Blog
Blog
Güvenlik ve uyum dökümanlarıSecurity & compliance docs
İş dilinde rehberler ve özellik dökümanları — risk, öncelik, aksiyon.
Business guides and feature docs — risk, priority, action.
-
How Guardbee works: scans, credits, and first steps
Add a brand, choose modules, use credits, and BeeAI. SEO-friendly getting-started documentation for Guardbee.
-
Subdomain takeover risk: dangling DNS and claimable hosting
Dangling CNAMEs and abandoned hosting records create brand-spoofing risk. Documentation for Guardbee subdomain takeover checks.
-
Discovery Surface: robots.txt, sitemap.xml, security.txt, and Technology Fingerprinting
Discovery surface analysis: robots.txt, sitemap.xml, security.txt, and technology fingerprinting. Guardbee reports the same passive signals an attacker can…
-
Third-Party Scripts and JavaScript Supply Chain Security
Explore third-party JavaScript, CDN, npm, SRI, and CSP risks. Learn how JavaScript supply chain attacks work and how…
-
Form security and open redirects: CSRF, autocomplete, and redirect risk
CSRF token signals, insecure autocomplete, passwords over HTTP, and CWE-601 open redirects. Guardbee form and redirect checks.
-
API security scanning: CORS, JWT, GraphQL, and response leaks
API response capture, CORS policy, JWT analysis, GraphQL introspection, and authenticated crawl. Documentation for Guardbee API security features.
-
BeeAI security copilot: explain findings in business language
BeeAI explains Guardbee findings with business impact, priority, and action language. Product documentation for the security copilot.
-
KVKK and privacy scanning: notices, cookie consent, and VERBİS signals
Privacy notices, cookie consent, tracker disclosure, VERBİS, cross-border transfer, and form consent. Comprehensive documentation for Guardbee KVKK modules.
-
AI security scanning: inventory, prompt injection, and data leakage
AI chat widgets, model endpoints, prompt-injection signals, and LLM data leakage. Detailed documentation for Guardbee AI security features.
-
Network and infrastructure security: ports, WAF/CDN, cloud exposure
Open-port signals, WAF/CDN detection, cloud storage exposure, and Firebase config. A business guide to Guardbee network and infrastructure…
-
Website security scanning: what Guardbee checks
HTTPS, SSL, security headers, cookies, sensitive paths, forms, and more. A business-friendly guide to Guardbee website security modules.
-
Why AI security is now a board-level topic
AI assistants embedded on your site create a new attack and data-leakage surface.
-
DNS and Email Security: Your First Line of Defense Against Brand Spoofing
How SPF, DKIM, DMARC and related DNS records protect your brand from spoofing — and what Guardbee checks.
-
Exposed .env and .git: quiet data disasters
Misconfigured servers can expose source code or secrets to the internet — often unnoticed.
-
Cookie security and privacy: trust meets compliance
Insecure cookies enable session risk; transparent consent reduces legal and reputation exposure.
-
Security headers: invisible risks with real cost
Headers like CSP, HSTS, and X-Frame-Options reduce clickjacking and script injection risk.
-
HTTPS and SSL: the first layer of customer trust
Encryption is not just a technical detail — it is a business requirement for trust and conversion.
-
KVKK İYS / Commercial Consent
KVKK İYS / Commercial Consent — Looks for separate commercial electronic communication (İYS) consent controls. Business-friendly documentation for…
-
KVKK Cookie Policy Page
KVKK Cookie Policy Page — Detects a dedicated cookie policy distinct from the general privacy notice. Business-friendly documentation…
-
KVKK Form Minimization
KVKK Form Minimization — Flags public forms that require an excessive number of personal-data fields. Business-friendly documentation for…
-
KVKK Deep PII Patterns
KVKK Deep PII Patterns — Detects card numbers, plates, DOB signals, and PII leaked in URL queries. Business-friendly…
-
KVKK Reject Behavior
KVKK Reject Behavior — Checks reject/essential-only UI and whether trackers still fire on a fresh load. Business-friendly documentation…
-
KVKK Consent Withdrawal
KVKK Consent Withdrawal — Looks for withdraw-consent / manage-cookie-preferences paths. Business-friendly documentation for this Guardbee scan module.
-
KVKK Policy Change
KVKK Policy Change — Tracks privacy-policy changes across scheduled scans. Business-friendly documentation for this Guardbee scan module.
-
KVKK Processor Inventory
KVKK Processor Inventory — Inventories third-party hosts contacted by the page. Business-friendly documentation for this Guardbee scan module.
-
KVKK Consent Runtime
KVKK Consent Runtime — Detects cookies and trackers loaded before opt-in. Business-friendly documentation for this Guardbee scan module.
-
KVKK Sensitive Data
KVKK Sensitive Data — Detects special-category personal data collection. Business-friendly documentation for this Guardbee scan module.
-
KVKK Children Data
KVKK Children Data — Checks age and parental-consent safeguards. Business-friendly documentation for this Guardbee scan module.
-
KVKK Marketing Consent
KVKK Marketing Consent — Checks separation of commercial communication consent. Business-friendly documentation for this Guardbee scan module.