General operational and educational information for corrections professionals. Not legal, medical, or compliance advice, and not a certification of compliance with any law or standard. Policies and standards vary by agency and jurisdiction; follow your facility's policy and your own legal, medical, and professional advisors.
Criminal justice information policy is applied by your state control agency and your local agency, not by a vendor. Virtual Patrol does not certify any agency as compliant and cannot. What this page does is lay out the questions a county should work through with its security reviewer before a monitoring layer touches correctional infrastructure.
The CJIS Security Policy is issued federally and administered through state control agencies, which set local implementation, run audits, and make determinations for agencies in their state. A vendor can describe its own architecture and controls. A vendor cannot determine whether your agency's deployment satisfies your state's requirements.
This distinction matters commercially because the category is full of loose claims. Treat any vendor statement that a product is compliant, certified, or approved as a claim requiring evidence about what specifically was assessed, by whom, and against which version of the policy.
The practical consequence for a county is that the deployment question is a local security review question, and it should run through the same process any other system touching agency infrastructure would.
Does the data in question fall within the scope your state control agency applies? Correctional video is not automatically criminal justice information, and the answer depends on the data, the systems it touches, and your state's interpretation. Ask rather than assume.
What networks does the system touch, and is the camera estate segmented from systems that are clearly in scope?
Does any data leave the facility, and if so what classes, to where, and under what protection?
Who has access, how is access granted and revoked, and does authentication meet your agency's requirements?
Is personnel screening required for anyone with access, including vendor personnel, and what is the process for that?
Architecture and data flow documentation, at a level your security reviewer can actually evaluate.
Authentication and session handling, and whether it integrates with your identity provider.
Logging: what is logged, where logs live, how long they are retained, and whether export actions are captured.
Patch and update responsibility, cadence, and notification, including whether an update can alter behavior the agency relies on.
Incident response commitments: notification timeline, contact, and vendor obligations during an investigation.
Physical security requirements for any on-premises equipment, and the offboarding process at end of contract including data return and deletion.
Virtual Patrol supports documentation, discipline, review, and proof. It does not make any agency compliant with the CJIS Security Policy or any other standard, and it does not certify compliance.
The design intent is to work with existing camera infrastructure and to add a review and record layer, with a person reviewing every raised event before action and no facial recognition in use.
Specific deployment architecture, hosting, and control details should be provided in writing for your security reviewer and evaluated against your state control agency's requirements. Ask for that documentation early rather than at contract signature.
Determinations belong to your state control agency and your local security authority. This page is general information, not compliance advice.
Not automatically. Whether it falls in scope depends on the data, the systems involved, and your state control agency's interpretation. Ask them rather than relying on a general answer.
There is no general vendor certification that substitutes for an agency determination. Be cautious with any claim framed that way and ask what specifically was assessed and by whom.
Whoever runs your normal security review for systems touching agency infrastructure, working with your state control agency contact and your terminal agency coordinator.
Export logging and offboarding. Agencies define view access carefully and then leave export rights and departed-user removal undefined.
It depends on the deployment design. Settle segmentation, firewall requirements, and whether processing is local before anything is connected, and get it in writing.
No. It is not used, which removes a set of consent and civil rights questions that would otherwise belong in this review.