Skip to content
SpicesBite
HomeExploreCollectionsDishesProfile
SpicesBite
HomeExploreCollectionsDishesProfile

Security

Last updated: 19 September 2026

We would rather hear about a problem from you than read about it later. This page says what we do to protect accounts, and how to tell us when we have got something wrong.

How accounts are protected

  • All traffic is served over HTTPS with strict transport security enforced.
  • Passwords are hashed with bcrypt. We never store or log them in readable form, which is why we can only reset a password, never tell you what it was.
  • Time-based one-time-password two-factor authentication is implemented and enforced at sign-in for accounts that have it enabled. Self-service enrolment is not available yet, so it is not something you can switch on from your account today.
  • Sessions are short-lived and renewed with a separate refresh token, so a leaked access token expires quickly.
  • Write requests carry a cross-site request forgery token, and the site sets a content security policy that restricts where scripts and frames may come from.
  • Administrative endpoints are behind role checks and are excluded from indexing.

Reporting a vulnerability

Email security@spicesbite.app with enough detail to reproduce the issue. Please give us a reasonable chance to fix it before disclosing it publicly.

Please do not run automated scanners against production, do not attempt denial of service, and do not access, modify or retain data belonging to anyone else. Testing against your own account is fine.

We will acknowledge a report within three working days and tell you what we intend to do about it. We do not currently run a paid bug bounty, and we will credit you when a fix ships if you would like us to.

SpicesBite

The Editorial Guide to Nepali & Indian Dining.

DiscoverExploreTop Dishes
GuidesCuisinesCitiesDishes
CompanyAboutContactHelp
LegalTermsPrivacyCookies
© 2026 SpicesBite.