Scope
This policy covers the customer panel and the testing services you request. It forms an integral part of the Terms of Service.
It applies to every member of your team who accesses the panel; you are responsible for their conduct.
Authorisation requirement
This is the most important clause here: you may only request testing of systems you are authorised to have tested.
Authorisation comes from owning the system, or from written permission by its owner. "It belongs to our client, it will be fine" is not enough.
Testing an unauthorised system is a computer crime in many jurisdictions. The consequences of such a request fall on you, and the indemnity clause in the Terms of Service applies.
Proving authorisation
Where we have any doubt we ask for evidence of your authorisation before starting. This is not a sign of distrust; it protects both of us.
Acceptable evidence includes: the relevant clause of your contract with the system owner, written permission from the owner, or verification of domain ownership.
If no evidence is provided, we do not start the test and we refund the payment.
Prohibited uses
Having a system tested that you are not authorised to test.
Using the service to harm a third party, deny them service, or exfiltrate data.
Publicly disclosing findings without the system owner’s permission, or using them for extortion.
Using the service to develop, distribute or trial malicious software.
Requesting testing of systems hosting unlawful content or running unlawful operations.
Copying our methodology, checklists or report templates in order to build a competing service.
Third-party services
Where your product relies on third-party services (payment provider, identity, maps, cloud infrastructure), obtaining permission to test them is your responsibility.
Most cloud providers require prior notice for load and penetration testing. You give that notice.
We are not responsible for a test being halted, or your account suspended, because notice was not given.
Load and performance testing rules
We run load testing only at the date and time agreed with you, and only up to the agreed load level.
We do not run load testing on shared hosting; the risk of affecting neighbouring systems is real.
If we see the system fail unexpectedly during a test, we stop and tell you.
Limits on security testing
Our security review is based on the OWASP Top 10 and is detection oriented: we demonstrate a vulnerability, we do not exploit it to extract data.
We do not carry out destructive testing: we delete no data, cause no permanent damage, and leave no persistent back door.
Social engineering and physical security testing are out of scope; unless separately agreed, we run no phishing exercise against your staff.
We do not access real user accounts; accounts created for testing are used instead.
Test environment rules
You ensure the test environment holds no real personal data. We recommend using synthetic data.
Where real data is unavoidable you tell us before the test and the Data Processing Agreement applies.
If you want us to test in production you confirm that in writing, and scenarios that create data are taken out of scope.
Panel usage rules
You will not reverse engineer the panel, attempt to extract its source, or try to circumvent its security controls.
You will not flood the panel with automated requests or try to exceed its rate limits.
You will not transfer your account to anyone else or share your credentials. You can create separate users for your team.
If you find a vulnerability in the panel, follow the route on the Responsible Disclosure page; do not exploit it.
Reporting abuse
If you believe our service is being abused, write to [email protected].
We take such reports seriously and suspend the account concerned immediately where we judge it necessary.
Enforcement
The measures available to us on a breach of this policy are: a warning, halting a test in progress, suspending the account and terminating the agreement.
Where unauthorised testing is identified or abuse is serious, we may suspend without prior warning.
No refund is given where termination follows unauthorised testing.
We notify the competent authorities where we are legally required to.
Appeal
You may appeal a suspension or termination. Send your reasons in writing within 30 days.
We assess the appeal within 10 business days and give our decision with reasons in writing. Where the decision turns out to have been wrong, we restore the account and make good the time lost.
These documents are published in English and Turkish. In the event of conflict the Turkish text prevails.