English · Türkçe

Drawoble · Vulnerability Disclosure

Security Policy

We welcome reports from security researchers. This page explains what is in scope, how to report a vulnerability, what to expect from us, and the safe-harbor terms that protect good-faith research.

Effective: 1 January 2026 · Version 1

1. How to report

Send vulnerability reports to security@drawoble.com. Please do not report security issues through public channels, social media, or the general support address.

A useful report includes:

You do not need to prove exploitability beyond what is necessary to demonstrate the issue. A single screenshot or a short proof-of-concept is enough; do not extract, alter, or retain more data than that requires.

2. Scope

In scope

Out of scope

3. What to expect from us

We are a small team and we take security seriously. When you report in good faith under this policy, we commit to:

These are operational commitments to the research community, not a contractual service-level agreement, and they do not form part of any customer contract.

4. Safe harbor

If you make a good-faith effort to comply with this policy during your research, we will consider your research authorised. We will not initiate or support legal action against you in connection with it, and we will not report it to law enforcement. If a third party brings a claim against you for activity that complied with this policy, we will make it known that your activity was authorised.

To stay within safe harbor, you must:

Activity that goes beyond good-faith research — extortion, data theft, service disruption, or accessing other users' data — is not authorised and is not protected by this policy.

5. Rewards

Drawoble does not currently operate a paid bug-bounty program. During private beta we recognise valid reports with credit in our security hall of fame, with your consent and under the name or handle you choose. We would rather be honest that there is no cash reward than have you spend time expecting one.

6. Other contacts

For security vulnerabilities, use security@drawoble.com. For content abuse, copyright takedown, or spam, use abuse@drawoble.com. Please do not use the general user-facing support addresses for security matters.

7. Governing terms

This policy is governed by the laws of the Republic of Türkiye. It is published in Türkçe and English; in case of any conflict between the two language versions, the Türkçe text prevails.