Security
How to report security issues, what is in scope, and how safe harbor works.
Note: The Turkish version of this document is legally binding; this English translation is provided for convenience only. If the two versions conflict, the Turkish text prevails.
Reporting a vulnerability
If you find a security vulnerability in TEBHOS, write to [email protected] and add "Güvenlik" or "Security" to the subject line. Please contact us before sharing the vulnerability anywhere public (servers, social media, public issues).
A good report contains: a clear title, the affected area, what the impact is, and steps to reproduce. Screenshots, request/response samples and environment details speed us up. Use test accounts wherever possible; do not include real users' data or session keys in a report unless strictly necessary.
Your report should include a proof of concept demonstrating impact against TEBHOS's live services. Observations based only on reading code or on a local setup can support a report, but are not sufficient on their own.
Scope
In scope: tebhos.com and its subdomains (including cdn.tebhos.com, livekit.tebhos.com, gateway.tebhos.com and test.tebhos.com), the TEBHOS desktop app, and infrastructure we directly manage. Abuse of TEBHOS features in ways that enable unauthorised access, persistence or data exposure is also in scope.
Out of scope:
- third-party services and infrastructure outside our control
- physical security, social engineering and phishing
- DoS, flooding, resource exhaustion and noisy scanning — application-layer DoS provable with a handful of requests may be reported, as long as it is not exploited at scale
- UI bugs, feature requests and support topics
- theoretical findings with no realistic attack path (e.g. missing "best practice" headers)
Safe harbour
Good-faith research that follows this policy is authorised. We will not pursue legal action against you for good-faith security research conducted in line with this policy. If a third party takes action against you over such research, we will make clear that the research was authorised under this policy.
This assurance does not cover extortion, deliberate harm to users, disrupting the service or destroying data. If you are unsure whether a test is in scope, ask first.
Testing rules
- Test only with your own accounts, servers and data (or those you have permission for).
- Do not access, modify or delete other people's data. If you accidentally reach someone else's data, stop, do not keep it, and tell us.
- Do not slow the service down; do not message users outside your test; do not scrape, flood or brute-force.
- If a test could trigger real notifications or payments, ask us first.
- When testing ends, delete any user data you hold, and follow the law.
What happens next
We aim to get back to you within a few days. Severity is assessed by real impact: who is affected, what data is at risk, how easy exploitation is. The more serious the issue, the faster we move.
If several people report the same vulnerability, credit goes to the first clear report. If we cannot reproduce a finding, we ask for more detail before closing the report.
Disclosure
We ask you to hold off public disclosure until we have confirmed and fixed the issue — usually at most 90 days. If a fix takes longer, we keep you in the loop and agree a timeline together; we will not ask for indefinite silence. If we publish an advisory, we will credit you by name if you wish and coordinate the timing with you.
Thanks
We currently have no monetary reward programme for valid reports — TEBHOS is built by a small team, and we say so honestly. With their permission, we publicly thank the authors of valid reports by name. To remain eligible, keep your report confidential, follow this policy, and do not use the vulnerability beyond what is needed to demonstrate it.
security.txt
This policy is also published in machine-readable form at /.well-known/security.txt (RFC 9116).
Contact
For security and everything else: [email protected]
Thank you for helping keep TEBHOS safe.