Built for Government-Grade Security

Essential Personnel meets the security and reliability standards public sector agencies require, from infrastructure to access controls, protecting sensitive data while keeping systems easy to use and available.

Data Security

How We Protect Your Data

EP is built around isolation, least-privilege access, and continuous validation, so sensitive personnel and criminal-justice data stays protected at every layer.

All data is encrypted in transit and at rest using FIPS 140-3 validated cryptography, helping prevent unauthorized access.

<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none">   <path fill-rule="evenodd" clip-rule="evenodd" d="M4.2,2.2759c-1.3237,0-2.4,1.0762-2.4,2.4v14.4c0,1.3237,1.0762,2.4,2.4,2.4h7.545c-1.3575-1.5975-2.145-3.6562-2.145-5.835v-1.1663c0-1.29,0.825-2.4375,2.0513-2.8462l4.2-1.3987c0.1162-0.0375,0.2325-0.0675,0.3488-0.0938v-1.4663c0-0.6375-0.2512-1.2487-0.7012-1.6987l-3.9975-3.9937c-0.45-0.45-1.0575-0.7012-1.695-0.7012H4.2ZM14.0062,8.8759h-3.5063c-0.4988,0-0.9-0.4012-0.9-0.9v-3.5063l4.4062,4.4062ZM17.2987,20.5946l-0.4988,0.2362v-7.0537l3.6,1.2v0.735c0,2.0925-1.2075,3.9937-3.1012,4.8863h0v-0.0037ZM16.4212,12.0071l-4.2,1.3987c-0.4912,0.165-0.8212,0.6225-0.8212,1.14v1.1663c0,2.79,1.6125,5.3287,4.1325,6.5137l0.6937,0.3262c0.18,0.0825,0.375,0.1275,0.57,0.1275s0.3937-0.045,0.57-0.1275l0.6937-0.3262c2.5275-1.1887,4.14-3.7275,4.14-6.5175v-1.1663c0-0.5175-0.33-0.975-0.8212-1.14l-4.2-1.3987c-0.2475-0.0825-0.5137-0.0825-0.7575,0h0v0.0037Z" fill="currentColor"/> </svg>

Administrators control exactly who can view and manage each type of information, enforced through hierarchical role-based authorization.

<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none">   <path fill-rule="evenodd" clip-rule="evenodd" d="M4.1981,12.1504c0-4.3087,3.4912-7.8,7.8-7.8s4.485,1.0537,5.9175,2.7188c0.3225,0.3787,0.8925,0.42,1.2675,0.0975s0.42-0.8925,0.0975-1.2675c-1.7587-2.0513-4.3687-3.3487-7.2825-3.3487-5.3025,0-9.6,4.2975-9.6,9.6v1.5c0,0.4988,0.4012,0.9,0.9,0.9s0.9-0.4012,0.9-0.9v-1.5ZM21.3919,10.1666c-0.1013-0.4875-0.5812-0.7987-1.065-0.6937s-0.7987,0.5812-0.6937,1.065c0.1087,0.5212,0.1687,1.0613,0.1687,1.6162v1.5c0,0.4988,0.4012,0.9,0.9,0.9s0.9-0.4012,0.9-0.9v-1.5c0-0.6788-0.0712-1.3425-0.2062-1.9837h0l-0.0037-0.0037ZM11.9981,5.5504c-0.7125,0-1.4025,0.1125-2.0437,0.3225-0.57,0.1875-0.7012,0.8887-0.3113,1.3462,0.2662,0.3113,0.705,0.405,1.1025,0.2963,0.3975-0.1087,0.8175-0.165,1.2525-0.165,2.6513,0,4.8,2.1487,4.8,4.8v0.9337c0,0.945-0.0562,1.8862-0.165,2.8237-0.0638,0.5475,0.3525,1.0425,0.9075,1.0425s0.8212-0.3225,0.8738-0.7612c0.1237-1.0275,0.1875-2.0625,0.1875-3.1012v-0.9337c0-3.645-2.955-6.6-6.6-6.6h-0.0037v-0.0037ZM8.0494,8.1266c-0.3412-0.3975-0.9487-0.4275-1.2712-0.015-0.8663,1.1175-1.38,2.5162-1.38,4.0388v0.9337c0,0.9075-0.0975,1.815-0.2925,2.6963-0.1275,0.585,0.2963,1.1663,0.8962,1.1663s0.7462-0.2625,0.8325-0.6488c0.24-1.0537,0.3637-2.13,0.3637-3.2175v-0.9337c0-1.02,0.3187-1.965,0.8587-2.7412,0.27-0.39,0.3-0.9225-0.0075-1.2825h0v0.0037ZM11.9981,8.5504c-1.9875,0-3.6,1.6125-3.6,3.6v0.9337c0,1.3462-0.1725,2.6812-0.5175,3.9787-0.1425,0.5363,0.2512,1.0875,0.8063,1.0875s0.6712-0.2325,0.765-0.5775c0.3937-1.4625,0.5962-2.97,0.5962-4.4887v-0.9337c0-1.0762,0.8738-1.95,1.95-1.95s1.95,0.8738,1.95,1.95v0.9337c0,1.3612-0.1313,2.715-0.39,4.0462-0.1013,0.5212,0.2888,1.02,0.8175,1.02s0.7125-0.2625,0.7875-0.6375c0.2888-1.455,0.435-2.9362,0.435-4.4287v-0.9337c0-1.9875-1.6125-3.6-3.6-3.6h0ZM12.8981,12.1504c0-0.4988-0.4012-0.9-0.9-0.9s-0.9,0.4012-0.9,0.9v0.9337c0,2.2462-0.4125,4.4737-1.2188,6.57l-0.2213,0.5737c-0.18,0.465,0.0525,0.9862,0.5175,1.1625,0.465,0.1762,0.9862-0.0525,1.1625-0.5175l0.2213-0.5737c0.885-2.3025,1.3388-4.7475,1.3388-7.215v-0.9337Z" fill="currentColor"/> </svg>

