HR Security Policy
Purpose
This policy sets out the personnel security controls Hybrowlabs applies before, during and after an engagement with any person who may access customer systems, customer data, or Hybrowlabs infrastructure.
Hybrowlabs delivers ERPNext implementations, custom Frappe applications and ongoing support. In the course of that work our people are granted access to customer production sites, administrative roles inside customer ERP instances, source repositories, hosting consoles and database backups. This policy exists so that access of that kind is granted deliberately, monitored while it is in use, and withdrawn promptly when it is no longer required.
Scope
The policy covers every person who performs work for Hybrowlabs, regardless of employment status or location. Contractors and subcontracted personnel are held to the same obligations as employees and are onboarded through the same process before any access is issued.
Roles and responsibilities
- The director approves this policy and any exceptions to it.
- Operations maintains the joiner, mover and leaver process and the associated records.
- Project leads confirm the access each team member requires for their assigned account and raise a change request when that requirement ends.
- Every individual is accountable for the credentials issued to them and for the customer data they handle.
Pre-engagement screening
No offer of employment or contract is confirmed without identity verification. Screening is proportionate to the role: personnel who will hold administrative access to customer environments, handle payroll or financial data, or work on regulated customer accounts undergo the fuller checks described in the Background Verification Process.
Standard pre-engagement steps are:
- Government-issued identity verification and address confirmation
- Verification of stated educational and employment history
- Reference checks for roles with customer-facing or privileged access
- Criminal record check where the role, jurisdiction or a specific customer contract requires it
- Written declaration of any conflict of interest, including work for a competing party or for a customer's competitor.
Screening outcomes are recorded and retained. An adverse finding is reviewed by the director before any access is issued and may result in the offer being withdrawn or the role being restricted.
Confidentiality obligations
Every individual signs a confidentiality agreement before their first day and before any customer information is shared with them. The agreement covers customer data, customer business information, Hybrowlabs source code and proprietary products, commercial terms, and any material shared during pre-sales or discovery.
Where a customer requires its own non-disclosure agreement or requires named individuals to be listed against the engagement, Hybrowlabs executes that agreement and restricts the account team to the named individuals. Confidentiality obligations survive the end of employment or contract.
Onboarding and access provisioning
Access is issued only after the confidentiality agreement is signed, screening is complete for the relevant tier, and the project lead has specified what the role requires. Access is granted on the principle of least privilege and for a named individual, shared or generic accounts are not issued.
During onboarding, personnel receive their access credentials, a briefing on the Acceptable Use Policy, security awareness training covering phishing, credential handling, device security and data classification, instruction on the approved channels for customer communication and file transfer, and the process for reporting a suspected incident.
Administrative access to a customer production environment, server or hosting console is a separate approval. It is granted to the smallest possible number of people on an account, is recorded against the customer, and is reviewed when the project moves from implementation into support.
During the engagement
Personnel are required to:
- Use only Hybrowlabs-approved systems and accounts for customer work
- Protect credentials and use multi-factor authentication where it is available
- Access customer data only where the task in hand requires it
- Keep customer data out of personal storage, personal email and unapproved messaging tools
- Report a suspected incident, lost device or accidental disclosure immediately rather than attempting to resolve it privately.
Security awareness training is repeated annually and upon material change to the threat landscape or our tooling. Completion is recorde.
Where work is performed remotely, personnel:
- Use their assigned device with disk encryption and screen lock enabled
- Connect over a trusted network
- Follow any additional customer-side controls, such as VPN or jump-host access
A change of role, project or account triggers a review of that individual's access. Entitlements from the previous assignment that are no longer required are removed at that point rather than at exit.
Contractors and subcontracted personnel
Contractors sign the same confidentiality agreement, complete the same screening tier for the access they will hold, and receive individually named accounts. Their access is provisioned for a defined period tied to the engagement and lapses at the end of it unless renewed. Where a subcontracting organisation is involved, it is assessed and recorded under the Vendor / Subprocessor Management Policy before any customer data is shared.
Offboarding
Operations is notified as soon as a resignation, contract end or termination is confirmed. Access revocation is completed on the last working day, and immediately where the exit is involuntary or where the individual held administrative access to a customer environment.
Offboarding covers:
- Deactivation of email, single sign-on and internal system accounts
- Removal from all customer ERP instances, hosting consoles and support desks
- Revocation of SSH keys, API tokens, VPN credentials and repository access
- Rotation of any shared or service credential the individual could have observed
- Return of laptops, storage media, access cards and any customer documentation
- Confirmed deletion of customer data from personal or local storage
- A written reminder of continuing confidentiality and intellectual property obligations
Affected customers are informed where a departure changes the named team on their account or where contractual notification terms apply.
Customer-specific requirements
Where a customer contract imposes personnel requirements beyond this policy – enhanced screening, restriction to named personnel, geographic restrictions on where work may be performed, mandatory customer-issued devices, or additional training.
Those requirements take precedence and are implemented for that account. Hybrowlabs will provide evidence of compliance on request.
Disciplinary process
A suspected breach of this policy is investigated by Operations, with access suspended during the investigation where there is a credible risk to customer data. Depending on the severity and intent, the outcome may be corrective action and retraining, formal warning, permanent removal of privileged access, termination of employment or contract, or referral to law enforcement. Customers are notified where their data is affected, within the timelines set out in the applicable agreement.
Evidence maintained
Hybrowlabs maintains the following records and can produce them for customer due diligence or audit, subject to redaction of personal data:
- Signed confidentiality agreements
- Background verification records and screening tier applied
- Policy acknowledgements
- Onboarding and offboarding checklists with completion dates
- Access request, approval and revocation records
- Role-change access review records
- Security awareness training completion records
- Incident and violation records
Related documents
- Acceptable Use Policy
- Background Verification Process
- NDA / Confidentiality Agreement Structure
- Security Awareness Training Evidence Structure
- Vendor / Subprocessor Management Policy
- Subprocessor Register
Questions on our personnel controls?
If your security or procurement team needs additional detail, a completed vendor questionnaire, or evidence against a specific control, our team can respond directly.