About
An archive of the region's security research
Sankore collects public security research from the Arab world and Africa — talks, tools, CVEs, papers, write-ups — and credits the researchers behind it on their own terms.
Mission
Research from this region is scattered across conference sites that go offline, threads that get deleted, and repositories nobody indexed. The point of this project is durability: one public, version-controlled record of what was found and who found it.
An archive, not a ranking. There are no scores, no leaderboards, and no "top researchers" lists here, and there never will be. Celebration, not competition.
The name
Sankore is named after the Sankoré madrasa in Timbuktu, in what is now Mali. Through the 15th and 16th centuries a community of scholars taught around it, and a trade in copied manuscripts grew into one of the city's most profitable industries — until the Moroccan invasion of 1591 ended that era.
The work those copyists did was unglamorous and it is the reason anything survived: transcribe accurately, note where a text came from, keep it somewhere it can be found again. That is the whole job here too.
Where the data lives
There is no database behind this site. Every entry is a plain YAML file in a public Git repository, and each page you read is generated from one of them at build time.
That is the point: you can read exactly what is recorded about anyone, see the source it was taken from, and read the full history of every change and who made it. Each work, person, and event page links straight to the file behind it.
elbraino/sankore · the data · source coverage · change history
What gets included
A work is eligible if all three hold:
- It is public — a published talk, released tool, assigned CVE, or published paper.
- At least one author is from, based in, or professionally rooted in the covered region. Self-identification is accepted and never interrogated.
- It is security research or security tooling, in a broad technical sense.
There is no judgment of quality, employer, nationality, or politics. Editorial selection is limited to relevance and public availability.
The consent model
Work entries are indexed by default, because published research is public record. People are not.
- Unclaimed entries show a display name, an optional country, and linked works. No photo, no biography, no social links, no employer.
- Claimed profiles — verified as belonging to that person — may add a biography, links, an Arabic-script name, and a photo. Nothing is added without the researcher asking for it.
- Country is always optional and is removed on request without question.
- Pseudonyms and handles are valid display names.
We recognise that in parts of the covered region, public association with offensive security research can carry legal or personal risk. That is why the default is minimal and the burden is on us, not on you.
Removal and corrections
Any person may request any of the following, with no justification required:
- Removal of their person entry — works remain, attributed to name-only text.
- Full removal of their name from specific entries, replaced with "researcher requested anonymity".
- Correction of any field.
Requests are honoured within 7 days, without debate. Open a takedown request — it is pre-labelled, and the account you use is the only identity we see.
Claim verification
A claim is accepted when the claimant proves control of an identity already publicly tied to the work, via one of:
- A post from a linked social or professional account referencing the claim.
- A DNS TXT record, or a file on a personal site referenced in the claim.
- Direct confirmation from an email address published in the original work.
Maintainers record which method was used in a private field. It is never rendered on the site.
Maintainers
The project aims for a majority of maintainers based in the covered region. The maintainer list is recorded in the repository.
Data is licensed CC BY 4.0. The site code is MIT.