Security explained clearly

Your agency's work stays protected and under control.

DutySuite keeps each agency's information separate, checks who is allowed to see or change it, protects private files, and records important activity for later review.

How you are protected

Straightforward safeguards for everyday agency work.

These protections are either included with DutySuite or can be turned on based on your agency's needs.

Included

Your agency's information stays separate

Users can only see information for agencies they belong to. DutySuite checks this rule in both the application and the database.

Included

Access is checked every time

Before showing or changing protected information, DutySuite checks the user's agency, job responsibilities, and allowed actions.

Your agency chooses

Extra sign-in protection

Agencies can require an extra sign-in step using an authenticator app. This helps protect accounts even if a password is stolen.

Included

Automatic sign-outs

DutySuite signs users out after set periods of inactivity. Administrators have shorter limits because their accounts have more access.

Included

Files are kept private

Operational attachments are not publicly available. A user must be signed in and have the right agency access to open them.

Included

Safer public forms and links

Public forms and shared links are limited to one job. DutySuite checks submissions and slows or challenges repeated attempts.

What belongs in DutySuite

Use DutySuite for agency administration—not criminal case data.

Clear rules help users know what they may enter and prevent sensitive criminal justice information from ending up in the wrong system.

Information that belongs here

Agency settings, staff profiles, job responsibilities, and user access

Extra-duty jobs, assignments, employers, invoices, and payments

Training, policy, fleet, subpoena, and other administrative records

Agency messages, approved attachments, and important activity history

Information that does not belong here

Criminal Justice Information (CJI), including NCIC, FCIC, Nlets, or criminal-history results

Incident or dispatch records copied from RMS or CAD systems

Criminal case details about suspects, victims, witnesses, defendants, or offenders

Evidence, body-camera files, evidence photos, or criminal case files

Behind the scenes

What DutySuite does to keep information safer.

Signing in and controlling access

DutySuite checks who a person is, which agency they belong to, and what their job allows them to do.

A sign-in is required

Agency membership is checked

Access is based on job responsibilities

Extra sign-in protection can be required

Inactive users are signed out

Keeping agency information separate

Agency separation is built into the system behind the screen. It does not depend only on hiding buttons or pages from view.

Records are tied to one agency

The database checks agency access

Important actions are checked again

Powerful system access stays behind the scenes

Operational files are stored privately

Protecting public forms and shared links

An employer or other outside user receives only the access needed for a specific form, portal, invoice, or agreement.

Links are created for one purpose

Submitted information is checked

Repeated attempts are slowed or blocked

Bot checks are used where needed

Important link activity is recorded safely

Keeping a useful activity history

DutySuite keeps useful history so authorized staff can review important sign-ins, changes, approvals, and system activity.

Successful and failed sign-ins

Blocked actions and shared-link use

Changes to users, jobs, invoices, and agreements

Email delivery and scheduled tasks

Browser protections against common attacks

Before your agency decides

Clear answers to common security questions.

Some protections are already included. Other details should be decided with your agency before launch.

See who helps us provide DutySuite

Who runs the technology?

In place

DutySuite runs on established cloud services. Vercel hosts the application, Supabase handles sign-in and data storage, Resend sends system emails, and Cloudflare helps stop automated abuse.

What information belongs here?

Clear rule

DutySuite is built for administrative and workforce records. It is not a criminal records, dispatch, criminal-history, or evidence system.

How is information protected?

We can explain

DutySuite uses secure web connections when information moves between a user's browser and the service. During an agency review, we can also explain how stored information is protected.

How long is information kept?

Decided together

Different agencies follow different records rules. Before launch, we document how long information should be kept, when it can be deleted, and what files users may upload.

What if something goes wrong?

Before launch

Before launch, we confirm who should be contacted, how an agency will be notified, and what the agency expects if service or information must be restored.

Does DutySuite have certifications?

No unsupported claims

DutySuite will share current security details during an agency review. We do not claim a certification or broad compliance approval that has not been independently completed.

Questions agencies ask

The short answers, without the technical language.

Does DutySuite claim to meet CJIS requirements?

No. DutySuite does not currently claim CJIS compliance. It is built for administrative and workforce information, not Criminal Justice Information (CJI). Users should not enter the prohibited information listed above.

Can we require an extra sign-in step?

Yes. Your agency can require users to enter a changing code from an authenticator app after entering their password. This is often called multi-factor authentication, or MFA.

Can we see who did what?

Authorized staff can review important activity involving sign-ins, users, jobs, invoices, agreements, public links, email delivery, and scheduled tasks. The exact history depends on the part of DutySuite being used.

What will you explain during a security review?

We can explain where DutySuite runs, what information belongs in it, who can access it, how public links work, and which decisions should be made before launch.

Talk with us

Walk through your agency's security questions.

Bring anyone responsible for technology, contracts, records, or agency leadership. We'll explain what is included, what your agency can choose, and what should be decided before launch.

Questions? Email info@dutysuite.com.