Trust and security

Built for the agencies that have to answer for it.

FINDER® operates inside criminal justice environments, which means it answers to criminal justice standards. This page covers how the platform supports your CJIS obligations, how your agency keeps control of its own data, and what we can put in writing when your auditor asks.

> hosting AWS GovCloud
> personnel CJIS screened and trained
> encryption in transit and at rest
> mfa authenticator app or hardware token
> ownership your records stay yours
How compliance actually works

CJIS compliance is not something a vendor hands you.

Compliance is a collaboration between your agency, your personnel, your contractors, and your vendors. The real test is whether your agency passes a CJIS audit on its policies, its user management, and its vendor management.

Our job is to make our part of that straightforward: screened personnel, documented controls, and records you can produce on request rather than assurances you have to take on faith.

> your agency policy and user management
> your personnel training and conduct
> your vendors screening and documentation
> the audit tests all three
Personnel and policy

Screened people, documented controls.

Background screening

Personnel who may access a customer system have completed background checks under the CJIS Security Policy. Fingerprint ORI is available on request.

Security Awareness training

CJIS Security Awareness training is completed and maintained by our team. Certifications are available on request.

CJIS Security Addendum

Security Addendums are executed and kept on file. We sign yours.

Audit cooperation

We support customer-requested background checks, audits, and documentation requests as a standard part of the relationship, not as an escalation.

Advanced authentication

Multi-factor moves to authenticator app or hardware token on September 15, 2026.

CJIS Security Policy v6.0 control IA-2 requires advanced authentication for access to criminal justice information. Email one-time passcodes do not satisfy that control. FINDER is removing email OTP entirely and moving all users to an authenticator app or a hardware token.

This is a forced enrollment, not a lockout. Users who have not enrolled by the cutover are prompted at next sign-in and continue into the platform once enrolled. Agency administrators can see enrollment status for their own users throughout.

> notice 1 Jul 08 2026
> notice 2 Aug 17 2026
> notice 3 Sep 01 2026
> notice 4 Sep 08 2026
> cutover Sep 15 2026
Data ownership

Your records remain your records.

01

You own what you contribute

Data your agency contributes remains your agency’s data. Contribution does not transfer ownership, and it does not grant us rights to sell, license, or repurpose it.

02

You control what is shared

Sharing across the network is governed by executed participation agreements, not by default settings. Your agency determines what is made available to other member agencies.

03

Corrections and expungement follow your system

Records flagged confidential in your source system are not read. A record flagged after loading is removed. When your agency corrects a report, the change syncs on the next run. Your records stay the source of truth.

04

You can withdraw

If your agency leaves the network, your contributed data is removed from FINDER on request and the parser on your network is terminated.

Access and accountability

Every query has a name on it.

Agency-approved accounts

New users are approved by their own agency administrator before access is granted. Agencies not yet on the network go through a separate review by the FINDER team.

Role-based access

Permissions are assigned by role. Add-on modules such as Public Records and AdTech are enabled per agency and per user, never opened by default.

Query logging

Access is granted to authorized agency personnel for criminal justice purposes, and searches are logged with user, timestamp, and query. Agency administrators can run audits and logs for their own agency, with a pre-filter for internal and agency audits.

Administrator control

Agency administrators approve and deny account requests, edit and delete accounts, expunge records, and run audits without opening a support ticket. Permission and deactivation changes take effect immediately.

Source boundaries

What each data source is, and what it is not.

Federal query access

N-DEx

FINDER provides query access to N-DEx under your agency’s own credential. N-DEx records are not held, copied, or resold by FINDER. Results return to the querying user under federal terms of use.

Add-on module

FINDER Public Records

Person and motor vehicle public records sourced through idiCORE. Compliance, including permissible use under the Driver’s Privacy Protection Act, runs through your agency’s own direct agreement with the provider. It is not a screening product and does not return driving history or license status.

Add-on module

FINDER AdTech

Commercially available advertising identifier data sourced through Sigilite, queried for a defined area and time window. Your agency determines permissible use under its own policy and applicable legal process.

Infrastructure

Where the platform runs.

AWS GovCloud

FINDER runs in AWS GovCloud, a cloud environment built to meet federal compliance requirements, which provides data protection, scalability, and resilience.

Encrypted in transit and at rest

Customer data is encrypted both in transit and at rest. Specific standards and configuration detail are available to your IT staff on request.

Backed up daily

The environment is backed up daily and monitored continuously.

Secure file transfer

Bulletins, hotlists, and other file transfers move over an SFTP server that is FIPS 140-2 compliant and secured end to end, consistent with the requirements for transferring CJIS data.

Nothing inside your network

FINDER is a web application, so there is no client software on user machines. The only component on your network is the data parser, a console application that runs behind your firewall on a schedule you set.

Federal directives

The architecture is designed to meet the technological directives established by the federal government for sharing law enforcement data.

Vendor assessment

Send us your requirements.

If your agency is running a vendor assessment, tell us what you need. Certifications, ORI, executed addendums, and the data processing agreement are available on request. We would rather answer the hard questions early than late.

Supporting law enforcement for over 20 years.

© 2026 FINDER® Software Solutions LLC