Vulnerability Disclosure Policy
RDD Labs is a two-person hybrid-casual mobile game studio based in Israel. We take the security of our products and our users' data seriously. We welcome responsible disclosure of security vulnerabilities from the security research community.
This Vulnerability Disclosure Policy (VDP) explains which of our systems are in scope, how to report a vulnerability, what you can expect from us, and the protections we extend to researchers who act in good faith.
The following systems and assets are in scope for security research under this policy:
The following are out of scope. Testing or research targeting these will not be covered by this policy or the safe harbor in Section 6:
If you believe you have discovered a security vulnerability in an in-scope system, please email us at:
Send a clear description of the vulnerability, including:
- The affected system or URL
- A description of the vulnerability and its potential impact
- Step-by-step instructions to reproduce the issue
- Any supporting evidence (screenshots, HTTP request/response logs, proof-of-concept code)
support@rdd-labs.com
Please write your report in English. Do not submit vulnerability reports through public issue trackers, social media, or any channel other than the email above.
We are a small team. We will make a genuine, best-effort attempt to:
- Acknowledge receipt of your report as promptly as reasonably practicable
- Investigate and assess the reported vulnerability
- Keep you informed of our progress where appropriate
- Remediate confirmed vulnerabilities affecting user security
We do not commit to specific response or remediation timelines. We do not operate a paid bug bounty programme and make no commitment to financial compensation of any kind for vulnerability reports.
To qualify for the safe harbor in Section 6, your research must comply with all of the following:
- Access only what is necessary. Limit your testing to the minimum access, data, and actions required to demonstrate the vulnerability. Do not access, download, modify, or delete user data beyond what is strictly necessary to confirm the vulnerability exists.
- Do not harm users or services. Do not degrade the availability, integrity, or confidentiality of our services or any user's data. Do not execute attacks that could affect other users.
- Do not exploit the vulnerability. Do not use the vulnerability to gain unauthorised access beyond the minimum required to confirm it exists. Do not leverage it for personal gain or the gain of any third party.
- Report before disclosing. Do not publicly disclose the vulnerability or share it with any third party before we have had a reasonable opportunity to investigate and remediate it, and before we have agreed to disclosure with you.
- Do not target out-of-scope systems. Only test systems listed as in scope in Section 2.
- Comply with applicable law. Your research must comply with all laws applicable to you in your jurisdiction. This policy does not authorise any activity that is unlawful under the laws of the State of Israel or any other applicable jurisdiction.
If you discover and report a security vulnerability strictly in accordance with this policy and all guidelines in Section 5, RDD Labs commits to the following:
We will not initiate civil legal proceedings against you solely for security research activities conducted in compliance with this policy.
We will not file or support a criminal complaint against you solely for security research activities conducted in compliance with this policy.
We will treat your research as authorised under this policy and will communicate that to relevant authorities if asked.
This safe harbor is strictly conditional. It applies only to research that fully complies with Section 5. It does not apply to any activity that is out of scope, causes actual harm, involves exploitation of vulnerabilities for personal or third-party gain, or violates applicable law in any way that goes beyond what is strictly necessary to identify and report the vulnerability. RDD Labs retains all rights and remedies under applicable law with respect to any non-compliant activity.
This safe harbor is personal to the individual researcher and is not transferable. It does not constitute a waiver of any rights with respect to third parties.
We may update this policy at any time by posting a revised version at rdd-labs.com/security. The updated policy will take effect immediately upon posting. We encourage you to review this page before conducting any security research.
Questions about this policy may be directed to support@rdd-labs.com.