- CJI classified at ingestion, fail-closed
- CJI processing confined to a US cloud boundary
- Encryption in transit via FIPS-validated endpoints
Compliance

CJIS Security Policy
Aligned

SOC 2 Type 1
Compliant

HECVAT 4.1.4
Completed
Resources
SOC 2 Type 1 Report
Access required
Penetration Test Report
Access required
HECVAT 4.1.4
Access required
Certificate of Insurance
Access required
Controls
Monitored continuously- Least privilege access
- Role-based authorization
- Quarterly access reviews
- Encryption in transit
- Encryption at rest
- Network segmentation
- Peer code review
- Protected branches
- Automated test gate
- Multi-factor authentication
- Secret management
- Secret scanning
- Hardened baselines
- Endpoint disk encryption
- Endpoint screen lock
- Centralized logging
- Immutable audit trail
- Availability monitoring
- Documented response plan
- Severity classification
- Customer notification
Subprocessors
Platform subprocessors only. Website subprocessors are listed on the subprocessors page.