Documents

Public documents can be downloaded directly. Locked documents require an approved access request and acceptance of a non-disclosure agreement.

DocumentCategoryAccess

Access Control & Account Management Policy

Account lifecycle, least privilege, MFA, session controls, remote access, and device rules. v1.0, effective 2026-07-03.

policyView Download

Audit & Accountability Policy

Logging requirements, log protection, weekly review, and one-year retention. v1.0, effective 2026-07-03.

policyView Download

CBI Fingerprint Background Check Authorization

Fingerprint-based background screening status for Focal Forensics personnel through the Colorado Bureau of Investigation under vendor program code COVCP0265, as of July 29, 2026. All personnel are authorized. Dates of birth are omitted; they remain in the source CBI records. Access is granted on request after review.

background check Request access

CJIS Security Awareness Training Status Report

Current CJIS Security and Privacy certification status for all Focal Forensics personnel, produced from the CJIS Online status report dated July 29, 2026. All personnel are certified. Access is granted on request after review.

training record Request access

Completed Vendor Security Questionnaire

Pre-completed security questionnaire (based on the BCA SaaS Vendor Security Assessment template): ~100 answers covering governance, operations, access control, encryption, media protection, and incident response. July 2026.

reportView Download

Encryption & Data Protection Standard

Encryption in transit and at rest, key management, FileCloud GovCloud transfer/storage, US data residency. v1.0, effective 2026-07-03.

policyView Download

Incident Response Plan

Detection, handling, 24-hour agency notification, The Hartford cyber policy engagement, and post-incident review. v1.0, effective 2026-07-03.

policyView Download

Information Security Policy

Umbrella security policy: governance, roles, core rules, and system maintenance baseline. v1.0, effective 2026-07-03.

policyView Download

Media Protection & Sanitization Policy

Media minimization, marking, storage, transport chain of custody, and NIST SP 800-88 sanitization. v1.0, effective 2026-07-03.

policyView Download

Personnel Security & Training Policy

Screening, fingerprinting, agreements, departures, and CJIS Security Awareness Training requirements. v1.0, effective 2026-07-03.

policyView Download

System & Data Flow Overview

One-page diagram of how CJI moves through a Focal Forensics engagement: agency, FileCloud GovCloud, encrypted analyst workstation, delivery. v1.0, 2026-07-03.

whitepaperView Download