Responsible Disclosure
Found a vulnerability? Tell us first
We value reports from security researchers. We do not pursue legal action for research done in good faith and in line with this policy. Below we explain which systems are in scope, how to report, and when you can expect to hear from us.
Report a vulnerabilityHow to report
- 1
Record the finding
Note the affected address, steps to reproduce, the possible impact and, if available, a screenshot or sample request.
- 2
Send it to us
Choose 'Security report' on our contact page. The current reporting channel is also in the /.well-known/security.txt file on the site.
- 3
Wait for our reply
We confirm receipt, assess the report and keep you updated while we fix it.
- 4
Disclose together
After the fix ships, we can agree together on when the finding is made public, if you wish.
Response time targets
Times are targets; they may vary with the complexity of the finding, and we will tell you if there is a delay.
| Stage | Target |
|---|---|
| Acknowledgement | 3 business days |
| Initial assessment and severity | 10 business days |
| Fix for a critical vulnerability | 30 days |
| Fix for other vulnerabilities | 90 days |
| Coordinated disclosure | After the fix, on a date agreed together |
Scope
In scope:
- The panel application and its API
- The marketing site
- Pages opened through shareable links: proposal page, reconciliation approval page, customer statement
- Authentication, session management and data isolation between companies
Out of scope:
- Denial of service (DoS, DDoS) and load testing
- Social engineering, phishing and physical access attempts
- Third-party services we do not operate (our subprocessors and services tenants connect); report those to the provider
- Findings without demonstrated impact, such as a missing security header, SPF or DMARC settings, or clickjacking on pages without a session
What not to do
- Access, modify, delete or exfiltrate data belonging to other users or companies
- Run automated scans or heavy request volumes that degrade the service
- Leave persistent access in the system (backdoor, user account, scheduled job)
- Disclose the finding publicly or to third parties before a fix ships
- Use the finding to demand payment
If you come across personal data during research, stop, do not keep the data and mention it in your report.
Good-faith research safe harbor
We consider research carried out in good faith and in line with this policy to be authorized, we will not start legal proceedings against you, and if a third party does, we will state that you followed this policy. If you are unsure whether something is in scope, ask through the contact page before testing.
security.txt
Our security reporting channel and the address of this policy are published in the /.well-known/security.txt file in RFC 9116 format.
Frequently asked questions
Do you run a bug bounty?
We do not have a paid bounty program today. For valid, in-scope findings, and with your permission, we credit you on our thanks list.
When will you not take legal action?
As long as you follow the rules in this policy, do not access other users' data (or stop and report immediately if access occurred), do not disrupt the service and do not share the finding before it is fixed, we treat your research as authorized.
Can I report by email?
To report, choose 'Security report' on our contact page; the current channel is also in the security.txt file. If your report must include personal data, keep it to the minimum.
Can I test on my own company account?
Yes, only on trial accounts you created yourself and with your own data. If you find a flaw that exposes another company's data, stop at the minimum access needed as proof and report it.
Related
Trust Center →
Security, KVKK and GDPR, subprocessors, backups and the compliance roadmap in one place.
Security →
Infrastructure, tenant isolation, encryption, access control and audit trail.
Status and SLA →
Target 99.9% availability, maintenance windows, incident communication and support times.
Contact →
Talk to the Müşavir team.
Send your security report
Choose 'Security report' on our contact page to send your finding; we aim to confirm receipt within 3 business days.
Report a vulnerability