LEDGER

Security and principles

Everything runs inside your CJIS boundary.

A government cloud tenant dedicated to your agency, behind your own sign-in, writing one append-only log that you own. Nothing leaves the boundary and nothing trains a model.

The boundary

CJIS BOUNDARY · GOVERNMENT CLOUD Agency-dedicated tenant · encrypted at rest and in transit BrowserAgency desktopNothing to install Your sign-inYour identity providerMulti-factor, named users LedgerChat · folders · checksMap · redaction · evidenceCitations · scope notes · labels Frontier modelsGovernment cloudFedRAMP High · standard APINo fine-tuning, no training StorageDocuments · extractionsExports · working copiesPurged on a set schedule Audit logEvery action and exportAppend-onlyExports with your data HTTPS Nothing leaves the boundary. Nothing trains a model.

How it runs

HostingAgency-dedicated government cloud tenant
IdentityYour identity provider, multi-factor, named users
AuditEvery action logged, append-only, exportable
ModelsFrontier models, FedRAMP High authorized, never trained on your data
DataExport any time, certified deletion on exit
DecisionsA person, under their name, every time

Today's deployment runs in Azure Government and calls Azure OpenAI Government from inside the tenant. Ledger is not tied to one provider; the boundary is the requirement.

Ledger runs inside a government cloud tenant dedicated to your agency. There is no shared multi-tenant store of agency records, and no copy of your data on our side of the line.

Will not

No facial recognition of the public
Ledger does not identify people from photographs or video of the public. We do not build it, license it, or connect a tool to a service that does.
No predictive policing
Ledger does not forecast who will commit a crime or where to send a patrol. It works on records that already exist, about incidents that already happened.
No sale or sharing of agency data
Agency records stay in the agency's tenant. We do not sell them, share them with a third party, or use them to improve a product for anyone else.
No automated decisions about any person
No release, charge, finding or referral happens because the software said so. A person makes the decision and the log carries their name.

The full page is written for county IT, county attorneys, reporters and residents.

How an engagement starts

A conversation
Half an hour with the people who would use it, and with whoever owns the environment it would run in.
Shadowing
We sit with detectives and records staff and watch the work before we propose anything.
A scoped agreement
We scope it together: a written scope with acceptance tests, so both sides know what finished means. There is no list price to try it; the scope sets the cost.
Build and review
We build, you review on your schedule, and the agency keeps its data and its log.

Questions county IT will ask

In a government cloud tenant dedicated to your agency, in the region you choose. Records, embeddings and the audit log stay inside that boundary, and we hold no copy outside it.