Security awareness, defensive validation, and authorized research.
Use TaiGong for internal awareness exercises, contracted red/purple-team assessments, control validation, and research covering assets you own or are explicitly authorized to test.
TaiGong may only be used for people, systems, providers, and environments included in an authorized exercise scope.
Use TaiGong for internal awareness exercises, contracted red/purple-team assessments, control validation, and research covering assets you own or are explicitly authorized to test.
Unauthorized phishing, credential theft, extortion, third-party attacks, unlawful surveillance, resale of cracked software, and support for criminal activity are prohibited.
Advanced environment, delivery, and proxy controls remain subject to entitlement, policy, written scope, and an operational stop condition.
Yofune_Labs may revoke licenses, refuse service, preserve relevant evidence, and cooperate with lawful investigations when verified misuse occurs.
The table distinguishes the 1.3.4 baseline from separately licensed governance surfaces and release-level controls.
| Control | Status | Current statement |
|---|---|---|
| Tenant-aware resources and tenant checks | Core | Resources and requests are scoped through tenant-aware application controls. |
| API tokens | Core | Scoped tokens support platform integrations. |
| Authentication, session rotation, CSRF, and trusted-proxy handling | Core | Hardened in the current 1.3.4 line. |
| Outbound-request validation and upload/extraction limits | Core | Controls address SSRF and resource-exhaustion paths in supported workflows. |
| RBAC management | Licensed | Role and permission management requires the RBAC entitlement. |
| Audit-log console | Licensed | Administrative audit views require the audit entitlement. |
| Build hash, integrity signature, and machine-bound commercial license | Release control | Release artifacts can include hashes and signatures; commercial self-hosted licenses bind to the approved machine. |
| Slack | Integration-only | Incoming-webhook event notification only; not phishing-simulation delivery. |
| Microsoft Teams delivery | Unsupported | Not a 1.3.4 exercise-delivery channel. |
Security depends on both shipped controls and correct deployment. Self-hosting transfers infrastructure responsibility to the customer.
Version 1.3.4 includes hardened authentication and session behavior, CSRF protection, tenant guards, trusted-proxy handling, rate-limiting components, outbound-request checks, and database schema validation.
Production deployments should isolate the management interface, separate exercise domains from production domains, keep credentials server-side, enforce TLS, and back up the database, configuration, and license material.
Managed SaaS uses tenant-aware application controls. Self-hosting lets the customer control infrastructure, database, credentials, logs, backups, and retention. This page does not claim a third-party security certification or a universal regulatory-compliance outcome.
Email contact@yofunesec.com with the affected version, reproduction steps, impact, and a safe contact method. Please allow a reasonable remediation window before publishing exploit details.
Review the exact version, deployment model, licensed controls, data path, and operating responsibility before procurement.