shield Güvenlik · Security

Güvenlik ve Zafiyet Bildirimi

Security & Vulnerability Disclosure

OnySoft ürünlerinde veya altyapısında bir güvenlik açığı bulduysanız bize bildirmenizi rica ederiz. Bildirimleri ciddiyetle inceler, doğrulanan açıkları gideririz.

If you have found a security vulnerability in an OnySoft product or in our infrastructure, please report it to us. We take every report seriously and fix the issues we confirm.

badge Güvenlik sorumlusu · Security lead
Ali Eren Onyıl
Kurucu ve CEO · Founder & CEO
mail Bildirim adresi · Report to
info@onysoft.com
Konu · Subject: “Güvenlik Bildirimi / Security Report”
schedule İlk yanıt · First response
3 gün içinde
within 3 days
Türkçe politika English policy description security.txt · Son güncelleme / Last updated:

Güvenlik sorumlusu

OnySoft'ta ürün ve altyapı güvenliğinden Ali Eren Onyıl (Kurucu ve CEO) sorumludur.

Nasıl bildirilir?

Bildiriminizi info@onysoft.com adresine, konu satırına “Güvenlik Bildirimi” (veya “Security Report”) yazarak gönderin. Bildiriminizde şunlar bulunsun:

  • Etkilenen ürün, alan adı veya URL
  • Açığın türü ve olası etkisi
  • Adım adım yeniden üretme yöntemi
  • Kanıt: istek/yanıt örnekleri, ekran görüntüsü veya kavram kanıtı (PoC)
  • Size ulaşabileceğimiz iletişim bilgisi ve teşekkür listesinde adınızla anılmak isteyip istemediğiniz

Bildiriminize başkalarına ait kişisel veri, parola veya erişim anahtarı eklemeyin; kanıt için gerekiyorsa maskeleyin.

Süreç ve taahhütlerimiz

  • Bildiriminizi aldığımızı 3 gün içinde size bildiririz.
  • İnceleme sonucunu ve açık doğrulanırsa düzeltme planını sizinle paylaşır, süreç boyunca sizi bilgilendiririz.
  • Düzeltme yayına alındığında size haber veririz.
  • İzin verirseniz adınızı bu sayfadaki teşekkür listesine ekleriz.

Kapsam

Aşağıdaki ürün ve alan adları için bildirim kabul ediyoruz:

  • onysoft.com — Kurumsal site, müşteri paneli, alan adı ve hosting satın alma/ödeme akışı
  • OnySoft AI Gateway — api.onysoft.com — yapay zeka API ağ geçidi
  • OnyAgent — agent.onysoft.com.tr ve izleme ajanı yazılımı
  • OnyDesk — onydesk.com ve uzak masaüstü uygulaması
  • OnySoft HR — ik.onysoft.com.tr — bulut İK ve bordro
  • OnyTransfer — transfer.onysoft.com.tr — dosya transferi

Listede olmayan bir OnySoft alan adıyla ilgili bir bulgunuz varsa yine bildirin; inceleriz.

Kapsam dışı

  • Üçüncü taraf hizmetler: bankaların ve ödeme kuruluşlarının ödeme sayfaları, alan adı kayıt otoriteleri (registry) ve kayıt kuruluşları (registrar), bulut sağlayıcıların kendi altyapısı ve kullandığımız hazır yazılımların (ör. hosting kontrol paneli) kendisindeki açıklar. Bunları ilgili kuruluşa bildirin.
  • Müşterilerimizin bizde barındırdığı kendi web siteleri ve içerikleri.
  • Tek başına gerçek bir güvenlik etkisi göstermeyen bulgular: eksik bir güvenlik başlığı, sürüm bilgisinin görünmesi, hassas işlem içermeyen sayfalarda clickjacking, SPF/DMARC yapılandırma önerileri, yalnız sizi etkileyen self-XSS.
  • Doğrulanmamış otomatik tarayıcı çıktıları.

Test kuralları

  • Müşteri verilerine erişmeyin, değiştirmeyin, silmeyin. Yanlışlıkla eriştiyseniz durun; açığı kanıtlamaya yetecek kadarından fazlasına bakmayın, veriyi saklamayın, kimseyle paylaşmayın ve bize hemen bildirin.
  • Yalnız kendi hesaplarınızla test yapın.
  • Hizmeti aksatabilecek testler yapmayın: DoS/DDoS, yük testi, yoğun otomatik tarama, spam.
  • Sosyal mühendislik (oltalama, telefonla kandırma) ve fiziksel erişim denemeyin; çalışanlarımızı ve müşterilerimizi hedef almayın.
  • Ödeme altyapısını kötüye kullanmayın; başkasına ait kartla işlem yapmayın, kart numarası denemesi (card testing) yapmayın.
  • Bulguyu düzeltilmeden ve bizimle anlaşmadan kamuya açıklamayın, üçüncü kişilerle paylaşmayın.

İyi niyet beyanı

Bu sayfadaki kurallara uyarak iyi niyetle araştırma yapan ve bulgularını bize bildiren kişilere karşı hukuki işlem başlatmaz, resmi makamlara şikâyette bulunmayız. Bir testin bu kurallara uyup uymadığından emin değilseniz, denemeden önce bize yazın.

Ödül

Para ödülü veren bir hata ödülü (bug bounty) programımız yok. Geçerli bir açık bildirenleri, izin verirlerse aşağıdaki teşekkür listesinde adıyla anarız.

