Security and trust
Clear boundaries, without vague promises.
A practical overview of RetroRally account security, room access, identity-hidden contributions, infrastructure, and responsible disclosure.
A practical RetroRally guide · Updated August 2026
Host accounts and sessions
Customer hosts use email verification and a password of at least 12 characters. Verification and reset links are time-limited, hashed at rest, and single-use. A password reset invalidates active customer sessions and outstanding account-action links.
Room access
Hosts control rooms through an authenticated account and a room-specific host pass. Participants enter with a short room code and receive a reconnect credential for that room. Administrative routes are separate from customer-host access.
Team separation
Customer dashboard and history queries require membership of the relevant team. The platform administrator can see operational statistics, contact messages, and post-retro feedback across customer teams, with participant names and player IDs omitted from the admin interface.
Transport and hosting
The production site uses HTTPS. The application runs in an isolated container behind a reverse proxy with a loopback-only application port, a non-root process, resource limits, and health checks. Infrastructure backups are maintained at server level.
Data minimisation
Participants do not need accounts. Public room snapshots use allowlists and do not expose host account IDs, reconnect hashes, normalised account data, or anonymous author IDs. Retention jobs remove expired rooms, stale demo data, consumed tokens, old rate-limit records, and aged contact and feedback records according to the service policy.
What RetroRally cannot promise
No internet service can promise perfect security or absolute anonymity from its operator. Do not submit secrets, regulated personal data, or information that should not be processed by the service. Use neutral descriptions of team problems rather than names.
Report a concern
Use the contact form and select the security topic. Include the affected URL, impact, and reproduction steps, but do not send credentials or exploit data belonging to other people.