Data Handling
Security and data handling
Certified payroll means sending records about real people. This is what happens to them, stated plainly, with what CPB does not claim stated just as plainly.
In place today
What CPB does with your records
No full Social Security numbers are kept
Certified payroll requires worker identification, and CPB does not retain a full Social Security number to provide it. Workers are identified internally by a CPB identifier, and where a submission requires the last four digits, that is what is held — never the whole number.
Personal details are held separately from the payroll work
The information that identifies a person is stored apart from the hours, classifications and rates the certified payroll work runs on. The day-to-day processing operates on the latter, which means most of the work touches no personal detail at all.
Nothing you send is reachable without authentication
Every route that can read payroll data requires a credential, and the check fails closed: if the credential is not configured, access is refused rather than allowed. There is no public URL that returns a payroll record.
Original files are not kept after they are processed
CPB works from the payroll data your system produces. The uploaded source file is not retained once its contents have been read into the records that the work actually uses, so there is no accumulating archive of raw spreadsheets.
Identifiers never appear in logs
Social Security numbers are excluded from application logs by construction rather than by convention, so the operational record of what the system did cannot become a second copy of the sensitive data it did it to.
Personal data is not sent to AI providers
CPB uses automated systems in parts of its work. Worker personal data is excluded from what those systems receive, and the telephone agents that speak with contractors are never given raw payroll records at all.
Credentials live in the deployment, never in the code
Every secret the service uses is supplied by the deployment environment. None is committed to the repository. CPB also does not store contractors' government portal passwords in code — where a filing requires a contractor's own credentials, they are not held that way.
Records are retained for a stated period, not indefinitely
Certified payroll records have a statutory retention period, and CPB keeps covered project records for it and can retrieve them on request. Retention is a defined policy with a defined end rather than keeping everything forever by default.
Stated plainly
What CPB does not claim
- CPB holds no SOC 2 report, no ISO 27001 certification, and no other third-party security certification.
- CPB has not undergone an external security audit or penetration test.
- CPB is not a HIPAA-covered entity and makes no HIPAA representation.
- CPB holds no government security accreditation of any kind, and is not certified, endorsed or approved by any agency.
- Nothing here is a warranty against every possible incident. It is a description of the controls in place.
Why it reads this way
CPB is a new organisation and states its controls rather than displaying badges it has not earned. The list above is what is in place today, not what is planned. If your own procurement process requires something that is not described here, ask Payroll Operations and you will get a straight answer about whether it exists.
Sending records
Records are received through the intake process agreed at engagement, confirmed with you before the first reporting cycle. CPB will not ask you to send payroll records to an address you have not agreed, and will never ask for the password to your own government filing account.