North Texas Commercial Cleaning Experts | Call (214)-586-0257
Print to PDF
Document IDHWB-QMS-9.6
Version4.0.0
Statusâ—Ź APPROVED
ClauseISO/IEC 27001:2022 & SOC 2 Type II
Document Control Institutional Specification
Document Title Information Security Management System (ISMS) & PII Vault SOP
Document ID HWB-QMS-9.6
Version 4.0.0
Status APPROVED
Author George (Systems Architect, mbB, Lead ISO Auditor)
Approved By Humberto Dominguez, CEO
Effective Date 10/01/2026
Regulatory Standards ISO/IEC 27001:2022 Controls (A.8.10, A.8.12, A.8.15, A.12.4), SOC 2 Type II (CC6.1, CC6.8), Texas Bus. & Com. Code § 521.053, TDPSA

Standard Operating Procedure: Information Security Management System (ISMS) & PII Vault

1.0 Purpose

This SOP aligns the IT, cryptographic, and operational security controls of HWB Cleaning Services LLC with ISO/IEC 27001:2022, SOC 2 Type II, the Texas Data Privacy and Security Act (TDPSA), and Texas Business and Commerce Code § 521.053. It guarantees that company databases, customer data, AI agent workflows, and employee identification records are safeguarded against unauthorized access, data compromise, and cyber threats.

2.0 Scope

Applies to all digital infrastructure, databases, container networks, APIs, administrative personnel, and physical commercial cleaning staff operating inside sensitive client facilities (data centers, defense facilities, corporate offices).

3.0 Operational Security Controls

3.1 Physical Security (Field Cleaning Personnel)

  1. Zero-Interaction Mandate: Field cleaning staff are strictly prohibited from touching, inspecting, or photographing client documents, unattended laptops, whiteboards, or server racks.
  2. Facility Access Badging: Staff may only enter areas approved by client security. Tailgating or propping secure perimeter doors open is grounds for immediate termination.
  3. Device Prohibition: Personal smartphones are prohibited from taking photos or videos inside client facilities or secure cleanrooms.

3.2 Digital Infrastructure Security

  1. Encryption in Transit: All HTTP traffic is secured via modern TLS 1.3 encryption. External API webhooks and internal database bridges communicate exclusively across private Docker networks or SSL-encrypted Azure endpoints.
  2. PostgreSQL Database Protection: All operational data resides in PostgreSQL with volume encryption at rest and strict connection pooling (ThreadedConnectionPool) enforcing sub-millisecond query verification.
  3. Role-Based Access Control (RBAC): The application enforces centralized gateway interception. Outside Sales personnel are strictly locked to the Field Sales Desk (/admin/sales-desk) and blocked from operational tables or data exports.
  4. 30-Minute Idle Session Timeout: All authenticated user sessions across administrative and backoffice desks automatically expire and invalidate following 30 minutes of inactivity.

3.3 Personally Identifiable Information (PII) Vault Protocol (SEC-001)

To eliminate data breach liabilities and comply with Texas identity theft statutes, all sensitive personal data follows the SigmaFidelity™ Cryptographic Protocol:

  1. AES-256 Column Encryption: Social Security Numbers, ITINs, and direct deposit checking/savings account numbers are encrypted at the PostgreSQL column level (ssn_encrypted, direct_deposit_account_encrypted) using deterministic Fernet keys derived from environment secret salts.
  2. Zero Plaintext Storage or Transmission: Plaintext SSNs and bank accounts are never written to disk, saved in logs, transmitted across general GET endpoints, or included in exported CSV rosters. Standard displays render only masked characters (***-**-#### and ••••••••####).
  3. Bulleted Keystroke Formatting: Form inputs for sensitive data use password-masked inputs and dynamic keystroke masking (maskSSNInput) enforcing ###-##-####.
  4. Audited 30-Second Timed Reveal: Authorized managers requesting unmasked views must trigger POST /api/v1/hr/employees/<id>/reveal-ssn. The gateway records the manager's user ID, username, and IP address into "GlobalActivities". The decrypted value is displayed with an active 30-second countdown timer that automatically locks and re-masks upon expiration or modal exit.
  5. Automated Violation Telemetry: Any unauthorized role attempting to call sensitive PII reveal endpoints is blocked with HTTP 403 Forbidden and logged as a SECURITY_VIOLATION event in the corporate audit ledger.

