Found a hole? Tell us.
We run a payment system for people who cannot afford to be exposed, on a small stack we maintain ourselves. If you have found a way to break it, we would much rather hear it from you than from a customer.
How to report
Send it here
dev@buyukesim.comOne email is enough. Tell us what you found, how to reproduce it, and what an attacker could do with it. A rough note beats a polished report you never send. Write in English or Turkish.
The same address is published machine-readably at /.well-known/security.txt
What you get back
What we promise
A human reply
This is a small team, not a triage desk. We aim to answer within a few days, and we will tell you plainly whether we think it is a real issue - including when we think it is not.
No legal threats
We will not pursue legal action, or ask anyone else to, over good-faith research that follows this page. If you stay inside these rules, you have nothing to fear from us.
Credit if you want it
Say the word and we will name you once it is fixed. Say nothing and we keep you out of it. We will not publish your name without asking.
Scope
What counts
In scope
- buyukesim.com and everything under it
- The order API and the payment and webhook endpoints
- The MCP endpoint at mcp.buyukesim.com
- The Telegram bot
- Our Tor onion mirror
Out of scope
- Our suppliers, carriers and payment processors - report those to them
- Missing headers or a scanner grade with no exploit behind it
- Denial of service, load testing and traffic floods
- Anything needing physical access or a stolen device
- Social engineering aimed at us, our customers or our suppliers
The rules
What not to do
These are not legal boilerplate. Each one is here because breaking it would hurt a real customer or cost us money we would rather spend on the fix.
- Do not touch data that is not yours. If you reach another customer's order, stop and tell us what you saw - do not collect it.
- Do not place fake orders to test payment flows. Ask us and we will help you test safely.
- Do not run automated scanners at volume against the live site.
- Do not degrade the service for customers. If a test would take the site down, describe it instead of running it.
- Give us a reasonable chance to fix it before you publish.
Why the scanner rule is not boilerplate
In July 2026 an automated scan created 95 junk orders and burned through our support budget in an afternoon. Nothing was breached and no customer lost anything, but the cleanup was real and the bill was real. Point a scanner at us and it will be blocked, and you will most likely find nothing but noise. Testing by hand finds more anyway.
We do not pay bounties
We would rather tell you that up front than dress it up. There is no bounty program and no payout, because we are a small operation and pretending otherwise would waste your time. What we can offer is a fast, honest answer, a real fix, and credit if you want it.
