Security & Privacy
Controlled Access Across Every Context
MealSecretary holds meal, payroll and—soon—nutrition and clinical information. Every access decision passes through identity, role, permission, scope and authority or consent, and every important change is recorded.
Start immediately. No demo required.
- Identity
- Role
- Permission
- Scope
- Authority / Consent
- Data Access
Data separation
Different records, different rules
Being able to see one kind of record never implies access to another. An organization admin cannot read a member’s personal nutrition log; a professional cannot see payroll.
Institutional foodservice records
Meal Programs, demand, serving and operations—visible to people with roles in that organization.
Personal nutrition records
A person’s own food log and intake—private unless they choose to share.
Professional / clinical records
Notes and plans created by professionals, protected by consent and verification.
Financial / payroll records
Charges and deductions—restricted to payroll and finance permissions.
Security information
Passwords, verification codes and sessions—never visible to anyone, including administrators.
Controls in place today
How MealSecretary protects your account and data
Verified identifiers
Email addresses and mobile numbers are verified with one-time codes before they can be used to sign in.
Strong password storage
Passwords are stored only as salted bcrypt hashes. Password resets never reveal whether an account exists.
Rate limiting
Sign-in, verification and reset attempts are limited to stop guessing attacks.
Session control
See every device signed in to your account and sign any of them out.
Roles & named permissions
Organization roles and platform permissions are specific and scoped—no single all-powerful admin switch.
Delegation with limits
Trusted people can act for someone else only with the permissions granted, and every action shows who acted.
Append-only audit history
Who did what, when, on whose behalf and why—for serving, corrections, payroll, roles and settings.
Safe Person Claim
Linking an existing record to a new account requires verification and review, so history is never handed to the wrong person.
Request protection
Every change requires a valid session token, and all output is escaped to prevent script injection.
MealSec AI
AI follows the same boundaries Beta
MealSec AI is designed to act strictly within the permissions of the person using it. It will not see data that person cannot see, and high-impact actions—payroll, clinical, food safety, recalls and financial changes—require authorized review and confirmation.
- AI
- Recommendation
- Authorized Review
- Confirmation
- Execution
- Audit
Privacy
Your data, your decisions
- People control their own contact details and notification preferences.
- Organizations manage only their own members’ institutional records.
- Sharing with professionals will always require the person’s consent.
- Contact details are masked in delivery logs.
Security review or data residency?
For security questionnaires, data residency, custom agreements or to report a vulnerability responsibly, contact our team.
Contact SecuritySecurity questions
Can my employer see my personal food log?
No. Personal nutrition records are separate from institutional records. Your organization sees your meal participation and charges, not your personal log.
Can MealSecretary staff see my password or codes?
No. Passwords are stored only as one-way hashes and verification codes are never shown to staff.
What is recorded in the audit history?
Important actions such as serving, corrections, reversals, role changes, payroll approvals, plan changes and account security events, with who acted, on whose behalf, when and why.
How do I report a security issue?
Use the contact form and choose Security. Please include steps to reproduce and do not access other people’s data.
Start with confidence
Create your account and invite your team with exactly the permissions they need.
Start immediately. No demo required.