| Document Control | Institutional Specification |
|---|---|
| Document Title | Disaster Recovery and Data Restoration SOP |
| Document ID | HWB-QMS-9.3 |
| Version | 4.0.0 |
| Status | APPROVED |
| Author | Peter (Recovery Specialist) & George (Systems Architect) |
| Approved By | Humberto Dominguez, CEO |
| Effective Date | 10/01/2026 |
| ISO Standard | ISO 9001:2015 Clause 7.1.3 & ISO 27001:2022 A.12.1 (Operational Continuity) |
Standard Operating Procedure: Disaster Recovery and Data Restoration
1.0 Purpose & Continuous Recovery Mandate
This procedure defines the protocol for recovering company operations, databases, application containers, cryptographic keys, and AI agent brains following a hardware failure, data corruption event, or cloud disruption. In strict adherence to our Continuous Recovery Mandate, this SOP is updated immediately following any new software installation, container dependency upgrade, or database migration.
2.0 Scope
Applies to all Linux host machines, Docker containers, PostgreSQL databases, Microsoft 365 integrations, and AI agent state directories across HWB Cleaning Services LLC.
3.0 Peter's 6 Institutional Recovery Directives
| Directive | Execution Cadence | Standard & Target |
|---|---|---|
| 1. Binary DB Snapshot | Hourly | Instant recovery for binary PostgreSQL database states via automated pg_dump and WAL shipping. |
| 2. Environment Freeze | Daily | Secure encrypted archive of .env configurations, secret salts, and Docker environment variables. |
| 3. Ghost Checkpoints | Pre-Restart | Automatic local Git branch checkpoint created before every system restart or container teardown. |
| 4. Institutional Mirror | Weekly | Off-site synchronization of the complete SigmaFidelity™ Brain to sovereign physical storage. |
| 5. Surge Protector | Every 15 Minutes | Disk-usage watchdog check enforcing a 500MB runaway log threshold to prevent disk exhaustion. |
| 6. Vault Guardian | Daily | Incremental backup of all active operational folders and QMS documentation vaults. |
4.0 System Dependencies & Cryptographic Vault Configuration
The system infrastructure relies on the following core dependencies (updated October 01, 2026):
- Operating System: Linux / WSL2 Ubuntu 22.04 LTS.
- Container Fleet: Docker 26+ running containers:
hwb_web_app(Gunicorn Flask, Port 5000),hwb_postgres_dev(PostgreSQL 13, Port 5432),hwb_compliance_engine(Nginx static QMS, Port 80),hwb_traffic_director(Port 8000), andhwb_agent_worker(Autonomous Worker Container). - Autonomous Worker Browser Engine:
playwright 1.63.0and Chrome Headless Shell (v1243) installed natively inhwb_agent_workerfor portal crawling. - Statewide Hunter Crawler Fleet:
scripts/hunter_portal_crawler.pycontinuously scouts 35 Texas municipal and ISD procurement portals on an autonomous 6-hour cycle. - Python Cryptography Core:
cryptography 48.0.0installed inhwb_web_appfor deterministic AES-256 Fernet ciphers. - Environment Secrets:
SECRET_KEY&PII_ENCRYPTION_KEY: Cryptographic seed keys for database column encryption. Never committed to Git.DATABASE_URL: PostgreSQL connection string formatted aspostgresql://postgres:...@localhost:5432/hwb_crm.AZURE_CLIENT_SECRET: Microsoft Graph API OAuth secret. Institutional Alert: Secret rotation required prior to expiration on 03/02/2027.
- Database Schema State (Migration 036 Baseline): Unified relational schema up to Migration 036 (
scripts/migrate_036_client_breadcrumbs.py), providing:ClientBreadcrumbs: Client DOM telemetry with session ID, event type, and target selectors.SecurityAuditLogs: Protected by Write-Once-Read-Many (WORM) triggerprevent_security_audit_mutation()blocking all updates and deletes.GovernmentPrograms,RackTelemetryHistory,GeneralContractors,InstitutionalBids,ConstructionBids, andSCA_WageDeterminations.- AES-256 encrypted PII vaulting on
Employees.
- Automated Data Retention: Native PostgreSQL stored function
purge_expired_client_breadcrumbs(retention_days=30)automatically purges telemetry logs older than 30 days to enforce ISO 27001 Control A.8.10 data minimization. - Timezone Standard: All system timestamps, database audit columns, and telemetry records are strictly pinned to Texas Central Time (
America/Chicago/ CDT/CST). - Session Timeout Standard: All authenticated administrative, backoffice, and executive web sessions automatically invalidate after 30 minutes of inactivity.
