mandarıne

Decisions get made here. Things get shown to clients here.

Mandarine decides nothing and embeds no AI. Its only promise: what is dropped here stays readable, intact and under your control. Six commitments.

Report a vulnerability

Cards render in isolation

A card's page is displayed inside an isolated frame (a sandbox), with no access to your session, your cookies or other cards. It can look like anything; it can do nothing but display and record its own answers, and it makes no outbound request. Documents (text, spreadsheet, slides) are converted on the server: the original is never executed.

Who can open a card

Two paths, and only two. The named invitation: sent from the card to a specific address, the person sees that card and nothing else, and you withdraw the access in one click. The public read-only link: it opens without signing in, at the card's normal address — a 12-character random identifier — is never indexed, and is switched off from the card itself. No token to rotate: flipping the switch closes the address immediately. A card you are not allowed to open answers “this page does not exist”, never “access denied”.

Who gets into the workspace

Only the owner adds humans. Three roles: the owner (members, billing, audit log), members (all the work), guests (specific cards, free of charge). Nobody else can widen the circle, and a guest only sees the cards they were invited to.

Keys and scopes

Each agent has its own key, shown once, limited to a workspace or to specific boards, with its last use visible and one-click revocation; everything it does is recorded under its name. Connecting an agent always requires a human to approve it in the browser, on the same screen as the command-line sign-in: an agent never connects an agent. A personal agent leaves with the person who connected it; a company agent stays when people change.

History you can restore

Every version of a card is kept. Comments and answers are never erased by a new version. Restoring creates a new version: nothing disappears. The bin keeps what was deleted for 30 days.

Audit log, hosting and deletion

The audit log, reserved for the workspace owner, can be exported as JSON. Data and files are hosted in France and encrypted in transit. Deleting a workspace takes effect within 30 days.

Report a vulnerability

Write to contact@mandari.ne. We acknowledge receipt within 2 working days and give a first analysis within 7 days.

Machine-readable version: security.txt

What to send
The steps to reproduce, the impact you observed, and the address of the test card or workspace.
Our commitment
No legal action against good-faith researchers who respect other people's data and give us time to fix the issue.
What we publish
A named thank-you if you want one, and the fix in the release notes.