Salus CJIS Security Posture

Maintained by the Salus security team · Confidential

Salus aligns its systems to the FBI CJIS Security Policy, executes the FBI CJIS Security Addendum with each agency customer, and supports our customers through their state CSA audits. This document describes the controls that protect Criminal Justice Information in Salus.

Scope

This document describes how Salus handles CJI-classed data: Criminal Justice Information, including criminal history record information and NCIC and state query returns, contained in records ingested from agency CAD and RMS systems.

Data Classification

Classification is fail-closed. All CAD- and RMS-derived records and fields are treated as CJI at ingestion unless affirmatively determined otherwise. Data is never assumed to be non-CJI by default.

Architecture

Agency CAD / RMS source systems Ingestion gate CJI classification (fail-closed) TLS / FIPS endpoints AWS BOUNDARY: US REGIONS ONLY Application services least-privilege IAM · MFA Database & storage AES-256 at rest · AWS KMS Amazon Bedrock inference in-region · no provider access · no training Agency users TLS + MFA
CJI-classed data is processed and stored exclusively within the AWS boundary, in United States regions.

AI Processing

All AI inference involving CJI-classed data runs on Amazon Bedrock inside the AWS boundary, in-region. Model providers never receive the data. Nothing is retained by the model layer, and no customer data is ever used to train models. AI output is advisory: authorized agency personnel make and record all determinations.

Access

CJI-classed data is accessible to a single designated data custodian. No other personnel, including company leadership, hold credentials to systems containing CJI. All access is logged, and logs are available to the agency. Personnel with CJI access complete state and national fingerprint-based background checks through each agency's state process, as required under the CJIS Security Addendum.

Audit & Incident Response

Every access to CJI-classed records is captured in an immutable audit trail (application activity log and AWS CloudTrail) and is available to the agency on request. Non-access is provable, not merely asserted. Security incidents affecting CJI are reported to the agency and its CSA as required by the CJIS Security Policy.

What we never do

CJIS Security Policy Control Mapping

CJIS Security Policy areaSalus control
Access ControlSingle-custodian model with least-privilege IAM. No CJI credentials are held outside the custodian role.
Identification & AuthenticationUnique accounts and multi-factor authentication for all system access.
Auditing & AccountabilityImmutable per-record access logging at the application layer plus AWS CloudTrail. Logs available to the agency.
EncryptionTLS with FIPS-validated endpoints in transit. AES-256 at rest with keys held in AWS KMS.
Media ProtectionNo removable media in the CJI path. Storage is encrypted, and deletion is governed by retention policy and key destruction.
Physical ProtectionInherited from AWS US data centers (SOC-audited physical controls).
Personnel SecurityFingerprint-based state and national background checks via each agency's state process. CJIS Security Awareness Training. Signed Security Addendum certification pages.
Incident ResponseDocumented response plan with agency and CSA notification per the CJIS Security Policy.
Formal AgreementsFBI CJIS Security Addendum executed with each agency customer. Subprocessor list available on request.

A Note on CJIS Certification

There is no "CJIS certification" and no certifying body. Any vendor claiming to be "CJIS certified" is misstating how CJIS works. Compliance with the FBI CJIS Security Policy is achieved through implemented controls, binding agreements, and audit, not a badge. That is the standard this document describes.