Achihiko / Security

The quiet parts are protected too.

Achihiko keeps security close to the product boundary: private sessions, explicit ownership, controlled sharing, and no source-document archive.

Security posture

Every workspace has a boundary.

Workspace reads and writes are tied to the authenticated user. Household access is the exception, and it is limited to accepted members and explicitly assigned actions.

Access

Sessions and permissions

  • HTTP-only session cookiesAuthentication state is refreshed through the server boundary rather than exposed as a browser token.
  • Database ownership policiesPostgres row-level security and route checks reinforce the workspace boundary.
  • Household rolesMembers and viewers receive only the access their owner has granted.
Operations

Abuse and failure controls

  • Rate-limited mutationsAuthentication attempts and state-changing requests are bounded at the edge.
  • Security headersProduction responses use content-security, framing, referrer, and cross-origin protections.
  • Observable deliveryReminder failures are bounded, retried, and correlated without logging passwords or source files.
Responsible use

Security is a product practice, not a badge.

Keep your password unique, review household invitations before accepting them, and remove devices or memberships you no longer recognize. To report a concern, email security@achihiko.com or use the support page.