Sakura
Sign in

Sakura ยท Product information

Security

Report a suspected vulnerability, sandbox escape, exposed token or cross-workspace issue privately to our security contact.

How to report

Email martin@shinrasec.com with the affected URL or audit, time observed, impact and reproducible steps. Do not include live credentials in the first message; we will provide a secure transfer method when needed.

Research boundaries

Do not access other customers' workspaces or material, disrupt the service, or publish sensitive details before we have had a chance to investigate. Testing confined to your own workspace and your own submitted material is welcome.

What to expect

We aim to acknowledge credible private-beta security reports within two business days, coordinate validation and remediation, and keep reporters informed. This is a response target rather than a contractual service level unless your agreement says otherwise.

Operational security

Sakura separates customer workspaces at the storage boundary, runs every audit in an isolated environment, delivers scoped API credentials that can be revoked individually, records irreversible actions, and confirms data erasure against the systems holding the underlying records. Detailed architecture or assurance material may be shared with customers under appropriate confidentiality terms.

Effective 2026-08-07 · Shinrasec, operated by Martin Mielke