Home

Security · Responsible Disclosure

Vulnerability Disclosure Policy

Last updated: October 5, 2026

At Berkay Çelik, we take the security of this website and its visitors seriously. If you have found a security vulnerability, please report it to us responsibly. We are glad to work with good-faith security researchers.

Türkçe sürüm

1. How to report

Email your findings to sec@celikberkay.com. You can write the report in English or Turkish. If possible, include:

  • The affected URL or endpoint.
  • The type of vulnerability and a short description.
  • Step-by-step instructions to reproduce the issue.
  • A proof of concept, screenshot or video, if available.
  • The potential impact and your assessment of its severity.
  • How we can reach you, and the name you would like listed in our acknowledgments.

If your report contains sensitive data, send a short initial email first and we will agree on a secure channel for the details.

2. Scope

  • All pages on celikberkay.com and www.celikberkay.com.
  • API endpoints on these domains, including the contact form and the free site analysis form.

3. Out of scope

  • Third-party services such as hosting, CDN, analytics or email providers. Please report issues in those services directly to the provider.
  • Denial of service (DoS/DDoS), load and stress testing.
  • Social engineering, phishing and physical attacks.
  • Spam or automated bulk submissions to forms.
  • Findings without a demonstrated impact: missing security headers, SPF/DKIM/DMARC recommendations, version disclosure, or raw output from automated scanners.
  • Self-XSS, and clickjacking on pages without sensitive actions.

4. Rules of engagement

  • Only test with accounts and data that belong to you.
  • Do not access, modify or delete other people's data. If you access it by accident, stop testing and tell us immediately.
  • Do not use methods that disrupt the site or affect its visitors.
  • Do not disclose details publicly until the issue is fixed and we have agreed on a date (coordinated disclosure).

5. Our commitments

  • We will acknowledge your report within 3 business days.
  • We will share our initial assessment within 10 business days.
  • We will keep you informed while we work on a fix.
  • The default disclosure timeline is 90 days from receipt of the report; we can adjust it together if needed.
  • If you wish, we will add your name to the acknowledgments below.

6. Safe harbor

We consider security research conducted in good faith and in line with this policy to be authorized, and we will not initiate legal action because of it. If you are unsure whether something is in line with this policy, contact us before going further.

7. Rewards

We do not currently run a paid bug bounty program. With your permission, we will publish your name in our acknowledgments for valid reports.

8. Acknowledgments

No entries yet. You could be the first.

9. Machine-readable file

A summary of this policy is published at /.well-known/security.txt, following RFC 9116.