Skip to content

Security

Last updated: 3 August 2026

Alanse Inc. ("we") welcomes vulnerability reports for Atelier ("the Service"). This page explains where and how to tell us what you found, and what we commit to in return.

1. How to report

Email security@alanse.co.jp with the subject line [Security] Atelier. If that does not reach us, support@alanse.co.jp also works.

Including the following helps us confirm the issue faster:

  • Where it is (URL, feature name, affected version)
  • Steps to reproduce, and what happens when you do
  • The impact you believe it has
  • Screenshots or logs, if they help

We do not publish a PGP key yet. If you need to send something encrypted, tell us and we will arrange it.

2. What we commit to

  • We acknowledge your report within 3 business days
  • We tell you our severity assessment and our plan once we have confirmed it
  • We keep you informed while we work on a fix
  • We tell you when it is fixed, and credit you by name if you would like that

We are a small team, so we do not publish deadlines we cannot meet. The targets above are ones we can actually keep.

3. Scope

  • atelierdeck.app — sign-in and dashboard
  • mcp.atelierdeck.app — the MCP server and the Bridge endpoint
  • The "Atelier" Figma plugin

4. Out of scope

We generally do not accept reports about:

  • Denial of service (DoS/DDoS) and load testing
  • Email spoofing, or SPF / DKIM / DMARC configuration
  • Missing security headers on their own, unless you can show a working exploit
  • Absence of rate limiting on its own, unless you can show real impact
  • Raw output from an automated scanner
  • Settings that affect only your own account, or self-XSS
  • Social engineering and physical intrusion
  • Issues in third-party services we do not operate (see section 5)

5. Third-party dependencies

We delegate identity to Clerk and run our infrastructure on Cloudflare. Vulnerabilities in those products should go to their own security teams — we cannot fix them ourselves.

Where such an issue affects our users, we treat it as ours to handle: we review our configuration, apply any mitigation available to us, and describe the impact here and in a notice to affected users.

6. Safe harbour

We will not pursue legal action against you as long as your research follows these rules:

  • Do not access other people's data. Test with your own account
  • Do not destroy, alter or exfiltrate data
  • Do not degrade the availability of the Service
  • Do not disclose the issue publicly until it is fixed
  • Do not go further than needed to demonstrate the vulnerability

Where we judge a report to be made in good faith, we will not bring a legal claim against you. If a third party brings one, we will state that your research was authorised under this policy.

7. Bounties

We do not run a paid bounty programme at this time. We are grateful for every report, and we will credit you by name if you would like that.

8. How we handle your data

We never hold your password. Sign-in does not happen inside the plugin: the plugin opens this site in your browser and you approve it there. Identity is handled by Clerk, so we neither receive nor store passwords.

We do not store your slides. Content read from Figma passes through our servers only to reach your own AI agent. What we record is the name of the tool that was called and the size of the response — not the content.

See our Privacy Policy for the full picture.

9. Changes to this policy

We may update this policy. When we make a material change, we will update the date at the top of this page.