Responsible Vulnerability Disclosure
How to report a suspected security vulnerability in PhiShark-owned systems.
- Version
- 1.0-draft
- Effective date
- Upon publication following legal approval
- Last updated
- 25 July 2026
- Change summary
- Initial consolidated draft covering the website, platform, API and client integrations.
1. Scope
This policy covers publicly reachable PhiShark-owned services explicitly identified by PhiShark. Customer systems, third-party providers, production data, social media and physical sites are out of scope unless written authorization states otherwise.
2. Research rules
- Use only accounts and data you own; stop if you encounter another person’s data.
- Do not perform denial of service, social engineering, phishing, malware, persistence, automated high-volume scanning, destructive testing or physical attacks.
- Use the minimum access needed to prove the issue; do not alter, download, retain or disclose unnecessary data.
- Do not publicly disclose before PhiShark has had a reasonable opportunity to investigate and remediate.
3. Reporting
Send a clear description, affected asset, reproduction steps, impact and safe proof to [email protected] with “Security Vulnerability” in the subject. Do not email live credentials, personal data or exploit payloads; ask for a secure transfer method.
4. Good-faith safe harbor
Where research is conducted in good faith and complies with this policy, PhiShark will not initiate legal action solely for that research and will work to clarify concerns. This does not authorize violations of third-party rights or law and cannot bind third parties or authorities.
5. Response and recognition
We aim to acknowledge reports, triage severity and communicate material progress, but do not promise a specific remediation time or bounty unless agreed in writing. Duplicate, spam, purely theoretical, self-XSS and automated low-impact findings may be closed without reward.
Company information
PHISHARK TEKNOLOJİ ANONİM ŞİRKETİ
Cevizli Mah. Zuhal Cad. Ritim İstanbul Sitesi A5 Blok No:46E İç Kapı No:179 Maltepe/İstanbul
Tax office / tax number: Kartal V.D. – 729 137 4297
MERSİS: 0729137429700001
Telephone information will be added as soon as possible.
Contact: [email protected] · [email protected] · [email protected]
Previous versions
No previous public version is archived for this draft.