Documents
Public documents can be downloaded directly. Locked documents require an approved access request and acceptance of a non-disclosure agreement.
| Document | Category | Access |
|---|---|---|
Access Control & Account Management Policy Account lifecycle, least privilege, MFA, session controls, remote access, and device rules. v1.0, effective 2026-07-03. | policy | View Download |
Audit & Accountability Policy Logging requirements, log protection, weekly review, and one-year retention. v1.0, effective 2026-07-03. | policy | View Download |
CBI Fingerprint Background Check Authorization Fingerprint-based background screening status for Focal Forensics personnel through the Colorado Bureau of Investigation under vendor program code COVCP0265, as of July 29, 2026. All personnel are authorized. Dates of birth are omitted; they remain in the source CBI records. Access is granted on request after review. | background check | Request access |
CJIS Security Awareness Training Status Report Current CJIS Security and Privacy certification status for all Focal Forensics personnel, produced from the CJIS Online status report dated July 29, 2026. All personnel are certified. Access is granted on request after review. | training record | Request access |
Completed Vendor Security Questionnaire Pre-completed security questionnaire (based on the BCA SaaS Vendor Security Assessment template): ~100 answers covering governance, operations, access control, encryption, media protection, and incident response. July 2026. | report | View Download |
Encryption & Data Protection Standard Encryption in transit and at rest, key management, FileCloud GovCloud transfer/storage, US data residency. v1.0, effective 2026-07-03. | policy | View Download |
Incident Response Plan Detection, handling, 24-hour agency notification, The Hartford cyber policy engagement, and post-incident review. v1.0, effective 2026-07-03. | policy | View Download |
Information Security Policy Umbrella security policy: governance, roles, core rules, and system maintenance baseline. v1.0, effective 2026-07-03. | policy | View Download |
Media Protection & Sanitization Policy Media minimization, marking, storage, transport chain of custody, and NIST SP 800-88 sanitization. v1.0, effective 2026-07-03. | policy | View Download |
Personnel Security & Training Policy Screening, fingerprinting, agreements, departures, and CJIS Security Awareness Training requirements. v1.0, effective 2026-07-03. | policy | View Download |
System & Data Flow Overview One-page diagram of how CJI moves through a Focal Forensics engagement: agency, FileCloud GovCloud, encrypted analyst workstation, delivery. v1.0, 2026-07-03. | whitepaper | View Download |