EP runs in high-availability AWS GovCloud environments with a cross-region replica to support uptime and continuity.

<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none">   <path fill-rule="evenodd" clip-rule="evenodd" d="M18,22.2007c-2.9812,0-5.4-2.4187-5.4-5.4s2.4187-5.4,5.4-5.4,5.4,2.4187,5.4,5.4-2.4187,5.4-5.4,5.4ZM9.4725,2.0445c0.4575-0.3488,1.1138-0.3262,1.545,0.075l8.16,7.575c-0.3825-0.0638-0.7762-0.0975-1.1738-0.0975-2.9475,0-5.4787,1.77-6.5925,4.305-0.1912-0.0675-0.3937-0.105-0.6075-0.105h-1.2c-0.9937,0-1.8,0.8063-1.8,1.8v3.6h3.4125c0.2287,0.6488,0.5475,1.2525,0.9413,1.8h-7.3575c-1.3237,0-2.4-1.0725-2.4-2.3962v-6.6h-0.6c-0.495,0-0.9375-0.3037-1.1175-0.7612-0.18-0.4575-0.06-0.9825,0.3-1.3162L9.3825,2.1232l0.09-0.075h0v-0.0037ZM20.1525,14.517c-0.2662-0.195-0.6412-0.135-0.8363,0.1313l-1.9875,2.73-1.0012-1.005c-0.2325-0.2325-0.615-0.2325-0.8475,0s-0.2325,0.615,0,0.8475l1.5,1.5c0.1237,0.1237,0.2963,0.1875,0.4725,0.1762s0.3337-0.105,0.4387-0.2475l2.4-3.3c0.195-0.2662,0.135-0.6412-0.1313-0.8363h-0.0075v0.0037Z" fill="currentColor"/> </svg>

Our controls are built on NIST SP 800-53 and aligned with the FBI CJIS Security Policy and are independently audited.

<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none">   <path fill-rule="evenodd" clip-rule="evenodd" d="M18,3.6c1.3237,0,2.4,1.0762,2.4,2.4v12c0,1.3237-1.0762,2.4-2.4,2.4H6c-1.3237,0-2.4-1.0762-2.4-2.4V6c0-1.3237,1.0762-2.4,2.4-2.4h12ZM16.425,7.8637c-0.4012-0.2925-0.9637-0.2025-1.2562,0.1987l-4.4775,6.1575-1.9537-1.9537c-0.3525-0.3525-0.9225-0.3525-1.2712,0s-0.3525,0.9225,0,1.2712l2.7,2.7c0.1875,0.1875,0.4462,0.2812,0.705,0.2625s0.5025-0.1537,0.6562-0.3675l5.0963-7.0125c0.2925-0.4012,0.2025-0.9637-0.1987-1.2562h0Z" fill="currentColor"/> </svg>

Built for Security

Security Standards & Controls

Technical specifications covering hosting, encryption, access controls, and compliance standards.

Hosting & Infrastructure

  • Hosted entirely in AWS GovCloud (US), primary in us-gov-east-1, replicated to us-gov-west-1.
  • US-based infrastructure and personnel; no data or resources leave the United States.
  • Hardened environments with restricted network access and redundant systems for availability.

Data Security

  • Fully isolated customer instances, without shared databases.
  • Encryption at rest using FIPS 140-3 validated cryptography.
  • Encryption in transit over TLS 1.2+ using FIPS 140-3 validated ciphers.
  • Key management aligned with NIST SP 800-57.

