Skip to content
Cyntrix ICM

For IT and security staff

Security and CJIS, line by line.

What your IT staff and your Local Agency Security Officer will ask before ICM holds a caseload: how people sign in, what is recorded, who can reach what, where it runs, and where ICM stands on each area of the CJIS Security Policy.

CJIS-ready

CJIS-ready · approved by your agency, audited by your state

ICM is built to the FBI CJIS Security Policy, with the written policies an audit asks for. ICM runs on AWS in the United States, in a production account built around the policy's technical requirements. There is no CJIS authorization for software: your agency approves its own use of ICM, through the CJIS Security Addendum, background checks and training, and its own review, and your state audits that. A move to AWS GovCloud (US) follows when an agency needs it.

9 in place1 ready for review4 next, with you

Controls

How people get in, and what is kept.

Passkeys or two-factor, never just a password
Sign in with a passkey, your fingerprint, face, or device PIN, or with a password and an authenticator app. Passkeys are checked by Amazon Cognito, not by ICM, and ten self-service recovery codes reset sign-in rather than bypass it.
Tamper-evident audit log
Every change is recorded with the value it replaced, along with case views, searches, exports, and prints. Entries are hash-chained and sealed daily, and readable by your supervisors and administrators, not by us.
Enforced password rules
At least 12 characters, checked against a blocklist, changed every 90 days, and never one of the last 10. Users are emailed whenever a password or sign-in method changes.
Sessions that lock
The screen locks after 30 minutes idle and every session ends after 12 hours. Exports ask for identity again, and anyone can sign out their other devices.
Accounts that open and close cleanly
Set up by emailed link, never a temporary password. Deactivating one removes its password, passkeys, and second factors at once, and its cases stay put for reassignment.
Access scoped to the unit
Case files open only inside the unit that owns them. The agency-wide At Large board names other units' defendants without opening their files.
Only from your network, if you choose
Your IT staff can limit ICM to your agency's own networks and VPN, checked at sign-in and on every page after. It stays off until they switch it on, and first shows who the list would have turned away.
Support on your terms
Cyntrix Labs can view your settings but changes them only while your agency has opened a support window, for a day up to a week. Every change we make, including an emergency switch-off, is in your own audit log.
Records rules set by the agency
Your agency sets its own retention periods and legal holds. Nothing is destroyed automatically, and disposal is a deliberate, confirmed step.
Your data leaves with you
A full agency archive of every case, person, note, and hour, plus CSV exports and PDF case packets. Leaving is a supported operation.

Where it runs

AWS, in the United States.

US East (Ohio) · dedicated production account

An account of its own
A production AWS account that holds nothing but ICM, under organization-level rules that stop it turning off audit logging or threat detection, lock out the root user, and allow only two US regions.
Encrypted at rest and in transit
The database, its backups, the files, and the application's logs encrypted with keys held for ICM alone. TLS 1.2 or higher from your browser to AWS and from the application to its database, and AWS services reached through their FIPS endpoints.
A database with no way in from the internet
Isolated subnets that only the application can reach, 35 days of point-in-time recovery, and protection against being deleted by accident.
A firewall in front
AWS WAF screening every request: known bad addresses, SQL injection, and common exploits blocked, and anything that floods the site slowed down.
Watched around the clock
GuardDuty threat detection across the account with alerts on anything serious, every action in the account recorded by CloudTrail in logs nobody can delete for a year, every setting checked continuously for drift by AWS Config and Security Hub, and network, DNS, firewall, and application logs kept for at least a year.
A domain that is hard to fake
cyntrixicm.com is signed with DNSSEC, only Amazon may issue its certificates, and its mail is signed so that forged messages are rejected.

CJIS

Where ICM stands on CJIS.

There is no CJIS certificate for software. Your agency is the party audited, by your state's CJIS Systems Agency, and a vendor is covered through its agreement with you. Whether ICM holds CJI depends on what your detectives type into it, so we plan as if it does. Here is each area of the CJIS Security Policy, where it stands, and who carries it.

9 in place1 ready for review4 next, with you

  • Encryption

    SC-8, SC-13, SC-28

    TLS 1.2 or higher on a FIPS security policy, AWS services reached through their FIPS endpoints, and data at rest under keys held for ICM alone.

    In place

    AWSCyntrix

  • Sign-in and multi-factor

    IA-2, IA-5

    A named account for every person, a passkey or an authenticator app on every one, and password rules enforced.

    In place

    Cyntrix

  • Lockout, use notice, screen lock

    AC-7, AC-8, AC-11

    Five failed sign-ins lock an account until a supervisor or administrator releases it, the sign-in page carries a system use notice, and idle screens lock at 30 minutes.

    In place

    Cyntrix

  • Least privilege

    AC-2, AC-6

    Case files open only inside their unit, administrators manage accounts without case access, and Cyntrix works from a separate platform account that changes your settings only in a support window you open.

    In place

    CyntrixYour agency

  • Audit and accountability

    AU

    Every change, view, search, export, and print recorded, hash-chained, and sealed daily. Your agency's weekly review is done in ICM and recorded there.

    In place

    CyntrixYour agency

  • Boundary and hosting

    SC-7

    AWS in the United States, a database with no route from the internet, and a firewall in front. Your agency can limit ICM to its own networks. AWS GovCloud (US) if your agency's policy calls for it.

    In place

    AWSCyntrix

  • Physical protection

    PE

    AWS data centers, under AWS's FedRAMP authorization.

    In place

    AWS

  • Malware and vulnerability scanning

    SI-3, RA-5

    Every uploaded file checked for malware, and the application rescanned whenever a new vulnerability is published.

    In place

    Cyntrix

  • Configuration and change control

    CM

    Every server and setting defined as code and pinned by version, every production change recorded, and every setting checked continuously against NIST SP 800-53 for drift.

    In place

    Cyntrix

  • Security plan and policies

    PL, IR, MP, RA

    The System Security Plan and the policies an audit asks for by name, checked against the running system and printed as one packet for your LASO to review.

    Ready for review

    CyntrixYour agency

  • CJIS Security Addendum

    SA-9

    Part of our agreement with your agency, with a signed certification page for each person at Cyntrix Labs who has access.

    Next, with you

    CyntrixYour agency

  • Personnel screening

    PS

    A fingerprint-based background check, processed through your agency, for each of those people.

    Next, with you

    Your agency

  • Security awareness training

    AT

    CJIS training at the level for administrative access, before access and every year after, with the records kept.

    Next, with you

    Cyntrix

  • Approval and audit

    Formal audits

    Your Local Agency Security Officer (LASO) decides whether ICM is acceptable, and your state's CJIS Systems Agency reviews that when it audits your agency.

    Next, with you

    Your agencyState CSA

There is no CJIS authorization for software, and we do not claim one. We will walk your IT and security staff through every line here, and your state's CJIS Systems Agency will answer an agency's questions about a proposed cloud system.

Walk through it with us.

We will go through every line here with your IT and security staff, on a demo agency with invented cases.