Responsible disclosure
If you identify a vulnerability or exploitable behavior on vciso.tr, send technical details to [email protected]. Where possible, include the affected URL, reproduction steps, expected/actual behavior, and risk explanation.
During security research, do not delete or alter data, disrupt service, access unnecessary personal information, use social engineering, or interfere with third-party systems.
Assessment tools and privacy
Readiness quizzes and governance builders are designed to operate in the browser where practical. No account or email is required to see an assessment result. Unless a tool page explicitly says otherwise, there is no submission flow intended to send questionnaire answers to the server.
Contact form
The contact form processes name, email, and the company/scope information you provide so a response can be sent. The endpoint applies input validation and anti-abuse controls; active production protections depend on deployed configuration. Form data is transmitted through email-delivery infrastructure for advisory communication.
Cookies and analytics
See the Cookie Policy and Privacy Policy for cookie and analytics behavior. This page does not replace those legal notices.
security.txt
A /.well-known/security.txt file is published for automated security-contact discovery.
What we do not guarantee
No internet service can promise absolute security. This page is not a certification claim, penetration-test result, or independent assurance opinion. It may be updated as controls and deployment architecture evolve.