Legal · Security

Responsible Security Disclosure

If you have found a security vulnerability, we invite you to share it with us safely and responsibly.

1. Our commitment

We invite security researchers to share their findings with us responsibly. We commit not to pursue legal action against researchers who act in good faith and follow the rules below (safe harbor), and we aim to respond to your reports within a reasonable time.

2. Scope

In scope: semagent.ai and its subdomains, the embedded widget, and public API endpoints.

Out of scope: denial of service (DoS/DDoS), social engineering or phishing, physical attacks, vulnerabilities in third-party services (e.g. our hosting provider), and automated scanner output without demonstrated impact.

3. Research rules

4. How to report

Send your findings to [email protected]. Please include: the type and impact of the vulnerability, reproduction steps, a proof of concept (PoC) if available, and the affected endpoint/parameter. Reports in English or Turkish are welcome.

5. Process

6. Legal

Good-faith security research conducted in line with this policy is considered "authorized," and we will not pursue legal action against you. Failure to follow the rules removes this protection.

Last updated: 8 July 2026