Security
Effective 2026-08-07 · Shinrasec, operated by Martin Mielke
Report a suspected Kura vulnerability, exposed credential, unauthorized download, or attribution issue privately to our security contact.
How to report
Email martin@shinrasec.com with the affected URL, approximate time, impact, and reproducible steps. Do not include live credentials or a customer-marked executable in the first message; we will provide a secure transfer method when needed.
Research boundaries
Testing confined to your own licensed Kura account is welcome. Do not access another customer's downloads, enumerate customer identifiers, disrupt the service, or publish sensitive details before we have had a chance to investigate.
What to expect
We aim to acknowledge credible security reports within two business days, coordinate validation and remediation, and keep reporters informed. This is an operating target rather than a contractual service level unless your agreement says otherwise.
Operational security
Kura verifies Shinra ID claims, stores only hashed session tokens, keeps its Control route off public ingress, issues a new signed marker for each download, and records typed unavailable states instead of substituting a different artifact.