Security and data boundary

The products are built so that we are never inside your CJIS scope.

Agency data

Both products store everything they produce on storage the agency designates. There is no vendor cloud, no synchronization, no telemetry, no crash reporting, no cloud transcription and no remote diagnostics. We cannot see agency data because nothing transmits it.

The license service

Online license keys are redeemed against a small service that signs a license for one computer. Check-ins are periodic and advisory: an outage never stops an application from opening, and offline license files never check in at all. The service stores the fields listed on the licensing page and nothing more.

This website

Accounts here hold a name, an agency email, orders, entitlements and a log of which build was downloaded by whom. Passwords are stored as salted PBKDF2 hashes. Download links are signed and expire within minutes. Every published build lists its SHA-256 so it can be verified before installation.

What we do not claim

We do not claim FIPS 140-3 validation of any cryptographic module, and we do not represent that any output is admissible in a proceeding. The license agreement states both plainly.