For IT and security staff
Security and CJIS, line by line.
What your IT staff and your Local Agency Security Officer will ask before ICM holds a caseload: how people sign in, what is recorded, who can reach what, where it runs, and where ICM stands on each area of the CJIS Security Policy.
CJIS-ready
CJIS-ready · approved by your agency, audited by your state
ICM is built to the FBI CJIS Security Policy, with the written policies an audit asks for. ICM runs on AWS in the United States, in a production account built around the policy's technical requirements. There is no CJIS authorization for software: your agency approves its own use of ICM, through the CJIS Security Addendum, background checks and training, and its own review, and your state audits that. A move to AWS GovCloud (US) follows when an agency needs it.
9 in place1 ready for review4 next, with you
Controls
How people get in, and what is kept.
- Passkeys or two-factor, never just a password
- Sign in with a passkey, your fingerprint, face, or device PIN, or with a password and an authenticator app. Passkeys are checked by Amazon Cognito, not by ICM, and ten self-service recovery codes reset sign-in rather than bypass it.
- Tamper-evident audit log
- Every change is recorded with the value it replaced, along with case views, searches, exports, and prints. Entries are hash-chained and sealed daily, and readable by your supervisors and administrators, not by us.
- Enforced password rules
- At least 12 characters, checked against a blocklist, changed every 90 days, and never one of the last 10. Users are emailed whenever a password or sign-in method changes.
- Sessions that lock
- The screen locks after 30 minutes idle and every session ends after 12 hours. Exports ask for identity again, and anyone can sign out their other devices.
- Accounts that open and close cleanly
- Set up by emailed link, never a temporary password. Deactivating one removes its password, passkeys, and second factors at once, and its cases stay put for reassignment.
- Access scoped to the unit
- Case files open only inside the unit that owns them. The agency-wide At Large board names other units' defendants without opening their files.
- Only from your network, if you choose
- Your IT staff can limit ICM to your agency's own networks and VPN, checked at sign-in and on every page after. It stays off until they switch it on, and first shows who the list would have turned away.
- Support on your terms
- Cyntrix Labs can view your settings but changes them only while your agency has opened a support window, for a day up to a week. Every change we make, including an emergency switch-off, is in your own audit log.
- Records rules set by the agency
- Your agency sets its own retention periods and legal holds. Nothing is destroyed automatically, and disposal is a deliberate, confirmed step.
- Your data leaves with you
- A full agency archive of every case, person, note, and hour, plus CSV exports and PDF case packets. Leaving is a supported operation.
Where it runs
AWS, in the United States.
US East (Ohio) · dedicated production account
- An account of its own
- A production AWS account that holds nothing but ICM, under organization-level rules that stop it turning off audit logging or threat detection, lock out the root user, and allow only two US regions.
- Encrypted at rest and in transit
- The database, its backups, the files, and the application's logs encrypted with keys held for ICM alone. TLS 1.2 or higher from your browser to AWS and from the application to its database, and AWS services reached through their FIPS endpoints.
- A database with no way in from the internet
- Isolated subnets that only the application can reach, 35 days of point-in-time recovery, and protection against being deleted by accident.
- A firewall in front
- AWS WAF screening every request: known bad addresses, SQL injection, and common exploits blocked, and anything that floods the site slowed down.
- Watched around the clock
- GuardDuty threat detection across the account with alerts on anything serious, every action in the account recorded by CloudTrail in logs nobody can delete for a year, every setting checked continuously for drift by AWS Config and Security Hub, and network, DNS, firewall, and application logs kept for at least a year.
- A domain that is hard to fake
- cyntrixicm.com is signed with DNSSEC, only Amazon may issue its certificates, and its mail is signed so that forged messages are rejected.
CJIS
Where ICM stands on CJIS.
There is no CJIS certificate for software. Your agency is the party audited, by your state's CJIS Systems Agency, and a vendor is covered through its agreement with you. Whether ICM holds CJI depends on what your detectives type into it, so we plan as if it does. Here is each area of the CJIS Security Policy, where it stands, and who carries it.
9 in place1 ready for review4 next, with you
Encryption
SC-8, SC-13, SC-28
TLS 1.2 or higher on a FIPS security policy, AWS services reached through their FIPS endpoints, and data at rest under keys held for ICM alone.
In place
AWSCyntrix
Sign-in and multi-factor
IA-2, IA-5
A named account for every person, a passkey or an authenticator app on every one, and password rules enforced.
In place
Cyntrix
Lockout, use notice, screen lock
AC-7, AC-8, AC-11
Five failed sign-ins lock an account until a supervisor or administrator releases it, the sign-in page carries a system use notice, and idle screens lock at 30 minutes.
In place
Cyntrix
Least privilege
AC-2, AC-6
Case files open only inside their unit, administrators manage accounts without case access, and Cyntrix works from a separate platform account that changes your settings only in a support window you open.
In place
CyntrixYour agency
Audit and accountability
AU
Every change, view, search, export, and print recorded, hash-chained, and sealed daily. Your agency's weekly review is done in ICM and recorded there.
In place
CyntrixYour agency
Boundary and hosting
SC-7
AWS in the United States, a database with no route from the internet, and a firewall in front. Your agency can limit ICM to its own networks. AWS GovCloud (US) if your agency's policy calls for it.
In place
AWSCyntrix
Physical protection
PE
AWS data centers, under AWS's FedRAMP authorization.
In place
AWS
Malware and vulnerability scanning
SI-3, RA-5
Every uploaded file checked for malware, and the application rescanned whenever a new vulnerability is published.
In place
Cyntrix
Configuration and change control
CM
Every server and setting defined as code and pinned by version, every production change recorded, and every setting checked continuously against NIST SP 800-53 for drift.
In place
Cyntrix
Security plan and policies
PL, IR, MP, RA
The System Security Plan and the policies an audit asks for by name, checked against the running system and printed as one packet for your LASO to review.
Ready for review
CyntrixYour agency
CJIS Security Addendum
SA-9
Part of our agreement with your agency, with a signed certification page for each person at Cyntrix Labs who has access.
Next, with you
CyntrixYour agency
Personnel screening
PS
A fingerprint-based background check, processed through your agency, for each of those people.
Next, with you
Your agency
Security awareness training
AT
CJIS training at the level for administrative access, before access and every year after, with the records kept.
Next, with you
Cyntrix
Approval and audit
Formal audits
Your Local Agency Security Officer (LASO) decides whether ICM is acceptable, and your state's CJIS Systems Agency reviews that when it audits your agency.
Next, with you
Your agencyState CSA
There is no CJIS authorization for software, and we do not claim one. We will walk your IT and security staff through every line here, and your state's CJIS Systems Agency will answer an agency's questions about a proposed cloud system.
Walk through it with us.
We will go through every line here with your IT and security staff, on a demo agency with invented cases.