CJISCJIS Security Policy

Built toward
CJIS compliance.

PulseSafety is actively implementing the controls required by the FBI's CJIS Security Policy. We are not yet certified — but we're transparent about where we stand and where we're headed.

CJIS
Alignment in progress
SOC 2
Audit in progress
AES-256
Encryption at rest
Zero
Data breaches
CJIS Security Policy

Our approach to
CJIS compliance.

The FBI's Criminal Justice Information Services (CJIS) Security Policy sets the minimum security requirements for agencies that access criminal justice information. PulseSafety is actively building toward full CJIS compliance — here's where we stand and what we're doing about it.

CJIS compliance is not a checkbox — it is an ongoing operational commitment. We are working closely with law enforcement partners to ensure CommandCORE meets or exceeds every applicable control in CJIS Security Policy v5.9.2.

We publish this page to be transparent with agencies that are evaluating or currently using CommandCORE. If you have specific questions about our controls or need a security questionnaire completed, our security team will respond within 48 hours.

OUR STATUS

Compliance in progress — not yet certified.

We are pursuing CJIS alignment and SOC 2 Type II certification. We are not currently CJIS-certified or SOC 2 compliant, but are actively implementing the controls and intend to achieve certification. We will update this page as milestones are reached.

Policy areas

How we address
key CJIS control areas.

The sections below map CJIS Security Policy control areas to our current implementation status and planned work.

1. Information Exchange Agreements

PulseSafety establishes written Information Exchange Agreements (IEAs) with each agency customer prior to any access to Criminal Justice Information (CJI). These agreements document the specific data exchanged, the purpose of exchange, and each party's responsibilities under CJIS Security Policy.

2. Security Awareness Training

All PulseSafety personnel who may access CJI or systems that process CJI are required to complete CJIS Security Awareness Training prior to access and annually thereafter. Training completion is tracked and documented. We are in the process of formalizing a CJIS Officer role within our organization.

3. Incident Response

PulseSafety maintains a written Incident Response Plan that addresses detection, containment, eradication, and recovery from security incidents. We commit to notifying affected agency customers of any confirmed breach involving CJI within 24 hours of discovery, consistent with CJIS requirements.

4. Auditing and Accountability

CommandCORE maintains immutable audit logs for all access to records containing CJI. Audit records include timestamps, user identifiers, action types, and record identifiers. Logs are retained for a minimum of 12 months and are accessible to agency administrators.

5. Access Control

Access to CJI within CommandCORE is role-based and follows the principle of least privilege. Multi-factor authentication is required for all administrative access and will be required for all officer access in the next release. Session timeouts and account lockout policies are enforced per CJIS requirements.

6. Identification and Authentication

CommandCORE enforces unique user identification, password complexity requirements, and MFA for privileged accounts. We are implementing agency-level identity provider (IdP) federation to support CJIS-compliant SSO via SAML 2.0 and OIDC.

7. Configuration Management

We maintain a configuration baseline for all systems that store or process CJI. Changes to baseline configurations are tracked, reviewed, and approved. Automated configuration drift detection is in active development as part of our SOC 2 readiness program.

8. Media Protection

All data at rest is encrypted using AES-256. Data in transit is encrypted using TLS 1.2 or higher. Physical media containing CJI is handled in accordance with CJIS requirements, including sanitization prior to disposal. Cloud storage is scoped to U.S. regions only.

9. Physical Protection

CommandCORE is hosted in SOC 2 Type II certified data centers with physical access controls including biometric authentication, CCTV, and access logging. PulseSafety staff do not have physical access to the underlying infrastructure — access is exclusively via secure, audited remote channels.

10. Systems and Communications Protection

Network segmentation, firewalls, and intrusion detection systems are in place. All inter-service communication is encrypted. We conduct quarterly vulnerability scans and annual penetration testing. Findings are tracked to remediation with defined SLAs.

11. Formal Audits

We are actively pursuing SOC 2 Type II certification with an expected audit completion in the coming months. Upon certification, we will make our SOC 2 report available to agency customers under NDA. CJIS compliance audits will be conducted in parallel with the SOC 2 program.

12. Personnel Security

All PulseSafety employees who may access CJI undergo background checks consistent with CJIS Security Policy requirements prior to employment and periodically thereafter. Contractor access to CJI-adjacent systems follows the same standard.

Questions?

Talk to our
security team.

If you have specific compliance questions, need a CJIS security addendum completed, or want to discuss our controls in detail, reach out directly.

[email protected]

PulseSafety, Inc. · Austin, Texas

We respond to all CJIS and compliance inquiries within 48 hours.

CJIS security addendum

  • We complete standard CJIS security questionnaires
  • We sign agency security addenda on request
  • 48-hour response on compliance inquiries
Security & compliance

See our full
security posture.

CJIS compliance is one layer of our broader security program. Our Security page covers encryption, access controls, infrastructure practices, and our coordinated disclosure policy.