TEBHOSTEBHOS⬇Download
PremiumPartnersBlogHelp
🌐TR·EN
Sign inOpen TEBHOS
DownloadPremiumPartnersBlogHelpSign inTürkçeOpen TEBHOS

Security

How to report security issues, what is in scope, and how safe harbor works.

Last updated: August 14, 2026

On this page

  • Reporting a vulnerability
  • Scope
  • Safe harbour
  • Testing rules
  • What happens next
  • Disclosure
  • Thanks
  • security.txt
  • Contact

Note: The Turkish version of this document is legally binding; this English translation is provided for convenience only. If the two versions conflict, the Turkish text prevails.

Reporting a vulnerability

If you find a security vulnerability in TEBHOS, write to [email protected] and add "Güvenlik" or "Security" to the subject line. Please contact us before sharing the vulnerability anywhere public (servers, social media, public issues).

A good report contains: a clear title, the affected area, what the impact is, and steps to reproduce. Screenshots, request/response samples and environment details speed us up. Use test accounts wherever possible; do not include real users' data or session keys in a report unless strictly necessary.

Your report should include a proof of concept demonstrating impact against TEBHOS's live services. Observations based only on reading code or on a local setup can support a report, but are not sufficient on their own.

Scope

In scope: tebhos.com and its subdomains (including cdn.tebhos.com, livekit.tebhos.com, gateway.tebhos.com and test.tebhos.com), the TEBHOS desktop app, and infrastructure we directly manage. Abuse of TEBHOS features in ways that enable unauthorised access, persistence or data exposure is also in scope.

Out of scope:

  • third-party services and infrastructure outside our control
  • physical security, social engineering and phishing
  • DoS, flooding, resource exhaustion and noisy scanning — application-layer DoS provable with a handful of requests may be reported, as long as it is not exploited at scale
  • UI bugs, feature requests and support topics
  • theoretical findings with no realistic attack path (e.g. missing "best practice" headers)

Safe harbour

Good-faith research that follows this policy is authorised. We will not pursue legal action against you for good-faith security research conducted in line with this policy. If a third party takes action against you over such research, we will make clear that the research was authorised under this policy.

This assurance does not cover extortion, deliberate harm to users, disrupting the service or destroying data. If you are unsure whether a test is in scope, ask first.

Testing rules

  • Test only with your own accounts, servers and data (or those you have permission for).
  • Do not access, modify or delete other people's data. If you accidentally reach someone else's data, stop, do not keep it, and tell us.
  • Do not slow the service down; do not message users outside your test; do not scrape, flood or brute-force.
  • If a test could trigger real notifications or payments, ask us first.
  • When testing ends, delete any user data you hold, and follow the law.

What happens next

We aim to get back to you within a few days. Severity is assessed by real impact: who is affected, what data is at risk, how easy exploitation is. The more serious the issue, the faster we move.

If several people report the same vulnerability, credit goes to the first clear report. If we cannot reproduce a finding, we ask for more detail before closing the report.

Disclosure

We ask you to hold off public disclosure until we have confirmed and fixed the issue — usually at most 90 days. If a fix takes longer, we keep you in the loop and agree a timeline together; we will not ask for indefinite silence. If we publish an advisory, we will credit you by name if you wish and coordinate the timing with you.

Thanks

We currently have no monetary reward programme for valid reports — TEBHOS is built by a small team, and we say so honestly. With their permission, we publicly thank the authors of valid reports by name. To remain eligible, keep your report confidential, follow this policy, and do not use the vulnerability beyond what is needed to demonstrate it.

security.txt

This policy is also published in machine-readable form at /.well-known/security.txt (RFC 9116).

Contact

For security and everything else: [email protected]

Thank you for helping keep TEBHOS safe.

Related policies

Terms of ServiceThe agreement between you and TEBHOS, written to explain your rights and responsibilities clearly.Privacy PolicyHow TEBHOS handles personal data, what we do not do with it, and the controls and rights you have.Community GuidelinesClear standards for using TEBHOS, protecting others, and keeping communities safe.Company InformationLegal details for TEBHOS, including how we make money and how to contact us.ChangelogA record of significant changes to our Terms of Service, Privacy Policy, and Community Guidelines.
TEBHOSTEBHOS

TEBHOS is a free instant messaging and VoIP chat app built for friends, groups, and communities.

✉ [email protected]

Product

  • Download
  • Premium
  • Discovery
  • Partners

Resources

  • Blog
  • Help center
  • Changelog
  • Security

Legal

  • Terms of Service
  • Privacy Policy
  • Community Guidelines
  • Company Information

© TEBHOS

🌐Türkçe·English

Made in Türkiye 🇹🇷

English translations are provided for convenience; for legal documents the Turkish version is binding.