Security and responsible disclosure policy
Last updated:
Short answer: If you find a security vulnerability on markastudio.com.tr, email marka@markastudio.com.tr with the subject “Security report”. We acknowledge the report, investigate it and let you know once it is fixed. The site uses HTTPS/HSTS, a Content Security Policy (CSP) and analytics that stay off until consent. We do not run a paid bug bounty programme.
Scope
This policy covers the markastudio.com.tr domain and all pages under it. Third-party services (form delivery provider, Google Analytics, hosting provider) are subject to their own security policies.
How to report
- Email marka@markastudio.com.tr with the subject “Security report”.
- Include the affected URL, a short description of the issue and steps to reproduce it.
- Machine-readable contact details are in /.well-known/security.txt.
What we ask of you
- Do not access, copy or modify personal data.
- Do not run tests that disrupt the service (load/DoS tests, aggressive automated scanning).
- Do not attempt social engineering or physical access.
- Do not disclose details publicly until the issue is resolved.
Our approach
We welcome reports made in good faith and in line with these principles. We acknowledge the report, investigate the finding and let you know when it is resolved. We do not run a paid bug bounty programme.
Security measures on the site
- All traffic is served over HTTPS; HSTS prevents browsers from connecting without encryption.
- A Content Security Policy (CSP) only allows scripts and connections from approved sources.
- Forms use a hidden honeypot field against automated spam.
- Analytics cookies do not run until you give consent (Google Consent Mode v2).
- Personal data processing is covered by our Privacy Notice and Privacy Policy.