Sakura ยท Product information
Security
Report a suspected vulnerability, sandbox escape, exposed token or cross-workspace issue privately to our security contact.
How to report
Email martin@shinrasec.com with the affected URL or audit, time observed, impact and reproducible steps. Do not include live credentials in the first message; we will provide a secure transfer method when needed.
Research boundaries
Do not access other customers' workspaces or material, disrupt the service, or publish sensitive details before we have had a chance to investigate. Testing confined to your own workspace and your own submitted material is welcome.
What to expect
We aim to acknowledge credible private-beta security reports within two business days, coordinate validation and remediation, and keep reporters informed. This is a response target rather than a contractual service level unless your agreement says otherwise.
Operational security
Sakura separates customer workspaces at the storage boundary, runs every audit in an isolated environment, delivers scoped API credentials that can be revoked individually, records irreversible actions, and confirms data erasure against the systems holding the underlying records. Detailed architecture or assurance material may be shared with customers under appropriate confidentiality terms.