Reporting a vulnerability
Email admin@founderreply.com with the affected URL or endpoint, the steps to reproduce, and what you were able to reach. We appreciate responsible disclosure, we respond promptly, and we will tell you what we found and when it will be fixed rather than closing the thread silently.
There is no bug-bounty programme, so we cannot offer a reward — what we can offer is a straight answer and credit if you want it. In return we ask that research stays inside your own workspace: do not access another customer’s data, do not degrade the service for anyone else, and give us a reasonable window to fix the issue before publishing it.
Certifications we do not hold
FounderReply has not completed a SOC 2, ISO 27001 or comparable audit, and you will not find a badge for one on this site. We are a small team, those audits have not happened, and a compliance graphic for an audit that did not happen is not a design decision.
If your procurement process needs paperwork, what genuinely exists is this page, our Data Processing Agreement, the sub-processor list and lawful-basis detail on the GDPR page, and a person who will answer a security questionnaire by email. If a certification is a hard requirement for you, we would rather tell you that now than after a contract.
Disconnection, deletion and retention
Disconnecting a platform account attempts a token revocation at the platform first — Reddit, X, LinkedIn, Facebook and Instagram all publish a revoke endpoint and we call it — and then deletes the stored credential rows regardless of whether that call succeeded, so a platform outage can never leave a token behind on our side. Deleting your account cascades through the workspaces you own: connected accounts, drafts, the approval queue, mentions, messages and billing records go with it, and the identity record itself is removed from the auth database.
Retention periods for the data that outlives a session — server logs, billing records — are set out on the privacy page, and you can start a deletion or an export from Data & Deletion without emailing anyone.
Your content and model training
We do not train any model on your content, and we do not sell or share it with anyone for that purpose. Drafting is a request to a third-party model API and nothing is retained by us for training; the terms that govern what those providers may do with an API request are theirs, and we name every one of them, with the region it processes in, on the GDPR page so you can read them yourself rather than take our summary for it.
Contact
Security questions, questionnaires and disclosure reports all go to admin@founderreply.com.