Bolapade Consulting

Trust & security

Your records deserve clear answers.

Property and tenant information carries real responsibility. This page explains the controls the current Bolapade platform actually implements, what those controls do, and the limits we should not pretend do not exist.

Passwords

Passwords are stored as one-way bcrypt hashes. The application does not store the original password for later retrieval.

Private access

Admin and tenant pages check the database-backed session on the server. Tenant accounts are linked to a single tenant record; admin access is a separate role.

Session limits

Admin sessions expire after 60 minutes of inactivity. Tenant sessions also have inactivity controls, and authentication cookies are HttpOnly, Secure in production and SameSite=Lax.

Administrative traceability

Important manual changes such as payment-status overrides, reminder overrides and rent-adjustment actions retain an audit record and reason.

Hosting & database

The production application and PostgreSQL database run on Railway. Database backups and infrastructure access are part of the Railway operating environment.

Browser protections

The application sends HTTPS/HSTS, content-security, anti-framing, content-type, referrer and browser-permission security headers on production responses.

What this does not mean

The platform is not end-to-end encrypted, not every property field is individually encrypted, and no internet system can honestly be described as impossible to breach. Privileged infrastructure or application operators can technically access data when required to operate or support the service.

What you should do

Use only the HTTPS production address, keep account credentials private, review staff access when responsibilities change, and never send passwords, authentication codes or full sensitive documents through an ordinary support message.

See a browser warning?

Do not enter credentials on an insecure connection.

The verified production address is served over HTTPS. If your browser reports “Not secure,” stop before signing in and contact Bolapade Consulting so the exact domain/DNS path can be checked.

Report a security concern