- First-Party DOM Sensor:
static/js/sigma_breadcrumbs.js(< 3.5KB vanilla JS) capturing page views, button clicks, rage clicks, and JavaScript runtime errors with automatic client-side PII sanitization. - Dual-Zone Air-Gap: Third-party visual replay scripts (Microsoft Clarity) strictly isolated to anonymous public marketing pages. Authenticated internal backoffice portals utilize 100% sovereign first-party telemetry.
- Automated Quality Gates:
scripts/tessa_regression_suite.py: 11-module platform verification battery supervised continuously inhwb_agent_worker.scripts/yamamoto_bid_test_suite.py: 8-module bidding engine verification battery certifying institutional estimating logic.
5.0 Step-by-Step Restoration Procedures
5.1 Cold Server Rebuild (Total Catastrophe Recovery)
- Clone primary repository:
git clone https://github.com/Humbertoed11/gemini_projects.git - Restore frozen
.envfile from the Vault Guardian archive intoHWB-COMPANY/HWB-IT/HWB-IT-WEBSITE/.env. - Execute master startup sequence:
bash scripts/startup_master.sh - Verify Docker containers are healthy:
docker ps
5.2 Database Restoration & Migration Alignment
- Restore the latest binary PostgreSQL backup:
docker exec -i hwb_postgres_dev psql -U postgres -d hwb_crm < backup_latest.sql - Run migration checks inside web container:
docker exec hwb_web_app python3 scripts/migrate_036_client_breadcrumbs.py - Verify lead count via audit endpoint:
curl -s http://localhost:5000/api/v1/db-audit - Run automated regression gate:
python3 scripts/tessa_regression_suite.pyandpython3 scripts/yamamoto_bid_test_suite.py
5.3 The Panic Button (Working Tree Clean Reset)
If local uncommitted code disrupts container execution: git reset --hard HEAD && git clean -fd followed by docker restart hwb_web_app.
6.0 Verification & Continuity Sign-Off
- Web application responds with HTTP 200 at
http://mop.test:5000. - PostgreSQL connection pool establishes within 1.0 ms latency.
- WORM immutability trigger actively prevents modification of
SecurityAuditLogs. - Telemetry breadcrumb ingestion (
POST /api/v1/telemetry/breadcrumbs) records client interactions with 0 errors. - SQL Brain synchronization (
docker exec hwb_web_app python3 /app/scripts/sigma_sync.py) completes with 0 errors.
7.0 Revision History
| Version | Date | Author | Change Description |
|---|---|---|---|
| 4.0.0 | 10/01/2026 | Peter & George | Upgraded per Continuous Recovery Mandate following Migration 036 (ClientBreadcrumbs table, sigma_breadcrumbs.js DOM sensor, and purge_expired_client_breadcrumbs(30) automated data lifecycle). Codified SecurityAuditLogs WORM immutability trigger, 30-minute idle session timeout, Texas Central Time standard, Yamamoto Moto AI Estimator test gate, and dual-zone air-gapped observability architecture. Approved by Humberto Dominguez, CEO. |
| 3.4.0 | 09/25/2026 | Peter & George | Upgraded per Continuous Recovery Mandate following installation of PyMuPDF 1.26+ and BeautifulSoup4 in requirements.txt (BUG-093) and integration of Tessa Test (scripts/tessa_regression_suite.py) as continuous 7-module supervisor daemon in worker_launcher.py (ARCH-008). Approved by Humberto Dominguez, CEO. |
| 3.3.0 | 09/25/2026 | Peter & George | Upgraded per Continuous Recovery Mandate following Migration 026 (Provisioned RackTelemetryHistory table in PostgreSQL and integrated 7-rack SPC snapshot persistence) and deployment of Telegram Operations Command Node v3.0. Approved by Humberto Dominguez, CEO. |
| 3.2.0 | 09/23/2026 | Peter & George | Upgraded per Continuous Recovery Mandate following Migration 025 (Master GeneralContractors Directory, 4-Point Vetting Scorecard, and Autonomous Profile Enricher). Approved by Humberto Dominguez, CEO. |
| 3.1.0 | 09/22/2026 | Peter & George | Upgraded per Continuous Recovery Mandate following installation of Playwright 1.63.0 and Chrome Headless Shell in hwb_agent_worker container and Statewide Hunter Contract Crawler. Approved by Humberto Dominguez, CEO. |
| 3.0.0 | 09/21/2026 | Peter & George | Upgraded per Continuous Recovery Mandate following Migration 016 and cryptography 48.0.0 installation. Approved by Humberto Dominguez, CEO. |
| 2.0.0 | 05/21/2026 | George | Modernized to post-May 1st, 2026 baseline. Standardized under Everyday Words. |
| 1.0.0 | 02/28/2026 | Gemini | Initial Release. |