Security Vulnerability Disclosure Policy
Last updated: July 31, 2026 · Next review: July 31, 2027
BrandWallet Digital Technologies LLC operates BrandWallet, a wallet-based loyalty platform for small and medium businesses. We take the security of our platform and of our merchants' data seriously. If you believe you have found a security vulnerability in our systems, we want to hear from you, and this page explains how to report it and what you can expect from us in return.
How to report
Send your report to [email protected].
Please include, where applicable:
- A description of the vulnerability and its potential impact
- The affected URL, endpoint, or component
- Clear, step-by-step instructions to reproduce the issue
- Any supporting evidence: request/response logs, screenshots, or a short video
- Your name or handle, if you would like to be credited publicly
Reports in Turkish or English are both welcome. If you wish to encrypt your report, contact us first and we will provide a key.
Please report the issue to us privately and give us a reasonable opportunity to fix it before disclosing it publicly or to any third party.
Scope
In scope
- brand-wallet.com and its subdomains
- Our public web application and merchant dashboard
- Our public API endpoints
- Our official mobile and wallet-pass integrations
Out of scope
- Systems, websites, and infrastructure operated by our merchants or partners, even where they integrate with BrandWallet
- Third-party services we consume (please report those to the relevant vendor)
- Any system not explicitly listed above — if you are unsure whether an asset is in scope, email us and ask before testing
Rules of engagement
When researching a vulnerability, please:
- Use only your own test accounts and test data
- Stop immediately if you gain access to any data that is not yours, and tell us what you accessed so we can assess the exposure
- Keep your testing to the minimum necessary to demonstrate the issue
The following activities are not authorised under this policy:
- Denial-of-service, stress, load, or volumetric testing
- Accessing, modifying, deleting, exfiltrating, or retaining personal data belonging to our merchants or their customers
- Social engineering, phishing, or physical attacks against our staff, our merchants, or our offices
- Spamming forms, endpoints, or our support channels
- Installing malware, backdoors, or persistence of any kind
- Publicly disclosing the issue, or sharing it with third parties, before we have had a reasonable opportunity to remediate it
Our commitments
If you follow this policy in good faith, we will:
- Acknowledge your report within 3 business days
- Provide an initial assessment, including our severity rating and expected remediation timeline, within 10 business days
- Keep you informed as we work on a fix, and let you know when it is deployed
- Not pursue or support legal action against you in relation to your research, and treat your activity as authorised for the purposes of applicable computer misuse and data protection law
We handle personal data in accordance with our Privacy Policy and applicable KVKK and GDPR obligations. If your report involves personal data, please do not include the data itself — describe it instead.
Recognition
We do not currently operate a paid bug bounty programme and cannot offer monetary rewards. We are glad to credit researchers who report valid issues and who would like to be acknowledged. Let us know in your report whether you would prefer to be named or to remain anonymous.
Commonly reported issues we generally do not treat as vulnerabilities
To help you decide whether an issue is worth your time, the following are usually accepted risks unless you can demonstrate a concrete, exploitable impact:
- Missing security headers with no demonstrated exploit
- Self-XSS, or issues requiring the victim to paste content into their own console
- Clickjacking on pages with no sensitive state-changing action
- Missing rate limiting on endpoints that are not authentication-related
- Outdated software versions with no demonstrated exploitable path
- Raw automated scanner output submitted without a working proof of concept
- SPF, DKIM, or DMARC configuration issues, absent a demonstrated spoofing impact
- Vulnerabilities that require a rooted, jailbroken, or otherwise compromised device, or a physically compromised browser session
- Issues affecting only unsupported or end-of-life browsers
We still read every report, and we would rather receive a borderline one than miss a real issue.
Contact
Our machine-readable contact information is published at /.well-known/security.txt.