Trust & Compliance / CJIS

CJIS compliance for criminal justice information in the cloud.

The FBI CJIS Security Policy sets how agencies and their vendors must protect Criminal Justice Information (CJI). XQ encrypts CJI in email, cloud storage and data transfers with AES-256, requires authenticated access, lets you self-host keys and policy, and records every access — so state and local agencies can use the cloud without losing control.

Built for State and local law enforcement agencies · Corrections agencies and courts · Vendors with access to CJI

At a glance

PolicyFBI CJIS Security Policy

ProtectsCJI in email, cloud storage and transfers

KeysSelf-hosted key and policy server option

AuditWho accessed which record, when and where

Works with Gmail · Outlook · AWS S3 · Azure · Google Cloud · Splunk · QRadar · SolarWinds

Move CJI to the cloud safely

Encrypt CJI before it leaves the physically secure location, with keys cloud providers never hold.

Remove human error

Automatic encryption and DLP rules protect CJI without relying on each user.

Pass audits with detail

Inspect when and where every message, file and record was accessed.

What the CJIS Security Policy requires

The CJIS Security Policy applies to every agency and vendor that accesses Criminal Justice Information — fingerprints, identity history, case and incident history, and criminal history record information. When CJI is transmitted or stored outside a physically secure location, it must be protected with encryption, and access requires advanced authentication, access control and auditing.

How XQ maps to CJIS policy areas

Policy areaHow XQ helps
Encryption of CJI outside secure locationsAES-256 encryption using FIPS 140-2 compliant modules protects CJI in email, cloud storage such as S3, and transfers to the cloud or partner sites.
Advanced authenticationRecipients authenticate — including with two-factor authentication — before a key is released.
Access controlPolicy decides who can open each record; access can be revoked or reprovisioned at any time.
Auditing and accountabilityEvery access attempt is logged, and events can be sent to SIEMs such as Splunk, QRadar or SolarWinds.
Key managementSelf-host the encryption keys and policy server so no third party — including cloud providers — can access CJI.

Planning a cloud migration for CJI?

Support remote and distributed agency teams

  • Protect CJI shared through Gmail and Outlook and stored in cloud buckets.
  • Automatically encrypt all data transfers to the cloud or partner sites.
  • Enable data loss prevention rules for CJIS-protected data.
  • Use secure file sharing for protected exchanges and collaboration.

Related resources and articles

CJIS, answered directly.

Can agencies store CJI in commercial cloud services with XQ?

XQ encrypts CJI before it reaches the cloud and keeps the keys with you — optionally on your own key and policy server — so the cloud provider stores only ciphertext.

Does XQ support advanced authentication for CJI?

Yes. Access to protected CJI requires the recipient to authenticate, including two-factor authentication, before any key is released.

How does XQ help with CJIS audits?

Every access to every protected record is logged with who, when and where, and can be exported or streamed to your SIEM for review.

What encryption does XQ use for CJI?

XQ encrypts CJI with AES-256 using FIPS 140-2 compliant cryptographic modules. Each object gets its own key, kept separate from the data, so CJI stays protected when it is transmitted or stored outside a physically secure location.

Can access to CJI be revoked?

Yes. Policy is checked every time a protected record is opened, so you can revoke or reprovision a user’s access at any time, including to CJI that has already been shared outside the agency.

Protect CJI without slowing your teams.

Talk to our team about CJIS-aligned encryption, authentication and auditing in your current tools.