Bridge4PS is a secure collaboration platform designed for public safety information sharing and
operational coordination. Unlike criminal justice information systems and databases, Bridge4PS does
not directly query Criminal Justice Information (CJI) repositories or serve as a system of record for
criminal justice data.
Bridge4PS has consulted directly with the FBI CJIS Office regarding the applicability of the CJIS
Security Policy to our platform. Based on guidance received during those discussions, because
Bridge4PS does not directly query CJI repositories or function as a criminal justice database, it may
not be subject to the CJIS Security Policy in the same manner as systems that directly access, query, or
maintain CJI databases. However, the applicability and interpretation of CJIS requirements ultimately
rests with each state’s CJIS Systems Agency (CSA), CJIS Security Officer (CSO), and applicable agency
policies.
Bridge4PS was architected and implemented to the FedRAMP Moderate security baseline as part of a
U.S. Department of Homeland Security-funded effort. As a result, Bridge4PS meets the FedRAMP
Moderate security requirements and incorporates comprehensive security, auditing, access control,
encryption, monitoring, retention, and governance controls. Where CJIS requirements exceed the
FedRAMP Moderate baseline, Bridge4PS has implemented the higher standard where technically and
operationally feasible. Based on our review of the CJIS Security Policy and discussions with the FBI
CJIS Office, the requirements that do not directly align between Bridge4PS and the policy are
automatic session timeout, CJIS Security Addenda, and interagency information-sharing agreement
requirements.
Bridge4PS does not implement automatic session timeout because doing so would prevent users
from receiving real-time notifications and significantly impair the operational effectiveness of a
real-time collaboration platform. The applicability of CJIS Security Addenda is determined by the
applicable CJIS authority and may vary by state and use case. Some jurisdictions may also require
information-sharing agreements governing the exchange of Criminal Justice Information between
participating agencies. Such agreements are generally established between the agencies themselves
and are independent of Bridge4PS, although administering these requirements across large-scale,
multi-agency interoperability environments may present practical challenges.
Agencies evaluating vendor claims of CJIS compliance should understand how those claims address
these and other applicable requirements. Agencies remain responsible for determining the
appropriate use of Bridge4PS for the transmission, storage, retention, and management of Criminal
Justice Information in accordance with their state’s policies and procedures.
Organizations seeking clarification regarding the applicability of the CJIS Security Policy are
encouraged to consult their state’s CJIS Systems Agency or contact the FBI CJIS Information Security
Officer Program Office at iso@fbi.gov.
Please contact us through our help center at https://help.bridge4ps.com or email
support@bridge4ps.app if you have any questions.