Security center · TaiGong 1.3.4

Security controls for an authorized simulation platform.

01 / Authorized use
Scope before capability

Written authorization is the starting point.

TaiGong may only be used for people, systems, providers, and environments included in an authorized exercise scope.

Permitted purposeREQUIRED

Security awareness, defensive validation, and authorized research.

Use TaiGong for internal awareness exercises, contracted red/purple-team assessments, control validation, and research covering assets you own or are explicitly authorized to test.

Prohibited useNO EXCEPTION

No fraud, unsolicited targeting, or phishing-as-a-service.

Unauthorized phishing, credential theft, extortion, third-party attacks, unlawful surveillance, resale of cracked software, and support for criminal activity are prohibited.

Advanced modulesLICENSED + SCOPED

Capability does not remove responsibility.

Advanced environment, delivery, and proxy controls remain subject to entitlement, policy, written scope, and an operational stop condition.

EnforcementLICENSE CONTROL

Misuse can end access.

Yofune_Labs may revoke licenses, refuse service, preserve relevant evidence, and cooperate with lawful investigations when verified misuse occurs.

02 / Delivered controls
Core · Licensed · Release

Publish what the current version actually controls.

The table distinguishes the 1.3.4 baseline from separately licensed governance surfaces and release-level controls.

ControlStatusCurrent statement
Tenant-aware resources and tenant checksCoreResources and requests are scoped through tenant-aware application controls.
API tokensCoreScoped tokens support platform integrations.
Authentication, session rotation, CSRF, and trusted-proxy handlingCoreHardened in the current 1.3.4 line.
Outbound-request validation and upload/extraction limitsCoreControls address SSRF and resource-exhaustion paths in supported workflows.
RBAC managementLicensedRole and permission management requires the RBAC entitlement.
Audit-log consoleLicensedAdministrative audit views require the audit entitlement.
Build hash, integrity signature, and machine-bound commercial licenseRelease controlRelease artifacts can include hashes and signatures; commercial self-hosted licenses bind to the approved machine.
SlackIntegration-onlyIncoming-webhook event notification only; not phishing-simulation delivery.
Microsoft Teams deliveryUnsupportedNot a 1.3.4 exercise-delivery channel.
03 / Application and operations
Defense in current code

Protect the management plane and the exercise boundary.

Security depends on both shipped controls and correct deployment. Self-hosting transfers infrastructure responsibility to the customer.

Application controls

Fail closed on sensitive state.

Version 1.3.4 includes hardened authentication and session behavior, CSRF protection, tenant guards, trusted-proxy handling, rate-limiting components, outbound-request checks, and database schema validation.

  • Random or injected first-use administrator password
  • First-login password change
  • Session and CSRF protections
  • Schema compatibility checks
Deployment controls

Reduce unnecessary exposure.

Production deployments should isolate the management interface, separate exercise domains from production domains, keep credentials server-side, enforce TLS, and back up the database, configuration, and license material.

  • Customer-managed network boundary when self-hosted
  • Tenant-aware workspace in managed SaaS
  • Documented production hardening checklist
  • Emergency campaign controls and audit trail
Review self-hosting
04 / Data boundary
Choose by operating responsibility

SaaS and self-hosted are different trust boundaries.

Managed SaaS uses tenant-aware application controls. Self-hosting lets the customer control infrastructure, database, credentials, logs, backups, and retention. This page does not claim a third-party security certification or a universal regulatory-compliance outcome.

05 / Responsible disclosure
Private report · Remediation window

Report suspected vulnerabilities privately.

Email contact@yofunesec.com with the affected version, reproduction steps, impact, and a safe contact method. Please allow a reasonable remediation window before publishing exploit details.

Certification noteTaiGong does not claim SOC 2, ISO 27001, or another third-party certification unless a current certificate is provided separately. Deployment teams remain responsible for their own legal, privacy, labor, and regulatory assessment.
Security review

Start with scope and boundary.

Review the exact version, deployment model, licensed controls, data path, and operating responsibility before procurement.