PulseSafety is actively implementing the controls required by the FBI's CJIS Security Policy. We are not yet certified — but we're transparent about where we stand and where we're headed.
The FBI's Criminal Justice Information Services (CJIS) Security Policy sets the minimum security requirements for agencies that access criminal justice information. PulseSafety is actively building toward full CJIS compliance — here's where we stand and what we're doing about it.
CJIS compliance is not a checkbox — it is an ongoing operational commitment. We are working closely with law enforcement partners to ensure CommandCORE meets or exceeds every applicable control in CJIS Security Policy v5.9.2.
We publish this page to be transparent with agencies that are evaluating or currently using CommandCORE. If you have specific questions about our controls or need a security questionnaire completed, our security team will respond within 48 hours.
We are pursuing CJIS alignment and SOC 2 Type II certification. We are not currently CJIS-certified or SOC 2 compliant, but are actively implementing the controls and intend to achieve certification. We will update this page as milestones are reached.
The sections below map CJIS Security Policy control areas to our current implementation status and planned work.
PulseSafety establishes written Information Exchange Agreements (IEAs) with each agency customer prior to any access to Criminal Justice Information (CJI). These agreements document the specific data exchanged, the purpose of exchange, and each party's responsibilities under CJIS Security Policy.
All PulseSafety personnel who may access CJI or systems that process CJI are required to complete CJIS Security Awareness Training prior to access and annually thereafter. Training completion is tracked and documented. We are in the process of formalizing a CJIS Officer role within our organization.
PulseSafety maintains a written Incident Response Plan that addresses detection, containment, eradication, and recovery from security incidents. We commit to notifying affected agency customers of any confirmed breach involving CJI within 24 hours of discovery, consistent with CJIS requirements.
CommandCORE maintains immutable audit logs for all access to records containing CJI. Audit records include timestamps, user identifiers, action types, and record identifiers. Logs are retained for a minimum of 12 months and are accessible to agency administrators.
Access to CJI within CommandCORE is role-based and follows the principle of least privilege. Multi-factor authentication is required for all administrative access and will be required for all officer access in the next release. Session timeouts and account lockout policies are enforced per CJIS requirements.
CommandCORE enforces unique user identification, password complexity requirements, and MFA for privileged accounts. We are implementing agency-level identity provider (IdP) federation to support CJIS-compliant SSO via SAML 2.0 and OIDC.
We maintain a configuration baseline for all systems that store or process CJI. Changes to baseline configurations are tracked, reviewed, and approved. Automated configuration drift detection is in active development as part of our SOC 2 readiness program.
All data at rest is encrypted using AES-256. Data in transit is encrypted using TLS 1.2 or higher. Physical media containing CJI is handled in accordance with CJIS requirements, including sanitization prior to disposal. Cloud storage is scoped to U.S. regions only.
CommandCORE is hosted in SOC 2 Type II certified data centers with physical access controls including biometric authentication, CCTV, and access logging. PulseSafety staff do not have physical access to the underlying infrastructure — access is exclusively via secure, audited remote channels.
Network segmentation, firewalls, and intrusion detection systems are in place. All inter-service communication is encrypted. We conduct quarterly vulnerability scans and annual penetration testing. Findings are tracked to remediation with defined SLAs.
We are actively pursuing SOC 2 Type II certification with an expected audit completion in the coming months. Upon certification, we will make our SOC 2 report available to agency customers under NDA. CJIS compliance audits will be conducted in parallel with the SOC 2 program.
All PulseSafety employees who may access CJI undergo background checks consistent with CJIS Security Policy requirements prior to employment and periodically thereafter. Contractor access to CJI-adjacent systems follows the same standard.
If you have specific compliance questions, need a CJIS security addendum completed, or want to discuss our controls in detail, reach out directly.
[email protected]PulseSafety, Inc. · Austin, Texas
We respond to all CJIS and compliance inquiries within 48 hours.
CJIS compliance is one layer of our broader security program. Our Security page covers encryption, access controls, infrastructure practices, and our coordinated disclosure policy.