1. How to Report
If you find a security vulnerability in Replyk, email contact@replyk.io with the subject "Security report". You can write in English, Arabic or French. Please include:
- What the vulnerability is and where it is (URL, endpoint or app screen)
- Steps to reproduce it
- What an attacker could do with it
- How we can reach you
2. Scope
In scope
- replyk.io and its subdomains
- Our APIs and webhook endpoints
- The Replyk mobile apps for iOS and Android
Out of scope
- Third-party services, such as Meta, Stripe, Shopify and shipping carriers. Report those to their owners.
- Denial-of-service and load testing
- Social engineering, phishing and physical attacks
- Reports from automated scanners with no demonstrated impact
- Missing security headers, email authentication records or rate limits with no demonstrated impact
- Self-XSS and clickjacking on pages with no sensitive action
3. Rules for Testing
- Test only with accounts and businesses you own.
- Never access, change or delete other people's data. If you reach any by accident, stop, do not keep it, and tell us.
- Never send messages to real customers or to phone numbers you do not own.
- Do not disrupt the Service or degrade it for other users.
- Keep the vulnerability confidential until we have fixed it.
4. Safe Harbor
If you act in good faith and follow this policy, we consider your research authorized. We will not take legal action against you or report you to law enforcement for it, and if a third party does, we will make clear that you acted with our permission. If you are unsure whether something is allowed, ask us first at contact@replyk.io.
5. What You Can Expect
- We acknowledge your report within 5 business days.
- We tell you whether we confirmed the issue and keep you updated until it is fixed.
- With your permission, we thank you publicly once the fix is live.
We do not offer paid rewards at this time.
6. Public Disclosure
Please give us 90 days, or until the fix is live if that is sooner, before you publish anything about the vulnerability, and tell us before you do.
7. Misuse of Meta or WhatsApp Data
To report suspected misuse of data from Meta, WhatsApp, Messenger or Instagram by Replyk or one of its users, email contact@replyk.io. We investigate every report and inform Meta where its terms require.
8. Contact Information
- Security Reports
- contact@replyk.io
- Mailing Address
- VERSAAS LLC8206 Louisiana Blvd Ne, Ste A #7849, Albuquerque, New Mexico 87113, United States