Access Control & Authentication

  • Hierarchical Role-based access control (RBAC) enforcing least privilege access even within complex public safety agencies.
  • Single Sign-On (SSO) via SAML and OIDC providers (Microsoft Entra ID, Google Workspace, Okta, and more).
  • Multi-factor authentication (MFA) meeting AAL2 standards, enforeable agency-wide for all users.
  • Administrative oversight and full auditability of access.

Compliance & Audits

  • SOC 2 Type II maintained annually.
  • Aligned with the latest FBI CJIS Security Policy.
  • Annual third-party audits and internal security reviews.
  • SOC 2 Type II report and CJIS Security Addendum available on request through the Trust Center.

Monitoring & Reliability

  • Continuous monitoring with Cloudflare WAF, Crowdstrike Falcon, and Amazon GuardDuty threat detection.
  • Automated alerting and centralized logging.
  • Encrypted backups and cross-region disaster recovery.

Security You Can Verify

See how we protect your data. Review our certifications, compliance reports, and security practices in the Trust Center.

 See Integrations Built for Your Sector

Essential Personnel connects with a wide range of sector-specific systems to streamline your workflows and enhance operational efficiency. Explore your sector page to see how these integrations work in law enforcement, fire service, local government, and more.
ProdigyEMS logo
ProdigyEMS

EP's closest partner is the best-in-space ProdigyEMS. Founder-led with a fanatical curation of their learning content library. Includes both EMS and Fire content. Seamlessly integrates with EP’s logbook.

ESO

ESO offers an integrated suite of software products for EMS agencies, fire departments, and hospitals.

Aladtec provides public safety employee scheduling to match shifts to your rotation patterns and monitor minimum staffing requirements.

Seamlessly transfer incident data into EP's early warning and case management system.

Real-time alerts, latest news, messaging, easy-to-update and automated mission-critical information.

Transfer critical incident information and integrate into EP wellness profiles and early warning alert systems.

Sync credentialing information for a comprehensive view of training and performance.

Access to a secure online exam platform. Create engaging exams or quizzes and integrate results into a user's profile.

Automatically populates mileage, runtime/engine hours and current location of any vehicle into EP fleet for better tracking and maintenance.

Sync e-learning and instructor-led training into Essential Personnel's Logbook.

Answers to Your Security and Compliance Questions

Your IT director will ask most of these before you get to a demo. Here are the specifics, in the form a security review actually wants them.

Yes, in the sense the phrase can be used. CJIS compliant software is a claim about controls rather than a certificate. The platform is aligned with the latest FBI CJIS Security Policy, with controls built on NIST SP 800-53 and independently audited. The CJIS Security Addendum, the document that underpins any CJIS compliance claim, is available on request.

It is worth being precise about language, because CJIS compliance is not a certification anyone can hand you. There is no CJIS certifying body issuing a badge. What exists is the CJIS Security Policy, a set of controls, and a vendor's ability to evidence that it meets them. Any vendor selling CJIS compliant software as CJIS certified is describing something that does not exist.

So the useful test of CJIS compliance is documentary rather than declarative. Ask for the Security Addendum, ask where data is hosted, ask which cryptographic modules are validated, and ask whether personnel are US based. Those four answers separate CJIS compliant software from marketing copy, and they are what your state CJIS Systems Officer will actually assess when reviewing CJIS compliance.

No, and it matters that the answer is direct. Essential Personnel is not itself FedRAMP authorized and does not hold a FedRAMP ATO.

The nuance that causes confusion is the hosting layer. The platform runs entirely in AWS GovCloud (US), which is itself FedRAMP High authorized as infrastructure. That is a genuine control inheritance and worth stating in a security review, but it is not the same as the application holding its own FedRAMP authorization, and any vendor that blurs the two is misleading you about what CJIS compliant software and FedRAMP each mean.

For most municipal and county agencies FedRAMP is not the applicable framework anyway. CJIS alignment and SOC 2 Type II are what state and local procurement typically asks for, whether the buyer is a law enforcement agency or a municipal HR team. If your jurisdiction genuinely requires FedRAMP, raise it early rather than late, because that is a scoping question rather than a paperwork one.

Entirely in AWS GovCloud (US), primary in us-gov-east-1 and replicated to us-gov-west-1. Infrastructure and personnel are US based, and no data or resources leave the United States.

AWS GovCloud is the isolated region built for US government workloads and sensitive data, with access restricted to vetted US persons. That is a meaningfully different posture from commercial regions, and it is the first thing to check when a vendor says government grade.

Environments are hardened with restricted network access and redundant systems, running high availability with a cross region replica. Ask any vendor to name their region. AWS GovCloud is a specific answer; hosted on AWS is not.

At rest using FIPS 140-3 validated cryptography, and in transit over TLS 1.2 and above using FIPS 140-3 validated ciphers. Key management is aligned with NIST SP 800-57.

