Skip to content
SpecMiru

Security

Last updated: October 5, 2026

Production draft — this text must be reviewed by a legal professional before public launch.

Local-first by design

The SpecMiru extension inspects pages inside your browser. Inspected content — DOM, text, styles, URLs, screenshots, assets, AI instructions — is processed locally and never sent to our servers or to any AI service.

  • Minimal permissions: activeTab, scripting, sidePanel, storage. No access to all websites at install; SpecMiru only reaches a tab when you invoke it there.
  • No remote code: the extension ships all its code in the Chrome Web Store package and loads no remote scripts.
  • Page data is untrusted: captured content is sanitized, never rendered as HTML in the panel, and marked as untrusted reference data in exports.
  • Isolation: in Overlay mode the panel runs in an extension frame inside a closed Shadow DOM; web pages cannot message the extension.
  • Secrets masked: emails and probable tokens are masked in captured text, and form values are never read.
  • Usage statistics are off until you opt in, and limited to a strict allow-list of predefined product events. No page content can be expressed in them.
  • Bug reports attach nothing by default. Technical diagnostic, page URL (origin and path only) and screenshot each require their own explicit switch.

The website and its backend

  • Private feedback, emails, bug URLs, screenshots, internal notes and uninstall answers are stored in a database area with no public access, protected by row-level security and least-privilege grants. Screenshots live in a private storage bucket and are only shown to administrators through short-lived signed links.
  • Administrators are manually provisioned, optional user accounts can never become administrators, and admin access requires multi-factor authentication. Important admin actions are recorded in an append-only audit log.
  • All inputs are strictly validated on the server; unknown fields are rejected. User messages are always displayed as plain text.
  • Public forms are protected by Cloudflare Turnstile with server-side verification, and all submissions are rate-limited. IP addresses are never stored in clear.
  • Strict security headers (Content-Security-Policy, HSTS, frame protection) are applied, and the site uses no third-party trackers.
  • Logs never contain feedback text, emails, URLs, screenshots, tokens or secrets.

Reporting a vulnerability

If you believe you have found a security issue in SpecMiru, please write to [security contact email] with:

  • a description of the issue and its impact,
  • steps to reproduce,
  • the affected version (extension version, or website URL).

Please give us reasonable time to fix the issue before any public disclosure, do not access or modify other people's data, and do not run denial-of-service, spam or social-engineering tests. We will acknowledge your report, keep you informed, and credit you if you wish. [A security.txt file and disclosure timelines to be finalized.]

We do not claim any security certification.