Passwords
Passwords are stored as one-way bcrypt hashes. The application does not store the original password for later retrieval.

Trust & security
Property and tenant information carries real responsibility. This page explains the controls the current Bolapade platform actually implements, what those controls do, and the limits we should not pretend do not exist.
Passwords are stored as one-way bcrypt hashes. The application does not store the original password for later retrieval.
Admin and tenant pages check the database-backed session on the server. Tenant accounts are linked to a single tenant record; admin access is a separate role.
Admin sessions expire after 60 minutes of inactivity. Tenant sessions also have inactivity controls, and authentication cookies are HttpOnly, Secure in production and SameSite=Lax.
Important manual changes such as payment-status overrides, reminder overrides and rent-adjustment actions retain an audit record and reason.
The production application and PostgreSQL database run on Railway. Database backups and infrastructure access are part of the Railway operating environment.
The application sends HTTPS/HSTS, content-security, anti-framing, content-type, referrer and browser-permission security headers on production responses.
The platform is not end-to-end encrypted, not every property field is individually encrypted, and no internet system can honestly be described as impossible to breach. Privileged infrastructure or application operators can technically access data when required to operate or support the service.
Use only the HTTPS production address, keep account credentials private, review staff access when responsibilities change, and never send passwords, authentication codes or full sensitive documents through an ordinary support message.
See a browser warning?
The verified production address is served over HTTPS. If your browser reports “Not secure,” stop before signing in and contact Bolapade Consulting so the exact domain/DNS path can be checked.