# Human Resources Security Policy
**Document ID**: KD-POL-010
**Owner**: Chief Technology Officer
**Approved By**: CEO, Arivaran
**Effective Date**: 2026-03-19
**Next Review Date**: 2027-03-19 (recomputed 2026-10-02 on the stated semi-annual cycle from the Effective Date; the 2026-09-19 occurrence was not recorded, and this date does not assert that a review has taken place)
**Review Cycle**: Semi-annual
**Classification**: Internal
## 1. Purpose
This policy defines the human resources security requirements for personnel who access KuiperDesk systems or data. People are both the strongest asset and the most variable risk factor in any security program. This policy ensures that personnel are vetted before access is granted, trained to recognize and prevent security threats, held accountable during employment, and properly offboarded when they leave. For a small team like Arivaran's, where individuals have broad access, these controls are especially critical.
## 2. Scope
This policy applies to:
- All Arivaran employees (full-time and part-time)
- Contractors and consultants with access to KuiperDesk systems or data
- Interns with any level of system access
This policy does not apply to KuiperDesk customers or their end users (customer-side access is governed by the customer's own HR policies and Arivaran's Access Control Policy KD-POL-002 for platform access).
## 3. Policy Statements
### 3.1 Pre-Employment Screening
3.1.1. All candidates for positions with access to KuiperDesk systems or customer data shall undergo background screening before access is granted. Screening includes:
- **Identity verification**: Government-issued photo ID confirmation
- **Employment history verification**: Verification of the most recent 3 years of employment
- **Criminal background check**: Jurisdiction-appropriate criminal record check focused on fraud, theft, and computer crimes
- **Reference checks**: Minimum two professional references contacted
3.1.2. For contractors and consultants, the contracting entity is responsible for conducting background screening equivalent to Section 3.1.1. Arivaran verifies that screening has been completed before granting access.
3.1.3. Screening results are reviewed by the CEO. A finding does not automatically disqualify a candidate; the relevance to the role and the sensitivity of access are considered. The decision and rationale are documented.
3.1.4. No system access is provisioned until screening is complete and the employment/contractor agreement is signed.
### 3.2 Employment Agreements
3.2.1. All personnel sign an employment or contractor agreement that includes:
- **Confidentiality obligations**: Non-disclosure of customer data, system architecture details, credentials, and PKI material. Obligations survive termination for 2 years.
- **Acceptable use agreement**: Defines permitted and prohibited uses of Arivaran systems (see Section 3.5).
- **Intellectual property assignment**: Work product related to KuiperDesk is assigned to Arivaran.
- **Security policy acknowledgment**: Personnel acknowledge they have read and understood all KuiperDesk security policies and agree to comply.
3.2.2. Confidentiality and security obligations are re-acknowledged annually during the security awareness training completion.
### 3.3 Security Awareness Training
3.3.1. All personnel complete security awareness training within 30 days of onboarding and annually thereafter. Training covers:
- **Phishing and social engineering**: Recognition of phishing emails, pretexting, and credential harvesting. Emphasis on KuiperDesk-specific attack vectors (e.g., fake customer support requests targeting backup data access).
- **Credential security**: Password management, MFA usage, SSH key handling, and prohibition of credential sharing. Specific to KuiperDesk: handling of OpenBao unseal keys, kubeconfig files, and Keycloak admin sessions.
- **Incident reporting**: How to recognize and report security incidents per KD-POL-003. Emphasis on reporting near-misses without fear of blame.
- **Data handling**: Classification of KuiperDesk data (customer backup blocks, metadata, system logs, PKI material). Prohibited actions: copying customer data to personal devices, sharing system credentials via unencrypted channels, committing secrets to Git repositories.
- **Physical security**: Securing laptops and workstations, screen lock requirements, secure disposal of storage media.
- **Regulatory awareness**: GDPR data subject rights, breach notification obligations, and the role of Arivaran as a data processor.
3.3.2. Training is delivered through a combination of documentation review and scenario-based exercises. For a small team, training is conducted as interactive sessions rather than passive e-learning.
3.3.3. Training completion is tracked. Personnel who do not complete training within the required timeframe have their system access suspended until training is complete.
3.3.4. **Role-Specific Training**: Personnel with Tier 0 or Tier 1 access (per KD-POL-002) receive additional training on:
- Kubernetes security (pod security standards, RBAC misconfigurations, container escape vectors)
- PKI operations (certificate issuance, revocation, OpenBao unsealing)
- Incident response procedures specific to their on-call responsibilities
- Secure coding practices (for engineers contributing to aaagent, aaHashSvc, aaTwinSvc)
### 3.4 Onboarding Procedure
3.4.1. The onboarding checklist is executed by the CTO (or delegated infrastructure engineer) and tracked in a Forgejo issue:
| Step | Action | Timing |
|------|--------|--------|
| 1 | Background screening completed and reviewed | Before start date |
| 2 | Employment agreement signed (including NDA, acceptable use, policy acknowledgment) | Day 1 |
| 3 | Keycloak account created with appropriate Organization and role assignment | Day 1 |
| 4 | SSH key registered (if Tier 0/1 access) via Ansible playbook | Day 1 |
| 5 | Admin satgw-tunnel access provisioned (if remote access required) | Day 1 |
| 6 | Forgejo team membership assigned | Day 1 |
| 7 | Monitoring access (Grafana) role assigned | Day 1 |
| 8 | Security awareness training scheduled | Within 30 days |
| 9 | Role-specific training scheduled (if Tier 0/1) | Within 30 days |
| 10 | Access review: verify provisioned access matches role requirements | Day 7 |
3.4.2. Access is granted based on the role's requirements (least privilege per KD-POL-002), not based on individual requests. The CTO approves the access level for each new hire.
