Skip to content
Corpshore Türkiye

Legal

Information security policy

Last updated: 20 July 2026

This is a translation provided for convenience; the Turkish version is the governing version.

This policy summarizes Corpshore Türkiye's approach to information security and the controls it applies. The aim is to protect the confidentiality, integrity and availability of the information processed.

Scope and principles

The policy covers customer, candidate and visitor data and corporate information. Information security is built on the principles of confidentiality, integrity and availability and is managed with a risk-based approach.

Access and identity management

Access to information is limited by the need-to-know principle. Access is managed through defined roles, reviewed regularly, and multi-factor authentication is applied on critical systems.

Transfer and storage security

Data transmitted through the site is encrypted during transfer. Form endpoints are protected with server-side validation, rate limiting and bot verification. Secret keys are kept only in server-side environment variables and are not included in the client bundle.

A strict content security policy, security headers and mandatory HTTPS are applied.

Monitoring and incident management

Systems are monitored for security incidents and incidents are handled through a defined response process. Breaches affecting personal data are notified in accordance with the periods and procedures prescribed by legislation.

Supplier security

Data processor suppliers work under appropriate security obligations. File uploads are subject to server-side validation and size limits and, where possible, are scanned for malware.

These documents are drafted to a professional standard and will be reviewed by Turkish legal counsel before going live. They are not legal advice.