Last updated: 30 September 2026 # Security reporting policy If you discover a security vulnerability affecting koksalkayali.com, please report it privately so I can investigate and address it. ## Where to report Email me@koksalkayali.com (mailto:me@koksalkayali.com) with the subject “Security report — koksalkayali.com”. The current reporting contact is also published in security.txt (https://koksalkayali.com/.well-known/security.txt). ## Scope This policy covers the public website and security tools served at koksalkayali.com and www.koksalkayali.com. It does not cover other subdomains, email infrastructure, third-party services, linked websites, or Cloudflare’s systems. Report issues in those services to their respective owners. ## What to include - The affected URL and a clear description of the issue. - Minimal, reproducible steps using your own data or synthetic examples. - The potential impact and any relevant browser or environment details. - Redacted screenshots or a minimal proof of concept, if useful. Do not include passwords, API keys, unnecessary personal information, or data belonging to anyone else. Please use a link to the affected page rather than attaching a full assessment containing sensitive inputs. ## Testing boundaries Use only minimal, non-disruptive checks against public functionality. This policy is a reporting channel, not blanket authorization to test infrastructure or bypass access controls. Contact me before any testing that goes beyond these boundaries. - Do not conduct denial-of-service tests, high-volume scanning, brute-force attempts, phishing, or social engineering. - Do not access, modify, copy, or delete other people’s data, or attempt to establish persistence. - If unexpected sensitive data becomes visible, stop testing and report the issue with the minimum evidence needed. - Do not test third-party systems under this policy. ## Handling and disclosure I will review reports, investigate reproducible issues, and communicate through the reporting email when possible. This personal site does not offer a guaranteed response or remediation deadline, a paid bug bounty, or a legal safe-harbor commitment. Please keep vulnerability details private while we discuss the issue and coordinate an appropriate disclosure date. Researcher acknowledgment can be discussed and would only be published with your permission. ## Privacy of reports Reports are handled through email and may contain your email address, message, and supporting evidence. Share only what is necessary to investigate the issue. See the privacy policy (https://koksalkayali.com/privacy/) for information about correspondence, hosting, and analytics. Canonical page: https://koksalkayali.com/security/