Legal documents

Information Security and Responsible Disclosure

Describes the security measures we apply, how to report a vulnerability, and our data breach procedure.

Last updated: 28 July 2026 · Data controller / service provider: Bildirim.io service operator

This English text is an informational translation. The agreement is concluded in Turkish and governed by Turkish law; in case of any discrepancy, the Turkish version prevails.

Measures we apply

What we offer: TOTP two-factor authentication with recovery codes, a panel-visible audit log of security actions on your account, scoped API keys with zero-downtime rotation, a block on sending from an unverified domain, and second-person approval for sends to large audiences. What we do not offer yet: an independent penetration test report and an independent status page hosted outside our own infrastructure. Those are on the roadmap and will not be described as if they existed before they do.

Responsible disclosure

If you find a security vulnerability, report it to [email protected]. We acknowledge your report within 3 business days and share the outcome of our assessment within 10 business days.

We will not take legal action against researchers acting in good faith. In return: test only with data on your own account, do not access other customers’ data, do not run load tests that disrupt the service, and do not share a vulnerability with third parties before it is fixed.

We do not run a paid bug bounty programme at present; with their permission we credit contributing researchers on a thanks list.

Data breach procedure

  1. Detection: an incident record is opened from monitoring, a customer report or a researcher report.
  2. Containment: the affected component is isolated and, if needed, the relevant keys are revoked and rotated.
  3. Impact analysis: which data categories, how many people and which customers are affected is established.
  4. Notification: affected customers are notified without undue delay and in any event within 72 hours.
  5. Regulator notification: where legislation requires it, the Turkish Data Protection Authority is notified.
  6. Recovery: the system is returned to a safe state, restoring from backup if necessary.
  7. Root-cause analysis and corrective actions are determined.
  8. A post-incident report is prepared and shared with affected customers.

The notice to customers covers the nature of the breach, the data categories affected, the likely consequences, and the measures taken and recommended.

Bildirim

For questions about this document, write to [email protected] .

All legal documents