PhiShark Logo
← Legal & Trust Center

Acceptable Use Policy

Last update: September 7, 2026

This Acceptable Use Policy (“Policy”) sets out the rules for safe, lawful and responsible use of the PhiShark services and is part of the Terms of Use.

1. Permitted Use

PhiShark is designed for defensive cybersecurity analysis.

You can analyze suspicious URLs, domain names, e-mails, links, QR codes, PDFs, files or similar contents that you have lawfully in your possession, have been sent to you or that you can lawfully access, for security purposes.

However, active scanning, penetration testing, vulnerability exploitation, credential testing, bypassing security controls or similar intrusive activities on third-party systems may only be carried out if you have the necessary express authorization.

You must have the necessary right, authority or legal reason to process and analyze the content you send to PhiShark.

2. Prohibited Uses

You may not use or assist in the use of PhiShark for the following purposes:

  • violate any law or regulation;
  • accessing or maintaining unauthorized access to a computer system, unlawful monitoring of data flows, or bypassing security controls;
  • create, conduct, distribute or facilitate phishing, credential harvesting, malware, ransomware, spam, fraud or other harmful activities;
  • engaging in unauthorized vulnerability scanning, exploitation, penetration testing or similar active intervention in third-party systems;
  • Disrupt the operation of PhiShark or third-party systems, overburden them, conduct a denial-of-service attack, or deny access to other users;
  • attempt to exceed or circumvent account, API, credit, usage quotas, rate limits or other technical limitations;
  • upload or process personal data, confidential information, trade secrets or protected content belonging to another person without the necessary legal reason or authority;
  • unlawfully surveilling, tracking, profiling or discriminating against individuals;
  • knowingly present the results of PhiShark in a false, misleading or out-of-context manner;
  • resell the Services, offer them as a standalone service to third parties or transfer access rights, unless the relevant plan or written contract permits; or
  • reverse engineer or bypass technical protections to access PhiShark's source code, models or underlying technology, except as expressly permitted by applicable law.

This list is not limiting. Other uses that are unlawful, abusive or that seriously endanger the security of PhiShark, its users or third parties' systems and data are also prohibited.

3. Personal and Sensitive Data in Security Analysis

You should not send personal data, passwords, authentication information, payment card information, sensitive personal data or other sensitive information to PhiShark that is not required for security analysis.

If a suspicious email, document or other content contains such information, you are advised to remove or mask unnecessary information to the extent possible and compatible with the analysis purpose.

Details regarding the processing of personal data are regulated within the scope of the Global Privacy Statement, KVKK Information Text and, to the extent applicable, the Data Processing Annex.

4. Good Faith Security Research

Individuals who wish to conduct security research on PhiShark's own systems, products or infrastructure must comply with the Responsible Vulnerability Disclosure Policy.

This Policy or PhiShark's Services;

  • access PhiShark customers or customer data;
  • perform social engineering or phishing;
  • to ensure permanence;
  • modify or delete data;
  • run destructive payload;
  • create service disruptions; or
  • clearly exceeding the permitted scope of testing

does not authorize .

5. Application and Abuse Reporting

PhiShark may take necessary and proportionate measures if it has reasonable grounds to believe that this Policy has been violated or the Services are used in a way that creates a serious security or legal risk for users, third parties or PhiShark.

Depending on the nature of the situation, these measures may include limiting use, imposing rate limits, blocking certain transactions, temporarily suspending the account, or terminating access to the Services for serious or repeated violations.

The user is informed to the extent permitted by the nature of the situation and is provided with a reasonable remedy for remediable violations. Cases of urgent security risk, fraud or legal obligation are reserved.

PhiShark may cooperate with competent authorities if required by law.

If you believe the services are being misused: [email protected]

Company Information

PHISHARK TEKNOLOJİ ANONİM ŞİRKETİ Cevizli Mah. Zuhal Cad. Ritim Istanbul Sitesi A5 Blok No:46E İç Kapı No:179 Maltepe/İstanbul Tax Office / Tax Number: Kartal V.D. – 729 137 4297 MERSIS: 0729137429700001