Salus aligns its systems to the FBI CJIS Security Policy, executes the FBI CJIS Security Addendum with each agency customer, and supports agencies through their state CSA audits. This document describes the controls that protect Criminal Justice Information, the records and query returns an agency classifies as CJI, once that data reaches Salus.
Everything enters through one gate and stays in United States regions
CJI classed data is processed and stored only inside the AWS boundary shown below. Two paths cross that boundary: records arriving from agency source systems, and authenticated agency users reading them. Nothing else crosses it.
What Salus treats as CJI
CJI classed data means Criminal Justice Information, including criminal history record information and NCIC and state query returns, contained in records ingested from agency CAD and RMS systems.
Classification is fail closed. Every CAD and RMS derived record and field is treated as CJI at ingestion unless it is affirmatively determined otherwise. Data is never assumed to be non CJI by default, so a misclassification leaves data more protected rather than less.
One person can reach it
CJI classed data is accessible to a single designated data custodian. No other personnel, including company leadership, hold credentials to systems containing CJI.
Personnel with CJI access complete state and national fingerprint based background checks through each agency's state process, as required under the CJIS Security Addendum.
Non access is provable, not asserted
Every access to a CJI classed record is captured in an immutable audit trail, comprising the application activity log and AWS CloudTrail, and is available to the agency on request. An agency can therefore verify that a record was not opened, rather than take that claim on trust.
Security incidents affecting CJI are reported to the agency and its CSA as required by the CJIS Security Policy.
AI inference runs inside the same boundary
All AI inference involving CJI classed data runs on Amazon Bedrock inside the AWS boundary, in region. Model providers never receive the data. Nothing is retained by the model layer, and no customer data is ever used to train models.
AI output is advisory. Authorized agency personnel make and record all determinations.
What Salus never does
- No CJI in email. Notifications contain links into the authenticated application, never record content.
- No CJI to third party model APIs.
- No training of any model on customer data.
- No processing or storage of CJI outside the United States.
- No CJI access without fingerprint based vetting.
CJIS Security Policy control mapping
Each policy area below names the Salus control that satisfies it. An agency auditor can read this alongside the executed Security Addendum.
| CJIS Security Policy area | Salus control |
|---|---|
| Access control | Single custodian model with least privilege IAM. No CJI credentials are held outside the custodian role. |
| Identification and authentication | Unique accounts and multi-factor authentication for all system access. |
| Auditing and accountability | Immutable per record access logging at the application layer plus AWS CloudTrail. Logs available to the agency. |
| Encryption | TLS with FIPS validated endpoints in transit. AES-256 at rest with keys held in AWS KMS. |
| Media protection | No removable media in the CJI path. Storage is encrypted, and deletion is governed by retention policy and key destruction. |
| Physical protection | Inherited from AWS United States data centers, under SOC audited physical controls. |
| Personnel security | Fingerprint based state and national background checks through each agency's state process. CJIS Security Awareness Training. Signed Security Addendum certification pages. |
| Incident response | Documented response plan with agency and CSA notification under the CJIS Security Policy. |
| Formal agreements | FBI CJIS Security Addendum executed with each agency customer. Subprocessor list available on request. |
There is no CJIS certification to hold
There is no "CJIS certification" and no certifying body. Any vendor claiming to be CJIS certified is misstating how CJIS works. Compliance with the FBI CJIS Security Policy is achieved through implemented controls, binding agreements, and audit, not a badge. That is the standard this document describes.
Salus is SOC 2 certified. The SOC 2 report, HECVAT, and penetration test results are available on request. Questions about anything above go to security@trysalus.com.