Vulnerability Disclosure Policy
URly / urly.tr
Authoritative English version • Effective date: [INSERT EFFECTIVE DATE]
This Policy provides a responsible channel for security researchers to report vulnerabilities.
1. Contact
Report vulnerabilities to abuse@urly.tr.
2. Good-faith testing
Limit testing to what is necessary to demonstrate the issue.
3. Prohibited testing
Do not access, modify, delete or expose other users’ data.
Do not conduct destructive or denial-of-service testing.
Do not deploy malware or persistence.
Do not social-engineer staff or users.
Do not extort or threaten URLy.
Do not publish sensitive details before reasonable coordination.
4. Short Link testing
Redirect and URL handling tests must avoid harming third parties and must not be used to facilitate real-world abuse.
5. Proof of concept
Provide concise reproduction steps and evidence. Redact personal data and secrets.
6. Credentials and secrets
Do not send passwords, API keys or other live secrets in a report. If accidentally exposed, notify URLy immediately without redistributing them.
7. Handling
URLy may acknowledge, investigate, request clarification, remediate or close a report.
8. Severity
Severity may consider impact, exploitability, affected scope, user exposure and realistic abuse potential.
9. Duplicates
Duplicate reports may be linked to an existing investigation.
10. Third-party vulnerabilities
Issues caused solely by third-party systems may be redirected to the relevant provider.
11. Bug bounty
No monetary reward is promised unless expressly announced.
12. Safe-harbor intent
URLy intends to avoid unnecessary legal escalation for good-faith research following this Policy, to the extent permitted by law. This is not a legal waiver.
13. Coordinated disclosure
Researchers are encouraged to coordinate publication where sensitive details could create user risk.
Scope examples
Examples include authentication bypass, authorization flaws, SQL injection, XSS, SSRF, insecure direct object references, sensitive-data exposure, API-key disclosure and Short Link security flaws.
Out-of-scope examples
Purely informational issues without meaningful security impact, unsupported third-party systems and social-engineering attempts against personnel may be out of scope.
Privacy
Researchers must minimize access to personal data and promptly stop testing if real user data is encountered.
Rate-limit testing
Do not intentionally exhaust production resources. Use low-volume demonstrations or coordinate a safer test where possible.
SSRF testing
Do not probe internal services or metadata endpoints beyond what is necessary to establish the vulnerability.
Account takeover
Do not use another person’s credentials. If a vulnerability demonstrates takeover potential, stop before accessing unrelated data.
Disclosure timeline
URLy may coordinate a disclosure timeline based on severity and remediation status.
Recognition
URLy may acknowledge valid reports at its discretion but does not promise public credit.
Emergency vulnerabilities
Critical vulnerabilities may require immediate temporary restrictions or emergency maintenance.
Security.txt
The public security.txt file should point to the security page and abuse reporting address.