Security & responsible disclosure
We take the security of Spec Layer seriously. If you believe you have found a security vulnerability in the Spec Layer plugin or its backend, we want to hear from you and will work with you to resolve it.
Reporting a vulnerability
Email oleksandr.kurchev@gmail.com with the details. Please include:
- a description of the issue and its potential impact;
- clear steps to reproduce it, ideally with a proof of concept;
- the affected component (the Figma plugin or the backend endpoint).
Please do not include real credentials or private design-system data in your report. Give us a reasonable amount of time to investigate and fix the issue before disclosing it publicly.
What to expect
- We aim to acknowledge your report within a few business days.
- We triage and fix confirmed issues ourselves and will keep you informed of progress.
- We are happy to credit you once the issue is resolved, if you would like that.
Spec Layer is maintained by an independent developer. We do not currently run a paid bug-bounty program.
Scope
This policy covers the Spec Layer Figma plugin and the backend it talks to. The backend runs on Cloudflare Workers, a managed runtime that Cloudflare keeps patched, so there is no server or operating system for us to maintain. Our Anthropic API key is held server-side and never reaches the plugin, prompts and generated text are never logged, and license keys are stored only as salted hashes. Payments are handled by Lemon Squeezy as merchant of record, so we never handle payment card data.
Safe harbor
If you make a good-faith effort to comply with this policy during your research, we will consider your testing to be authorized, and we will not pursue legal action against you. Please act in good faith: avoid privacy violations, data destruction, and any disruption of the service, and only interact with accounts or data that belong to you.
Contact
Security questions or reports: oleksandr.kurchev@gmail.com.