URLy
Ana Sayfa Nasıl Çalışır? Güvenlik İhlal Bildir Tehdit SSS İletişim Yasal
EnglishEnglishTürkçeTürkçe✓GermanDeutschFrenchFrançaisSpanishEspañolRussianРусскийArabicالعربية
Giriş Yap Kayıt Ol
🏠 Ana Sayfa ℹ️ Nasıl Çalışır? 🛡️ Güvenlik 🚨 İhlal Bildir Tehdit ❓ SSS 💬 İletişim 📜 Yasal
Giriş Yap Kayıt Ol

📜 Yasal Belgeler 26 Belge

Hizmet & Genel Kullanım
  • 📜 01. Hizmet Şartları (Terms of Service)
  • 🚫 02. Kabul Edilebilir Kullanım Politikası (AUP)
  • ⚖️ 16. İçerik Moderasyonu & İfade Özgürlüğü
Gizlilik & Veri Koruma (KVKK / GDPR)
  • 🛡️ 03. Genel Gizlilik Politikası (Global Privacy)
  • 🍪 04. Çerez Politikası (Cookie Policy)
  • ⏱️ 06. Veri Saklama ve Silme Takvimi
  • 🇹🇷 10. KVKK Genel Aydınlatma Metni (Türkiye)
  • 🇪🇺 11. GDPR (EEA & UK) Gizlilik Bildirimi
  • 👤 13. İlgili Kişi / Veri Sahibi Başvuru Prosedürü
  • 🌐 14. Alt Veri İşleyenler (Subprocessors) Listesi
  • ✍️ 23. Açık Rıza Metni (Türkçe)
  • ✍️ 24. Explicit Consent Statement (İngilizce)
Bilgi Güvenliği & Zafiyet Bildirimi
  • 🔒 07. Bilgi Güvenliği Politikası
  • 🚸 12. Çocuk Güvenliği & CSAM Önleme Politikası
  • 🎯 15. Güvenlik Açığı Bildirim Politikası (VDP)
  • 💻 18. Güvenlik Sayfası Spesifikasyonu
  • 📑 19. RFC 9116 security.txt Standardı
Yasal Talepler & Kolluk Süreçleri
  • 🚨 05. Kötüye Kullanım (Abuse) Prosedürü
  • ©️ 08. Telif Hakkı & DMCA/FSEK Kaldırma Bildirimi
  • 🏛️ 09. Kolluk Kuvvetleri & Adli Makamlar Kılavuzu
  • 📊 17. Şeffaflık Raporu Çerçevesi
Resmi Başvuru Form Standartları
  • 📝 20. KVKK & Gizlilik Başvuru Formu Kılavuzu
  • ⚠️ 21. Kötüye Kullanım (Abuse) Bildirim Formu
  • 🏷️ 22. Telif & Marka İhlali Bildirim Formu
Master Arşiv & Teknik Kılavuzlar
  • 📌 25. Hukuki Paket Özeti & Devir Notu (README)
  • 📚 26. Konsolide Master Hukuk Metni & Teknik Ek
🎯 Bilgi Güvenliği & Zafiyet Bildirimi ✍️ İlgili Başvuru Kanalı →

15. Güvenlik Açığı Bildirim Politikası (VDP)

🏢 Firma Life 📍 Selçuklu / Konya, Türkiye ⚖️ Konya Mahkemeleri 📑 15_Vulnerability_Disclosure.txt

Vulnerability Disclosure Policy

URly / urly.tr

Authoritative English version • Effective date: [INSERT EFFECTIVE DATE]

This Policy provides a responsible channel for security researchers to report vulnerabilities.

1. Contact

Report vulnerabilities to abuse@urly.tr.

2. Good-faith testing

Limit testing to what is necessary to demonstrate the issue.

3. Prohibited testing

Do not access, modify, delete or expose other users’ data.

Do not conduct destructive or denial-of-service testing.

Do not deploy malware or persistence.

Do not social-engineer staff or users.

Do not extort or threaten URLy.

Do not publish sensitive details before reasonable coordination.

4. Short Link testing

Redirect and URL handling tests must avoid harming third parties and must not be used to facilitate real-world abuse.

