SECURITY OVERVIEW

WHERE YOUR DATA LIVES

Everything you enter — case numbers, subjects, rosters, photographs, the audit trail — is stored on your device and nowhere else. There is no server behind this product. No cloud. No account. No analytics. No transmission of any kind. If your device is in airplane mode in a staging area, the platform works exactly as it does anywhere else, because it never needed a connection in the first place.

HOW IT’S PROTECTED

On first launch you create a passcode. From that moment, everything the platform stores is sealed with AES-256-GCM — the same cipher approved by the U.S. government for TOP SECRET material. The key is derived from your passcode and exists only in memory while the app is unlocked. Lock the app, and your device holds nothing but ciphertext. The passcode is not a setting you can skip — there is no way into the platform without one.

RECOVERY STAYS INSIDE YOUR AGENCY

At setup, the platform generates a one-time recovery key. Record it and store it with your agency’s critical records. Your passcode or your recovery key each unlock the device; a forgotten passcode is recoverable through your own records unit — not through us. You can rotate the recovery key at any time.

NO VENDOR ACCESS. EVER.

We hold no keys, no copies, and no ability to unlock any customer’s data. If a court order arrived tomorrow demanding your operational data from us, we would have nothing to produce. That is not a policy promise that could change — it is how the software is built.

ENCRYPTED HAND-OFF

Exported operation files are sealed with their own passcode, set at export. Share the file through any channel; only someone holding that passcode can open it.

WHAT WE’RE STRAIGHT WITH YOU ABOUT

Your passcode is the key — literally. Four digits is the minimum; six or more, or a passphrase, makes the encryption effectively uncrackable. Lose both the passcode and the recovery key, and the data is gone — no exceptions, including for us. That guarantee is the product. And encryption protects data at rest: an unlocked screen is an unlocked screen, so lock the app when you set the device down.

FOR YOUR IT AND COMPLIANCE REVIEWERS

AES-256-GCM authenticated encryption · keys derived via PBKDF2-SHA256 (310,000 iterations) · envelope architecture with agency-held recovery · zero data transmission · no external dependencies at runtime · fully functional offline · no vendor data custody. The no-transmission architecture substantially simplifies review under agency data-handling policies. Your agency’s compliance determination is its own — we’ll gladly walk your reviewers through the architecture.

QUESTIONS

Security questions get direct answers. Ask the hard ones — we wrote this page hoping you would.