Vulnerability Disclosure Policy
Last updated: July 2026 · Applies to ReplyChrono, including our Slack app and the service at replychrono.com
Report a vulnerability
Email security@replychrono.com with a description of the issue and, where possible, steps to reproduce it, affected URLs or endpoints, and any proof-of-concept material. We welcome reports from security researchers, customers and Slack.
What you can expect from us
- Acknowledgement of your report within five business days
- Updates while we investigate, and notice when a fix is released
- Public credit for your finding, if you would like it
- No legal action against researchers who follow this policy in good faith
Scope
In scope: the ReplyChrono Slack application, the hosted service at replychrono.com (including its install, OAuth and Slack event endpoints), and the data handling described in our Privacy Policy. Out of scope: the Slack platform itself (report those to Slack), our hosting provider's infrastructure, and findings that require physical access to our devices.
Guidelines
- Do not access, modify, or exfiltrate data belonging to workspaces other than your own
- Do not run denial-of-service, spam or social-engineering tests
- Give us reasonable time to remediate before any public disclosure
- Use a test workspace where possible; ReplyChrono offers a free plan for exactly this
Bug bounty
ReplyChrono does not operate a paid bug bounty program. We are a small company and rely on responsible disclosure — which we take seriously and respond to promptly.
Our security posture
ReplyChrono never stores message content: only timestamps, channel IDs, user IDs and workspace settings. Slack tokens are encrypted at rest with AES-256-GCM, all traffic is TLS-protected, every inbound Slack request is signature-verified, and uninstalling the app deletes all workspace data immediately. Details in our Privacy Policy.