Security

Security and service status

This page explains account security, sessions, roster permissions, and service monitoring.

Last updated: August 10, 2026

Security

Passwords are hashed. Sessions are stored server-side and sent in HTTP-only cookies. Access to each roster is checked against membership and role permissions.

Diagnostics are designed to exclude sensitive recipe, allergy, nutrition, and workspace content. When reporting a possible security issue, include reproducible details but leave out unrelated personal information.

Service status

BiteRoster is preparing for beta. Configured infrastructure providers monitor uptime, imports, email delivery, and service errors. Optional beta areas may be disabled without interrupting the core Roster, recipe, planner, and shopping-list workflow.