Reporting a security problem

2026-08-27

If you have found a vulnerability in SamaReply, we want to hear about it. This page tells you where to send it and what to expect.

Where to send it

Email: [email protected]

Please include the steps to reproduce the problem, and what you were able to access or change. A short proof is more useful than a long description.

You may write in Arabic, English or German.

What we will do

We aim to acknowledge your report within 3 working days.

We will tell you whether we could reproduce the problem, and what we intend to do about it.

We will tell you when it is fixed.

What we ask of you

Please do not access, modify or delete data belonging to anyone else. If you reach data that is not yours, stop and tell us what you reached.

Please do not run tests that degrade the service for merchants, such as denial-of-service or bulk automated traffic.

Please give us a reasonable opportunity to fix the problem before you disclose it publicly.

What is in scope

samareply.com and its API endpoints.

Out of scope: Facebook itself, and any service we do not operate. Report those to the operator concerned.

Reward

We do not operate a paid bug bounty. We will credit you by name if you would like us to, and we will say thank you properly.