Skip to main content
Responsible disclosure

Security Vulnerability Reporting

Published: 29 August 2026

If you believe you have found a security vulnerability affecting evrenbal.com, please report it through the channel below. This policy is a practical contact guide for a personal website, not a security certification or assurance.

How to report

You can reach me at the address below to report a security issue. In the address, [at] represents the at sign and [dot] represents a period.

hello [at] evrenbal [dot] com

Thank you for taking the time to report it. Including “[security] evrenbal.com” in the subject, together with the affected URL, a short description, safe reproduction steps, and the likely impact will make the report easier to review. For your safety, please avoid sharing passwords or personal data, and do not send attack code or sensitive output beyond what is needed to demonstrate the issue.

Scope

This process covers suspected vulnerabilities in the publicly served evrenbal.com website. Third-party platforms and services are governed by their own disclosure processes unless the issue is caused by this site's configuration or integration.

Responsible testing

A security.txt file does not grant authorization to test. Do not access or alter other people's data, disrupt the site, use social engineering, phishing or spam, perform denial-of-service activity, run high-volume automated scans, or violate privacy or applicable law.

How reports are handled

This is a personal site with no guaranteed response or remediation time. I will review good-faith reports when reasonably able, may ask for more information, and will prioritize changes according to the apparent risk. There is no bug bounty or promised reward.

Sensitive information

No public encryption key is currently provided for this address. If a finding is highly sensitive, send only a minimal initial description and avoid unnecessary secrets or personal data until a suitable exchange method is agreed.

Limits of this policy

Publishing this contact route does not mean that the site has been independently audited, is free of vulnerabilities, or conforms to OWASP or another security standard.

Machine-readable record and reference