5. Proof of concept

Provide concise reproduction steps and evidence. Redact personal data and secrets.

6. Credentials and secrets

Do not send passwords, API keys or other live secrets in a report. If accidentally exposed, notify URLy immediately without redistributing them.

7. Handling

URLy may acknowledge, investigate, request clarification, remediate or close a report.

8. Severity

Severity may consider impact, exploitability, affected scope, user exposure and realistic abuse potential.

9. Duplicates

Duplicate reports may be linked to an existing investigation.

10. Third-party vulnerabilities

Issues caused solely by third-party systems may be redirected to the relevant provider.

11. Bug bounty

No monetary reward is promised unless expressly announced.

12. Safe-harbor intent

URLy intends to avoid unnecessary legal escalation for good-faith research following this Policy, to the extent permitted by law. This is not a legal waiver.

13. Coordinated disclosure

Researchers are encouraged to coordinate publication where sensitive details could create user risk.

Legal entity: Firma Life, Horozluhan Mah. Öksüz Cad. No: 168, Selçuklu / Konya, Türkiye
Contact: support@urly.tr • Abuse & security: abuse@urly.tr • Legal, privacy, copyright & trademark: legal@urly.tr
Governing law: Republic of Türkiye. Jurisdiction: competent courts and enforcement offices of Konya, Türkiye, subject to mandatory applicable law.

Scope examples

Examples include authentication bypass, authorization flaws, SQL injection, XSS, SSRF, insecure direct object references, sensitive-data exposure, API-key disclosure and Short Link security flaws.

Out-of-scope examples

Purely informational issues without meaningful security impact, unsupported third-party systems and social-engineering attempts against personnel may be out of scope.

Privacy

Researchers must minimize access to personal data and promptly stop testing if real user data is encountered.

Rate-limit testing

Do not intentionally exhaust production resources. Use low-volume demonstrations or coordinate a safer test where possible.

SSRF testing

Do not probe internal services or metadata endpoints beyond what is necessary to establish the vulnerability.

Account takeover

Do not use another person’s credentials. If a vulnerability demonstrates takeover potential, stop before accessing unrelated data.

Disclosure timeline

URLy may coordinate a disclosure timeline based on severity and remediation status.

Recognition

URLy may acknowledge valid reports at its discretion but does not promise public credit.

Emergency vulnerabilities

Critical vulnerabilities may require immediate temporary restrictions or emergency maintenance.

Security.txt

The public security.txt file should point to the security page and abuse reporting address.

Hukuki Not & İletişim Kanalları:
Bu metin Firma Life tarafından yürürlüğe konulmuştur. Türkiye Cumhuriyeti kanunlarına tabidir. Haklarınızı kullanmak, itiraz bildirmek veya resmi müzekkere iletmek için yukarıdaki iletişim kanallarından ilgili departmanla temas kurabilirsiniz.

Destek: support@urly.tr • Kötüye Kullanım: abuse@urly.tr • Hukuk & KVKK: legal@urly.tr • Güvenlik (RFC 9116): security@urly.tr
URLy

URLy.tr, bağlantılarınızı kısaltan, detaylı analizler ve 500px yüksek çözünürlüklü QR kodlar sunan yeni nesil global link yönetim servisidir.

Created by FirmaLife Creative

Hızlı Bağlantılar

  • Ana Sayfa
  • Nasıl Çalışır?
  • SSS
  • İletişim
  • Panelim

Yasal & Güvenlik

  • Kullanım Koşulları
  • Gizlilik & Çerez Politikası
  • KVKK Aydınlatma Metni
  • GDPR / EEA Compliance
  • Çerez Politikası
  • 📜 26 Yasal Belge Merkezi

Güvenlik & Tehdit Masası

Zararlı bağlantı, kimlik avı (phishing) veya kötüye kullanım şikayetlerinizi anında bildirin.
  • 🛡️ Bilgi Güvenliği Politikası
  • 🚨 Kötüye Kullanım Bildir
  • 📩 support@urly.tr
  • 📄 RFC 9116 security.txt
🔒 256-Bit TLS & Çok Katmanlı Güvenlik
© 2026 URLy.tr — Tüm hakları saklıdır.
Bu proje bir FirmaLife Creative iştirakidir.