Home/Trust

Trust & operations

Compliance disclosures & assurance topics

For procurement, legal, and security reviewers who need disclosure language before a formal questionnaire. We describe control intent and alignment — not formal certifications — unless your contract references executed accreditation artifacts.

Start with the security posture overview for a top-level summary; use this page for topic-by-topic disclosures.

CJIS-aligned controls

Control mapping and evidence collection for agencies requiring CJIS Security Policy alignment—without claiming formal CJIS approval until your program has executed required agreements.

SOC 2 roadmap

Policy, evidence, pen tests, vendor risk, and uptime reporting aligned toward SOC 2 readiness.

Encryption posture

TLS in transit plus KMS-backed encryption envelopes for persisted secrets/tokens/media metadata.

Audit logging

API request envelopes with tenant/key identifiers suited for agency audit exports.

Tenant isolation

Per-tenant scoping enforced on every authenticated call; denies cross-tenant reads/writes by default.

Data retention

Configurable retention horizons for transcripts, QA artifacts, and media TTL (contract bound).

Subprocessors

Disclosed infrastructure stack (AWS primitives, KMS, telemetry) documented for procurement reviews.

Incident response contact

Coordinated escalation for API availability and suspected credential compromise workflows.

Responsible disclosure

Coordinated researcher reporting path with agreed SLAs.

Security contact

Public safety–aware security desk for agencies and CAD vendor partners.

Uptime transparency

Planned ingestion of SLA counters into the public `/developers/status` timeline.

Security contact pathways, executed DPAs/BAA packages, CJIS SLA riders, SOC 2 reports, uptime exports, and vendor questionnaires — request those artifacts through sales & operations; this page is explanatory only.