Salus CJIS Security Posture
Salus aligns its systems to the FBI CJIS Security Policy, executes the FBI CJIS Security Addendum with each agency customer, and supports our customers through their state CSA audits. This document describes the controls that protect Criminal Justice Information in Salus.
Scope
This document describes how Salus handles CJI-classed data: Criminal Justice Information, including criminal history record information and NCIC and state query returns, contained in records ingested from agency CAD and RMS systems.
Data Classification
Classification is fail-closed. All CAD- and RMS-derived records and fields are treated as CJI at ingestion unless affirmatively determined otherwise. Data is never assumed to be non-CJI by default.
Architecture
- In transit: TLS with FIPS-validated endpoints on the CJI path.
- At rest: AES-256 encryption with keys held in AWS KMS.
- Tenancy: Salus is multi-tenant with strict per-organization isolation. Row-level security ensures that an organization's data is accessible only to that organization's members.
- Residency: United States AWS regions only. No CJI is processed or stored outside this boundary.
AI Processing
All AI inference involving CJI-classed data runs on Amazon Bedrock inside the AWS boundary, in-region. Model providers never receive the data. Nothing is retained by the model layer, and no customer data is ever used to train models. AI output is advisory: authorized agency personnel make and record all determinations.
Access
CJI-classed data is accessible to a single designated data custodian. No other personnel, including company leadership, hold credentials to systems containing CJI. All access is logged, and logs are available to the agency. Personnel with CJI access complete state and national fingerprint-based background checks through each agency's state process, as required under the CJIS Security Addendum.
Audit & Incident Response
Every access to CJI-classed records is captured in an immutable audit trail (application activity log and AWS CloudTrail) and is available to the agency on request. Non-access is provable, not merely asserted. Security incidents affecting CJI are reported to the agency and its CSA as required by the CJIS Security Policy.
- No CJI in email. Notifications contain links into the authenticated application, never record content.
- No CJI to third-party model APIs.
- No training of any model on customer data.
- No processing or storage of CJI outside the United States.
- No CJI access without fingerprint-based vetting.
CJIS Security Policy Control Mapping
| CJIS Security Policy area | Salus control |
|---|---|
| Access Control | Single-custodian model with least-privilege IAM. No CJI credentials are held outside the custodian role. |
| Identification & Authentication | Unique accounts and multi-factor authentication for all system access. |
| Auditing & Accountability | Immutable per-record access logging at the application layer plus AWS CloudTrail. Logs available to the agency. |
| Encryption | TLS with FIPS-validated endpoints in transit. AES-256 at rest with keys held in AWS KMS. |
| Media Protection | No removable media in the CJI path. Storage is encrypted, and deletion is governed by retention policy and key destruction. |
| Physical Protection | Inherited from AWS US data centers (SOC-audited physical controls). |
| Personnel Security | Fingerprint-based state and national background checks via each agency's state process. CJIS Security Awareness Training. Signed Security Addendum certification pages. |
| Incident Response | Documented response plan with agency and CSA notification per the CJIS Security Policy. |
| Formal Agreements | FBI CJIS Security Addendum executed with each agency customer. Subprocessor list available on request. |
A Note on CJIS Certification
There is no "CJIS certification" and no certifying body. Any vendor claiming to be "CJIS certified" is misstating how CJIS works. Compliance with the FBI CJIS Security Policy is achieved through implemented controls, binding agreements, and audit, not a badge. That is the standard this document describes.