Sakura ยท Product information
Acceptable use
Sakura reproduces vulnerabilities against material you supply, inside isolated environments. This policy keeps that work authorized and contained.
Submit only what you may test
Only submit archives, binaries and repositories you own or are explicitly authorized to have tested. A repository being public does not make it authorized. Do not submit third-party material, customer material you hold under confidentiality without the right to have it tested, or anything you cannot lawfully share with a sub-processor.
Prohibited activity
- Submitting targets you have no authorization to test, or using results to attack systems you do not control.
- Attempting to reach Sakura control systems, other customers' workspaces, the public internet or any third-party asset from an audit environment.
- Malware distribution, persistence, cryptomining, denial of service or traffic flooding.
- Bypassing credit, capacity, size, isolation or access controls.
- Sharing API keys, invitations or session credentials with unauthorized people.
- Uploading unlawful or harmful material, or personal data an audit does not require.
Resource and content rules
Use resources reasonably. Do not upload production secrets. Proof-of-concept artifacts Sakura produces are working exploit material for the target you supplied; handle and store them accordingly.
Enforcement and reporting
We may cancel audits, preserve audit evidence, suspend a workspace and contact its members when activity presents risk. Report suspected escape, exposed credentials or unsafe content immediately to martin@shinrasec.com.