← Back

Security Policy

Version 1 · published August 6, 2026

SAMMURAI Security Policy

Last updated: 25 April 2026

This Security Policy gives a public-facing overview of Sammurai’s security approach and explains how users or researchers can report security concerns.

1. Purpose

Sammurai aims to protect confidentiality, integrity, availability, resilience, and user trust. This page is a high-level security and responsible-disclosure surface. It does not disclose sensitive internal architecture or operational detail.

3. Account Security

Users are responsible for keeping credentials confidential and using strong passwords and good account hygiene. If you believe your account has been accessed without permission, contact security@sammurai.com.

4. Platform and Data Protection

Sammurai may use controls such as TLS, access restrictions, secrets-management processes, audit logging, monitoring, backups, and environment separation where implemented. Public security statements are kept high-level to avoid exposing implementation detail that could increase risk.

5. Access Control and Internal Permissions

Administrative, support, or engineering access is granted only to authorized personnel or contractors acting under Sammurai’s control and according to operational need.

6. Monitoring and Incident Response

Sammurai may use operational logs, alerts, triage processes, and internal investigation steps to detect and respond to technical or security issues. Incident-handling language in this policy is not a fixed guarantee of response timelines or outcomes.

2. Security Approach

  • Use access controls to limit internal access to systems and data.

  • Use secure authentication and session-management practices for user accounts.

  • Protect data in transit and at rest where appropriate for the environment.

  • Use logging, monitoring, and investigation processes to detect and respond to issues.

  • Apply least-privilege access principles for operational and engineering access.

  • Review vendors and service providers that support hosting, infrastructure, AI, communications, analytics, moderation, and support.

7. Vulnerability Reporting

If you believe you have discovered a vulnerability or security issue affecting Sammurai, please report it to security@sammurai.com.

Please include a clear description of the issue, steps to reproduce, potential impact, affected pages or systems, and any supporting evidence.

8. Responsible Disclosure and Safe Harbour

Sammurai appreciates good-faith security research. Sammurai will not pursue legal action against researchers who report promptly and in good faith, do not access or exfiltrate data beyond what is minimally necessary, do not disrupt services or users, do not publicly disclose before reasonable investigation/remediation, and comply with applicable laws. This safe harbour does not apply to intentional misuse, unauthorized data access, attacks on users, extortion, disruption, or use of a vulnerability for personal gain.

9. Bug Bounty

Sammurai does not currently operate a paid bug bounty programme. Responsible disclosures are still welcome and may be acknowledged where appropriate.

10. Vendors and Service Providers

Sammurai may use third-party providers for hosting, infrastructure, analytics, security, communications, AI, moderation, and support. Sammurai uses appropriate contractual, technical, and access-management safeguards when working with providers.

11. Changes to This Policy

Sammurai may update this Security Policy when its reporting channels, public commitments, or security posture disclosures change materially.

12. Contact Us