Security and CJIS controls

Security controls built for the full citation workflow.

Citation Platform is designed around the FBI CJIS Security Policy control areas that apply when systems process, store, or transmit Criminal Justice Information. Here is what the platform uses and what agencies can expect to manage.

Inside Citation Platform

What the platform uses to protect agency access and data.

These controls work together. Authentication confirms the user, device approval confirms the endpoint, permissions limit access, encryption protects the data, and audit history records important activity.

Named accounts and MFA

Live agency users sign in with individual accounts and multi-factor authentication. Administrators can see enrollment status, require setup, reset MFA, and sign out active sessions.

CJIS area: Identification and Authentication

Role-based access

Officer, Agency Administrator, Court Clerk, Read-Only Auditor, and Platform Owner roles receive different tools and data access. Permissions follow job responsibility and least privilege.

CJIS area: Access Control

Agency-approved devices

A new browser or device must be registered and approved before it can receive protected agency information. Until approval and key provisioning are complete, citation records, audit details, and print jobs remain unavailable.

CJIS areas: Access Control and Authentication

Encryption and agency-held keys

Protected data uses encrypted connections and encrypted storage. The Agency Data Gateway controls key provisioning for approved endpoints so protected agency records are not opened to every signed-in device.

CJIS area: System and Communications Protection

Audit and version history

Authentication events, security and administrative actions, citation lifecycle changes, voids, amendments, and version history are recorded for authorized review.

CJIS area: Audit and Accountability

Account and agency lifecycle

Authorized administrators can disable users, end sessions, and manage agency states without erasing accountability. Production records are preserved through suspension, archival, correction, and recovery workflows.

CJIS areas: Access Control and Contingency Planning

CJIS control lifecycle

The policy covers more than sign-in.

FBI CJIS Security Policy v6.1 addresses the complete lifecycle of CJI. Citation Platform is designed so an agency can evaluate the product across the same major operational areas.

Access and authentication

Named users, MFA, approved devices, session controls, role separation, and least privilege.

Audit and accountability

Reviewable security events, administrative actions, citation history, and authorized changes.

Configuration and updates

Controlled changes, maintained software, secure settings, and visibility into operational state.

Continuity and recovery

Agency data storage choices, backups, recovery planning, retained history, and service restoration.

Incident response

Defined reporting, containment, recovery, and coordination responsibilities for security events.

Shared responsibility

The platform, agency, devices, network, personnel, training, agreements, and local procedures all contribute to the final security posture.

Policy reference: FBI Criminal Justice Information Services Security Policy, Version 6.1, June 25, 2026.

Agency administration

Security controls have to be visible and manageable.

Agency leaders should not have to guess which users are protected, which devices are approved, or whether access has been shut down. Citation Platform brings those tasks into the administrative workflow.

MFA status and recovery

Review user enrollment, require MFA at the next login, reset an enrollment when appropriate, and end active sessions.

Device registration and approval

Review a new endpoint before allowing it to receive protected records or agency-controlled key material.

User roles and capacity

Create users within agency limits and assign only the role needed for officer, administrator, court, or audit responsibilities.

Live, suspended, and archived states

Manage agency access without treating production history like disposable test data. Reset tools remain limited to demo or training environments.

Security and activity review

Use audit information to understand important account, device, administrative, and citation events.

Direct answers

Common agency security questions.

What happens on an unapproved device?

The device can be identified and registered, but protected citation records, audit details, and print jobs remain unavailable until an Agency Administrator approves it and the Agency Data Gateway provisions the required key.

Is MFA required?

Live agency environments are designed to require MFA. Demo or training environments may be configured differently so agencies can evaluate workflow without confusing test access with production access.

Where does agency data live?

Agencies choose and control their production system of record, such as approved SharePoint, OneDrive, or local network storage reached through the Agency Data Gateway. Deployment choices must match agency and CJIS requirements.

What does the audit history cover?

The design records authentication and security events, administrative actions, citation creation and issue activity, voids, amendments, and retained versions for authorized review.

Does the FBI endorse or approve Citation Platform?

No. The FBI publishes the CJIS Security Policy, while agencies and the appropriate CJIS authorities evaluate the full deployment. LevelReach does not claim FBI endorsement or formal government approval.

Is the software alone enough for compliance?

No. Software controls are one part of the deployment. Agency policies, personnel screening, training, devices, physical safeguards, networks, agreements, incident procedures, and ongoing administration also matter.

Compliance is a shared deployment responsibility.

Citation Platform is designed to support an agency's CJIS Security Policy obligations. Final compliance depends on the complete agency environment and the requirements of the appropriate CJIS authorities.

Agency security review

Review the controls against your environment.

Bring your device, identity, storage, court, and operating requirements to a focused Citation Platform discussion.

Request a Security Review