How to report
Email security@replayfoundry.com with the affected version, operating-system version, impact, reproducible steps, and a safe proof of concept. Use synthetic data whenever possible. Do not include passwords, OAuth tokens, personal media, private transcripts, or another person's data.
Good-faith boundaries
- Do not access, modify, destroy, or retain data that is not yours.
- Do not disrupt services, distribute malware, conduct denial-of-service tests, or use social engineering.
- Stop testing and notify us if you encounter sensitive information.
- Allow reasonable time for investigation before public disclosure.
Current security posture
ReplayFoundry is designed around local media processing, explicit network permissions, HTTPS for approved endpoints, Google OAuth with the system browser and PKCE, current-user credential storage, verified runtime payloads, and sanitized opt-in diagnostics. The public release is being held until code signing and installer trust checks are complete.
Response
We will make a best-effort acknowledgment, validate impact, communicate material status changes, and credit a reporter when appropriate and desired. This page is not a bug-bounty promise or authorization to violate law or third-party terms.