Last updated: 30 September 2026

Security reporting policy

If you discover a security vulnerability affecting koksalkayali.com, please report it privately so I can investigate and address it.

Where to report

Email [email protected] with the subject “Security report — koksalkayali.com”. The current reporting contact is also published in security.txt.

Scope

This policy covers the public website and security tools served at koksalkayali.com and www.koksalkayali.com. It does not cover other subdomains, email infrastructure, third-party services, linked websites, or Cloudflare’s systems. Report issues in those services to their respective owners.

What to include

Do not include passwords, API keys, unnecessary personal information, or data belonging to anyone else. Please use a link to the affected page rather than attaching a full assessment containing sensitive inputs.

Testing boundaries

Use only minimal, non-disruptive checks against public functionality. This policy is a reporting channel, not blanket authorization to test infrastructure or bypass access controls. Contact me before any testing that goes beyond these boundaries.

Handling and disclosure

I will review reports, investigate reproducible issues, and communicate through the reporting email when possible. This personal site does not offer a guaranteed response or remediation deadline, a paid bug bounty, or a legal safe-harbor commitment.

Please keep vulnerability details private while we discuss the issue and coordinate an appropriate disclosure date. Researcher acknowledgment can be discussed and would only be published with your permission.

Privacy of reports

Reports are handled through email and may contain your email address, message, and supporting evidence. Share only what is necessary to investigate the issue. See the privacy policy for information about correspondence, hosting, and analytics.