SecuritySecurity & Compliance

Built for the
most sensitive
environments.

PulseSafety is built on a CJIS-compliant, SOC 2-aligned foundation — so agencies can focus on protecting their communities, not worrying about their data.

CJIS
v5.9.2 compliant
SOC 2
Type II (in progress)
AES-256
Encryption at rest
Zero
Data breaches
Security at PulseSafety

Built secure
from the ground up.

CommandCORE handles sensitive law-enforcement data. We treat that responsibility with full seriousness — layering technical controls, policy, and ongoing audit into every deployment from day one.

Every tenant environment is isolated at the database level. No shared tables, no cross-tenant queries. Agency data is encrypted at rest and in transit, and every action is stamped to a named user with a timestamp that cannot be altered.

We are actively pursuing CJIS compliance certification and SOC 2 Type II attestation. In the interim, our architecture is aligned to both frameworks — we hold ourselves to those standards whether or not the certificate is in hand.

OUR COMMITMENT

Security isn't a tier — it's the floor.

Every CommandCORE deployment ships with the same security baseline. There is no 'basic' plan that skips encryption or audit logging — those are invariants, not add-ons.

How we protect agency data

Security controls,
not security theater.

We don't check boxes — we implement the controls that actually reduce risk for agencies that carry sensitive law-enforcement data.

Data isolation

Per-tenant database schemas.

Each agency's data lives in its own isolated schema. No shared tables. A misconfigured query cannot bleed data between tenants.

Encryption

At rest and in transit.

All data is encrypted at rest using AES-256 and in transit over TLS 1.3. Encryption keys are managed separately from the data they protect.

Audit logging

Every action, timestamped.

Every read, write, and delete in CommandCORE is logged to a tamper-evident audit trail — who, what, when, and from which IP. Logs are immutable and retained for the period your policy requires.

Access control

RBAC with least privilege.

Role-based access control is enforced at every layer. Officers see what their role permits. Supervisors see what their role permits. No overrides without an audit trail.

Authentication

Strong auth, no exceptions.

Enforced MFA for all admin-level accounts. Session tokens expire. Inactive sessions time out. No shared credentials or service accounts with standing access.

Minimal data footprint

We store what we need, nothing more.

CommandCORE is designed around data minimisation. If a field isn't needed for a workflow, we don't collect it. What we do store, we protect.

Compliance posture

Where we stand
today.

We are transparent about our current compliance status. We are actively pursuing both CJIS certification and SOC 2 Type II attestation — and we hold our architecture to those standards in the meantime.

CJIS Compliance

In Progress

Our architecture is aligned to CJIS Security Policy v5.9.2. We are actively working through the formal certification process. Current deployments follow CJIS-aligned controls for data handling, access, and audit.

SOC 2 Type II

In Progress

We are pursuing SOC 2 Type II attestation covering Security, Availability, and Confidentiality. Our controls are in place and we are in the active audit period.

FedRAMP-Aligned Hosting

Active

All CommandCORE environments run on FedRAMP-authorized cloud infrastructure. We inherit the physical and infrastructure controls of a FedRAMP-authorized provider.

Annual Penetration Testing

Active

We conduct third-party penetration tests annually and address findings before they reach the next deployment cycle. Results are available to agencies under NDA.

Coordinated disclosure

Found something?
Tell us first.

If you believe you've found a security vulnerability in CommandCORE or any PulseSafety system, we want to hear from you before it becomes a problem. We follow responsible disclosure and commit to a timely response.

[email protected]

We will acknowledge your report within one business day and keep you informed as we investigate. We ask that you give us a reasonable window to address findings before public disclosure.

We do not pursue legal action against researchers who act in good faith and follow responsible disclosure practices.

Responsible disclosure

  • We acknowledge reports within 1 business day
  • We keep you informed as we investigate
  • We do not pursue legal action against good-faith researchers
Questions about security?

Talk to our
security team.

If you're evaluating CommandCORE for your agency and have specific compliance or security questions, we'll put you in touch with the right person — no gatekeeping.