PhiShark Logo
← Legal & Trust Center

Responsible Vulnerability Disclosure Policy

PhiShark supports good faith security research that helps improve the security of its products and systems. This Policy explains how security vulnerabilities can be investigated and reported.

1. Scope

This Policy applies only to systems that PhiShark owns or operates and has expressly included in security research.

Customer systems and data, third party services, social media accounts and physical facilities are excluded without express written consent.

2. Research rules

During research:

  • only use your own account or accounts expressly permitted for testing;
  • use the least access and data necessary to illustrate the problem;
  • stop testing and report if you access personal, confidential or sensitive data belonging to other people;
  • do not engage in denial of service (DoS/DDoS), social engineering, phishing, malware, persistence, high-volume automated scanning, data deletion/alteration, or physical testing;
  • do not exploit the vulnerability on real users or systems; and
  • Coordinate with PhiShark before making a public statement.

3. Report vulnerability

Send your report to [email protected] with the subject “Security Vulnerability”.

If possible, in the report:

  • the system or feature affected;
  • a description of the vulnerability and its potential impact;
  • steps to safely reproduce; and
  • necessary screenshots or technical proofs

specify.

Do not send sensitive information such as passwords, access keys, personal data or working exploit codes via regular email; Request a secure transmission channel if necessary.

4. Good faith assurance

If your research complies with this Policy and is in good faith, PhiShark will not initiate or support legal action against you based solely on this research.

This assurance; It does not cover intentional damage, data misuse, blackmail, unauthorized access to out-of-scope systems or other unlawful activities and is not binding on third parties or public authorities.

5. Evaluation and coordinated disclosure

PhiShark aims to confirm and evaluate valid notifications within a reasonable time and communicate with the researcher about important developments.

Public disclosure of the vulnerability should be made in coordination with PhiShark to the extent possible to protect users and allow reasonable time for remediation.

This Policy is not a bug bounty program and does not create the right to payment or reward for notification unless PhiShark also makes a reward commitment in writing.

If requested by the researcher and deemed appropriate, public acknowledgment or naming can be made for valid security vulnerabilities that have been resolved.

Contact

PHISHARK TEKNOLOJİ ANONİM ŞİRKETİ Cevizli Mah. Zuhal Cad. Ritim Istanbul Sitesi A5 Blok No:46E İç Kapı No:179 Maltepe/İstanbul MERSIS: 0729137429700001 Security notices: [email protected]