Vulnerability disclosure

If you found a vulnerability, write to us before sharing it publicly. We ask you to keep the details between us until it is fixed.

How to report

Write to iletisim@agzyazilim.com with the subject “Security report”. We can confirm the issue faster if you include:

  • The affected address, product or version
  • The impact: who can access or change what
  • Steps to reproduce it safely

Good-faith testing

  • Test only with your own account and data.
  • Look at the least data needed to prove the issue; do not view or keep more.
  • Do not run attempts that slow down or stop the service.

Out of scope

Denial of service, social engineering, physical access, testing third-party systems and exporting real user data are out of scope.

For automated tools

The disclosure details are also published at the standard /.well-known/security.txt path: open the security.txt file. For how personal data is processed, see the privacy policy (in Turkish).