Skip to main content
Legal

Vulnerability Disclosure Policy

If you have found a security vulnerability, report it to us with confidence. This page explains how to report it and what we promise in return.

How to report

Send what you found to [email protected]. We can move much faster if your report includes: the affected URL or screen, the steps you followed to reproduce it, the result you observed and a screenshot if you have one. You may write in English or Turkish.

What we promise

We confirm receipt of your report in writing within 3 business days. We share our first assessment within 10 business days. If the issue is confirmed, we keep you informed while we fix it and let you know once it is closed.

Safe harbour

We will not pursue legal action against you for good-faith research carried out under this policy. In return we ask you to follow three rules: only touch data in your own account, never view, copy or delete anyone else's data; do not disrupt the service; and do not share the issue with third parties until we have fixed it.

Out of scope

The following are outside this policy: tests that slow down or stop the service, social engineering and phishing attempts, physical security attempts, actions targeting our staff, findings caused only by an outdated browser or device, and automated scanner output with no demonstrated impact.

Rewards and credit

We do not run a paid bounty programme at this time. If you help us close an issue and you agree to it, we will credit you as the reporter.

Operator Information

Workinno software is operated by the following legal entity.

Operator
MİNOTOR FİNANSAL YAZILIM TEKNOLOJİLERİ ANONİM ŞİRKETİ
Address
Çınarlı Mh. 1572 Sk. No:33, Konak / İzmir 35170, Türkiye
Phone
+90 532 452 48 38
Website
workinno.com
Tax Number (VKN)
6211127647
MERSIS No
0621112764700001
Trade Registry No
245941
Chamber Registry No
2296021
Vulnerability Disclosure Policy — Workinno