Trust & Compliance / CJIS
CJIS compliance for criminal justice information in the cloud.
The FBI CJIS Security Policy sets how agencies and their vendors must protect Criminal Justice Information (CJI). XQ encrypts CJI in email, cloud storage and data transfers with AES-256, requires authenticated access, lets you self-host keys and policy, and records every access — so state and local agencies can use the cloud without losing control.
Built for State and local law enforcement agencies · Corrections agencies and courts · Vendors with access to CJI
At a glance
PolicyFBI CJIS Security Policy
ProtectsCJI in email, cloud storage and transfers
KeysSelf-hosted key and policy server option
AuditWho accessed which record, when and where
Works with Gmail · Outlook · AWS S3 · Azure · Google Cloud · Splunk · QRadar · SolarWinds
Move CJI to the cloud safely
Encrypt CJI before it leaves the physically secure location, with keys cloud providers never hold.
Remove human error
Automatic encryption and DLP rules protect CJI without relying on each user.
Pass audits with detail
Inspect when and where every message, file and record was accessed.
What the CJIS Security Policy requires
The CJIS Security Policy applies to every agency and vendor that accesses Criminal Justice Information — fingerprints, identity history, case and incident history, and criminal history record information. When CJI is transmitted or stored outside a physically secure location, it must be protected with encryption, and access requires advanced authentication, access control and auditing.
How XQ maps to CJIS policy areas
| Policy area | How XQ helps |
|---|---|
| Encryption of CJI outside secure locations | AES-256 encryption using FIPS 140-2 compliant modules protects CJI in email, cloud storage such as S3, and transfers to the cloud or partner sites. |
| Advanced authentication | Recipients authenticate — including with two-factor authentication — before a key is released. |
| Access control | Policy decides who can open each record; access can be revoked or reprovisioned at any time. |
| Auditing and accountability | Every access attempt is logged, and events can be sent to SIEMs such as Splunk, QRadar or SolarWinds. |
| Key management | Self-host the encryption keys and policy server so no third party — including cloud providers — can access CJI. |
Planning a cloud migration for CJI?
Support remote and distributed agency teams
- Protect CJI shared through Gmail and Outlook and stored in cloud buckets.
- Automatically encrypt all data transfers to the cloud or partner sites.
- Enable data loss prevention rules for CJIS-protected data.
- Use secure file sharing for protected exchanges and collaboration.
Related resources and articles
FAQ
CJIS, answered directly.
Can agencies store CJI in commercial cloud services with XQ?
XQ encrypts CJI before it reaches the cloud and keeps the keys with you — optionally on your own key and policy server — so the cloud provider stores only ciphertext.
Does XQ support advanced authentication for CJI?
Yes. Access to protected CJI requires the recipient to authenticate, including two-factor authentication, before any key is released.
How does XQ help with CJIS audits?
Every access to every protected record is logged with who, when and where, and can be exported or streamed to your SIEM for review.
What encryption does XQ use for CJI?
XQ encrypts CJI with AES-256 using FIPS 140-2 compliant cryptographic modules. Each object gets its own key, kept separate from the data, so CJI stays protected when it is transmitted or stored outside a physically secure location.
Can access to CJI be revoked?
Yes. Policy is checked every time a protected record is opened, so you can revoke or reprovision a user’s access at any time, including to CJI that has already been shared outside the agency.
Protect CJI without slowing your teams.
Talk to our team about CJIS-aligned encryption, authentication and auditing in your current tools.