v0.1.4 - Portal auth production gates
Documents the portal v0.1.4 production install contract: OWNER_PORTAL_SECRET, OWNER_PORTAL_PASSCODE_HASH, optional OWNER_PORTAL_API_TOKEN, PROPERTY_OS_DEMO_AUTH=false, passcode hash generation, protected owner API access, auth smoke, and live Postgres RLS smoke before paid production handoff. Local gates passed: validate, privacy scan, agent workflow dry run, MCP smoke, diff check, repo security scan, staged security scan.