Security Policy
Last Updated: June 9, 2026
1. Purpose
Talnir takes the security of its website, managed email deliverability infrastructure, and client service data seriously. This Security Policy explains how to report security issues, suspected vulnerabilities, or incident-related notices to us.
2. Security Contact
Security reports should be sent to security@talnir.eu. Please do not send security reports through public social media channels or unrelated website forms.
3. What to Report
Please contact us if you believe you have found a vulnerability or security issue affecting Talnir, including:
- Unauthorized access or account/session issues.
- Exposure of personal data, client data, credentials, logs, or configuration secrets.
- Server, DNS, email infrastructure, or web application misconfigurations.
- Authentication, authorization, or access-control weaknesses.
- Abuse, phishing, spoofing, or suspicious activity involving Talnir systems or domains.
4. What to Include
To help us review your report efficiently, please include:
- A clear description of the issue and affected system, page, domain, or service.
- Steps to reproduce the issue, if safe and applicable.
- Evidence such as screenshots, request/response samples, timestamps, or logs, with sensitive data minimized.
- Your contact details so we can ask follow-up questions if needed.
5. Responsible Testing
If you test Talnir systems, you must act responsibly and avoid harming Talnir, its clients, or other users. You agree to:
- Use only the minimum testing needed to confirm the issue.
- Stop testing immediately if you access data that is not yours.
- Keep any discovered information confidential and report it promptly.
- Avoid service disruption, degradation, spam, social engineering, phishing, or physical attacks.
- Do not delete, alter, exfiltrate, or publicly disclose data.
6. Client and Third-Party Systems
Do not test client-owned infrastructure, third-party systems, or accounts that you do not own or have permission to assess. If you believe a report affects infrastructure managed by Talnir for a client, send the report to Talnir and avoid contacting the client publicly unless you are already authorized to do so.
7. How We Handle Reports
Talnir will review good-faith security reports, assess severity and impact, and take appropriate remediation steps. Where a report materially affects managed infrastructure or client service data, we will use reasonable efforts to notify affected clients without undue delay, consistent with our legal and contractual obligations.
8. Good-Faith Reports
We appreciate responsible, good-faith reports that help protect Talnir and its clients. Talnir does not currently operate a public bug bounty or reward program unless separately agreed in writing. Submitting a report does not create an employment, contractor, or service relationship with Talnir.
9. Changes to This Policy
We may update this Security Policy from time to time to reflect changes in our security practices, reporting process, or legal requirements.
Talnir Group | contact@talnir.eu | talnir.eu