If you have found a security vulnerability, we invite you to share it with us safely and responsibly.
We invite security researchers to share their findings with us responsibly. We commit not to pursue legal action against researchers who act in good faith and follow the rules below (safe harbor), and we aim to respond to your reports within a reasonable time.
In scope: semagent.ai and its subdomains, the embedded widget, and public API endpoints.
Out of scope: denial of service (DoS/DDoS), social engineering or phishing, physical attacks, vulnerabilities in third-party services (e.g. our hosting provider), and automated scanner output without demonstrated impact.
Send your findings to [email protected]. Please include: the type and impact of the vulnerability, reproduction steps, a proof of concept (PoC) if available, and the affected endpoint/parameter. Reports in English or Turkish are welcome.
Good-faith security research conducted in line with this policy is considered "authorized," and we will not pursue legal action against you. Failure to follow the rules removes this protection.
Last updated: 8 July 2026