Achihiko / Security
The quiet parts are protected too.
Achihiko keeps security close to the product boundary: private sessions, explicit ownership, controlled sharing, and no source-document archive.
Security posture
Every workspace has a boundary.
Workspace reads and writes are tied to the authenticated user. Household access is the exception, and it is limited to accepted members and explicitly assigned actions.
Sessions and permissions
- HTTP-only session cookiesAuthentication state is refreshed through the server boundary rather than exposed as a browser token.
- Database ownership policiesPostgres row-level security and route checks reinforce the workspace boundary.
- Household rolesMembers and viewers receive only the access their owner has granted.
Abuse and failure controls
- Rate-limited mutationsAuthentication attempts and state-changing requests are bounded at the edge.
- Security headersProduction responses use content-security, framing, referrer, and cross-origin protections.
- Observable deliveryReminder failures are bounded, retried, and correlated without logging passwords or source files.
Security is a product practice, not a badge.
Keep your password unique, review household invitations before accepting them, and remove devices or memberships you no longer recognize. To report a concern, email security@achihiko.com or use the support page.