Security
How to report a vulnerability, what we promise in return, and how the service is put together.
Last updated 29 August 2026
Framebook is a small product run by Tably LLC. There is no security team behind this page — there is one maintainer who reads every report and answers it. That is worth knowing before you decide how to tell us something.
Reporting a vulnerability
Email tulgaa.mgl@gmail.com. Please do not open a public issue, post it publicly, or leave it in the plugin’s feedback box — those are read, but not privately.
Include whatever you have. What helps most:
- What the issue lets someone do, in one sentence.
- The steps to reproduce it, and the URL or plugin version you saw it on.
- Anything you needed in order to exploit it — an account, a licence key, a role.
What we promise
- We acknowledge within 2 business days. A real reply from a person, not an autoresponder.
- We keep you updated while we work on it, and tell you when it is fixed.
- We will credit you by name or handle if you want it, and stay quiet about you if you do not.
- We will not pursue legal action over research done in good faith under this policy, and will not ask your employer or your hosting provider to.
We do not run a bug bounty and cannot offer money. Saying so plainly seems better than letting anyone find out after the work.
Good-faith research
Testing is welcome within these limits, which exist to protect other people’s work rather than to protect us:
- Use your own account and your own Figma files. Never another customer’s.
- Do not run denial-of-service or load tests, and do not use automated scanners that generate significant traffic.
- If you reach data that is not yours, stop, do not save it, and tell us what you reached.
- Give us reasonable time to fix an issue before describing it publicly. We will agree a date with you rather than ask you to wait indefinitely.
In scope
- framebook.app — the site, the dashboard, and the API the plugin calls.
- The Framebook Figma plugin, including how it stores and transmits the licence key.
Out of scope
- Our infrastructure providers — Vercel, Supabase, Stripe and Figma. Report those to them; they each run their own disclosure programme, and we cannot fix their code.
- Social engineering, phishing, or anything aimed at a person rather than the software.
- Scanner output with no demonstrated impact — a missing header or a permissive setting that you cannot show does something.
- Attacks that require a machine already compromised, or physical access to one.
How the service is built
This is not a certification. It is a description, so that a report can be aimed somewhere useful.
- Hosting and data. The site runs on Vercel; the database and authentication are Supabase, in ap-northeast-1. Everything is served over HTTPS, and data is encrypted in transit and at rest.
- Accounts. Passwords are handled by Supabase Auth and never reach our code or our logs. Google and Facebook sign-in are also offered.
- Separation between accounts. Every table is protected by row-level security, so a query can only reach the rows belonging to the account that asked. Templates a studio saves are readable by that account alone.
- Payments. Handled end to end by Stripe Checkout. No card details ever reach our systems, and we could not store one if we wanted to.
- The plugin. Its licence key identifies an account; on its own it grants nothing, because entitlement is checked separately against the subscription on every request. Your logos, colours and type never leave your Figma file. The one thing that is uploaded is a template you explicitly choose to save, and that is structure — layer names, layout, colour roles — not brand assets.
Tably LLC holds no SOC 2, ISO 27001 or comparable accreditation. If you need one from a supplier, we are not that supplier yet, and we would rather you knew now.
Anything else
For questions that are not security issues, use the contact page. What we do with your data is set out in the Privacy Policy.
Design the brand
Framebook the rest.
Turn your logo, colors and type into a complete, editable brand guideline right inside Figma.
