Kura
Sign in

Security

Report a suspected Kura vulnerability, exposed credential, unauthorized download, or attribution issue privately to our security contact.

How to report

Email martin@shinrasec.com with the affected URL, approximate time, impact, and reproducible steps. Do not include live credentials or a customer-marked executable in the first message; we will provide a secure transfer method when needed.

Research boundaries

Testing confined to your own licensed Kura account is welcome. Do not access another customer's downloads, enumerate customer identifiers, disrupt the service, or publish sensitive details before we have had a chance to investigate.

What to expect

We aim to acknowledge credible security reports within two business days, coordinate validation and remediation, and keep reporters informed. This is an operating target rather than a contractual service level unless your agreement says otherwise.

Operational security

Kura verifies Shinra ID claims, stores only hashed session tokens, keeps its Control route off public ingress, issues a new signed marker for each download, and records typed unavailable states instead of substituting a different artifact.