Uyguladığımız güvenlik önlemleri

  • Şifreli bağlantı: onysoft.com yalnız HTTPS üzerinden çalışır; HTTP istekleri HTTPS'e yönlendirilir ve HSTS kullanılır.
  • Kart verisi: Kart bilgileri sunucularımıza ulaşmaz ve bizde saklanmaz; ödemeler bankanın veya ödeme kuruluşunun güvenli ödeme sayfasında alınır.
  • Parolalar: onysoft.com hesap parolaları düz metin olarak saklanmaz; tuzlanmış, tek yönlü bcrypt özeti olarak tutulur.
  • Erişim kontrolü: Yönetim panellerine yalnız yetkili hesaplar giriş yapabilir. Müşteri paneli, ödeme ve yönetim panellerindeki işlem formlarında CSRF koruması; onysoft.com hesap girişinde IP ve hesap başına deneme sınırı uygulanır.
  • Barındırma: onysoft.com (müşteri paneli dahil) ve onydesk.com İzmir'deki (Türkiye) sunucularda çalışır. OnySoft AI Gateway (api.onysoft.com), OnyAgent, OnySoft HR, OnyTransfer ve sattığımız web hosting hizmetleri Microsoft Azure'un Batı Avrupa (Hollanda) bölgesindeki sunucularda barındırılır.
  • KVKK: Kişisel veriler 6698 sayılı KVKK kapsamında işlenir. Aydınlatma metni · Veri sahibi başvurusu

Teşekkür listesi

Henüz kayıt yok.

Bu politika hakkında

Bu politikayı zaman zaman güncelleyebiliriz; son güncelleme tarihi sayfanın başında yer alır. Makine tarafından okunabilir iletişim bilgisi: /.well-known/security.txt

English

Security lead

Ali Eren Onyıl (Founder & CEO) is responsible for product and infrastructure security at OnySoft.

How to report

Email your report to info@onysoft.com with the subject line “Security Report” (or “Güvenlik Bildirimi”). Please include:

  • The affected product, domain or URL
  • The type of vulnerability and its potential impact
  • Step-by-step instructions to reproduce it
  • Evidence: request/response samples, screenshots or a proof of concept (PoC)
  • How we can reach you, and whether you would like to be named in our acknowledgments

Do not include other people's personal data, passwords or access keys in your report; mask them if they are needed as evidence.

Our process and commitments

  • We acknowledge your report within 3 days.
  • We share the outcome of our review and, if the vulnerability is confirmed, our plan to fix it, and keep you informed throughout.
  • We let you know when the fix has been deployed.
  • With your permission, we add your name to the acknowledgments on this page.

Scope

We accept reports for the following products and domains:

  • onysoft.com — Corporate website, customer panel, domain and hosting purchase/payment flow
  • OnySoft AI Gateway — api.onysoft.com — AI API gateway
  • OnyAgent — agent.onysoft.com.tr and the monitoring agent software
  • OnyDesk — onydesk.com and the remote desktop application
  • OnySoft HR — ik.onysoft.com.tr — cloud HR and payroll
  • OnyTransfer — transfer.onysoft.com.tr — file transfer

If you find an issue on an OnySoft domain that is not listed here, please report it anyway; we will review it.

Out of scope

  • Third-party services: payment pages of banks and payment providers, domain registries and registrars, the infrastructure of cloud providers themselves, and vulnerabilities in off-the-shelf software we use (e.g. the hosting control panel). Please report these to the respective provider.
  • Our customers' own websites and content hosted with us.
  • Findings with no demonstrated security impact on their own: a missing security header, visible version information, clickjacking on pages without sensitive actions, SPF/DMARC configuration suggestions, self-XSS that only affects you.
  • Unverified output from automated scanners.

Rules of engagement

  • Do not access, modify or delete customer data. If you access it by accident, stop, view no more than is needed to demonstrate the issue, do not keep or share it, and tell us immediately.
  • Test only with your own accounts.
  • Do not run tests that could disrupt the service: DoS/DDoS, load testing, high-volume automated scanning, spam.
  • Do not attempt social engineering (phishing, vishing) or physical access, and do not target our employees or customers.
  • Do not abuse the payment infrastructure: do not make transactions with cards that are not yours, and do not attempt card testing (trying card numbers).
  • Do not disclose the finding publicly or share it with third parties before it is fixed and we have agreed on disclosure.

Safe harbor

We will not take legal action against, or file a complaint with the authorities about, anyone who researches in good faith, follows the rules on this page and reports their findings to us. If you are unsure whether a test is within these rules, ask us before you try it.

Rewards

We do not run a paid bug bounty program. With their permission, we name people who report valid vulnerabilities in the acknowledgments below.

Security measures in place

  • Encrypted connections: onysoft.com is served only over HTTPS; HTTP requests are redirected to HTTPS and HSTS is enabled.
  • Card data: Card details never reach our servers and are not stored by us; payments are taken on the secure payment page of the bank or payment provider.
  • Passwords: onysoft.com account passwords are never stored in plain text; they are kept as salted, one-way bcrypt hashes.
  • Access control: Only authorized accounts can sign in to the admin panels. State-changing forms in the customer panel, checkout and admin panels are protected against CSRF, and sign-in to onysoft.com accounts is rate-limited per IP and per account.
  • Hosting: onysoft.com (including the customer panel) and onydesk.com run on servers in İzmir, Türkiye. The OnySoft AI Gateway (api.onysoft.com), OnyAgent, OnySoft HR, OnyTransfer and the web hosting we sell are hosted on servers in Microsoft Azure's West Europe region (Netherlands).
  • Data protection: Personal data is processed under the Turkish Personal Data Protection Law No. 6698 (KVKK). Privacy notice (Turkish) · Data subject requests (Turkish)

Acknowledgments

No entries yet.

About this policy

We may update this policy from time to time; the last updated date is shown at the top of the page. Machine-readable contact information: /.well-known/security.txt