KolayIK · Vulnerability Disclosure

Kolayik Vulnerability Disclosure

Vulnerability disclosure

KolayIK runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyHuman ResourcesHRPayrollHCMEmployee ManagementTime and AttendanceApplicant TrackingSoftware-as-a-ServiceTurkey
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Contact
bilgiguvenligi@kolayik.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-19'
method: searched
probe: true
found: false
policy: []
contact:
- bilgiguvenligi@kolayik.com
security_policy_page: https://kolayik.com/bilgi-guvenligi-politikasi
bug_bounty:
  program: null
  platform: null
  found: false
evidence:
- source: https://kolayik.com/bilgi-guvenligi-politikasi
  kind: information-security-policy
  detail: Published information security policy naming TS ISO/IEC 27001:2013, TS ISO/IEC
    27701:2019 and TS EN/ISO 9001:2015 certifications maintained through annual audits,
    with bilgiguvenligi@kolayik.com given as the security contact.
- source: https://kolayik.com/.well-known/security.txt
  kind: security.txt
  status: 404
  detail: No RFC 9116 security.txt is published.
notes:
- 'Kolay İK publishes a security policy page and a security contact address, but no
  formal vulnerability disclosure policy, coordinated-disclosure process, safe-harbour
  statement, or bug bounty program (HackerOne / Bugcrowd / Intigriti) was found. The
  `VulnerabilityDisclosure` pointer is therefore withheld; a `Security` pointer to
  the published security policy is wired in apis.yml.'
gaps_to_raise_with_provider:
- Publish /.well-known/security.txt (RFC 9116) with Contact and Policy fields.
- Publish a coordinated vulnerability disclosure policy with response-time expectations.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/kolayik-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.