Spec LayerSpec Layer

Security & responsible disclosure

Last updated 23 July 2026

We take the security of Spec Layer seriously. If you believe you have found a security vulnerability in the Spec Layer plugin or its backend, we want to hear from you and will work with you to resolve it.

Reporting a vulnerability

Email oleksandr.kurchev@gmail.com with the details. Please include:

Please do not include real credentials or private design-system data in your report. Give us a reasonable amount of time to investigate and fix the issue before disclosing it publicly.

What to expect

Spec Layer is maintained by an independent developer. We do not currently run a paid bug-bounty program.

Scope

This policy covers the Spec Layer Figma plugin and the backend it talks to. The backend runs on Cloudflare Workers, a managed runtime that Cloudflare keeps patched, so there is no server or operating system for us to maintain. Our Anthropic API key is held server-side and never reaches the plugin, prompts and generated text are never logged, and license keys are stored only as salted hashes. Payments are handled by Lemon Squeezy as merchant of record, so we never handle payment card data.

Safe harbor

If you make a good-faith effort to comply with this policy during your research, we will consider your testing to be authorized, and we will not pursue legal action against you. Please act in good faith: avoid privacy violations, data destruction, and any disruption of the service, and only interact with accounts or data that belong to you.

Contact

Security questions or reports: oleksandr.kurchev@gmail.com.