Security & Compliance
Security is the product
CLERS moves criminal-justice information between agencies and the companies that hold evidence. That responsibility shapes every layer of the system: identity, transport, storage, and audit.
Compliance Frameworks
CJIS V5.9
We align with the FBI CJIS Security Policy on access control, advanced authentication, audit and accountability, and encryption of CJI in transit and at rest.
FIPS 140-3
Validated cryptographic modules for TLS termination and storage encryption.
NIST 800-53
Controls mapped to the NIST SP 800-53 moderate baseline.
SOC 2 TYPE II
Annual independent audit of security, availability, and confidentiality controls.
28 CFR PART 20
Criminal-justice information handled per federal CHRI regulations.
US RESIDENCY
Evidence stored and processed exclusively in U.S. data centers.
Identity & Access
A one-time code sent to the agency email verifies every request
Personal email providers are rejected, and .gov addresses are flagged verified-preferred
Company and staff consoles sign in with TOTP multi-factor authentication
Participant access is scoped, revocable, and expiring
Console permissions are role-based
Encryption & Data Handling
TLS 1.3 on all traffic, with HSTS enforced
AES-256 at rest on FIPS 140-3 validated modules
A SHA-256 hash is recorded for every delivered file
Download links are signed and expire automatically
Every upload is virus-scanned before delivery
Tamper-evident chain of custody
Every audit event is written with the SHA-256 hash of the event before it, so altering any record breaks the chain. The full history of a request can be verified and exported as a chain-of-custody certificate for court.
EVT 04810
REQUEST_CREATED
SHA-256 · a41f…09be
EVT 04811
EMAIL_VERIFIED
SHA-256 · 77c2…d1a4
EVT 04812
FILE_DELIVERED
SHA-256 · 9f3a…6c10
EVT 04813
DOWNLOADED
SHA-256 · 0be7…44da
Found a vulnerability? Tell us at security@echo911.com.
We acknowledge every report within one business day.