North Texas Commercial Cleaning Experts | Call (214)-586-0257
Print to PDF
Document IDHWB-QMS-7.6
Version3.1.0
Statusâ—Ź APPROVED
Clause8.1 & 8.5.1 (Operational Control) & ISO 27001
Document Control
Document TitleBackend Architecture and Enterprise Standards SOP
Document IDHWB-QMS-7.6
Version3.1.0
StatusAPPROVED
AuthorGeorge (Systems Architect)
Approved ByHumberto Dominguez, CEO
Date09/21/2026
ISO 9001 Clause8.1 Operational Planning & 8.5.1 Service Provision / ISO 27001:2022 ISMS

Standard Operating Procedure: Backend Architecture, RBAC Gateway & PII Cryptography

1.0 Purpose

This procedure establishes the Zero-Hotfix Enterprise Mandate and cryptographic security standards across all software systems at HWB Cleaning Services LLC. The purpose is to eliminate quick patches, temporary workarounds, and on-the-fly code. Every engineering change must be designed to enterprise standards, protecting company data and preventing defects from recurring.

2.0 Scope

This standard applies to all software engineers, autonomous AI agents, technical contractors, and administrative systems operating within the HWB ecosystem, including the web application, background workers, databases, and APIs.

3.0 The Zero-Hotfix Enterprise Mandate

The Institutional Law

From September 18, 2026 onward, only enterprise-level solutions are permitted in the HWB codebase. Ad-hoc hotfixes, local workaround scripts, and quick patches are strictly prohibited.

When an issue or security gap is discovered, developers must find the root cause in the architecture and fix the system as a whole, rather than patching a single screen or endpoint.

4.0 The 6 Pillars of Enterprise Architecture

Pillar Core Requirement Industrial Purpose
1. Root Cause Engineering Solve systemic causes, never mask symptoms with local if statements. Prevents identical bugs from emerging in adjacent modules.
2. Centralized Gateway Enforce access control at the request gatekeeper (@app.before_request). Fail-safe default: new endpoints are secure by default.
3. Declarative Contracts Use explicit decorators like @roles_required on endpoints. Code is readable, self-documenting, and impossible to bypass.
4. Defense-in-Depth Triple protection: Database checks + Backend interceptors + Clean UI rendering. Even if a user bypasses the UI, backend locks stop unauthorized requests.
5. Automated Testing Mandatory test scripts verifying both authorized and blocked paths. Proves code works before deployment with zero guesswork.
6. Immutable Audit Trail Log every access violation to GlobalActivities in PostgreSQL. Provides full accountability and traceability for ISO audits.

5.0 Role-Based Access Control (RBAC) Quarantine Standard

User access is partitioned into distinct operational zones based on verified roles:

  • Executive & Admin: Global system access, Warchest financial controls, user provisioning, and strategy modules.
  • Manager: Operations oversight, accounts, and SOP manual. Restricted from user provisioning and financial Warchest.
  • Operator: Daily cleaning dispatch, work orders, and commercial lead pipeline.
  • Sales: Strict isolation to the Field Sales Desk (/admin/sales-desk), assigned facility queue, 1-tap dialer/maps, and walkthrough quoting. All bulk data exports, payroll summaries, and sensitive workforce endpoints are blocked with HTTP 403.

6.0 Sensitive PII Vault & Cryptographic Architecture (SEC-001)

All sensitive worker identifiers and financial credentials are protected by the SigmaFidelity™ Cryptographic Core (core/security.py):

  1. AES-256 Fernet Cipher: Social Security Numbers, ITINs, and direct deposit checking/savings accounts are encrypted at the column level before writing to PostgreSQL (ssn_encrypted, direct_deposit_account_encrypted).
  2. Deterministic Key Derivation: The cipher key is derived deterministically via SHA-256 hashing of system environment secrets (PII_ENCRYPTION_KEY / SECRET_KEY), guaranteeing persistence across container restarts without key drift.
  3. Zero Plaintext API Exposure: All general endpoints (GET /api/v1/hr/employees and GET /api/v1/hr/employees/<id>) strip encrypted ciphertext blobs and transmit only masked strings (***-**-#### and ••••••••####).
  4. Audited Timed Reveal Protocol: Authorized personnel requesting unmasked views must use POST /api/v1/hr/employees/<id>/reveal-ssn. The gateway checks credentials, records an immutable audit log to "GlobalActivities" (stamping user ID, username, and IP address), and returns the decrypted value with a strict 30-second client-side lifetime.
  5. Automatic Security Violation Logging: If unauthorized roles (e.g. Sales) attempt to call sensitive reveal endpoints, the gateway returns HTTP 403 Forbidden and writes an automatic SECURITY_VIOLATION event to the audit ledger.

7.0 Verification (Zero-Defect Check)

  • All admin routes must declare explicit role requirements using @roles_required.
  • The centralized gatekeeper (@app.before_request) must automatically intercept out-of-bounds requests.
  • Templates must receive permissions through nav_access context engine without scattered manual role checks.
  • All employee queries must sanitize output dictionaries, ensuring no raw ciphertexts or unmasked bank accounts exist in memory.
  • Automated test suite verifying RBAC quarantine and PII encryption must pass 100% prior to any container deployment.

8.0 Revision History

Date Version Description of Change Approved By
09-21-2026 3.1.0 Added Section 6.0 Sensitive PII Vault and Cryptographic Architecture (SEC-001): AES-256 Fernet encryption, deterministic key derivation, zero-plaintext API serialization, 30s timed reveal, and GlobalActivities audit logging. Approved by Humberto Dominguez, CEO. Humberto Dominguez, CEO
09-18-2026 3.0.0 Codified the Zero-Hotfix Enterprise Mandate and Centralized RBAC Gateway Architecture following CEO decree. Humberto Dominguez, CEO
05-21-2026 2.0.0 Modernized to post-May 1st, 2026 baseline. Standardized under Everyday Words. George (Systems Architect)
Document Structure