Security
Your community trusts us with names, addresses, and payment records. Here is how we look after them.
Encryption
Every page and every request to myhoamsph is served over HTTPS, so what you send and see is encrypted in transit. Passwords are never stored in readable form — only a salted, one-way hash.
Each community kept separate
Every record belongs to one community, and every request is checked against the community it comes from. A resident or board member of one subdivision cannot see another subdivision's households, bills, or requests.
The right access for each role
Residents see only their own household's balance, payments, and requests. Board members and admins see what they need to run their community. Platform staff access a community only to support it or keep the service secure.
Protecting your account
- Sign-in, password reset, and registration are rate-limited to slow down password guessing.
- New logins get a temporary password generated by the server and sent only to the email address on the account — no one, including your board, is shown it. You're asked to choose your own after signing in.
- “Forgot password” emails a one-time link that expires in an hour. Your current password keeps working until the link is used.
- Forms are protected against cross-site request forgery.
- You can show or hide your password while typing, and change it anytime from your account page.
A record of who did what
Board actions — such as confirming a payment, changing a household, or adding an admin — are written to an activity log with the time and the person who did it, so every change can be traced.
Infrastructure and backups
myhoamsph runs on DigitalOcean servers in Singapore behind Cloudflare's network, which filters malicious traffic before it reaches us. The database is backed up every night, and uploaded files are kept in separate object storage with per-person upload limits.
No payment cards
Residents pay their HOA directly through GCash, Maya, bank transfer, or cash. myhoamsph records the payment but never collects or stores card numbers or e-wallet credentials.
Report a vulnerability
If you believe you have found a security issue, email [email protected] with the subject “Security report” and enough detail for us to reproduce it. Please give us a reasonable chance to fix it before telling anyone else, and do not access or change other people's data while testing. We will acknowledge your report and keep you updated.
For how we handle personal information, see our Privacy Policy.