
CJIS compliance is not a product certification. It is a shared responsibility among a law enforcement agency, its state CJIS Systems Agency, and the vendor, verified through audits. Scot Thomasson explains what CJIS means for AI investigative software, the security controls to require, the risks of general-purpose AI assistants, and six questions every agency should ask before signing.
CJIS compliance means meeting the requirements of FBI Criminal Justice Information Services (CJIS) Security Policy. This policy sets the minimum security standard for any system that stores, processes, or transmits criminal justice information, including case files, evidence logs, and records from national databases such as NCIC.
No. The FBI does not certify software products. Compliance rests on agreements among a law enforcement agency, its state CJIS Systems Agency (CSA), and the vendor, and it is verified through audits. A credible vendor can provide four things: a signed CJIS Security Addendum, fingerprint-based background checks for personnel with access, evidence of CJIS Awareness Training, and documentation an auditor can review.
Not by itself. eSleuth AI runs in AWS , and has added the components needed for the environment to support CJIS requirements, which provides a strong foundation for handling criminal justice information. However, CJIS compliance is a shared responsibility. The application must enforce its own security controls, and the vendor must meet personnel and contractual requirements. eSleuth AI was designed with CJIS compliance as a core architectural requirement, not an add-on.
The FBI has modernized the policy to align more closely with NIST SP 800-53 federal security controls, and the new requirements are phasing in over time. Vendors whose platforms were built for compliance from the start, as eSleuth AI was, are better positioned to adapt as audit standards evolve.
AI tools that analyze case files, rank unsolved cases, or recommend leads handle criminal justice information, so the full policy applies. AI also adds an accountability requirement, because every output must be traceable. The eSleuth AI Solvability Matrix™, for example, ranks unsolved cases by likelihood of resolution, and it logs every recommendation. eSleuth AI follows the principle that AI recommends and humans decide and validate. Its chain-of-custody audit trail records what the system surfaced and what the investigator did with it.
No. When security controls frustrate investigators, they tend to work around them. Effective platforms make compliant behavior the default. eSleuth AI, for example, gives investigators secure access on mobile devices in the field and loads data from records management systems through automated collection processes rather than relying on manual entry.
Not without meeting the same CJIS requirements that apply to any other system. Pasting case files, reports, or evidence into a general-purpose assistant such as ChatGPT, Claude, Gemini, or Copilot sends criminal justice information to an environment outside agency control. Commercial consumer tiers typically sit in general commercial cloud infrastructure, do not operate under a CJIS Security Addendum with the agency, and do not subject their support personnel to fingerprint-based background checks. Some vendors offer government cloud versions of these products, but the agency must still confirm hosting location, data-handling terms, and personnel screening with its state CSA before any criminal justice information goes in. The safe rule for investigators is simple. If the platform is not covered by an agreement your agency has signed, do not upload case data into it.
Yes. The obligation follows the data, not the product category. Any platform that ingests, stores, processes, or transmits criminal justice information falls under the CJIS Security Policy, whether it is marketed as a case management system, an analytics tool, or an AI assistant. Investigators uploading the data themselves does not change the requirement. Agencies should ask every vendor in this space the same questions: where is the data hosted, who has access, will you sign the CJIS Security Addendum with our state CSA, and can you produce documentation for an audit?
#CJIS #eSleuthAI #LawEnforcement #PublicSafety #AI #ColdCase #GovTech
Enter your investigator count, fully burdened cost, and the hours your team loses to manual review. You'll see what that time is worth — grounded in data from agencies already running eSleuth AI.
See how eSleuth helps agencies solve more cases with the resources they already have.
Book a Demo