replyk.io

Security Policy

Effective date: October 7, 2026 · Replyk, VERSAAS LLC

Table of Contents

1. How to Report

If you find a security vulnerability in Replyk, email contact@replyk.io with the subject "Security report". You can write in English, Arabic or French. Please include:

  • What the vulnerability is and where it is (URL, endpoint or app screen)
  • Steps to reproduce it
  • What an attacker could do with it
  • How we can reach you

2. Scope

In scope

  • replyk.io and its subdomains
  • Our APIs and webhook endpoints
  • The Replyk mobile apps for iOS and Android

Out of scope

  • Third-party services, such as Meta, Stripe, Shopify and shipping carriers. Report those to their owners.
  • Denial-of-service and load testing
  • Social engineering, phishing and physical attacks
  • Reports from automated scanners with no demonstrated impact
  • Missing security headers, email authentication records or rate limits with no demonstrated impact
  • Self-XSS and clickjacking on pages with no sensitive action

3. Rules for Testing

  • Test only with accounts and businesses you own.
  • Never access, change or delete other people's data. If you reach any by accident, stop, do not keep it, and tell us.
  • Never send messages to real customers or to phone numbers you do not own.
  • Do not disrupt the Service or degrade it for other users.
  • Keep the vulnerability confidential until we have fixed it.

4. Safe Harbor

If you act in good faith and follow this policy, we consider your research authorized. We will not take legal action against you or report you to law enforcement for it, and if a third party does, we will make clear that you acted with our permission. If you are unsure whether something is allowed, ask us first at contact@replyk.io.

5. What You Can Expect

  • We acknowledge your report within 5 business days.
  • We tell you whether we confirmed the issue and keep you updated until it is fixed.
  • With your permission, we thank you publicly once the fix is live.

We do not offer paid rewards at this time.

6. Public Disclosure

Please give us 90 days, or until the fix is live if that is sooner, before you publish anything about the vulnerability, and tell us before you do.

7. Misuse of Meta or WhatsApp Data

To report suspected misuse of data from Meta, WhatsApp, Messenger or Instagram by Replyk or one of its users, email contact@replyk.io. We investigate every report and inform Meta where its terms require.

8. Contact Information

Security Reports
contact@replyk.io
Mailing Address
VERSAAS LLC8206 Louisiana Blvd Ne, Ste A #7849, Albuquerque, New Mexico 87113, United States

View Privacy Policy