3.4 Advanced ISO 27001:2022 & SOC 2 Controls (Version 4.0.0 Architecture)

ISO 27001 Control Technical Implementation Compliance Target
Control A.8.12 (Data Leakage Prevention) Strict Dual-Zone Air-Gap in templates/base.html. Third-party heatmap scripts (Microsoft Clarity) are strictly prohibited from loading on authenticated portals, admin pages, or login screens. Only anonymous public marketing pages may execute external scripts. Zero third-party exposure of employee PII, financial records, or operational data.
Control A.8.15 (Logging & Telemetry) First-party DOM Sensor (static/js/sigma_breadcrumbs.js) and ClientBreadcrumbs PostgreSQL table. Tracks page navigation, button clicks, rage clicks, and JavaScript errors with automated client-side redacting of passwords, cards, and tax IDs. 100% sovereign client-side observability without third-party vendor data transfer.
Control A.8.10 (Information Deletion) Automated PostgreSQL lifecycle stored procedure: purge_expired_client_breadcrumbs(retention_days=30). Runs scheduled automated purges of telemetry logs older than 30 days. Relentless data minimization and compliance with TDPSA / GDPR storage limitation.
Control A.12.4 (Log Tamper Protection) Write-Once-Read-Many (WORM) immutability trigger prevent_security_audit_mutation() on the SecurityAuditLogs table. Strictly blocks UPDATE and DELETE statements at the database engine level. Permanent, tamper-evident security audit trail for SOC 2 Type II and regulatory auditors.

4.0 Verification & Compliance Audit

  • Automated Regression Testing: scripts/tessa_regression_suite.py verifies RBAC gates, PostgreSQL connection pool latency, and security audit integrity.
  • Cryptographic Verification: Direct SQL queries confirm that all SSN and banking columns contain exclusively AES-256 ciphertext blobs with zero plaintext leaks.
  • Air-Gap Verification: Automated browser tests confirm third-party script tags do not exist in the DOM on /admin/* and /login routes.
  • WORM Immutability Verification: Direct SQL tests confirm that attempts to mutate SecurityAuditLogs are rejected with PostgreSQL exception SECURITY AUDIT LOG IS IMMUTABLE (WORM).

5.0 Notes and Cautions

Breach Notification Law (Texas Bus. & Com. Code § 521.053)

Under Texas law, any unauthorized acquisition of unencrypted computerized sensitive data requires immediate formal notification to affected individuals and the Texas Attorney General. Our AES-256 column encryption provides safe harbor status, shielding HWB from notification mandates and legal liability in the event of database media compromise.


6.0 Revision History

Version Date Author Change Description
4.0.0 10/01/2026 George (Systems Architect) Major upgrade: Codified Section 3.4 documenting ISO 27001 Controls A.8.10 (30-day purge_expired_client_breadcrumbs), A.8.12 (Strict Dual-Zone Air-Gap on third-party analytics), A.8.15 (ClientBreadcrumbs first-party DOM sensor), and A.12.4 (SecurityAuditLogs WORM immutability trigger). Added 30-minute idle session timeout standard. Approved by Humberto Dominguez, CEO.
3.0.0 09/21/2026 George (Systems Architect) Major upgrade: Codified Section 3.3 Sensitive PII Vault Protocol (SEC-001) incorporating AES-256 Fernet column encryption, 30-second timed reveal, SOC 2 / ISO 27001 immutable audit logging to GlobalActivities, and Texas Bus. & Com. Code § 521.053 safe harbor compliance. Approved by Humberto Dominguez, CEO.
2.0.0 05/21/2026 George Modernized to post-May 1st, 2026 baseline. Standardized under Everyday Words.
1.0.0 03/08/2026 George Initial ISMS framework established per ISO/IEC 27001:2022.
Document Structure