Sakura ยท Product information
Privacy notice
Data we process
- Account, workspace, invitation and authentication information, including API key metadata.
- Material you submit for audit: uploaded archives, binaries, and repositories you ask us to import.
- Audit records, findings, candidates, proof-of-concept artifacts, fixes and reports.
- Security, audit, and service logs needed to protect and troubleshoot the platform.
- Support messages and files you choose to provide.
Why we process it
We use this data to run the audits you request, authenticate users, enforce workspace limits, maintain security, prevent abuse, provide support, measure service reliability and meet legal obligations. We do not sell personal information.
Sharing and processing
Material you submit is processed by automated analysis that uses third-party large language model providers. Those providers are sub-processors of your submitted material, and the current list is Anthropic, OpenAI, xAI, GitHub, OpenCode, Hack The Box, Hetzner, and Ollama; the route-specific list is available from martin@shinrasec.com before material is submitted. Data may also be handled by providers that host, secure or support Sakura. We disclose data when legally required or necessary to protect users, the platform or others.
Retention
Uploaded source material is held only for a limited working period, seven days by default, and is then deleted from the intake store. Backups deliberately exclude that store, so a backup does not extend how long your submitted material is kept. Workspace records, audits, findings and evidence are retained for the period needed to provide the service, preserve audit evidence, resolve disputes and meet contractual or legal requirements. Retention details may be set in your agreement.
Deletion
You can erase your workspace's audits, findings and artifacts from within the product, and you can delete your account. Erasure is confirmed against the systems that hold the underlying records. Anonymized monthly usage totals are retained after erasure for billing integrity and cannot be linked back to you.
Security
We use access controls, workspace isolation, isolated execution for audits, encrypted transport, monitoring and incident procedures appropriate to the service.
Your choices
Depending on applicable law, you may request access, correction, deletion, restriction or export of personal data, or object to certain processing. Send privacy requests to martin@shinrasec.com. You may also have the right to contact your local data protection authority.