PhiShark Logo
Legal & Trust Center

Responsible Vulnerability Disclosure

How to report a suspected security vulnerability in PhiShark-owned systems.

Version
1.0-draft
Effective date
Upon publication following legal approval
Last updated
25 July 2026
Change summary
Initial consolidated draft covering the website, platform, API and client integrations.

1. Scope

This policy covers publicly reachable PhiShark-owned services explicitly identified by PhiShark. Customer systems, third-party providers, production data, social media and physical sites are out of scope unless written authorization states otherwise.

2. Research rules

  • Use only accounts and data you own; stop if you encounter another person’s data.
  • Do not perform denial of service, social engineering, phishing, malware, persistence, automated high-volume scanning, destructive testing or physical attacks.
  • Use the minimum access needed to prove the issue; do not alter, download, retain or disclose unnecessary data.
  • Do not publicly disclose before PhiShark has had a reasonable opportunity to investigate and remediate.

3. Reporting

Send a clear description, affected asset, reproduction steps, impact and safe proof to [email protected] with “Security Vulnerability” in the subject. Do not email live credentials, personal data or exploit payloads; ask for a secure transfer method.

4. Good-faith safe harbor

Where research is conducted in good faith and complies with this policy, PhiShark will not initiate legal action solely for that research and will work to clarify concerns. This does not authorize violations of third-party rights or law and cannot bind third parties or authorities.

5. Response and recognition

We aim to acknowledge reports, triage severity and communicate material progress, but do not promise a specific remediation time or bounty unless agreed in writing. Duplicate, spam, purely theoretical, self-XSS and automated low-impact findings may be closed without reward.

Company information

PHISHARK TEKNOLOJİ ANONİM ŞİRKETİ

Cevizli Mah. Zuhal Cad. Ritim İstanbul Sitesi A5 Blok No:46E İç Kapı No:179 Maltepe/İstanbul

Tax office / tax number: Kartal V.D. – 729 137 4297

MERSİS: 0729137429700001

Telephone information will be added as soon as possible.

Contact: [email protected] · [email protected] · [email protected]

Previous versions

No previous public version is archived for this draft.