Privacy Policy & Evidence Security Architecture

Data Protection, FBI CJIS Security Posture, DPPA & HIPAA PHI Safeguards

Back to Login

FIPS 140-2 Encryption

AES-256 at rest across all media storage; TLS 1.3 in transit with HSTS and strict CSP.

Multi-Tenant RLS

PostgreSQL Row-Level Security ensures logical and physical data isolation between agencies.

No AI Model Training

Customer evidence and case prompts are never used to train public or commercial AI models.

1. Driver's Privacy Protection Act (DPPA - 18 U.S.C. § 2721)

The platform processes vehicle registration details, VIN numbers, and driver's license data strictly in accordance with permissible statutory uses under the federal Driver's Privacy Protection Act (18 U.S.C. § 2721(b)), including:

  • Official Government & Law Enforcement Use: By courts, law enforcement, or government agencies carrying out statutory functions (18 U.S.C. § 2721(b)(1)).
  • Judicial & Arbitral Proceedings: In connection with any civil, criminal, administrative, or arbitral proceeding in any federal, state, or local court or agency (18 U.S.C. § 2721(b)(4)).
  • Insurance & Claims Investigation: By insurance carriers and Special Investigations Units (SIU) investigating claims, fraud, or subrogation (18 U.S.C. § 2721(b)(6)).

2. FBI CJIS Security Posture & Criminal Justice Information

For law enforcement, police departments, and state highway patrols managing Criminal Justice Information (CJI):

Granular Access Control (RBAC)Restricted role tiers (Investigator, Supervisor, Admin) with mandatory multi-factor authentication (MFA) and badge number tracking.
Immutable Audit LoggingChain of custody logging records user ID, IP address, timestamp, and cryptographic hash for every evidence access or export.

3. Medical Records & Protected Health Information (HIPAA PHI)

When case files incorporate coroner toxicology reports, occupant biomechanics injury data, or EMS triage logs:

NexusRecon enforces strict confidentiality under the Health Insurance Portability and Accountability Act (HIPAA). All PHI data is encrypted at rest and in transit. For enterprise healthcare and government municipal deployments, NexusRecon executes standard Business Associate Agreements (BAAs).

4. On-Premise Air-Gapped & Sovereign Deployment Options

For intelligence agencies, sovereign defense departments, or air-gapped forensic labs requiring zero external network egress:

The platform supports unprivileged on-premise container deployment (Ubuntu LXC / Proxmox VE / Docker Compose) utilizing a local PostgreSQL instance and on-premise containerized Ollama LLM nodes, guaranteeing that no data leaves agency-controlled infrastructure.

© 2026 NexusRecon Forensics Platform. Confidential & Proprietary.