Trust center
Security at Dinner Plans
Last reviewed August 2, 2026
Dinner Plans uses verified email accounts, server-enforced family boundaries, encrypted transport, and encrypted planning storage as part of its layered security design.
Our approach
Security is a continuous risk-management process, not a promise that any service can never be compromised. Dinner Plans is designed to minimize data collection, keep credentials out of the browser, enforce family boundaries on the server, and fail closed when production services are not configured.
Controls in the release design
- Supabase Auth for email confirmation, password validation, and recovery. Dinner Plans does not receive or store plaintext passwords.
- Opaque, hashed, expiring server sessions in managed storage; secure, HTTP-only, same-site cookies.
- Server-derived family identity and authorization checks for every household operation.
- Managed PostgreSQL over verified TLS, provider encryption at rest, encrypted backups, point-in-time recovery, and least-privilege credentials.
- Application-layer authenticated encryption for sensitive planning payloads, with keys held outside the database.
- Strict browser security headers, request-size limits, origin checks, rate limits, safe output encoding, and restricted remote recipe fetching.
- Automated authorization, tenant-isolation, migration, restore, dependency, and security-header tests as release gates.
Before public registration opens
We will complete production hosting and database configuration, email verification for invitations, account export and deletion, retention automation, monitored backups with a restore exercise, centralized security logging and alerts, dependency monitoring, incident-response procedures, and an independent penetration test.
Report a vulnerability
Please email security@yourdinnerplans.com with a clear description, affected URL, reproduction steps, and impact. Do not access other users’ data, disrupt service, or publicly disclose an unresolved issue. We will publish a full coordinated disclosure policy before general availability.
Your Dinner PlansLog in