The word doing the work there is validated. Plenty of products use strong algorithms without using a FIPS 140-3 validated module, and for CJIS purposes that distinction is the whole point. FIPS 140-3 is a validation of the cryptographic module itself rather than a claim about the algorithm.

If your review asks vendors about encryption, ask specifically whether the module is FIPS 140-3 validated rather than whether data is encrypted. Everyone answers yes to the second question.

Yes. Customer instances are fully isolated, without shared databases.

This is a bigger deal than it sounds in a security review. Most SaaS is multi tenant with logical separation, meaning your records and another agency's records sit in the same database distinguished by a tenant identifier. That is normal and usually fine, and it is also the thing a CJIS reviewer will probe hardest.

Fully isolated instances remove that question. It also changes the blast radius of a misconfiguration, which is the real world risk rather than the theoretical one.

SOC 2 Type II is maintained annually, with annual third party audits and internal security reviews, and the report is available on request.

The Type II part matters. A Type I report says controls were designed appropriately on a given date. A SOC 2 Type II report says an auditor tested that those controls actually operated over a period, usually twelve months. Vendors sometimes say SOC 2 without saying which, and the difference is substantial.

When you get the report, read the exceptions section rather than the cover page. A SOC 2 Type II with a couple of noted exceptions and clear remediation is more informative than a clean summary you never opened.

Through hierarchical role based access control enforcing least privilege, with administrators controlling exactly who can view and manage each type of information, plus administrative oversight and full auditability of access.

The hierarchical element is what makes this workable in a public safety agency. A flat permission model forces you to choose between giving a supervisor too much and giving them too little, and agencies end up over granting because under granting stops people working.

Specialist role permissions handle the sensitive categories, which is how wellness and critical incident data reaches designated staff without being visible to everyone with a login. That is a security control and a trust control at the same time, and the wellness data on the Safety and Wellness side depends on it, as does policy acknowledgement in Guidance.

Single sign on is supported via SAML and OIDC providers, and multi factor authentication meets AAL2 standards and is enforceable agency wide.

Both single sign on and multi factor authentication matter, for different reasons. Single sign on means deprovisioning actually works: when your identity provider disables an account, access ends everywhere rather than depending on someone remembering this system exists. For agencies with turnover that is the single most valuable security control available.

The AAL2 detail is worth noting because multi factor authentication is not one thing. AAL2 is the NIST assurance level CJIS expects for advanced authentication, so multi factor authentication that meets it is a specific claim rather than a generic one. Single sign on is an optional line item at $800 per year per agency, listed on the pricing page.

Continuous monitoring using Cloudflare WAF, CrowdStrike Falcon and Amazon GuardDuty, with automated alerting and centralized logging.

Naming the stack is unusual and useful. Most vendors answer this question with the phrase continuous monitoring and nothing else, which tells a reviewer nothing. A named web application firewall, endpoint detection and cloud threat detection layer is something your IT team can actually assess.

Centralized logging is the part that matters after an incident rather than during one. Detection tells you something happened; logging tells you what it touched.

Encrypted backups with cross region disaster recovery, running against the us-gov-west-1 replica, plus redundant systems within the primary environment.

Cross region is the meaningful qualifier. Backups held in the same region as production protect you against a database failure and not against a regional outage, and the difference only becomes visible on the day it matters.

Recovery objectives, retention periods and incident notification timelines are the numbers to pin down in contracting rather than take from a web page. Ask for RPO, RTO and the breach notification window in writing, and get them into the agreement.

The SOC 2 Type II report and the CJIS Security Addendum are both available on request, and a Trust Center publishes certifications, compliance reports and security practices.

For most agencies those two documents plus the hosting and encryption specifics answer a standard security compliance software questionnaire outright. Bring your own questionnaire rather than accepting a summary, because the gaps in a vendor's standard security compliance software packet are usually the interesting part. Every security compliance software vendor has a prepared answer set; your questionnaire is what finds the edges.

If your jurisdiction has its own supplemental requirements, put them on the table before procurement rather than during. Security compliance software reviews stall far more often on a missing document than on a missing control.

Infrastructure and personnel are US based, no data or resources leave the United States, and access is governed by least privilege with full auditability.

For a CJIS review the personnel question usually goes further than that, into background screening and signed addenda for anyone with potential access to criminal justice information. The CJIS Security Addendum is the document that covers it, and it is the piece your CJIS compliance review will ask for. It is available on request.

Put the specifics in writing during contracting rather than relying on any web page, including this one. Ask which roles can access agency data, under what circumstances, whether access is logged, and what screening those individuals have completed. Any vendor that cannot answer all four in writing has told you something.

Need the SOC 2 report or CJIS Security Addendum for your review? Ask and we will send them.

Request a Demo