North Texas Commercial Cleaning Experts | Call (214)-586-0257
Print to PDF
Document IDHWB-QMS-11.10
Version4.0.0
Statusâ—Ź APPROVED
Clause8.2 & 8.5 (Service Integrity & Executive Command)
Document Control Institutional Specification
Document TitleSpam Protection, Enterprise Bot Defense, and Mobile Operations System SOP
Document IDHWB-QMS-11.10
Version4.0.0
StatusAPPROVED
AuthorGeorge (Systems Architect)
Approved ByHumberto Dominguez, CEO
Effective Date10/01/2026
ISO 9001 ClauseClause 8.2 (Customer Ingestion) & Clause 8.5 (Operations Integrity)

Standard Operating Procedure: Spam Protection, Enterprise Bot Defense, and Mobile Operations System

1.0 Purpose

This Standard Operating Procedure (SOP) defines the operational guidelines for HWB Cleaning Services' Mobile Operations System (MOS v4.0) and Enterprise Bot Defense Battery. It establishes how the CEO exercises executive control via Telegram, manages automated commercial construction bidding, neutralizes automated marketing form bots, and prevents database pollution through multi-layered submission filtering.

2.0 Scope

This procedure applies to:

  • The Enterprise Bot Defense Battery on public quote routes (/get-quote, /get-quote-v2).
  • The Telegram executive command node (scripts/telegram_listener.py) running inside hwb_agent_worker.
  • The host-level decoupled automation worker (scripts/host_task_runner.py) running on Linux host infrastructure.
  • The PostgreSQL database queues (task_queue, PendingOutbox, and ConstructionBids).
  • The Telegram Mini-App (TMA) Scope Configurator (/tma/estimator).

3.0 Enterprise Bot Defense Battery (Multi-Layer Protection)

To eliminate automated internet bots, spam scripts, and credential stuffing attacks from polluting the sales pipeline:

  1. Invisible Honeypot Trap (hp_organization_url):

    An invisible input field is embedded in all public proposal forms. This field is hidden from legitimate humans using off-screen CSS positioning (position: absolute; left: -9999px;) and tabindex="-1". Automated autofill web scrapers populate this field automatically. Any submission with this field populated is immediately blackholed.

  2. Sub-Second Submission Timing Filter (form_render_ts):

    The system injects an encrypted timestamp when the quote form renders in the browser. Upon POST submission, the backend measures the elapsed time. If the submission completes in less than 3.0 seconds (< 3s), the request is recognized as automated bot injection and silently dropped.

  3. Direct cURL & Header Validation:

    Submissions initiated via raw scripts lacking valid browser user-agent signatures or valid CSRF session tokens are rejected at the edge.

  4. Financial Spam Keyword Blacklist:

    The system inspects company names, contact names, and notes for high-frequency spam terms (e.g., us dollars, usdc, crypto transfer, balance payment, get the transfer, graph.org). Submissions containing these phrases are dropped.

  5. The Silent Blackhole Rule:

    When a submission triggers any bot defense filter, the server returns HTTP 200 and displays the standard confirmation template (quote_success.html). This prevents malicious actors from knowing their bot was blocked, preventing them from iterating attack vectors, while ensuring zero spam records enter the PostgreSQL database.

4.0 The Telegram Mobile Operations System (MOS v4.0)

The Telegram bot serves as the executive operational command console across 6 strategic frontiers:

  1. 1-Tap Takeoff Calculation & Proposal Approval:

    ITB emails from general contractors are parsed by PyMuPDF, generating automated square footage takeoffs and pricing proposals dispatched directly to the CEO's Telegram with inline Approve and Adjust Scope buttons.

  2. Telegram Mini-App (TMA) Scope Configurator:

    Allows real-time toggling of cleaning scopes (Rough, Final, Touch-Up, Floor Scrubbing) inside Telegram with dynamic price recalibration.

  3. Gemini 2.5 Flash Voice Directives:

    CEO voice notes sent in Telegram are transcribed and processed using Gemini 2.5 Flash, providing immediate spoken and text operational status.

  4. Blueprint Vision & Drawing Analysis:

    Floor plan photos sent to the bot are analyzed by the vision engine to detect flooring finishes and estimate square footage.

  5. Decoupled Subcontractor Portal Automation:

    Heavy browser tasks (BuildingConnected, Bonfire) are queued in task_queue and executed by the host runner with automated completion callbacks to Telegram.

  6. Daily Executive Briefing Daemon:

    Automated 7:00 AM Central Time audit delivering a morning briefing on pending bids, outbox status, and system telemetry.

5.0 Verification & Testing Quality Gate

  • Automated Bot Defense Test Battery: Run python3 scripts/bot_defense_test_suite.py to verify that all 6 bot defense modules pass with 100% detection accuracy.
  • Telegram Latency Audit: Confirm /status responses in Telegram within 2 seconds.
  • Database Purity Audit: Confirm that honeypot-triggered submissions generate zero rows in the Leads table.

6.0 Revision History

Version Date Author Change Description
4.0.0 10/01/2026 George (Systems Architect) Major upgrade: Codified Enterprise Bot Defense Battery in Section 3.0 detailing invisible honeypot trap (hp_organization_url), sub-second timing filter (<3s), direct cURL blocking, and automated bot_defense_test_suite verification. Approved by Humberto Dominguez, CEO.
3.0.0 09/04/2026 George Upgraded SOP to Mobile Operations System (MOS v3.0). Codified 6 Telegram frontiers, TMA scope configurator, voice parsing, blueprint vision, decoupled task_queue host runner, and daily briefing daemon. Approved by CEO.
2.0.0 09/21/2026 George Modernized to post-May 1st, 2026 baseline. Standardized under Everyday Words.
1.0.0 06/01/2026 George Initial Release.
Document Structure