Account protections

Passwords are stored as one-way password hashes. Session cookies are HTTP-only and protected by HTTPS. Sensitive integration secrets are encrypted before database storage.

Sign-in protection

HomeStart supports passkeys, authenticator codes, single-use recovery codes, expiring reset links, request rate limits and session revocation.

Your part

Good to know
  • Use a unique password.
  • Protect your email account with two-step verification.
  • Keep devices and browsers updated.
  • Never share passwords, recovery codes or API tokens.