Skip to main content

U.S. Public Works

Data Handling

Security and data handling

Certified payroll means sending records about real people. This is what happens to them, stated plainly, with what CPB does not claim stated just as plainly.

In place today

What CPB does with your records

Each of these describes the system as it is now, not as it is intended to be.

No full Social Security numbers are kept

Certified payroll requires worker identification, and CPB does not retain a full Social Security number to provide it. Workers are identified internally by a CPB identifier, and where a submission requires the last four digits, that is what is held — never the whole number.

Personal details are held separately from the payroll work

The information that identifies a person is stored apart from the hours, classifications and rates the certified payroll work runs on. The day-to-day processing operates on the latter, which means most of the work touches no personal detail at all.

Nothing you send is reachable without authentication

Every route that can read payroll data requires a credential, and the check fails closed: if the credential is not configured, access is refused rather than allowed. There is no public URL that returns a payroll record.

Original files are not kept after they are processed

CPB works from the payroll data your system produces. The uploaded source file is not retained once its contents have been read into the records that the work actually uses, so there is no accumulating archive of raw spreadsheets.

Identifiers never appear in logs

Social Security numbers are excluded from application logs by construction rather than by convention, so the operational record of what the system did cannot become a second copy of the sensitive data it did it to.

Personal data is not sent to AI providers

CPB uses automated systems in parts of its work. Worker personal data is excluded from what those systems receive, and the telephone agents that speak with contractors are never given raw payroll records at all.

Credentials live in the deployment, never in the code

Every secret the service uses is supplied by the deployment environment. None is committed to the repository. CPB also does not store contractors' government portal passwords in code — where a filing requires a contractor's own credentials, they are not held that way.

Records are retained for a stated period, not indefinitely

Certified payroll records have a statutory retention period, and CPB keeps covered project records for it and can retrieve them on request. Retention is a defined policy with a defined end rather than keeping everything forever by default.

Stated plainly

What CPB does not claim

A security page without this section invites you to assume the certifications every competitor implies. CPB would rather tell you.
  • CPB holds no SOC 2 report, no ISO 27001 certification, and no other third-party security certification.
  • CPB has not undergone an external security audit or penetration test.
  • CPB is not a HIPAA-covered entity and makes no HIPAA representation.
  • CPB holds no government security accreditation of any kind, and is not certified, endorsed or approved by any agency.
  • Nothing here is a warranty against every possible incident. It is a description of the controls in place.

Why it reads this way

CPB is a new organisation and states its controls rather than displaying badges it has not earned. The list above is what is in place today, not what is planned. If your own procurement process requires something that is not described here, ask Payroll Operations and you will get a straight answer about whether it exists.

Sending records

Records are received through the intake process agreed at engagement, confirmed with you before the first reporting cycle. CPB will not ask you to send payroll records to an address you have not agreed, and will never ask for the password to your own government filing account.