Skip to content
Meet Turkuaz VPN — enterprise VPN with Zero-Touch technology, no configuration at the branch →

PONA Product Security and Vulnerability Disclosure Policy (PSIRT)

PONA Teknoloji considers the security of its products a core responsibility as a vendor. This page explains how to report security vulnerabilities in PONA products to us, how reports are handled and how fixes are announced. Our Product Security Incident Response Team (PSIRT) evaluates every report in accordance with this policy.

Scope

This policy covers all products and services developed by PONA Teknoloji: PONIVA Firewall (hardware and software), the PONIVA central management server, Turkuaz VPN appliances, PONIVA XDR, Sectify, GateFi, the Ponarize API and the Cyberthreat Live Map, as well as the mobile and desktop clients for these products. Our corporate website www.pona.com.tr is also in scope.

Out of scope: deployments and networks belonging to our customers (these may not be tested without permission), third-party services, social engineering, physical attacks and denial-of-service (DoS) testing.

How to report

Submit vulnerability reports using the form below or by email to security@pona.com.tr. Reports may be written in English or Turkish. To help us assess your report quickly, please include:

  • The affected product and version number
  • The type of vulnerability and its impact (e.g. unauthenticated command execution)
  • Steps to reproduce, a proof of concept or request/response samples
  • Screenshots or logs, if available
  • How we can contact you, and whether you would like to be named on our acknowledgments page

Vulnerability report form

The form goes directly to our PSIRT team. Fields marked with an asterisk are required.

To send screenshots or proof-of-concept files, email them to security@pona.com.tr quoting your tracking number.

Response times

PSIRT handles reports within the following target times:

  • Initial response and tracking number: within 3 business days
  • Validation and severity rating (CVSS v3.1): within 10 business days
  • Fix for critical and high-severity vulnerabilities: within 30 days of validation
  • Fix for medium and low-severity vulnerabilities: in the next scheduled release, within 90 days at the latest

We keep you informed throughout the process and let you know when a fix is released.

Coordinated disclosure

We follow the principle of coordinated disclosure. Before sharing your findings publicly, we ask that you wait 90 days from the date of your report or until a fix is released, whichever comes first. For actively exploited vulnerabilities, this period can be shortened by mutual agreement. For fixed vulnerabilities we publish a security advisory on this page and in the release notes, listing the affected versions, the fixed version, the severity and any available workarounds. We request CVE IDs for eligible vulnerabilities.

Safe harbor

We consider good-faith security research conducted in accordance with this policy to be authorized. As long as you comply with this policy during your research, PONA Teknoloji will not initiate legal action against you. Good-faith research means: using only systems under your own control or explicitly authorized test environments, limiting data access to the minimum needed to demonstrate the issue, not viewing, modifying or retaining customer data, not causing service disruption, and not sharing the vulnerability with third parties before it is fixed.

Security advisories

No security advisories have been published to date. Published advisories will be listed here.

Product support and updates

PONIVA appliances receive security updates through the automatic update mechanism. We recommend that customers keep automatic updates enabled on their appliances and do not run unsupported versions. For version support and end-of-life dates, contact your reseller or destek@pona.com.tr.

For the list of researchers we thank, see Acknowledgments.

This policy was last updated on 28 September 2026. For machine-readable contact information, see security.txt.