Data Security & Evidentiary Integrity

Exhibit In-Sight is engineered specifically to withstand the rigors of the Canadian judicial system. We recognize that evidentiary continuity, jurisdictional data sovereignty, and endpoint security are vital to public safety and criminal prosecutions.

1. Zero-Cloud Evidence Model & Data Sovereignty

In-Situ Software Solutions Inc. operates under a strict Zero-Cloud Evidence Rule. We maintain zero custody, zero access, and zero cloud backups of your operational data:

  • 100% Local Case Custody: All evidentiary case files (.eis containers), crime scene imagery, search warrant pages, officer notes, and continuity logs are processed and stored exclusively on your agency’s authorized physical endpoints.

  • No Cloud Exposure: Evidentiary case data is never uploaded, analyzed, or routed through external cloud infrastructure or AI models.

  • Sovereign Canadian Infrastructure (FOIPPA Compliant): Administrative billing metadata (agency contact details and license keys) is hosted in Google Cloud’s Toronto, Ontario region (northamerica-northeast2), ensuring full compliance with provincial and federal privacy frameworks, including the BC Freedom of Information and Protection of Privacy Act (FOIPPA).

2. Cryptographic Evidentiary Integrity (Canada Evidence Act s. 31.3)

To satisfy the presumption of electronic records integrity under Section 31.3 of the Canada Evidence Act, Exhibit In-Sight implements court-validated cryptographic controls:

  • SHA-256 Hash-Chained Audit Ledger: Every operational action—exhibit entry, field modification, photo attachment, continuity transfer, and user login—is written to an immutable, internal SHA-256 hash chain linked back to a root genesis block. Any retroactive file tampering breaks the mathematical chain and is immediately flagged upon opening.

  • Append-Only Version Control (R. v. Stinchcombe): Active case records cannot be overwritten. Corrections spawn incremental revision snapshots (v1 -> v2) archived in isolated disclosure annexes alongside automated field diffs. Deletions require mandatory, non-blank justifications preserved permanently for Crown disclosure.

  • Monotonic Clock Anchoring & Anti-Rollback Auditing: The mobile application locks to hardware monotonic clock ticks (SystemClock.elapsedRealtime()) to prevent manual clock drift or tampering. Active MDT sessions query Windows authoritative time synchronization sources (w32tm /query /source), continually auditing and recording device time alignment.

3. Encryption Standards & Endpoint Hardening

In Transit (Field Hotspots & Cruiser Subnets)

  • Dual-Layer Transport Security: Field synchronization between mobile devices and MDTs does not rely solely on Wi-Fi network passwords. Communications are encapsulated within an embedded TLS 1.3 transport layer utilizing ephemeral 2048-bit RSA keys and AES-256-GCM encryption over TCP Port 51038.

  • Strict SHA-256 Certificate Pinning: The mobile application enforces cryptographic certificate pinning against the exact SHA-256 fingerprint embedded within the pairing QR code, rendering mobile connections immune to local Man-in-the-Middle (MitM) attacks or rogue access points.

  • Zero-Data UDP Discovery: Workstation discovery over UDP Port 51039 broadcasts only ephemeral connection metadata (port, computer name, and public TLS certificate hash). Zero case facts, exhibit descriptions, or personnel details are ever exposed over UDP.

At Rest (Endpoints & Cloud)

  • Operating-System Level Storage Security: Case archives (.eis) rely on enterprise-grade Full Disk Encryption (e.g., Windows BitLocker and Android File-Based Encryption).

  • Windows DPAPI Credential Protection: Officer profiles and salted PIN credentials stored on desktop MDTs are encrypted at rest using the Windows Data Protection API (DPAPI) before being written to the registry.

  • Mandatory Mobile Screen Lock Verification: Exhibit In-Sight Mobile interfaces directly with Android’s KeyguardManager. If an endpoint does not have an active, secure lock screen (PIN, Pattern, Password, or Biometric), the application blocks access to protect evidence from unauthorized physical extraction.

4. Enterprise Financial & Procurement Security

In-Situ Software Solutions Inc. does not store, process, or transmit credit card details. All billing transactions, tier calculations, and automated tax calculations (GST/HST/PST) are processed through Stripe, certified under PCI-DSS Level 1 Service Provider standards.

IT Implementation & Whitelist Guide