Security
Security and service status
This page explains account security, sessions, roster permissions, and service monitoring.
Last updated: August 10, 2026
Security
Passwords are hashed. Sessions are stored server-side and sent in HTTP-only cookies. Access to each roster is checked against membership and role permissions.
Diagnostics are designed to exclude sensitive recipe, allergy, nutrition, and workspace content. When reporting a possible security issue, include reproducible details but leave out unrelated personal information.
Service status
BiteRoster is preparing for beta. Configured infrastructure providers monitor uptime, imports, email delivery, and service errors. Optional beta areas may be disabled without interrupting the core Roster, recipe, planner, and shopping-list workflow.