Vulnerability Disclosure Policy

Last updated: July 2026 · Applies to ReplyChrono, including our Slack app and the service at replychrono.com

Report a vulnerability

Email security@replychrono.com with a description of the issue and, where possible, steps to reproduce it, affected URLs or endpoints, and any proof-of-concept material. We welcome reports from security researchers, customers and Slack.

What you can expect from us

Scope

In scope: the ReplyChrono Slack application, the hosted service at replychrono.com (including its install, OAuth and Slack event endpoints), and the data handling described in our Privacy Policy. Out of scope: the Slack platform itself (report those to Slack), our hosting provider's infrastructure, and findings that require physical access to our devices.

Guidelines

Bug bounty

ReplyChrono does not operate a paid bug bounty program. We are a small company and rely on responsible disclosure — which we take seriously and respond to promptly.

Our security posture

ReplyChrono never stores message content: only timestamps, channel IDs, user IDs and workspace settings. Slack tokens are encrypted at rest with AES-256-GCM, all traffic is TLS-protected, every inbound Slack request is signature-verified, and uninstalling the app deletes all workspace data immediately. Details in our Privacy Policy.