Verify the Android release
Use only our Official Android Release page. It publishes the versioned filename, exact byte size, published SHA-256 digest, current signer fingerprint, and V1 signer fingerprint. Compare those published values independently before installing.
- Do not install a raw Gradle output, renamed mirror, or file shared through a message.
- Stop if the file digest, filename, or signer differs from the release page.
- Never disable Play Protect or ignore a harmful-app warning just to complete installation.
- V1 users should update in place; a certificate mismatch means the file is not a valid update.
Report a vulnerability
Email contact@kdramasl.sitewith “Security Report” in the subject. Include affected URL/app version, reproducible steps, impact, and a safe proof. Ask us for a secure submission channel before sending sensitive evidence; ordinary email is not end-to-end encrypted.
Safe testing rules
- Use your own account and data; do not access, change, download, or retain another person’s data.
- Do not perform denial-of-service, spam, social engineering, physical testing, or destructive actions.
- Do not publish an unpatched vulnerability or secrets before we have had a reasonable opportunity to respond.
- Stop and report immediately if testing exposes credentials, personal data, or production write access.
What to expect
We will triage good-faith reports and may request more detail. We do not currently promise a bug bounty or fixed resolution time. These rules do not authorise illegal access or activity against third-party providers.
Security controls
Depending on the platform, KDSL uses HTTPS, Firebase App Check/device attestation, restricted server credentials, signed media URLs, security headers, scoped local storage, release signing, and operational feature gates. These controls reduce risk but do not guarantee that any software or service is completely secure.