SAMMURAI Security Policy
Last updated: 25 April 2026
This Security Policy gives a public-facing overview of Sammurai’s security approach and explains how users or researchers can report security concerns.
1. Purpose
Sammurai aims to protect confidentiality, integrity, availability, resilience, and user trust. This page is a high-level security and responsible-disclosure surface. It does not disclose sensitive internal architecture or operational detail.
3. Account Security
Users are responsible for keeping credentials confidential and using strong passwords and good account hygiene. If you believe your account has been accessed without permission, contact security@sammurai.com.
4. Platform and Data Protection
Sammurai may use controls such as TLS, access restrictions, secrets-management processes, audit logging, monitoring, backups, and environment separation where implemented. Public security statements are kept high-level to avoid exposing implementation detail that could increase risk.
5. Access Control and Internal Permissions
Administrative, support, or engineering access is granted only to authorized personnel or contractors acting under Sammurai’s control and according to operational need.
6. Monitoring and Incident Response
Sammurai may use operational logs, alerts, triage processes, and internal investigation steps to detect and respond to technical or security issues. Incident-handling language in this policy is not a fixed guarantee of response timelines or outcomes.
2. Security Approach
Use access controls to limit internal access to systems and data.
Use secure authentication and session-management practices for user accounts.
Protect data in transit and at rest where appropriate for the environment.
Use logging, monitoring, and investigation processes to detect and respond to issues.
Apply least-privilege access principles for operational and engineering access.
Review vendors and service providers that support hosting, infrastructure, AI, communications, analytics, moderation, and support.
7. Vulnerability Reporting
If you believe you have discovered a vulnerability or security issue affecting Sammurai, please report it to security@sammurai.com.
Please include a clear description of the issue, steps to reproduce, potential impact, affected pages or systems, and any supporting evidence.
8. Responsible Disclosure and Safe Harbour
Sammurai appreciates good-faith security research. Sammurai will not pursue legal action against researchers who report promptly and in good faith, do not access or exfiltrate data beyond what is minimally necessary, do not disrupt services or users, do not publicly disclose before reasonable investigation/remediation, and comply with applicable laws. This safe harbour does not apply to intentional misuse, unauthorized data access, attacks on users, extortion, disruption, or use of a vulnerability for personal gain.
9. Bug Bounty
Sammurai does not currently operate a paid bug bounty programme. Responsible disclosures are still welcome and may be acknowledged where appropriate.
10. Vendors and Service Providers
Sammurai may use third-party providers for hosting, infrastructure, analytics, security, communications, AI, moderation, and support. Sammurai uses appropriate contractual, technical, and access-management safeguards when working with providers.
11. Changes to This Policy
Sammurai may update this Security Policy when its reporting channels, public commitments, or security posture disclosures change materially.
12. Contact Us
Security and vulnerability reports - security@sammurai.com
General support - support@sammurai.com
Privacy questions - privacy@sammurai.com