Legal & Security
Report a Security Issue
If you've found a security vulnerability in Simit GPT, please contact us for responsible disclosure.
Our users' security is a priority. We are glad to work with security researchers.
How to report
Send your findings to info@cmtedu.com. If possible, include:
- The type of vulnerability and the affected URL or component
- Steps to reproduce and a proof of concept (PoC)
- The potential impact
- Contact details so we can reach you
Our commitments
- We acknowledge your report within 3 business days.
- We keep you informed about assessment and remediation.
- We will not take legal action over research done in good faith and in line with these rules.
- If you wish, we credit your contribution in our acknowledgements after the fix.
Scope
simitgpt.comandwww.simitgpt.com- The Simit GPT web application and API endpoints
Things to keep in mind
The following are outside good-faith security research and are prohibited:
- Running tests that disrupt the service (DoS/DDoS, load tests)
- Accessing, modifying or deleting other users' data
- Social engineering, phishing or physical attacks
- Disclosing the issue publicly before it is fixed
Attempts that break these rules are assessed under the cybercrime provisions of the Turkish Penal Code No. 5237 and related legislation; legal action may be taken.
We don't currently run a paid bug bounty programme.
Simit GPT™. All rights reserved.