Credentials are held in this deployment’s .env as a scrypt verifier; the plaintext is read once at boot and dropped. Sessions expire after 8 hours or 10 minutes idle, are bound to the source address, and every action is written to a hash-chained audit log.