Solutions
CJIS-Compliant Justice Cloud & Local AI
Infrastructure for the CJIS-compliant environments your agency operates — on-premises compute, segmented storage and secure networking that keep criminal justice information, and any AI that reads it, inside a boundary you control.

- Policy basis
- CJIS Security Policy v6.0 (12/27/2024)
- Audit reality
- v5.9.5 through 03/31/2027 → v6.0 by Oct 1, 2027
- Data residency
- APB-member country, agency legal authority
- What we supply
- Compute, storage, network & security hardware
CJIS compliance is your agency's to certify — the infrastructure is ours to source
The FBI's CJIS Security Policy governs every system that stores, processes or transmits criminal justice information (CJI). Certifying against it belongs to your CJIS Systems Agency and the CJIS Systems Officer who, by policy, holds ultimate responsibility for CJIS security in your state or agency — a role that cannot be outsourced to a vendor. Uniqcli doesn't sign that responsibility and doesn't touch your CJI. We source and integration-test the compute, storage, encryption and network security your team deploys behind the policy's technical controls — including the on-premises hardware that lets AI read CJI without it ever leaving a boundary you control — TAA- and §889-screened on every line.
There is no AI carve-out in the CJIS policy — so the AI comes to the data
CJIS Security Policy v6.0 has no dedicated AI or LLM policy area. Its only mention of artificial intelligence is a passing note that non-signature detection may include AI techniques. The practical consequence: any AI that touches CJI is governed by exactly the same controls as every other system — access control, encryption, audit, personnel screening, physical protection and incident response. There is no exemption for sending CJI to an outside model.
Control SC-28 restricts where CJI at rest can live at all: inside the physical boundaries of an APB-member country — the United States, its territories, Indian Tribes and Canada — and under the legal authority of an APB-member agency. A cloud AI service invokes the policy's remote-access, physically-secure-location, encryption, breach-notification, Security-Addendum and audit-rights questions all at once. Keeping inference on-premises — the AI compute sitting next to the data inside your own controlled environment — is how many agencies sidestep those questions entirely. That is the hardware we supply.
- No CJIS AI exemption — AI on CJI meets the same controls as any other system
- SC-28 data-residency limits where CJI at rest may be stored
- On-premises inference keeps CJI out of a third-party model's remote-access and audit scope
- GPU compute, storage and networking sized to run models inside your boundary

The policy in motion
Two CJIS policy versions are live at once — build for both
The modernized v6.0 and the still-audited v5.9.x overlap for years. Infrastructure has to satisfy the current audit basis and the modernized controls at the same time.
Dec 2024
v6.0 dated and approved
The FBI CJIS Information Security Officer dates CJIS Security Policy v6.0 12/27/2024 and the CJIS Advisory Policy Board approves it. The change log labels the release “Policy Modernization Completion” — the largest CJIS update in more than a decade.
Jan 2025
v6.0 released
Version 6.0 publishes on 01/22/2025, expanding the prior 13-area structure to 20 policy areas across more than 1,300 subcontrols, now mapped to NIST SP 800-53 control families.
Through Mar 2027
Audits still run on v5.9.5
The version most audits are actually conducted against through 03/31/2027 remains v5.9.5 — so the equipment behind your controls has to hold up under today's audit basis as well as the modernized one.
Oct 1, 2027
v6.0 accountability
Agencies are expected to demonstrate continuous, audit-ready governance and accountability under v6.0.
CJIS v6.0 policy areas, mapped to what we source
The 20 policy areas of v6.0 map to NIST SP 800-53 control families. CJIS compliance stays your agency's to certify; these are the infrastructure categories we supply so your systems can meet the controls your CSA and assessors evaluate — the equipment behind the control, never a Uniqcli certification.
Access Control (AC)
Identity and network-access hardware — role-based access enforcement, network access control, and console/KVM access restriction — behind the least-privilege access CJI systems require.
Audit & Accountability (AU)
SIEM and log-aggregation appliances, high-throughput audit-log storage and time-synchronization hardware sized to retain and correlate the access records the policy expects.
Configuration Management (CM)
Endpoints and network gear imaged and hardened to a known-good baseline and staged before delivery, so systems arrive at the configuration your assessors test.
Contingency Planning (CP)
Backup appliances, immutable and alternate-site storage, and redundant power and failover systems behind the recovery and reconstitution the policy requires.
