URLy
الرئيسية كيف يعمل؟ الأمان إبلاغ عن انتهاك تهديد الأسئلة الشائعة اتصل بنا قانوني
EnglishEnglishTürkçeTürkçeGermanDeutschFrenchFrançaisSpanishEspañolRussianРусскийArabicالعربية✓
تسجيل الدخول إنشاء حساب
🏠 الرئيسية ℹ️ كيف يعمل؟ 🛡️ الأمان 🚨 إبلاغ عن انتهاك تهديد ❓ الأسئلة الشائعة 💬 اتصل بنا 📜 قانوني
تسجيل الدخول إنشاء حساب

📜 Legal Policies 26 Docs

Service & Usage
  • 📜 01. Terms of Service
  • 🚫 02. Acceptable Use Policy
  • ⚖️ 16. Content Moderation & Expression
Privacy & Data Protection
  • 🛡️ 03. Global Privacy Policy
  • 🍪 04. Cookie Policy
  • ⏱️ 06. Data Retention & Deletion Policy
  • 🇹🇷 10. KVKK Privacy Notice (Turkey)
  • 🇪🇺 11. GDPR (EEA & UK) Privacy Notice
  • 👤 13. Data Subject Request Procedure
  • 🌐 14. Subprocessors Disclosure
  • ✍️ 23. Explicit Consent Statement (TR)
  • ✍️ 24. Explicit Consent Statement (EN)
Security & Disclosure
  • 🔒 07. Security Policy
  • 🚸 12. Child Safety & CSAM Policy
  • 🎯 15. Vulnerability Disclosure Policy
  • 💻 18. Security Page Specification
  • 📑 19. RFC 9116 security.txt Standard
Legal Requests & Compliance
  • 🚨 05. Abuse Reporting Procedure
  • ©️ 08. Copyright & DMCA Takedown Policy
  • 🏛️ 09. Law Enforcement Guidelines
  • 📊 17. Transparency Report Framework
Official Submission Forms
  • 📝 20. Privacy & DSR Request Form Spec
  • ⚠️ 21. Abuse Report Form Spec
  • 🏷️ 22. Copyright & Trademark Form Spec
Master Archive & Directives
  • 📌 25. Policy Package Overview (README)
  • 📚 26. Consolidated Master Policy & Alignment
🎯 Security & Disclosure ✍️ Related Submission Channel →

15. Vulnerability Disclosure Policy

🏢 Firma Life 📍 Selçuklu / Konya, Türkiye ⚖️ Konya Mahkemeleri 📑 15_Vulnerability_Disclosure.txt

Vulnerability Disclosure Policy

URly / urly.tr

Authoritative English version • Effective date: [INSERT EFFECTIVE DATE]

This Policy provides a responsible channel for security researchers to report vulnerabilities.

1. Contact

Report vulnerabilities to abuse@urly.tr.

2. Good-faith testing

Limit testing to what is necessary to demonstrate the issue.

3. Prohibited testing

Do not access, modify, delete or expose other users’ data.

Do not conduct destructive or denial-of-service testing.

Do not deploy malware or persistence.

Do not social-engineer staff or users.

Do not extort or threaten URLy.

Do not publish sensitive details before reasonable coordination.

4. Short Link testing

Redirect and URL handling tests must avoid harming third parties and must not be used to facilitate real-world abuse.

5. Proof of concept

Provide concise reproduction steps and evidence. Redact personal data and secrets.

6. Credentials and secrets

Do not send passwords, API keys or other live secrets in a report. If accidentally exposed, notify URLy immediately without redistributing them.

7. Handling

URLy may acknowledge, investigate, request clarification, remediate or close a report.

8. Severity

Severity may consider impact, exploitability, affected scope, user exposure and realistic abuse potential.

9. Duplicates

Duplicate reports may be linked to an existing investigation.

10. Third-party vulnerabilities

Issues caused solely by third-party systems may be redirected to the relevant provider.

11. Bug bounty

No monetary reward is promised unless expressly announced.

12. Safe-harbor intent

URLy intends to avoid unnecessary legal escalation for good-faith research following this Policy, to the extent permitted by law. This is not a legal waiver.

13. Coordinated disclosure

Researchers are encouraged to coordinate publication where sensitive details could create user risk.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Scope examples

Examples include authentication bypass, authorization flaws, SQL injection, XSS, SSRF, insecure direct object references, sensitive-data exposure, API-key disclosure and Short Link security flaws.

Out-of-scope examples

Purely informational issues without meaningful security impact, unsupported third-party systems and social-engineering attempts against personnel may be out of scope.

Privacy

Researchers must minimize access to personal data and promptly stop testing if real user data is encountered.

Rate-limit testing

Do not intentionally exhaust production resources. Use low-volume demonstrations or coordinate a safer test where possible.

SSRF testing

Do not probe internal services or metadata endpoints beyond what is necessary to establish the vulnerability.

Account takeover

Do not use another person’s credentials. If a vulnerability demonstrates takeover potential, stop before accessing unrelated data.

Disclosure timeline

URLy may coordinate a disclosure timeline based on severity and remediation status.

Recognition

URLy may acknowledge valid reports at its discretion but does not promise public credit.

Emergency vulnerabilities

Critical vulnerabilities may require immediate temporary restrictions or emergency maintenance.

Security.txt

The public security.txt file should point to the security page and abuse reporting address.

Legal Notice & Contacts:
This document is issued by Firma Life under Turkish law. For official inquiries or data subject rights, please contact the designated department above.

Destek: support@urly.tr • Kötüye Kullanım: abuse@urly.tr • Hukuk & KVKK: legal@urly.tr • Güvenlik (RFC 9116): security@urly.tr
URLy

URLy.tr هي منصة متطورة لإدارة الروابط وتوليد رموز QR فائقة الدقة 500px مع تحليلات متقدمة.

Created by FirmaLife Creative

روابط سريعة

  • الرئيسية
  • كيف يعمل؟
  • الأسئلة الشائعة
  • اتصل بنا
  • لوحة التحكم

القانونية والأمان

  • شروط الاستخدام
  • الخصوصية وملفات تعريف الارتباط
  • إشعار حماية البيانات (KVKK)
  • GDPR / EEA Compliance
  • Cookie Policy
  • 📜 26 Yasal Belge Merkezi

Trust & Safety

Report suspicious links, phishing, malware, or brand abuse.
  • 🛡️ Security Policy
  • 🚨 Report Abuse
  • 📩 support@urly.tr
  • 📄 RFC 9116 security.txt
🔒 256-Bit TLS & Çok Katmanlı Güvenlik
© 2026 URLy.tr — جميع الحقوق محفوظة.
هذا المشروع تابع لـ FirmaLife Creative الإبداعية.