Your agency's information stays separate
Users can only see information for agencies they belong to. DutySuite checks this rule in both the application and the database.
Security explained clearly
DutySuite keeps each agency's information separate, checks who is allowed to see or change it, protects private files, and records important activity for later review.
How you are protected
These protections are either included with DutySuite or can be turned on based on your agency's needs.
Users can only see information for agencies they belong to. DutySuite checks this rule in both the application and the database.
Before showing or changing protected information, DutySuite checks the user's agency, job responsibilities, and allowed actions.
Agencies can require an extra sign-in step using an authenticator app. This helps protect accounts even if a password is stolen.
DutySuite signs users out after set periods of inactivity. Administrators have shorter limits because their accounts have more access.
Operational attachments are not publicly available. A user must be signed in and have the right agency access to open them.
Public forms and shared links are limited to one job. DutySuite checks submissions and slows or challenges repeated attempts.
What belongs in DutySuite
Clear rules help users know what they may enter and prevent sensitive criminal justice information from ending up in the wrong system.
Agency settings, staff profiles, job responsibilities, and user access
Extra-duty jobs, assignments, employers, invoices, and payments
Training, policy, fleet, subpoena, and other administrative records
Agency messages, approved attachments, and important activity history
Criminal Justice Information (CJI), including NCIC, FCIC, Nlets, or criminal-history results
Incident or dispatch records copied from RMS or CAD systems
Criminal case details about suspects, victims, witnesses, defendants, or offenders
Evidence, body-camera files, evidence photos, or criminal case files
Behind the scenes
DutySuite checks who a person is, which agency they belong to, and what their job allows them to do.
A sign-in is required
Agency membership is checked
Access is based on job responsibilities
Extra sign-in protection can be required
Inactive users are signed out
Agency separation is built into the system behind the screen. It does not depend only on hiding buttons or pages from view.
Records are tied to one agency
The database checks agency access
Important actions are checked again
Powerful system access stays behind the scenes
Operational files are stored privately
An employer or other outside user receives only the access needed for a specific form, portal, invoice, or agreement.
Links are created for one purpose
Submitted information is checked
Repeated attempts are slowed or blocked
Bot checks are used where needed
Important link activity is recorded safely
DutySuite keeps useful history so authorized staff can review important sign-ins, changes, approvals, and system activity.
Successful and failed sign-ins
Blocked actions and shared-link use
Changes to users, jobs, invoices, and agreements
Email delivery and scheduled tasks
Browser protections against common attacks
Before your agency decides
Some protections are already included. Other details should be decided with your agency before launch.
See who helps us provide DutySuiteDutySuite runs on established cloud services. Vercel hosts the application, Supabase handles sign-in and data storage, Resend sends system emails, and Cloudflare helps stop automated abuse.
DutySuite is built for administrative and workforce records. It is not a criminal records, dispatch, criminal-history, or evidence system.
DutySuite uses secure web connections when information moves between a user's browser and the service. During an agency review, we can also explain how stored information is protected.
Different agencies follow different records rules. Before launch, we document how long information should be kept, when it can be deleted, and what files users may upload.
Before launch, we confirm who should be contacted, how an agency will be notified, and what the agency expects if service or information must be restored.
DutySuite will share current security details during an agency review. We do not claim a certification or broad compliance approval that has not been independently completed.
Questions agencies ask
No. DutySuite does not currently claim CJIS compliance. It is built for administrative and workforce information, not Criminal Justice Information (CJI). Users should not enter the prohibited information listed above.
Yes. Your agency can require users to enter a changing code from an authenticator app after entering their password. This is often called multi-factor authentication, or MFA.
Authorized staff can review important activity involving sign-ins, users, jobs, invoices, agreements, public links, email delivery, and scheduled tasks. The exact history depends on the part of DutySuite being used.
We can explain where DutySuite runs, what information belongs in it, who can access it, how public links work, and which decisions should be made before launch.
Talk with us
Bring anyone responsible for technology, contracts, records, or agency leadership. We'll explain what is included, what your agency can choose, and what should be decided before launch.
Questions? Email info@dutysuite.com.