TRUST / SECURITY

Found a security problem? Let us know.

Email us the affected version and steps to reproduce the problem. Please use sample data and keep private files and credentials out of the report.

SECURITY CONTACT
security@replayfoundry.com

CONTACT US BEFORE
SHARING DETAILS PUBLICLY

How to report

Email security@replayfoundry.com with the affected version, operating-system version, impact, reproducible steps, and a safe proof of concept. Use synthetic data whenever possible. Do not include passwords, OAuth tokens, personal media, private transcripts, or another person's data.

Good-faith boundaries

  • Do not access, modify, destroy, or retain data that is not yours.
  • Do not disrupt services, distribute malware, conduct denial-of-service tests, or use social engineering.
  • Stop testing and notify us if you encounter sensitive information.
  • Allow reasonable time for investigation before public disclosure.

How the app protects your work

Media processing stays on your PC. You choose which online features to enable and which reports to send. The current public beta uses a Microsoft-signed installer; only the latest published beta receives security fixes.

Technical safeguards

Network connections use HTTPS and approved endpoints. Google sign-in uses your browser with PKCE, and Windows Credential Manager protects the saved account credential. AI downloads are verified before activation, local model loading disables remote code, and support reports are sanitized before sending.

Release checks include dependency advisories, source-export boundaries, and tests for reporting and installation failures. These checks reduce risk; they are not a guarantee that software is free of vulnerabilities.

Response

We will make a best-effort acknowledgment, validate impact, communicate material status changes, and credit a reporter when appropriate and desired. This page is not a bug-bounty promise or authorization to violate law or third-party terms.