Authenticated application access
The current product baseline includes protected application routes, user sessions, and role-aware administrative functions.
Security & deployment
An agency should be able to inspect the proposed hosting, identity, data flow, model services, administrative access, retention, evidence, and responsibility split before a pilot begins.
The complete system and operating model—not a product label—determine whether a proposed deployment meets agency and CJIS responsibilities.
These are application-level foundations, not a claim that every deployment control is already decided. Hosting, providers, operating commitments, and evidence remain configuration-specific.
The current product baseline includes protected application routes, user sessions, and role-aware administrative functions.
Application records and administrative views are organized around agency scope rather than a shared public workspace.
The application preserves working-draft and reviewer context and records operational activity used for oversight.
Supported instruction and policy workflows return authorized users to the retained source document and relevant page.
“Cloud,” “private,” “GovCloud,” “on-prem,” and “air-gapped” are not complete security answers. Each path changes the data flow, provider chain, update model, support access, evidence, cost, and responsibility split.
A deployment option should only be represented as available after LeoPen and the agency validate the architecture and put the obligations into the pilot scope or contract.
Where each service runs, who operates it, whether resources are shared or dedicated, and which service tier applies.
Where application data, source documents, logs, backups, and model processing can occur.
Public or private ingress, egress destinations, administrative paths, allow-lists, and agency connectivity.
The exact model and provider, data sent to it, region, retention behavior, training terms, and fallback path.
Who owns encryption keys, where secrets live, how access is approved, and how rotation and recovery work.
Which LeoPen or provider personnel can access production systems or agency data, for what purpose, and with what approval and logging.
What is backed up, where copies reside, how long they remain, and how restoration and continuity are tested.
How the agency exports its records, ends access, verifies deletion, and handles backup expiration at contract termination.
The intended first production path is a managed Google Cloud deployment for one agency per boundary, so an agency does not need its own AI engineering team to operate LeoPen. This is a target architecture for validation and contracting—not a claim that real CJI is authorized today.
Google's public CJIS material currently describes validation against FBI policy v6.0, while the FBI published policy v6.1 on June 25, 2026. Version coverage and the applicable Management Agreement must be confirmed before a live agency deployment.
The review must cover more than report text. Identity records, source documents, logs, support artifacts, exports, caches, telemetry, and backups each need an owner, purpose, location, retention rule, and deletion path.
Identify every category entering LeoPen: identity data, notes, narratives, policy files, instruction sources, feedback, and support material.
Document which application services and model providers receive each category, why they need it, and what can be minimized or redacted.
Map application records, uploaded sources, logs, telemetry, exports, caches, and backups to their exact storage locations and owners.
Set retention by data category, define legal-hold and records obligations, and confirm agency-accessible export formats and procedures.
Define user deletion, source replacement, contract termination, backup aging, verification, and exceptions required by law or agency policy.
The application baseline has authenticated sessions and role-aware administration. A pilot still needs a written identity design that matches the agency's provider, MFA policy, account lifecycle, privileged roles, and support model.
The FBI CJIS Security Policy addresses protection across the lifecycle of Criminal Justice Information. A useful LeoPen review connects every applicable requirement to the actual agency workflow, application, providers, people, and evidence.
FBI CJIS Security Policy v6.1Name the agency, LeoPen, hosting, model, identity, and support owners for every applicable requirement.
Validate user identity, MFA, privileged access, session behavior, service accounts, and account lifecycle.
Limit users and administrators to the agency data and functions required for their role and approved use.
Define logged events, actor identity, timestamps, source and workflow versions, integrity, retention, export, and review.
Document encryption, key management, network paths, storage, backups, media handling, and the complete CJI lifecycle.
Cover secure development, inventory, patching, dependency review, scanning, penetration testing, and remediation.
Set escalation, notification, evidence preservation, recovery, restoration testing, and post-incident obligations.
Address screening, training, least-access support, physical access, provider personnel, and termination of access.
The final matrix must be tailored to the purchased deployment and reviewed by the agency.
| Review area | Agency | LeoPen | Service providers |
|---|---|---|---|
| Approved use and final report review | Agency | Workflow boundaries and product disclosures | — |
| Identity, MFA, and user lifecycle | Agency / identity provider | Application role integration | Identity service operation |
| Application security and changes | Review and approve material scope | Secure application operation and change evidence | Hosting dependencies |
| Model processing | Approve use and data categories | Configure and document the model path | Model service controls and terms |
| Retention, legal hold, and records | Set requirements | Implement contracted application behavior | Storage and backup behavior |
| Incident response | Agency response and reporting duties | Service investigation, notice, and cooperation | Provider investigation and evidence |
The pilot package should make it possible for the CJIS Systems Officer, security team, procurement staff, counsel, and operational owners to evaluate the same architecture and commitments.
Use the printable checklist to assign owners, request evidence, and document open decisions before a pilot is approved.