Security and vulnerability disclosure
How to report a security problem in Sunsato BI Studio, what we promise in return, and what we ask of you while you look.
Version 2026-09-18 · last updated 2026-09-18
DRAFT · needs legal and business sign-offThis text has not been reviewed by a lawyer yet. It describes how the product actually works today, but it is not final and should not be relied on as legal advice.
How to report
Email security@sunsato.com with what you found, the steps to reproduce it and the impact you expect. English or Turkish is fine. Please do not include other people's personal data.
What we promise
- we confirm your report within two working days;
- we keep you updated until it is fixed, and tell you when it is;
- we will not take legal action against research done in good faith within these rules;
- with your permission, we credit you once the fix is out.
What we ask
- use your own accounts and workspaces; do not access, change or delete other people's data;
- do not run automated scans or load tests against production; ask us for a test account instead;
- no social engineering, phishing or physical attacks;
- give us reasonable time to fix the problem before you make it public.
Contact
Sunsato · info@sunsato.com. Privacy requests: privacy@sunsato.com. Security reports: security@sunsato.com.