KolayIK · Vulnerability Disclosure

Kolayik Vulnerability Disclosure

Vulnerability disclosure

KolayIK runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyHuman ResourcesHRPayrollHuman Capital ManagementEmployee ManagementTime and AttendanceApplicant TrackingSaaSTurkey
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Contact
bilgiguvenligi@kolayik.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-19'
method: searched
probe: true
found: false
policy: []
contact:
- bilgiguvenligi@kolayik.com
security_policy_page: https://kolayik.com/bilgi-guvenligi-politikasi
bug_bounty:
  program: null
  platform: null
  found: false
evidence:
- source: https://kolayik.com/bilgi-guvenligi-politikasi
  kind: information-security-policy
  detail: Published information security policy naming TS ISO/IEC 27001:2013, TS ISO/IEC
    27701:2019 and TS EN/ISO 9001:2015 certifications maintained through annual audits,
    with bilgiguvenligi@kolayik.com given as the security contact.
- source: https://kolayik.com/.well-known/security.txt
  kind: security.txt
  status: 404
  detail: No RFC 9116 security.txt is published.
notes:
- 'Kolay İK publishes a security policy page and a security contact address, but no
  formal vulnerability disclosure policy, coordinated-disclosure process, safe-harbour
  statement, or bug bounty program (HackerOne / Bugcrowd / Intigriti) was found. The
  `VulnerabilityDisclosure` pointer is therefore withheld; a `Security` pointer to
  the published security policy is wired in apis.yml.'
gaps_to_raise_with_provider:
- Publish /.well-known/security.txt (RFC 9116) with Contact and Policy fields.
- Publish a coordinated vulnerability disclosure policy with response-time expectations.