Home/Trust
Trust & operations
Compliance disclosures & assurance topics
For procurement, legal, and security reviewers who need disclosure language before a formal questionnaire. We describe control intent and alignment — not formal certifications — unless your contract references executed accreditation artifacts.
Start with the security posture overview for a top-level summary; use this page for topic-by-topic disclosures.
CJIS-aligned controls
Control mapping and evidence collection for agencies requiring CJIS Security Policy alignment—without claiming formal CJIS approval until your program has executed required agreements.
SOC 2 roadmap
Policy, evidence, pen tests, vendor risk, and uptime reporting aligned toward SOC 2 readiness.
Encryption posture
TLS in transit plus KMS-backed encryption envelopes for persisted secrets/tokens/media metadata.
Audit logging
API request envelopes with tenant/key identifiers suited for agency audit exports.
Tenant isolation
Per-tenant scoping enforced on every authenticated call; denies cross-tenant reads/writes by default.
Data retention
Configurable retention horizons for transcripts, QA artifacts, and media TTL (contract bound).
Subprocessors
Disclosed infrastructure stack (AWS primitives, KMS, telemetry) documented for procurement reviews.
Incident response contact
Coordinated escalation for API availability and suspected credential compromise workflows.
Responsible disclosure
Coordinated researcher reporting path with agreed SLAs.
Security contact
Public safety–aware security desk for agencies and CAD vendor partners.
Uptime transparency
Planned ingestion of SLA counters into the public `/developers/status` timeline.
Security contact pathways, executed DPAs/BAA packages, CJIS SLA riders, SOC 2 reports, uptime exports, and vendor questionnaires — request those artifacts through sales & operations; this page is explanatory only.