Identification & Authentication (IA)
FIDO2/WebAuthn security keys, PIV/CAC smart-card readers and the ICAM hardware behind the advanced (multi-factor) authentication CJI access calls for.
Maintenance (MA)
Controlled-maintenance tooling, sanitized maintenance media and vetted spares so servicing a CJI system doesn't become an uncontrolled path to the data.
Media Protection (MP)
FIPS-validated self-encrypting drives, encrypted removable media, and degaussers and shredders for the media sanitization and destruction the policy specifies.
Physical & Environmental (PE)
Badge access control, surveillance cameras, secure racks and cabinet locks, tamper-evident enclosures and environmental monitoring for the physically secure locations CJI demands.
System & Communications Protection (SC)
Next-gen firewalls, VPN/IPSec appliances, TLS inspection and segmentation switching, plus FIPS 140-3 / FIPS 197 cryptographic modules for CJI encrypted at rest (SC-28) and in transit (SC-8).
System & Information Integrity (SI)
Endpoint detection and response sensors, intrusion detection and malware protection — including the non-signature detection the policy notes may use AI techniques.
Supply Chain Risk Management (SR)
TAA (FAR 52.225-5) and NDAA §889 screening and authorized-distribution provenance on every line — the country-of-origin and covered-manufacturer diligence behind supply-chain risk work.
Mobile Devices (Area 20)
Managed mobile devices, mobile device management, encrypted mobile storage and mobile multi-factor hardware for CJI reached from the field.
The policy areas we don't sell — and won't pretend to
Several CJIS policy areas are governance, process and people. No vendor can supply them. We support them only through clean procurement mechanics — the CJIS Security Addendum discipline any contractor touching in-scope systems signs, and documentation your program can file.
- Information Exchange Agreements (Area 1) — the agreements between your agency and its partners are yours to author
- Awareness & Training (AT) — your security-awareness program, run by your agency
- Assessment, Authorization & Monitoring (CA) — your assessment and authorization, though we supply the scanning and monitoring sensors it uses
- Incident Response (IR) — your IR plan and reporting; we supply only the forensic-capture and out-of-band hardware behind it
- Planning (PL) & Risk Assessment (RA) — your system security plan and risk decisions
- Personnel Security (PS) — background screening of your people and any contractor with CJI access
A local-AI reference architecture, described generically
Every build is scoped to your CSO's requirements — but the shape is consistent: keep the model, the data and the people who query it inside one controlled boundary, with each tier mapped to the controls it serves.
Compute tier
GPU-accelerated servers sized for on-premises inference (and fine-tuning where warranted), so prompts and CJI never leave your environment for an outside model.
Storage tier
Segmented, FIPS-validated encrypted storage for models, embeddings and the CJI they draw on — isolated from general-purpose storage and sized for retention.
Network tier
Zero-trust segmentation, boundary firewalls and encrypted east-west paths so the inference environment is an isolated enclave, not a flat extension of the LAN.
Identity & access tier
Phishing-resistant multi-factor authentication and role-based access in front of the model, so only screened, authorized users reach it — and every query is attributable.
Audit & logging tier
Log-aggregation and immutable audit storage capturing who queried what, for the accountability the policy expects around CJI.
Resilience tier
Redundant power, backup and alternate-site capacity so an evidence-critical AI service degrades gracefully instead of going dark.
Body-worn, in-car and CCTV video is the storage problem underneath it all
Public-safety agencies generate more high-resolution video every year — body-worn cameras, in-car systems, interview rooms and fixed CCTV — and each file is evidence with retention schedules measured in years, not weeks. The same AI that makes that footage searchable multiplies the read and compute load against it.
We size the storage tier for that reality: high-density primary storage for active cases, tiered and immutable archive for long-retention evidence, and the encryption and access controls that keep every frame inside the policy's boundary. Capacity is scoped to your retention schedule and camera count, not a generic template.
