IncidentDraft

Security & Agency Trust

Security, accountability, and agency control for sensitive report drafting.

IncidentDraft is designed to support sensitive law-enforcement drafting workflows with security, accountability, and agency control in mind. The platform helps officers prepare report drafts while preserving officer review responsibility, role-based access, and auditability across key actions.

Role-based access
Agency-scoped data
Officer review required
Designed to support CJIS-aligned deployment review

Security Pillars

Five core commitments that protect your law enforcement data structure.

Encryption

Encryption in transit and at rest where implemented, configured for the selected deployment model.

Access Control

Role-based permissions ensure only authorized personnel access reports.

Audit Logs

Designed to support audit logging for key workflow events where enabled.

Secure Credentials

Secrets and credentials managed via environment configuration.

Infrastructure

Least-access operational practices with strong environment separation.

Data Protection Layers

Multi-layered defense strategy protecting your law enforcement report drafts.

Encryption & Storage

TLS Encryption in Transit

Production deployment

Encrypted transport is expected for production deployments through HTTPS/TLS.

Data at Rest Protections

Configuration dependent

Data-at-rest protections depend on the configured database, storage provider, and deployment environment.

Secure Credential Handling

Recommended control

Secrets and credentials should be managed through environment-specific configuration and restricted operational access.

Key Configuration

Configuration dependent

Cryptographic keys are managed within environment parameters based on agency deployment preferences.

Infrastructure Posture

Environment Separation

Production deployment

Development, testing, and production environments are strictly separated to prevent leakage.

Operational Practices

Recommended control

Production infrastructure should follow least-access operational practices and environment separation.

Infrastructure Access Control

Recommended control

Administrative infrastructure access is restricted to authorized operations staff.

Vulnerability Review

Production deployment

The platform is built to support regular patching and vulnerability review cycles as part of deployment operations.

Access Controls

Access is role-based and scoped by agency to enforce least-privilege operations.

Role Progression

Officer → Supervisor → Admin

Isolation Scope

Agency-Scoped Data

Granular Scoping

Division/Unit Scoping

Access Policy

Least-Privilege Permissions

Officers

  • Create and edit own report drafts
  • View supervisor feedback and comments
  • Prepare reports for final submission
  • Access incident-specific templates

Supervisors

  • Review assigned unit draft narratives
  • Add inline comments and annotations
  • Approve or return drafts for revision
  • View team-level draft status summaries

Administrators

  • Configure agency-specific report layouts
  • Manage user roles and permissions
  • Access and search agency audit history
  • Define agency template requirements

Agency Scoping & Planned MFA

Officer, supervisor, and agency administrator permissions are separated. The platform is designed around least-privilege access patterns, ensuring data remains isolated to the respective agency. Multi-factor authentication (MFA) support may be included depending on deployment configuration or future rollout. Where MFA is not enabled, it should be treated as a planned or deployment-dependent control.

Audit Logs & Accountability

Complete traceability into important actions and lifecycle events.

Workflow Event Logging

Track key draft actions and user transitions

  • IncidentDraft tracks key workflow events such as draft creation, quality checks, readiness changes, exports, comments, and administrative actions where enabled.
  • Log captures include timestamp, user identity, action description, and event category.
  • Audit records help agencies review who performed important actions and when.
  • Protections prevent general user modification or clearing of administrative logs.

Traceability & Future Enhancements

Audit review support built for records verification

  • Supports compliance checks by documenting access to sensitive report drafts.
  • Logs are structured to assist during agency audit operations.
  • Additional audit views, retention controls, and exportable audit reports may be expanded as deployment requirements mature.
  • Provides supervisors with visibility into draft annotations and historical edits.

Example Tracked Events

Examples of events the platform can track or is designed to track depending on configuration.

Draft created

Quality check run

Marked ready for RMS

Supervisor comment added

Export generated

User role updated

Admin setting changed

AI & Data Usage Policy

Transparent and responsible policies regarding AI draft assistance.

⚠️ AI output is draft assistance only. Officers remain responsible for final review, edits, and agency submission.

Officer Ownership of Narratives

AI-assisted narrative generation is used to help officers create draft language from structured report information. AI output is not a final official report. Officers remain responsible for reviewing, editing, and approving all final report content before RMS handoff or agency submission. IncidentDraft does not replace officer judgment.

Intended Model Training Policy

Agency report content is not used to train public AI models. Final terms are documented in the agency agreement and deployment configuration. We support configuring API routes with strict data privacy flags.

How AI-Assisted Drafting Fits Your Workflow

1

Incident Capture

Officer enters facts and details

2

Draft Assistance

System generates narrative draft

3

Officer Edit & Review

Officer verifies and edits facts

4

Supervisor Review

Supervisor approves draft for RMS

Data Ownership & Retention

Clear ownership boundaries and configurable retention scopes.

Agency Data Ownership

Agency-controlled

Agencies retain ownership of their report content and agency data. IncidentDraft does not claim ownership of agency report narratives, draft content, or supporting report information. Data handling, access, export, and retention should follow the agency agreement and deployment configuration.

Policy-Based Retention

Policy-based / deployment-dependent

Data retention should be configured according to agency policy, deployment requirements, and applicable agreements. Where configurable retention controls are not yet enabled, retention should be treated as a planned capability or handled through deployment-specific operational procedures.

CJIS Readiness

IncidentDraft's approach to aligning with law enforcement data policies.

Compliance Approach & Disclaimer

IncidentDraft should be evaluated as CJIS-aligned / CJIS-ready depending on deployment controls, not automatically CJIS certified. Final CJIS compliance depends on deployment model, agency policies, agreements, hosting, encryption configuration, access controls, audit logging, and operational procedures.

Agency Security Review

Designed with CJIS-aligned controls in mind. We cooperate with agency audits by providing detailed documentation regarding architecture, data flows, and encryption capabilities to support agency security review.

Hosting and Infrastructure

Working toward CJIS-ready deployment practices. Compliance relies on hosting environments satisfying CJIS requirements, whether deployed on-premises or on agency-managed cloud infrastructure. Final CJIS compliance depends on deployment and agency controls.

Need to review IncidentDraft for your agency?

Our team can walk through access controls, audit logging, AI usage, deployment assumptions, and CJIS-aligned requirements with your agency stakeholders.