generated: '2026-09-13' method: searched probe: true source: https://www.zynga.com/security/rdp name: Zynga Responsible Disclosure Program program_type: responsible-disclosure managed_platform: null bounty: false bounty_note: The published program makes no offer of monetary reward, and names no managed platform (no HackerOne, Bugcrowd or Intigriti listing was found). contact: email: whitehat@zynga.com form: https://www.zynga.com/security/rdp scope: Vulnerabilities in Zynga applications and services that could adversely affect Zynga or its players, or give an unfair advantage when abused. prohibited: - malicious destruction of data - violation of player privacy - denial-of-service or other network attacks - any activity that violates applicable law safe_harbor: none-published terms_note: The program requires reporters to keep vulnerability information strictly confidential and to grant Zynga an irrevocable, perpetual, worldwide, royalty-free license to the submission. No public disclosure timeline is stated. security_txt: served: false note: '/.well-known/security.txt returns 403 on www.zynga.com and zynga.com (the edge blocks the whole /.well-known/ prefix) and 400 on api.zynga.com. The disclosure program is published as an HTML page only.' evidence: - source: https://www.zynga.com/security/ http_status: 200 kind: security hub keywords: - responsible disclosure - security research - source: https://www.zynga.com/security/rdp http_status: 200 kind: disclosure policy fields: - contact email - scope - prohibited activity related_pages: - https://www.zynga.com/security/protecting-your-account - https://www.zynga.com/security/hacks-bots-and-cheats - https://www.zynga.com/security/frequently-asked-questions