Security & Agency Trust
Security, accountability, and agency control for sensitive report drafting.
IncidentDraft is designed to support sensitive law-enforcement drafting workflows with security, accountability, and agency control in mind. The platform helps officers prepare report drafts while preserving officer review responsibility, role-based access, and auditability across key actions.
Security Pillars
Five core commitments that protect your law enforcement data structure.
Encryption
Encryption in transit and at rest where implemented, configured for the selected deployment model.
Access Control
Role-based permissions ensure only authorized personnel access reports.
Audit Logs
Designed to support audit logging for key workflow events where enabled.
Secure Credentials
Secrets and credentials managed via environment configuration.
Infrastructure
Least-access operational practices with strong environment separation.
Data Protection Layers
Multi-layered defense strategy protecting your law enforcement report drafts.
Encryption & Storage
TLS Encryption in Transit
Production deploymentEncrypted transport is expected for production deployments through HTTPS/TLS.
Data at Rest Protections
Configuration dependentData-at-rest protections depend on the configured database, storage provider, and deployment environment.
Secure Credential Handling
Recommended controlSecrets and credentials should be managed through environment-specific configuration and restricted operational access.
Key Configuration
Configuration dependentCryptographic keys are managed within environment parameters based on agency deployment preferences.
Infrastructure Posture
Environment Separation
Production deploymentDevelopment, testing, and production environments are strictly separated to prevent leakage.
Operational Practices
Recommended controlProduction infrastructure should follow least-access operational practices and environment separation.
Infrastructure Access Control
Recommended controlAdministrative infrastructure access is restricted to authorized operations staff.
Vulnerability Review
Production deploymentThe platform is built to support regular patching and vulnerability review cycles as part of deployment operations.
Access Controls
Access is role-based and scoped by agency to enforce least-privilege operations.
Role Progression
Officer → Supervisor → Admin
Isolation Scope
Agency-Scoped Data
Granular Scoping
Division/Unit Scoping
Access Policy
Least-Privilege Permissions
Officers
- ✓Create and edit own report drafts
- ✓View supervisor feedback and comments
- ✓Prepare reports for final submission
- ✓Access incident-specific templates
Supervisors
- ✓Review assigned unit draft narratives
- ✓Add inline comments and annotations
- ✓Approve or return drafts for revision
- ✓View team-level draft status summaries
Administrators
- ✓Configure agency-specific report layouts
- ✓Manage user roles and permissions
- ✓Access and search agency audit history
- ✓Define agency template requirements
Agency Scoping & Planned MFA
Officer, supervisor, and agency administrator permissions are separated. The platform is designed around least-privilege access patterns, ensuring data remains isolated to the respective agency. Multi-factor authentication (MFA) support may be included depending on deployment configuration or future rollout. Where MFA is not enabled, it should be treated as a planned or deployment-dependent control.
Audit Logs & Accountability
Complete traceability into important actions and lifecycle events.
Workflow Event Logging
Track key draft actions and user transitions
- IncidentDraft tracks key workflow events such as draft creation, quality checks, readiness changes, exports, comments, and administrative actions where enabled.
- Log captures include timestamp, user identity, action description, and event category.
- Audit records help agencies review who performed important actions and when.
- Protections prevent general user modification or clearing of administrative logs.
Traceability & Future Enhancements
Audit review support built for records verification
- Supports compliance checks by documenting access to sensitive report drafts.
- Logs are structured to assist during agency audit operations.
- Additional audit views, retention controls, and exportable audit reports may be expanded as deployment requirements mature.
- Provides supervisors with visibility into draft annotations and historical edits.
Example Tracked Events
Examples of events the platform can track or is designed to track depending on configuration.
Draft created
Quality check run
Marked ready for RMS
Supervisor comment added
Export generated
User role updated
Admin setting changed
AI & Data Usage Policy
Transparent and responsible policies regarding AI draft assistance.
⚠️ AI output is draft assistance only. Officers remain responsible for final review, edits, and agency submission.
Officer Ownership of Narratives
AI-assisted narrative generation is used to help officers create draft language from structured report information. AI output is not a final official report. Officers remain responsible for reviewing, editing, and approving all final report content before RMS handoff or agency submission. IncidentDraft does not replace officer judgment.
Intended Model Training Policy
Agency report content is not used to train public AI models. Final terms are documented in the agency agreement and deployment configuration. We support configuring API routes with strict data privacy flags.
How AI-Assisted Drafting Fits Your Workflow
Incident Capture
Officer enters facts and details
Draft Assistance
System generates narrative draft
Officer Edit & Review
Officer verifies and edits facts
Supervisor Review
Supervisor approves draft for RMS
Data Ownership & Retention
Clear ownership boundaries and configurable retention scopes.
Agency Data Ownership
Agency-controlledAgencies retain ownership of their report content and agency data. IncidentDraft does not claim ownership of agency report narratives, draft content, or supporting report information. Data handling, access, export, and retention should follow the agency agreement and deployment configuration.
Policy-Based Retention
Policy-based / deployment-dependentData retention should be configured according to agency policy, deployment requirements, and applicable agreements. Where configurable retention controls are not yet enabled, retention should be treated as a planned capability or handled through deployment-specific operational procedures.
CJIS Readiness
IncidentDraft's approach to aligning with law enforcement data policies.
Compliance Approach & Disclaimer
IncidentDraft should be evaluated as CJIS-aligned / CJIS-ready depending on deployment controls, not automatically CJIS certified. Final CJIS compliance depends on deployment model, agency policies, agreements, hosting, encryption configuration, access controls, audit logging, and operational procedures.
Agency Security Review
Designed with CJIS-aligned controls in mind. We cooperate with agency audits by providing detailed documentation regarding architecture, data flows, and encryption capabilities to support agency security review.
Hosting and Infrastructure
Working toward CJIS-ready deployment practices. Compliance relies on hosting environments satisfying CJIS requirements, whether deployed on-premises or on agency-managed cloud infrastructure. Final CJIS compliance depends on deployment and agency controls.
Need to review IncidentDraft for your agency?
Our team can walk through access controls, audit logging, AI usage, deployment assumptions, and CJIS-aligned requirements with your agency stakeholders.