Security & deployment

Security is an architecture,
not a badge.

An agency should be able to inspect the proposed hosting, identity, data flow, model services, administrative access, retention, evidence, and responsibility split before a pilot begins.

The complete system and operating model—not a product label—determine whether a proposed deployment meets agency and CJIS responsibilities.

Current application baseline

What is present in the product for technical review

These are application-level foundations, not a claim that every deployment control is already decided. Hosting, providers, operating commitments, and evidence remain configuration-specific.

Authenticated application access

The current product baseline includes protected application routes, user sessions, and role-aware administrative functions.

Agency-scoped records

Application records and administrative views are organized around agency scope rather than a shared public workspace.

Review and activity context

The application preserves working-draft and reviewer context and records operational activity used for oversight.

Retained source access

Supported instruction and policy workflows return authorized users to the retained source document and relevant page.

Deployment boundary

Write down the whole system before the pilot starts

“Cloud,” “private,” “GovCloud,” “on-prem,” and “air-gapped” are not complete security answers. Each path changes the data flow, provider chain, update model, support access, evidence, cost, and responsibility split.

A deployment option should only be represented as available after LeoPen and the agency validate the architecture and put the obligations into the pilot scope or contract.

Hosting and tenancy

Where each service runs, who operates it, whether resources are shared or dedicated, and which service tier applies.

Regions and residency

Where application data, source documents, logs, backups, and model processing can occur.

Network boundary

Public or private ingress, egress destinations, administrative paths, allow-lists, and agency connectivity.

Model services

The exact model and provider, data sent to it, region, retention behavior, training terms, and fallback path.

Keys and secrets

Who owns encryption keys, where secrets live, how access is approved, and how rotation and recovery work.

Administrative access

Which LeoPen or provider personnel can access production systems or agency data, for what purpose, and with what approval and logging.

Backups and recovery

What is backed up, where copies reside, how long they remain, and how restoration and continuity are tested.

Exit and deletion

How the agency exports its records, ends access, verifies deletion, and handles backup expiration at contract termination.

Planned first live-pilot model

LeoPen-managed SaaS with a dedicated single-agency boundary

The intended first production path is a managed Google Cloud deployment for one agency per boundary, so an agency does not need its own AI engineering team to operate LeoPen. This is a target architecture for validation and contracting—not a claim that real CJI is authorized today.

  • A dedicated Google Cloud CJIS Assured Workloads folder or equivalent approved boundary for each agency
  • Separate production and nonproduction projects with no shared agency database or object-storage bucket
  • Dedicated application data, uploaded files, vector data, keys, logs, and service accounts
  • LeoPen-operated containers from a controlled artifact registry, deployed by immutable version or digest
  • Agency-approved identity, connectivity, retention, support access, provider path, and records rules
  • Written approval and responsibility mapping with the agency, applicable state CJIS authority, Google, and any AI provider before CJI
Google Cloud CJIS control-package documentation

Google's public CJIS material currently describes validation against FBI policy v6.0, while the FBI published policy v6.1 on June 25, 2026. Version coverage and the applicable Management Agreement must be confirmed before a live agency deployment.

Data handling

Follow each data category from collection through deletion

The review must cover more than report text. Identity records, source documents, logs, support artifacts, exports, caches, telemetry, and backups each need an owner, purpose, location, retention rule, and deletion path.

  1. 1. Collect

    Identify every category entering LeoPen: identity data, notes, narratives, policy files, instruction sources, feedback, and support material.

  2. 2. Process

    Document which application services and model providers receive each category, why they need it, and what can be minimized or redacted.

  3. 3. Store

    Map application records, uploaded sources, logs, telemetry, exports, caches, and backups to their exact storage locations and owners.

  4. 4. Retain and export

    Set retention by data category, define legal-hold and records obligations, and confirm agency-accessible export formats and procedures.

  5. 5. Delete

    Define user deletion, source replacement, contract termination, backup aging, verification, and exceptions required by law or agency policy.

Identity and access

Start with agency identity. End with provable least privilege.

The application baseline has authenticated sessions and role-aware administration. A pilot still needs a written identity design that matches the agency's provider, MFA policy, account lifecycle, privileged roles, and support model.

  • Agency identity provider and supported SSO protocol
  • MFA and conditional-access enforcement
  • Officer, reviewer, administrator, security, and support roles
  • Provisioning, role changes, deprovisioning, and optional automation
  • Session length, reauthentication, device, and location controls
  • Service accounts, API credentials, secrets, and machine access
  • Time-limited vendor support access with approval and activity logging
  • Regular access review and privileged-role recertification
CJIS review

Map the current FBI policy to the exact deployment

The FBI CJIS Security Policy addresses protection across the lifecycle of Criminal Justice Information. A useful LeoPen review connects every applicable requirement to the actual agency workflow, application, providers, people, and evidence.

FBI CJIS Security Policy v6.1

Governance and responsibility

Name the agency, LeoPen, hosting, model, identity, and support owners for every applicable requirement.

Identification and authentication

Validate user identity, MFA, privileged access, session behavior, service accounts, and account lifecycle.

Access control

Limit users and administrators to the agency data and functions required for their role and approved use.

Audit and accountability

Define logged events, actor identity, timestamps, source and workflow versions, integrity, retention, export, and review.

Data and system protection

Document encryption, key management, network paths, storage, backups, media handling, and the complete CJI lifecycle.

Configuration and vulnerability management

Cover secure development, inventory, patching, dependency review, scanning, penetration testing, and remediation.

Incident response and continuity

Set escalation, notification, evidence preservation, recovery, restoration testing, and post-incident obligations.

Personnel and support

Address screening, training, least-access support, physical access, provider personnel, and termination of access.

Example shared-responsibility map

The final matrix must be tailored to the purchased deployment and reviewed by the agency.

Review areaAgencyLeoPenService providers
Approved use and final report reviewAgencyWorkflow boundaries and product disclosures
Identity, MFA, and user lifecycleAgency / identity providerApplication role integrationIdentity service operation
Application security and changesReview and approve material scopeSecure application operation and change evidenceHosting dependencies
Model processingApprove use and data categoriesConfigure and document the model pathModel service controls and terms
Retention, legal hold, and recordsSet requirementsImplement contracted application behaviorStorage and backup behavior
Incident responseAgency response and reporting dutiesService investigation, notice, and cooperationProvider investigation and evidence
Evidence package

Turn claims into documents the agency can review

The pilot package should make it possible for the CJIS Systems Officer, security team, procurement staff, counsel, and operational owners to evaluate the same architecture and commitments.

  • Final architecture and data-flow diagrams for the purchased configuration
  • CJIS responsibility matrix assigning agency, LeoPen, and provider ownership
  • Hosting, model, identity, analytics, support, and other subprocessor list
  • Identity, role, privileged-access, and support-access design
  • Encryption, key, network, secrets, logging, retention, backup, and deletion design
  • Secure-development, vulnerability, patching, and testing summary
  • Incident response, notification, recovery, and evidence-preservation commitments
  • AI evaluation plan, known limitations, pilot acceptance criteria, and change process
Security, procurement, and operational review

Bring the proposed architecture—not just a list of promises.

Use the printable checklist to assign owners, request evidence, and document open decisions before a pilot is approved.

Open buyer checklist