy available to RDD Labs under applicable law except as expressly stated in Section 6 (Safe Harbor). This policy is governed by the laws of the State of Israel.
1 Introduction

RDD Labs is a two-person hybrid-casual mobile game studio based in Israel. We take the security of our products and our users' data seriously. We welcome responsible disclosure of security vulnerabilities from the security research community.

This Vulnerability Disclosure Policy (VDP) explains which of our systems are in scope, how to report a vulnerability, what you can expect from us, and the protections we extend to researchers who act in good faith.

2 Scope

The following systems and assets are in scope for security research under this policy:

rdd-labs.com rdd-labs.com/colordrain Color Drain mobile app (iOS & Android, when publicly released) Any API endpoints hosted under rdd-labs.com

The following are out of scope. Testing or research targeting these will not be covered by this policy or the safe harbor in Section 6:

Social engineering or phishing of RDD Labs personnel Denial of service (DoS / DDoS) attacks of any kind Physical security of our devices or premises Third-party infrastructure we do not control (Cloudflare, Apple, Google, Unity, etc.) Any system or domain not listed as in scope above
3 How to Report

If you believe you have discovered a security vulnerability in an in-scope system, please email us at:

Send a clear description of the vulnerability, including:

  • The affected system or URL
  • A description of the vulnerability and its potential impact
  • Step-by-step instructions to reproduce the issue
  • Any supporting evidence (screenshots, HTTP request/response logs, proof-of-concept code)

support@rdd-labs.com

Please write your report in English. Do not submit vulnerability reports through public issue trackers, social media, or any channel other than the email above.

4 What to Expect From Us

We are a small team. We will make a genuine, best-effort attempt to:

We do not commit to specific response or remediation timelines. We do not operate a paid bug bounty programme and make no commitment to financial compensation of any kind for vulnerability reports.

5 Researcher Guidelines

To qualify for the safe harbor in Section 6, your research must comply with all of the following:

6 Safe Harbor

If you discover and report a security vulnerability strictly in accordance with this policy and all guidelines in Section 5, RDD Labs commits to the following:

Our commitment to good-faith researchers

We will not initiate civil legal proceedings against you solely for security research activities conducted in compliance with this policy.

We will not file or support a criminal complaint against you solely for security research activities conducted in compliance with this policy.

We will treat your research as authorised under this policy and will communicate that to relevant authorities if asked.

This safe harbor is strictly conditional. It applies only to research that fully complies with Section 5. It does not apply to any activity that is out of scope, causes actual harm, involves exploitation of vulnerabilities for personal or third-party gain, or violates applicable law in any way that goes beyond what is strictly necessary to identify and report the vulnerability. RDD Labs retains all rights and remedies under applicable law with respect to any non-compliant activity.

This safe harbor is personal to the individual researcher and is not transferable. It does not constitute a waiver of any rights with respect to third parties.

7 Policy Updates

We may update this policy at any time by posting a revised version at rdd-labs.com/security. The updated policy will take effect immediately upon posting. We encourage you to review this page before conducting any security research.

Questions about this policy may be directed to support@rdd-labs.com.