Legal
Security & Vulnerability Disclosure
Good-faith vulnerability reports are welcome. There is no public bounty and no promise of immunity.
- Effective date:
- Pending approval
- Last updated:
- 10 October 2026
Status
Pending legal review. This page is a draft prepared for SaaSInvader. It is not a claim that the platform is certified or compliant with KVKK, GDPR, or any other law.
Draft date: 10 October 2026.
A separate security@ address and a paid bounty program have not been approved.
Reporting a vulnerability
Email info@mhtsoftware.net with a description, the steps to reproduce it, the affected URL, and the impact you believe it has. Do not access unrelated accounts, download other people's data, run destructive tests, use denial-of-service techniques, deploy malware, or publish the issue before there has been a reasonable chance to respond.
A report does not authorize unlawful access and does not grant immunity. Credible reports are acknowledged and assessed according to capacity and legal duties. We do not promise a reward or a formal safe harbor. Use the protections on your account, and tell us if you think someone else has signed in.