Security
Last updated: 3 August 2026
Alanse Inc. ("we") welcomes vulnerability reports for Atelier ("the Service"). This page explains where and how to tell us what you found, and what we commit to in return.
1. How to report
Email security@alanse.co.jp with the subject line [Security] Atelier.
If that does not reach us, support@alanse.co.jp also works.
Including the following helps us confirm the issue faster:
- Where it is (URL, feature name, affected version)
- Steps to reproduce, and what happens when you do
- The impact you believe it has
- Screenshots or logs, if they help
We do not publish a PGP key yet. If you need to send something encrypted, tell us and we will arrange it.
2. What we commit to
- We acknowledge your report within 3 business days
- We tell you our severity assessment and our plan once we have confirmed it
- We keep you informed while we work on a fix
- We tell you when it is fixed, and credit you by name if you would like that
We are a small team, so we do not publish deadlines we cannot meet. The targets above are ones we can actually keep.
3. Scope
atelierdeck.app— sign-in and dashboardmcp.atelierdeck.app— the MCP server and the Bridge endpoint- The "Atelier" Figma plugin
4. Out of scope
We generally do not accept reports about:
- Denial of service (DoS/DDoS) and load testing
- Email spoofing, or SPF / DKIM / DMARC configuration
- Missing security headers on their own, unless you can show a working exploit
- Absence of rate limiting on its own, unless you can show real impact
- Raw output from an automated scanner
- Settings that affect only your own account, or self-XSS
- Social engineering and physical intrusion
- Issues in third-party services we do not operate (see section 5)
5. Third-party dependencies
We delegate identity to Clerk and run our infrastructure on Cloudflare. Vulnerabilities in those products should go to their own security teams — we cannot fix them ourselves.
Where such an issue affects our users, we treat it as ours to handle: we review our configuration, apply any mitigation available to us, and describe the impact here and in a notice to affected users.
6. Safe harbour
We will not pursue legal action against you as long as your research follows these rules:
- Do not access other people's data. Test with your own account
- Do not destroy, alter or exfiltrate data
- Do not degrade the availability of the Service
- Do not disclose the issue publicly until it is fixed
- Do not go further than needed to demonstrate the vulnerability
Where we judge a report to be made in good faith, we will not bring a legal claim against you. If a third party brings one, we will state that your research was authorised under this policy.
7. Bounties
We do not run a paid bounty programme at this time. We are grateful for every report, and we will credit you by name if you would like that.
8. How we handle your data
We never hold your password. Sign-in does not happen inside the plugin: the plugin opens this site in your browser and you approve it there. Identity is handled by Clerk, so we neither receive nor store passwords.
We do not store your slides. Content read from Figma passes through our servers only to reach your own AI agent. What we record is the name of the tool that was called and the size of the response — not the content.
See our Privacy Policy for the full picture.
9. Changes to this policy
We may update this policy. When we make a material change, we will update the date at the top of this page.