How it works
How secure is it, and who controls the data?
The tribe controls the data end to end. Records are encrypted on your own hardware, access is set by role, the AI makes no external calls, and every record proves itself. Security here is not a promise on paper; it is how the software is built.
Encrypted, role-based, air-gap capable · you hold the keys
Storage is encrypted, access follows the job, and sensitive actions need a sign-off. Only you hold the keys.
The seals and the encryption use cryptography built to last, and the whole record can be verified end to end.
Because nothing runs in an outside cloud, there is no external service to breach and no outside party in the data.
Security by structure, not by promise
Most security claims are commitments about behavior: we will not look at your data, we will not sell it, we will guard it carefully. Those commitments may be sincere, and they are still promises, which means they can be broken, compelled, or sold with the company.
The stronger claim is structural. A company that never holds your records cannot be compelled to produce them. A system with no path to an outside network cannot leak through one. A record that proves itself does not require anyone's honesty to be trustworthy.
That is the design principle here: wherever a promise could be replaced with a structure, replace it.
| The usual promise | The structure that replaces it |
|---|---|
| We will not look at your data | We never hold your data. It sits on your hardware, under your keys. |
| Our AI will not send your information anywhere | The model runs on your machine, and outbound calls are refused by default. It can run with no network path at all. |
| Our staff are carefully vetted | There is no vendor console with standing access to your records, so there is no privileged outsider to vet. |
| We keep a thorough audit log | Every action is sealed into a chain that you can verify yourself, offline, with a tool that is not ours. |
| We will delete your data if you ask | The records are files on your hardware. You do not have to ask. |
Each row replaces something you would otherwise have to take on trust.
The layers, from the outside in
- Nothing runs in an outside cloud. There is no external service to breach, and no account to take over.
- The AI is denied outbound calls by default, and can be run with no route to any outside network.
- Storage is locked on hardware you hold, with an encrypted backup you keep off site.
- Anything that leaves the building leaves encrypted, using cryptography built to hold up against future machines.
- Access starts at nothing and is granted for a job, a scope, and a period. A matter outside your scope does not appear at all.
- Sensitive actions need a person's sign-off, and every approval is itself a sealed record.
- Every action is sealed and chained, so tampering leaves a mark and the mark names the record.
- A kill switch stops the system and cannot be turned off by anyone.
The rules that apply to tribal records
Where a tribal justice system handles criminal justice information, the FBI's CJIS Security Policy governs how that information is stored, moved, and reached. Its current version maps onto the federal government's standard control framework and phases requirements in over several years, including a move to a newer validated-encryption standard as the older one is retired.
Grant terms add their own obligations on top, and records retention rules set how long the history has to survive. All of these are easier to satisfy when the records sit inside your own physically secure location, on machines you administer, with a complete and provable history you can produce on request.
Above the federal floor sits the tribe's own authority. Indigenous data sovereignty is the right of a people to govern the collection, ownership, and use of their own data, and it stands against the default principle that data is subject to the laws of wherever it happens to be stored. Keeping the records in the building is how that right stops being an argument and becomes a fact.
Security, from each seat
Tribal IT
A surface small enough to actually defend.
No cloud tenancy, no outside administrators, no standing external access, default-deny on both network egress and record access, and an audit trail you can verify without us.
Council
Sovereignty you can operate.
The tribe decides who sees what, keeps every version of every act, and can prove any decision it made, on hardware it owns and under its own law.
Staff
The system protects the person doing the work.
Nobody can act in your name, nothing you did can be quietly altered, and an honest mistake is visible and correctable rather than a liability you carry alone.
Questions IT and council ask about security
- Do you hold any of our data?
- No. The records live on your hardware. There is no vendor-side copy, which is also why there is nothing on our end to breach, subpoena, or sell.
- Are you certified against a security standard?
- The cryptography used is the kind specified by federal standards, and the system is built to satisfy the controls that tribal justice records attract. We will tell you plainly which certifications exist and which do not, rather than implying a certificate the product has not earned.
- What is your worst weakness?
- The same one every honest on-premises answer has: it depends on your government actually running its own machines and keeping its own backups. We stand it up with your IT and rehearse recovery with you, because that is where the real risk lives.
Sources
- CJIS Security Policy, Version 6.0 (December 27, 2024) · Federal Bureau of Investigation. le.fbi.gov
- FIPS 140-3, Security Requirements for Cryptographic Modules · National Institute of Standards and Technology. csrc.nist.gov
- About Indigenous data sovereignty · US Indigenous Data Sovereignty Network. usindigenousdatanetwork.org
- Event
- Record edited
- By
- the clerk
- When
- 2026-07-12 · 09:31
- Chain
- seq 042 to 043
Every change is signed and saved for good. If someone edits a record, it shows exactly who did it and when.