Şahinler Tercüme
ŞahinlerYeminli Tercüme
Responsible Disclosure

Security & Bug Bounty

If you've found a security vulnerability in our system, please report it responsibly. We have a thank-you and reward program for valid findings.

This legal document is currently available in Turkish only. For questions please contact info@sahinlertercume.com.tr.

Contact

In-Scope

  • sahinlertercume.com.tr and its subdomains
  • Payment and order flows
  • Customer and admin panels
  • File upload + processing
  • API endpoints (/api/*)

Out-of-Scope

  • DoS / DDoS testing
  • Social engineering (targeting staff)
  • Physical attacks
  • Spam / phishing
  • Automated scanner output (without manual verification)
  • Third-party services (Supabase, Vercel, iyzico, PayTR)

Process

  1. Send a detailed PoC (proof-of-concept) by email.
  2. We review your report and acknowledge it as soon as possible.
  3. Verified findings are addressed based on priority.
  4. After confirmation, with your consent, you're added to the thank-you list.

Recognition & Rewards

  • Critical (RCE, auth bypass, card data leak)
  • High (SQL injection, IDOR, authorization bypass)
  • Medium (XSS, CSRF, information disclosure)
  • Low (clickjacking, disclosure issues)

Thanks and rewards are goodwill-based and determined at our discretion according to the finding's impact, quality and our assessment. No fixed reward is guaranteed.

Acknowledgements

Researchers who contribute to our program will be listed here. We're awaiting our first report.

This policy complies with the RFC 9116 standard: security.txt

Cookie Usage

Our site uses essential cookies to improve your experience and keep your session secure. Learn more