SCNET · Enterprise IT · Ankara, Türkiye

Sanal Çekirdek

Verify first. Then publish.

A trust center is the single page where a technology provider presents its security, privacy, and accuracy practices in a verifiable form. The Sanal Çekirdek trust center publishes verified information only; unverified certificates, figures, or references do not appear in it. Documents are listed in the trust center with their date and scope as each one completes verification.

This page is written for security, procurement, and IT leaders who evaluate suppliers. It is not an inventory of badges; it is a public commitment that describes what gets published, under which conditions, and how questions are answered with evidence.

Publication principle: verify first

Information enters the trust center only after its source document has been verified. Topics awaiting a corporate decision or an ongoing verification process are not published as claims; once the process is complete, the item is added with its date and scope. The same principle governs removal: information that is no longer valid is updated or taken down.

  • No unverified certificates, figures, or references
  • Every item is added with source, date, and scope
  • Pending topics never turn into claims
  • Updates are tracked in a change log

Secure working practices

Security work is carried out only under explicit written authorization, a defined scope, a time window, and stop conditions. Access follows the principle of least privilege, and the duties of Sanal Çekirdek, the customer, and third parties are written into a RACI or equivalent responsibility matrix.

  • Written authorization, defined scope, emergency stop
  • Least privilege and controlled access
  • RACI or equivalent responsibility matrix
  • Change and incident records
  • Findings reported with evidence and business impact

Data residency and privacy

Sanal Çekirdek does not claim to own a data center facility; for hosting and cloud services, enterprise-class third-party facility and platform capacity is selected according to workload requirements. Provider names and evidence are disclosed at the proposal stage, after verification and once they enter the contract scope. Documents concerning personal data are published on the dedicated privacy pages.

  • Enterprise-class facility and platform capacity
  • Provider evidence shared at the proposal stage
  • Data residency terms written into the contract
  • Privacy documents published on dedicated pages

Accessibility and content accuracy

The site is developed toward the WCAG 2.2 AA target, and accessibility findings are corrected under recorded changes. Turkish and English content carry the same claims, and parity between the two languages is audited separately. Every page passes a claim audit before publication: numbers, superlatives, and references that cannot be verified are removed from the text. The current status against that target, the known limits and how to report a problem are set out on the Accessibility Statement page.

  • Development toward the WCAG 2.2 AA target
  • Turkish-English claim parity audits
  • Claim audit before publication
  • Findings closed with recorded changes

How we work

  1. Information goes live only after its source document has been verified.
  2. Each published item is listed with its date and scope.
  3. Verification questions are answered together with the underlying evidence.
  4. Information that changes or expires is updated or removed.
  5. Every update is tracked in a change log.

How success is measured

  • Consistency between published information and source documents
  • Traceability of responses to verification questions
  • Claim parity between Turkish and English content
  • Closure of accessibility audit findings

Frequently asked questions

Why is there no certificate list here?

Because this page publishes verified documents only. Every document that completes verification and the related corporate decisions will be added here with its date and scope.

Where is your data center located?

Provider and location details are disclosed at the proposal stage, after verification and once they enter the contract scope. Sanal Çekirdek does not claim to own a facility; enterprise-class third-party capacity is selected per workload.

Will you complete our vendor assessment questionnaire?

Yes; security and procurement questionnaires are completed so that the basis of every answer can be shown. Items that cannot be verified are marked as such rather than estimated.

How often is this page updated?

It is updated whenever a new document is verified or existing information changes. No fixed schedule is promised; every update is tracked in a change log.

For any topic in your evaluation that requires verified information, write to us; we will answer with the underlying evidence.

Ask a verification question