EresusSecurity
ComplianceSolutions

KVKK Penetration Testing

Penetration testing that shows whether the technical measures required by Article 12 of Turkey's data protection law (KVKK, Law No. 6698) actually stop unauthorized access to personal data.

Risk & Regulation Signals

Personal data reachable through broken object-level authorization in APIs.

Technical measures that exist on paper but have never been tested against an attacker.

AI assistants and RAG systems leaking personal data from connected sources.

Built For

Data controllers processing customer, patient, or employee data in Türkiye.

Teams preparing evidence of technical measures for the KVKK Board or an audit.

Product and platform teams whose web apps, APIs, or AI assistants touch personal data.

Use Cases

01

Test authorization on every endpoint that returns personal data (IDOR / BOLA).

02

Validate that access logs, masking, and encryption hold up under a real attack path.

03

Map findings to the technical measures listed in the KVKK Personal Data Security Guide.

AI Security Starter Training

Request a practical checklist for prompt injection, RAG data leakage, MCP risks, and model-file security before launch.

Prompt injection and guardrail bypass checks.
RAG data leakage and permission-boundary review.
MCP identity, transport, and command-risk controls.

No spam. Used only to send the resource and related security notes.

Frequently Asked Questions

Does KVKK require penetration testing?

Article 12 of Law No. 6698 obliges data controllers to take the technical and administrative measures needed to prevent unlawful access to personal data. The KVKK Personal Data Security Guide lists penetration testing among those technical measures and states that vulnerability scans and penetration tests should be performed regularly. The law does not set a fixed frequency.

What do we receive at the end?

A report where each finding has reproduction steps, evidence, the affected personal data category, remediation direction, and retest notes, so it can serve as evidence of tested technical measures.

Need help validating this attack surface?

Talk with Eresus Security about scoped testing, threat modeling, and remediation priorities for this workflow.

Talk to Eresus