Scope
This policy covers our site, the customer panel, the systems where test data is stored, and the working environment of the people who carry out testing.
As a security-adjacent business our benchmark is simple: we do not apply less to ourselves than we recommend to our customers.
Governance
A named person is responsible for security, and [email protected] reaches them directly.
We review this policy at least annually, and again after any material change or security incident.
Risks are recorded, each with an owner and a mitigation plan.
Encryption
In transit: TLS 1.2 and above. Legacy protocols and weak cipher suites are disabled. HSTS is enabled.
At rest: AES-256, covering the database, object storage and backups.
Keys are held in a managed key service, kept separate from application code, and rotated on a schedule.
Your credentials sit in a separate encrypted vault; every read from that vault is logged.
Access control
Least privilege applies: nobody has more access than their work requires.
Access to test data is specific to a test and its duration. It closes automatically when the test ends.
We review the access list quarterly. Access for anyone leaving or changing role is revoked the same day.
Direct access to production is an exception; where needed it is granted for a fixed period with a stated reason, and the session is recorded.
Authentication
Multi-factor authentication is mandatory on all internal systems. We do not use SMS as a second factor.
Passwords are generated and stored in a password manager and are never shared.
We recommend keeping multi-factor authentication on for your panel accounts too; it can be enforced on enterprise accounts.
Network and infrastructure
Production systems run in a separate network segment with only the necessary ports exposed.
Administrative interfaces are not reachable from the internet and are accessed only over the corporate VPN.
Infrastructure is defined as code; manual changes are exceptional and are recorded.
Endpoint security
Working devices require full-disk encryption, automatic screen lock, a current operating system and endpoint protection software.
Copying test data to personal devices is prohibited.
A lost or stolen device is reported immediately and wiped remotely.
Personnel security
Core team members sign a confidentiality agreement before starting, and that obligation survives their departure.
Background checks are carried out at hiring to the extent the law permits.
Annual security and data protection training is mandatory, and phishing exercises are repeated regularly.
Tester network security
Every tester passes identity verification and signs a confidentiality undertaking before joining the network.
Testers reach test data only through the controlled panel; they cannot download raw data.
Evidence recordings are written directly to our storage, leaving no persistent copy on a tester’s device.
A tester who breaks the rules is removed from the network immediately and affected customers are notified.
Supplier security
We assess sub-processors on their security practices and do not use a provider that will not sign a data processing agreement.
We review the independent audit reports of critical providers annually.
Logging and monitoring
Authentication, permission change and data access events are logged. Logs are retained for 12 months.
Logs are held in tamper-evident form; no individual account holds delete permission over them.
Alert rules cover unusual access patterns and alerts are monitored around the clock.
Incident response
We maintain a written incident response plan and a defined response team.
The steps are: detection, containment, root cause analysis, remediation, notification and post-incident review.
On a personal data breach we inform you within 24 hours; the detail is in the Data Processing Agreement.
We exercise the plan in a tabletop drill at least once a year.
Backup and continuity
Backups are taken daily, encrypted, and held in a separate region.
Restore testing runs quarterly; taking a backup means nothing until restoring from it has been tested.
Our recovery time objective is 8 hours and our recovery point objective is 24 hours.
Change management
Every change reaching production is reviewed; nobody approves their own change alone.
Dependencies are scanned automatically, and known critical vulnerabilities block a release.
A rollback path is prepared for every deployment.
Vulnerability management
We run regular automated scanning at both infrastructure and application level.
Our remediation targets: critical 7 days, high 30 days, medium 90 days.
We have our own product tested by an independent party once a year. Our own team auditing our own product would contradict the very service we sell.
Retention and destruction
Test data, recordings and credentials are permanently deleted 90 days after a test ends.
A request for earlier deletion is met within 30 days and the deletion record is shared.
Physical media is securely destroyed when decommissioned.
Reporting a vulnerability
If you find a vulnerability in our systems, report it to [email protected]. The rules and our commitments are on the Responsible Disclosure page.
We take no legal action over reports made in good faith.
These documents are published in English and Turkish. In the event of conflict the Turkish text prevails.