About
An archive of the region's security research
Sankore collects public security research from the Arab world and Africa — talks, tools, CVEs, papers, write-ups — and credits the researchers behind it on their own terms.
Mission
Research from this region is scattered across conference sites that go offline, threads that get deleted, and repositories nobody indexed. The point of this project is durability: one public, version-controlled record of what was found and who found it.
An archive, not a ranking. There are no scores, no leaderboards, and no "top researchers" lists here, and there never will be. Celebration, not competition.
Where the data lives
There is no database behind this site. Every entry is a plain YAML file in a public Git repository, and each page you read is generated from one of them at build time.
That is the point: you can read exactly what is recorded about anyone, see the source it was taken from, and read the full history of every change and who made it. Each work, person, and event page links straight to the file behind it.
What gets included
A work is eligible if all three hold:
- It is public — a published talk, released tool, assigned CVE, or published paper.
- At least one author is from, based in, or professionally rooted in the covered region. Self-identification is accepted and never interrogated.
- It is security research or security tooling, in a broad technical sense.
There is no judgment of quality, employer, nationality, or politics. Editorial selection is limited to relevance and public availability.
The consent model
Work entries are indexed by default, because published research is public record. People are not.
- Unclaimed entries show a display name, an optional country, and linked works. No photo, no biography, no social links, no employer.
- Claimed profiles — verified as belonging to that person — may add a biography, links, an Arabic-script name, and a photo. Nothing is added without the researcher asking for it.
- Country is always optional and is removed on request without question.
- Pseudonyms and handles are valid display names.
We recognise that in parts of the covered region, public association with offensive security research can carry legal or personal risk. That is why the default is minimal and the burden is on us, not on you.
Removal and corrections
Any person may request any of the following, withno justification required:
- Removal of their person entry — works remain, attributed to name-only text.
- Full removal of their name from specific entries, replaced with "researcher requested anonymity".
- Correction of any field.
Requests are honoured within 7 days, without debate.Open a takedown request — it is pre-labelled, and the account you use is the only identity we see.
Claim verification
A claim is accepted when the claimant proves control of an identity already publicly tied to the work, via one of:
- A post from a linked social or professional account referencing the claim.
- A DNS TXT record, or a file on a personal site referenced in the claim.
- Direct confirmation from an email address published in the original work.
Maintainers record which method was used in a private field. It is never rendered on the site.
Maintainers
The project aims for a majority of maintainers based in the covered region. The maintainer list is recorded inthe repository.
Data is licensed CC BY 4.0. The site code is MIT.