JuratJURAT

Security & Compliance

Isolated per agency — hosted in Jurat Cloud.

Jurat is not multi-tenant SaaS. Jurat Cloud runs your deployment in Ultrafar's own Azure Government subscription, isolated per agency — no shared runtime, database, or storage with any other agency. Officers keep their own Microsoft Entra identity; only the infrastructure moves.

Hosting

We run it for you.

Jurat Cloud

Ultrafar hosts it in Azure Government on your subdomain. You do not need your own Azure Government tenant or DevOps shop. Officers still sign in through your Entra tenant. Guest accounts the agency invites into that same tenant — including prosecutor reviewers — sign in the same way. They get the reviewer role the agency assigns. Those seats are not billed separately. Compliance approvals for a hosted deployment are worked during onboarding, not before.

$95 / OFFICER / YEAR

Reference

CJIS Security Policy section matrix

This is a working reference for your CSO or TAC. It is not a substitute for your security addendum or a formal audit.

FBI CJIS SECURITY POLICY, VERSION 6.1
CJIS §5.4
Auditing & Accountability
Auditable records of system access and CJI-affecting actions.
Opens, creates, signatures, revocations, and downloads write to an append-only audit log enforced by a database trigger. Actor, timestamp, and IP are captured then.
CJIS §5.5
Access Control
Role-based access, least privilege, and session enforcement.
Role-scoped officer / admin / records permissions. Admin idle timeout is independent of the browser session.
CJIS §5.6
Identification & Authentication
Unique identification and advanced authentication for CJI access.
Sign-in through the agency's own Entra ID. No separate Jurat password store. No shared logins.
CJIS §5.9
Physical & Environmental Protection
Physical safeguards for systems that store or process CJI.
U.S. Microsoft Azure data centers — commercial or Azure Government, depending on the model. No on-prem or vendor-office gear in the data path.
CJIS §5.10
System & Communications Protection
Encryption in transit and at rest; boundary protection.
Modern TLS, negotiating the strongest protocol either side supports. Data encrypted in transit and at rest, meeting FIPS 140-2 validated cryptography. Per-request CSP nonce, HSTS, and strict headers on every response.
CJIS §5.13
Mobile Devices
Controls for CJI accessed from mobile/portable devices.
No native app and no local CJI stored on the device. Sessions run in the browser against a scoped, expiring link or an authenticated session.

Connections use modern TLS. The platform negotiates the strongest protocol either side supports, so most devices land on the latest version automatically. A minimum floor is configured rather than a single fixed version, so an agency laptop on an older browser isn't locked out entirely.