Security without mystery.
Updated September 18, 2026
Chirroo is still in private testing. This page describes protections that are working now and the checks that must pass before paid households are invited.
What protects the test app now
- Google handles sign-in; Chirroo does not collect or store account passwords.
- Firebase App Check rejects unverified sign-in, database, file, and managed-service traffic.
- Household access is checked on every database request.
- Automated tests try to cross household boundaries and must fail before a release.
- Uploaded files are type-checked, size-limited, private to their owner or household, and never accepted anonymously.
- Lists, tasks, notes, boards, and channels use Archive or Trash instead of silent permanent deletion.
- The app can export a readable copy of the information an account can access.
- Test data has seven days of point-in-time recovery, a daily backup schedule with 14-week retention, and seven-day recovery for deleted files.
- Outside checks watch the website and test app from three US regions and alert support after a sustained outage.
What must be proven before paid access
Paid access remains blocked until a managed database backup has passed a real restore drill and production has separate recovery, monitoring, and data from the test version. Account deletion, abuse protection, and file permissions already pass their staging checks.
What Chirroo cannot promise
No online service is risk-free. During early access, keep your own copy of anything you cannot afford to lose. We will not advertise a backup or security control until it has been tested in the environment customers will use.
Report a security problem
Email [email protected] with “Security” in the subject. Please do not include passwords, sign-in codes, or private household content in the first message.