- High-density primary storage for active-case and pre-trial evidence
- Tiered, immutable archive sized to multi-year retention schedules
- Encryption at rest and access logging on evidence stores
- Capacity scoped to your camera fleet and AI workload, not a template

Procurement built for justice-agency budgets
- Open-market POs or the cooperative or contract vehicle your program already holds
- GPC / P-Card accepted up to threshold; no payment up front on quoted orders
- TAA (FAR 52.225-5) and NDAA §889 screening documented per line item
- FIPS 140-3 / FIPS 197 validated encryption options where CJI at rest requires them
- System & Services Acquisition (SA) support — sourcing, market research and brand-name-or-equal justification
- One accountable partner across compute, storage, networking and physical security
Deployment and chain of custody — as procurement support, not CJI access
Hardware bound for a CJI environment can be racked, imaged and hardened to your baseline at a US-based integration facility before it ships, so installation is a controlled swap rather than a build on a live justice system. Staging touches the equipment, never your criminal justice information — that stays inside your boundary, under your CSO's control, at all times.
Every unit ships with chain-of-custody and asset-tagging documentation from receipt through delivery, so the provenance of the gear entering your secure space is on the record. Where your agency requires the CJIS Security Addendum and personnel screening of any contractor with physical or logical access, we structure the engagement so that discipline is straightforward — the agency and its CSO remain the approval authority for who and what touches CJI.
This is deliberately a procurement and logistics service, not a data service. We supply and document the infrastructure; your agency operates it, authorizes access to it, and owns the compliance posture around the information it holds.
CJIS infrastructure questions
Can Uniqcli make our systems CJIS compliant?
No vendor can. Under the CJIS Security Policy your CJIS Systems Agency and its CJIS Systems Officer hold ultimate, non-outsourceable responsibility for CJIS security in your state or agency. What we do is source and integration-test the infrastructure your team deploys to meet the policy's technical controls — the encryption, compute, storage, networking and physical-security hardware — TAA- and §889-screened, so the equipment side of your environment clears procurement cleanly.
Does the CJIS policy require AI to run on-premises?
The policy names no AI-specific rule; it simply governs anything that touches CJI with its general controls, and SC-28 limits where CJI at rest may be stored. A cloud AI service triggers the policy's remote-access, physically-secure-datacenter, encryption, breach-notification, Security-Addendum and audit-rights evaluations. Running inference on-premises keeps CJI inside a boundary you already control and out of that scope — which is why many agencies choose it. We supply the local GPU compute and storage that makes it practical.
How do you handle encryption for CJI at rest and in transit?
We source FIPS 140-3 certified cryptographic modules (or FIPS 197 with a 256-bit key) for CJI stored outside a physically secure location, as SC-28 requires, and the TLS/IPSec-capable network hardware behind SC-8's transmission-confidentiality controls. The validated-crypto selection is documented with the quote.
Do you sign the CJIS Security Addendum or access our CJI?
Our role is to supply and stage hardware, not to access criminal justice information — CJI stays inside your boundary under your CSO's authority. Where your agency requires the Security Addendum and personnel screening for any contractor with physical or logical access to in-scope systems, we structure the engagement to meet that requirement; the agency remains the approval authority.
Can hardware be staged before it reaches a live justice system?
Yes. Racking, imaging and hardening to your baseline happen at a US-based integration facility before delivery, with chain-of-custody and asset-tagging documentation, so installation on an operational system is a controlled swap rather than a build.
What payment methods do you accept?
GPC / P-Card up to your threshold and standard net-terms purchase orders. We confirm stock and final total before any payment moves, and quote against the open market or the contract vehicle your program already holds.
Procurement
Procure like a prime.
FIPS-validated, TAA-screened hardware, integration-tested and staged — one accountable partner from bill of materials to a CJIS environment your agency controls.
The solutions atlas
Every solution, one accountable partner.
UniQ platforms
By technology
By customer
- TAA & NDAA-889 Compliance Screening
- CMMC & CUI Solutions
- Federal & DoD
- State, Local & Education
- Healthcare
- Enterprise
- Rapid Procurement & GPC Buys
- Multi-Vendor Integration Projects
- eProcurement & Custom Catalogs
- FISMA Modernization
- CJIS-Compliant Justice Cloud & Local AIThis page
- Federal Storage Modernization
- Government ERP & Business Systems Infrastructure
- Managed Procurement
- Secure AV & Conferencing
- Fiber Network Infrastructure
- Satellite & Resilient Connectivity
- Wavelength & Optical Transport
- Decentralized Data Centers
- Data Center Design & Build
Talk to us about your CJIS justice cloud
Send your CSO's requirements or a target architecture and we'll return a bill of materials mapped to the CJIS control families — TAA- and §889-screened, with FIPS-validated encryption options and lead times.