Trust Center
Focal Forensics provides forensic video analysis and redaction services to criminal justice agencies. Our security program is built to meet the requirements of the FBI CJIS Security Policy: signed CJIS Security Addenda for each agency engagement, fingerprint-based background checks and Security Awareness Training for all personnel with CJI access, and documented technical and administrative controls. This Trust Center is where we publish our posture, our policies, and the evidence behind them.
Compliance frameworks
Security practices
Encryption in transit and at rest
Data Security — All data is encrypted in transit using TLS 1.2 or higher and encrypted at rest. Client work product is stored only in access-controlled systems for the duration of an engagement.
Least-privilege access control
Access Control — Access to systems and client data is granted per engagement on a least-privilege basis, protected by multi-factor authentication, and reviewed regularly. Sessions lock automatically after inactivity.
Personnel security
Personnel Security — Every team member with access to criminal justice information completes fingerprint-based background screening and CJIS Security Awareness Training, with recertification tracked and renewed before expiration.
Incident response
Incident Response — We maintain a documented incident response plan covering identification, containment, notification, and recovery. Security incidents affecting agency data are reported to the affected agency without undue delay.
Infrastructure and auditing
Infrastructure — Production systems run on hardened, access-logged cloud infrastructure in the United States. Administrative actions and file access are written to an immutable audit log.
Featured documents
System & Data Flow Overview
One-page diagram of how CJI moves through a Focal Forensics engagement: agency, FileCloud GovCloud, encrypted analyst workstation, delivery. v1.0, 2026-07-03.
Information Security Policy
Umbrella security policy: governance, roles, core rules, and system maintenance baseline. v1.0, effective 2026-07-03.
Completed Vendor Security Questionnaire
Pre-completed security questionnaire (based on the BCA SaaS Vendor Security Assessment template): ~100 answers covering governance, operations, access control, encryption, media protection, and incident response. July 2026.
Frequently asked questions
Is Focal Forensics CJIS certified?
The FBI does not certify private vendors, so no vendor can truthfully claim an FBI certification. Focal Forensics is CJIS Security Policy compliant: we align our security program with the FBI CJIS Security Policy and evidence it through signed CJIS Security Addenda, fingerprint-based background checks, current Security Awareness Training for all personnel with CJI access, and audit-ready documentation available in this Trust Center.
Does this Trust Center store criminal justice information (CJI)?
No. This platform stores compliance artifacts about our security program — policies, training records, and agreements. It never stores case evidence, body-worn camera footage, criminal history data, or any other CJI.
What agreements does Focal Forensics sign with agencies?
For each engagement we execute the FBI CJIS Security Addendum, and where applicable a Management Control Agreement, before any personnel access agency data. Copies of executed agreements are available to the contracting agency on request.
How do I get access to non-public documents?
Use the Request access form. Requests require acceptance of a non-disclosure agreement and are reviewed by our team. Approved requesters receive a secure sign-in link by email; access expires automatically.