Trust & Compliance
Security & data handling
Summary for fire chiefs, fire marshals, municipal IT security directors, and city privacy officers in the United States and Canada. Detailed runbooks, questionnaire banks, and our signable Pilot Data Processing Addendum live in our trust pack on request.
Authentication & identity
- Pilot / production today: Amazon Cognito user pools — email/password sign-in, MFA-capable, short-lived JWT sessions on HTTPS-only cookies. Each user belongs to exactly one department tenant; roles control admin, author, and inspector access.
- Single Sign-On / SAML: Supported on the municipal roadmap via Cognito SAML 2.0 / OIDC federation to city IdPs (Azure AD / Entra ID, Okta, ADFS, Google Workspace). Pilots ship without waiting on SSO; production departments that require directory login can enable federation during enterprise onboarding without changing inspection workflows.
- Team identity: Inspectors and signees use tenant membership display names (not raw email addresses) on assignments and close-out signatures.
Backups & continuity
- Database: Automated Aurora Postgres snapshots with point-in-time recovery (PITR) up to 35 days; backup storage encrypted.
- Files: Inspection photos and PDFs in S3 with server-side encryption; versioning and lifecycle controls per environment policy.
- Restore: Documented backup/restore runbook for ops; demo sandbox is ephemeral and is not the production backup boundary.
IT director FAQ (pilot sign-off)
- Does it support SSO / SAML?
- Yes for production departments that require it — Cognito federation to the city IdP. Current pilots use Cognito email accounts with MFA available so field work can start without waiting on IdP tickets.
- How often is data backed up?
- Continuous/automated Aurora backups with up to 35 days of point-in-time recovery; object storage is encrypted at rest. Ask for the trust pack restore runbook if your city needs RTO/RPO numbers in writing.
- Where does our data live?
- Default production in AWS us-east-1. Canadian in-country residency (
ca-central-1) available for enterprise contracts. - Is this CJIS / HIPAA / FedRAMP?
- Civil fire prevention only — no CJI, CAD police records, or PHI. Not FedRAMP authorized; hosted on commercial AWS. Full demarcation is in the trust pack.
Environments & Hosting
- Production (US Primary) — Amazon Cognito identity, Aurora Postgres database, and S3 encrypted object storage in AWS US (us-east-1). Customer operational tenant data lives strictly here.
- Canadian Data Residency Option — Enterprise dedicated tenant deployment in AWS Canada Central (
ca-central-1Montreal) is available upon request for Canadian public safety agencies requiring in-country storage. - Demo Sandbox — Public try-before-buy environment with demo auth and embedded database. Strictly isolated; not a certified production boundary.
Multi-Tenancy & Isolation
Every database query is scoped by verified organization ID from the authenticated session. Roles are admin, author, and inspector. Platform operator actions are segregated from customer tenants, and cross-tenant access is continuously verified by automated isolation tests in CI.
Encryption & Secrets
- TLS 1.2+ mandatory in transit across all endpoints with HSTS enforcement
- Aurora Postgres and S3 storage encrypted at rest using AES-256
- Secrets managed in AWS Secrets Manager / SSM Parameter Store — never in git or client bundles
- Sanitized logging with zero credentials, tokens, or raw personal identifiers in log streams
US Public Sector Compliance
- CJIS Boundary: FireVantage handles civil fire safety, life safety checklist items, permits, and building pre-plans. It does not ingest or interface with Criminal Justice Information (CJI) or CAD police records, operating outside the CJIS compliance boundary.
- HIPAA Demarcation: Fire inspections and pre-plans do not contain Protected Health Information (PHI) or emergency medical run data (ePCR).
- Public Records / FOIA: Fire departments can instantly export complete JSON data archives and generate tamper-evident PDF inspection certificates to satisfy state public records (Sunshine Law) requests.
Canadian Privacy Compliance
- PIPEDA Alignment: Operates in accordance with the 10 Fair Information Principles (Accountability, Limiting Collection, Safeguards, Openness, and Individual Access).
- Provincial Public Sector Acts: Supports municipal fire services under BC FIPPA (Bill 22 cloud transfer requirements), Ontario MFIPPA, Alberta FOIP, and Quebec Law 25 with documented Privacy Impact Assessment (PIA) safeguards.
- Breach Notification: Incident response runbook mandates immediate customer notification and cooperation under the statutory “Real Risk of Significant Harm” (RROSH) standard.
AI Safety & Governance
- Optional vision assist and Cody assistant use OpenAI enterprise API endpoints
- No Training on Customer Content: Municipal photos and inspection notes are strictly never used to train third-party foundation models under our enterprise terms
- Human in the Loop: AI suggestions are advisory drafts; sworn fire prevention inspectors retain sole legal authority for citations and sign-offs
- Complete tenant-level opt-out available for agencies prohibiting generative AI tools
What We Do Not Claim
- FedRAMP authorization (standard commercial AWS cloud)
- CJIS certification (civil fire safety only; police/CAD data out of scope)
- SOC 2 / ISO 27001 attestation today — on our active certification roadmap
- Live NERIS national incident reporting bureau submit (field presets provided)
Need the complete trust pack?
We provide our Pilot Data Processing Addendum (with US Municipal and Canadian Privacy Schedules), subprocessors list, retention schedule, incident response runbook, and municipal security questionnaire answers during pilot onboarding.
© 2026 Crucible Labs Ltd. FireVantage™