### 3.5 Acceptable Use
3.5.1. KuiperDesk systems and data shall be used only for authorized business purposes. The following are prohibited:
- Using KuiperDesk infrastructure for personal projects or non-business workloads
- Accessing customer backup data without a documented business justification (e.g., support request, incident investigation)
- Sharing credentials, SSH keys, or access tokens with any other person (including other Arivaran personnel)
- Installing unauthorized software on infrastructure nodes
- Disabling security controls (SELinux, FIPS mode, auditd, Tetragon) without CTO authorization and a change management PR
- Connecting personal devices to the production network (satgw admin tunnel)
- Storing customer data on personal devices or in personal cloud storage
- Using KuiperDesk email (Mailcow) for non-business purposes that could harm Arivaran's reputation
3.5.2. All activity on KuiperDesk systems is subject to monitoring (auditd, Tetragon, Loki). Personnel have no expectation of privacy when using company systems.
### 3.6 Disciplinary Process
3.6.1. Security policy violations are handled proportionally:
| Severity | Example | Action |
|----------|---------|--------|
| Minor (first occurrence) | Failure to complete training on time, unlocked workstation | Verbal warning, re-training |
| Minor (repeated) | Repeated training delays, repeated acceptable use violations | Written warning, access restriction |
| Major | Sharing credentials, disabling security controls without authorization, accessing customer data without justification | Written warning, access suspension, potential termination |
| Critical | Deliberate data exfiltration, intentional sabotage, concealing a security incident | Immediate termination, legal action |
3.6.2. Disciplinary actions are documented and retained in personnel records for the duration of employment plus 2 years.
### 3.7 Offboarding Procedure
3.7.1. When personnel leave the organization (voluntarily or involuntarily), the following offboarding procedure is executed within 24 hours of the last working day:
| Step | Action | Responsible |
|------|--------|-------------|
| 1 | Keycloak account disabled | CTO / Infrastructure Engineer |
| 2 | SSH key removed from all nodes (Ansible playbook) | Infrastructure Engineer |
| 3 | Admin satgw-tunnel access revoked | Infrastructure Engineer |
| 4 | Kubeconfig certificate revoked (added to CRL) | Infrastructure Engineer |
| 5 | Forgejo account deactivated | Infrastructure Engineer |
| 6 | Grafana / Harbor sessions invalidated | Infrastructure Engineer |
| 7 | OpenBao unseal key share rotated (if the departing person held one) | CTO |
| 8 | Company devices collected and wiped | CTO |
| 9 | Exit interview: remind departing person of ongoing NDA obligations | CEO / CTO |
| 10 | Offboarding Forgejo issue closed with completion confirmation | CTO |
3.7.2. For involuntary termination, access revocation (steps 1-6) is executed simultaneously with the termination notification, before the person is informed, to prevent retaliatory access.
3.7.3. A post-offboarding access audit is conducted 7 days after departure to verify no residual access exists.
### 3.8 Key Person Risk
3.8.1. Arivaran acknowledges key person risk as inherent to a small team. Mitigations:
- All infrastructure is defined as code (Ansible/OpenTofu/Helm) and documented in CLAUDE.md and ARCHITECTURE.md
- OpenBao unseal keys use 3-of-5 Shamir's Secret Sharing; no single person's departure prevents unsealing
- Runbooks for critical operations (DR failover, incident response, certificate renewal) are documented and tested
- Cross-training is conducted so that at least 2 people can perform any critical operation
## 4. Roles and Responsibilities
| Role | Responsibility |
|------|---------------|
| CEO | Approve hiring decisions after screening review. Conduct exit interviews. Approve termination decisions. |
| CTO | Execute onboarding/offboarding checklists. Deliver security training. Monitor training compliance. Approve access levels. |
| All Personnel | Complete training on time. Follow acceptable use policy. Report policy violations. |
## 5. Compliance Mapping
| Policy Statement | SOC 2 Criteria | ISO 27001:2022 |
|-----------------|----------------|----------------|
| 3.1 Pre-Employment Screening | CC1.4 | A.6.1 |
| 3.2 Employment Agreements | CC1.4 | A.6.2 |
| 3.3 Security Awareness Training | CC1.4 | A.6.3 |
| 3.4 Onboarding | CC6.2 | A.6.1 |
| 3.5 Acceptable Use | CC1.4 | A.5.10 |
| 3.6 Disciplinary Process | CC1.5 | A.6.4 |
| 3.7 Offboarding | CC6.5 | A.6.5 |
| 3.8 Key Person Risk | CC1.3 | A.6.1, A.8.14 |
## 6. Exceptions
Exceptions to background screening requirements require CEO approval with documented justification (e.g., urgent contractor engagement where screening is delayed but in progress). Temporary access with enhanced monitoring may be granted for up to 14 days while screening completes.
## 7. Enforcement
Training compliance is monitored monthly. Non-compliance is escalated to the CEO after 14 days past deadline. Offboarding completion within 24 hours is tracked as a KPI.
## 8. Revision History
| Version | Date | Author | Changes |
|---------|------|--------|---------|
| 1.0 | 2026-03-19 | CTO | Initial release |