Security and record integrity

Understand the controls.
Review the requirements.

Sensitive records deserve a careful evaluation. Review how 4tress handles record integrity, access, and optional AI-assisted triage before deployment.

Controls implemented in the application

Hash-linked event history

Grievance events are linked using hashes. Exports include verification results to help identify inconsistencies in the recorded sequence. This is an integrity check, not independent proof of the underlying events.

Restricted PREA access

Sexual-abuse grievance views and exports are restricted to designated reviewers and administrators. Facilities must configure reviewer assignments and administrative access appropriately.

Facility and staff access

Staff review tools use role and facility settings. Confirm each user’s permissions and the deployment’s configuration during evaluation.

Optional AI triage

AI-assisted classification can be disabled at deployment. Review data sent to any AI service, provider arrangements, and staff review procedures before enabling it.

Review before using live records

  • Hosting arrangements, encryption configuration, and service providers.
  • Staff permissions, sensitive-record access, and account administration.
  • Retention, ownership, exports, backup and recovery, and incident response.
  • Applicable county procurement and security requirements.
  • Whether AI processing is appropriate for the proposed data and workflow.

Assurance status

This page does not represent a completed SOC 2 examination or a determination that a deployment meets CJIS requirements. Request current documentation and review requirements with your county’s IT and security teams.

For general data practices, read the privacy policy. Facility-specific access and data handling should be established in the deployment agreement.