LEGAL INFORMATION

Information Security Policy

At Bilnet Yazılım Teknolojileri A.Ş., we consider the security of information belonging to our customers, business partners and employees — and of the systems that process it — a fundamental part of our corporate responsibility. This English version is provided for information purposes; in the event of any discrepancy, the Turkish version prevails.

Last updated:

Purpose and Scope

The purpose of this policy is to protect our information assets against internal and external threats and to ensure the continuity of our operations. It covers all of our activities — including software development, cloud and infrastructure services, SaaS products and support processes — as well as our employees and the suppliers who access information.

Our Core Principles

  • Confidentiality: ensuring that information is accessed only by authorized people, to the extent they need it.
  • Integrity: protecting the accuracy and completeness of information and preventing unauthorized changes.
  • Availability: ensuring that information and services are accessible to authorized users when needed.

Our Commitments

  • Identifying information assets, assessing risks regularly and reducing them to an acceptable level.
  • Defining access rights based on roles and the principle of least privilege, and reviewing them regularly.
  • Encrypting sensitive data in transit and at rest.
  • Applying secure software development principles and including code reviews, dependency checks and vulnerability scans in the development process.
  • Monitoring systems, logging security events and responding to them quickly.
  • Preparing and testing business continuity and disaster recovery plans.
  • Expecting the same level of security care from our suppliers and business partners, and securing this through contracts.
  • Raising our employees' information security awareness through regular training.

Legal Compliance and Standards

We comply with applicable legislation — first and foremost Turkish Personal Data Protection Law No. 6698 — and with our contractual obligations. We run and continuously improve our information security management system based on the requirements of the ISO/IEC 27001 standard.

Reporting Security Incidents

If you believe you have discovered a security vulnerability or incident in our systems, please report it to info@bilnet.com.tr. Reports are handled confidentially and assessed as quickly as possible.

Responsibility and Review

Senior management is responsible for implementing this policy, and all employees are required to comply with it. The policy is reviewed and updated regularly in line with changing risks, technologies and legal requirements.