SalusSalus's Trust Center

Security at Salus

Clery Act and campus safety compliance platform for higher education. Transparent visibility into how Salus secures customer data, governs its platform, and evidences its controls.

Security Controls

55 safeguards monitored across our infrastructure and processes, grouped by the area they govern.

CJIS controls

Controls aligned to the FBI CJIS Security Policy for environments where criminal justice information is in scope.

11 controls
CJI classified at ingestion, fail-closed

CAD- and RMS-derived records are treated as CJI unless affirmatively determined otherwise.

CJI processing confined to a US cloud boundary

Storage, processing, and inference remain in US regions within our cloud environment.

Encryption in transit via FIPS-validated endpoints

TLS with FIPS-validated endpoints on the CJI path.

AES-256 encryption at rest with managed keys

Data at rest is encrypted with keys held in the cloud key management service.

Single designated data custodian for CJI systems

No other personnel, including leadership, hold credentials to systems containing CJI.

Fingerprint-based background screening for CJI access

State and national checks completed through each agency's state process.

CJIS Security Awareness Training completed

Required for personnel with CJI access and repeated on the required cycle.

CJIS Security Addendum executed with agency customers

The Attorney General-approved addendum is signed for each agency engagement.

Per-record access logging retained and available to the agency

Every access to a CJI-classed record is captured in an immutable audit trail.

No CJI transmitted by email

Notifications carry links into the authenticated application, never record content.

No CJI sent to third-party model APIs

Inference runs inside our cloud boundary rather than at an external AI provider.

Access Management

Who can reach production, and on whose approval.

8 controls
Least privilege access

Access is granted at the minimum scope needed for a role.

Role-based authorization

Application permissions are derived from assigned roles, not per-user grants.

Quarterly access reviews

Production and administrative access is reviewed on a fixed cadence.

Onboarding approval

New access requires documented approval before provisioning.

Offboarding revocation

Access is revoked across systems on the last day of employment.

Unique user accounts

Shared logins are prohibited; every actor is individually attributable.

Tenant isolation

Customer data is scoped by organization at every read and write path.

Remote access controls

Administrative access requires authenticated, encrypted sessions.

Infrastructure Security

How the platform and its network are built and defended.

7 controls
Encryption in transit

All external traffic is served over TLS with modern cipher suites.

Encryption at rest

Databases, object storage, and backups are encrypted at rest.

Network segmentation

Application, data, and management tiers are separated.

Firewall rules

Inbound access is denied by default and opened by explicit rule.

Backup and restore

Automated backups are taken and restores are exercised.

Infrastructure as code

Environments are declared in version-controlled configuration.

Third-party penetration testing

An independent assessor tests the platform and findings are tracked to closure.

Change Management

How code reaches production without surprises.

6 controls
Peer code review

Changes to production code require review by another engineer.

Protected branches

Direct pushes to release branches are blocked.

Automated test gate

Type checks and tests must pass before a change can merge.

Version-controlled releases

Every deployment maps to an identifiable commit.

Rollback procedure

A documented path exists to revert a bad release quickly.

Separate environments

Development and production are isolated from each other.

Credential Handling

How secrets and identities are protected.

6 controls
Multi-factor authentication

MFA is enforced for administrative and production access.

Secret management

Credentials are held in a managed secret store, never in source.

Secret scanning

Repositories are scanned for committed credentials.

Password hashing

Account passwords are stored using a modern one-way hash.

API key scoping and rotation

Keys are scoped to an organization and can be rotated or revoked.

Session expiry

Authenticated sessions expire and can be terminated centrally.

System Configuration

Hardened defaults across endpoints and services.

6 controls
Hardened baselines

Services are deployed from reviewed, hardened configurations.

Endpoint disk encryption

Company workstations enforce full-disk encryption.

Endpoint screen lock

Workstations lock automatically after inactivity.

Patch management

Operating systems and dependencies are kept current.

Dependency vulnerability scanning

Third-party packages are scanned and upgraded on findings.

Security response headers

Applications set CSP, HSTS, and frame protections.

Monitoring

What is watched, recorded, and reviewed.

6 controls
Centralized logging

Application and infrastructure logs are aggregated.

Immutable audit trail

Security-relevant actions are recorded with actor and timestamp.

Availability monitoring

Uptime and error rates are monitored continuously.

Alerting and on-call

Alerts route to a responsible on-call engineer.

Log retention

Logs are retained for the period set by policy.

Anomalous access review

Unusual administrative access is surfaced for review.

Incident Response

What happens when something goes wrong.

5 controls
Documented response plan

Roles, severities, and escalation paths are defined in advance.

Severity classification

Incidents are triaged against a documented severity scale.

Customer notification

Affected customers are notified within contractual timelines.

Post-incident review

Every significant incident gets a written retrospective.

Annual plan exercise

The response plan is tested and updated at least annually.