We welcome reports from security researchers, and we'll work with you to confirm and fix any issue you find.
Please don't report security issues through public GitHub issues, pull requests, or discussions — anyone can see them, and we don't want a security issue to become public before we've fixed it. Instead, email us privately at security@replayfy.app.
Please include enough detail for us to reproduce the issue — the affected version, steps to reproduce, and a proof of concept if you have one. We aim to acknowledge your report within a few business days and will keep you updated as we work on a fix.
We're grateful to everyone who helps keep Replayfy and our users safe, and we're happy to credit you once an issue is resolved (with your permission).