Markets · Law Enforcement
Intelligence-led investigations with a defensible record of every step.
Caseloads grow faster than staffing, and every finding has to survive discovery. Analysts spend their hours on open-source triage and paperwork instead of investigative work. Evidence handling that fails scrutiny undoes all of it. EternaEdge is designed to carry a case from intake to authenticated export on one governed platform — with an investigator deciding at every step.
For investigators · analysts · supervisors · command staff
The caseload outruns the staffing, and the record has to hold up anyway.
Sworn staffing has not kept pace with caseloads, or with the volume of digital evidence each case now carries. Every finding still has to survive discovery, an audit, and a use policy the public can read.
Detectives re-key the same facts between the records system, dispatch, the camera platform, and evidence storage. Analysts spend their hours on open-source triage and paperwork. Discovery volume grows until exculpatory material is hard to find inside it. Each new tool arrives with its own login, its own data model, and a council vote.
Intelligence-led policing means decisions driven by analyzed information rather than by the last call for service. That only works when the analysis is documented: the predicate, the sources, who evaluated them, and who decided. The point-solution stack an agency assembles today leaves one auditable record to be assembled by hand.
For investigators · analysts · supervisors · command staff · prosecutor liaison
Where the record breaks today
Records and dispatch systems
They hold the incident. Scoring intent and carrying a case to discovery is a different job — it belongs to the layer above them.
Camera and sensor aggregation platforms
They show what happened. The layer above them records what it meant and who decided.
Standalone open-source intelligence (OSINT) tools
They return feeds. Investigators need relevance scored to a predicate, with the sourcing recorded.
Digital evidence management systems
They store media. The investigation around it — access, transfer, export — still needs a record.
Spreadsheets and shared drives
No audit trail, version chaos, and evidence whose authenticity is hard to prove later.
The investigative lifecycle, from initiation to archive.
The investigative spine: a case opens at threshold or by hand, evidence enters custody hashed and logged, and the record leaves as an authenticated export. An investigator acts at every stage.
Initiation
A case opens automatically when platform risk scoring crosses threshold, from an Intake report, or by hand.
Human roleA supervisor confirms the predicate and the assignment.
Assignment
Tasks, owners, deadlines, and escalation paths are set on the case.
Human roleThe detective sergeant owns the assignment and the workload.
Evidence collection
Items enter Chain custody: hashed, logged, and access-controlled from the first entry.
Human roleInvestigators decide what is collected. Integrity is automatic rather than procedural.
Investigation
The entity-centric timeline grows as records resolve to the people, places, and matters the case concerns. Scribe — part of AI FORCE, in development — is designed to draft summaries and chronologies as work proceeds.
Human roleThe investigator authors, reviews, and signs every record.
Resolution
Findings are documented. Outcomes feed back into the platform's intelligence picture.
Human roleInvestigators and supervisors make the determination. The record shows why.
Archive
An audit-ready record is retained and exportable with authentication for discovery, oversight, or review.
Human roleCounsel and the prosecutor liaison decide what is produced.
AI assistants operate within APEX, using governed, auditable data. They do not bypass authority, workflows, or oversight.
Chain of custody, step by step
Intake
intake · logged · 3f9a…c21e
The item enters custody. Who logged it, and when, goes on the record.
Hashed
sha256 · 3f9a…c21e
A SHA-256 hash fixes the item's content at the moment it was received.
Assigned
custodian · investigator · 3f9a…c21e
Assigned to an investigator with a deadline and an escalation path. The hash travels with it.
Analyzed
access · verified · 3f9a…c21e
Every access is logged. Any change to the item surfaces as a hash mismatch.
Transferred
transfer · logged · 3f9a…c21e
Every transfer is recorded: from whom, to whom, and when.
Exported
export · certificate · 3f9a…c21e
Authenticated export packages the record with its hashes and a certificate for discovery.
Hash fragments illustrative
Findings that stand up to scrutiny.
Digital evidence chain of custody, designed for scrutiny.
Integrity is automatic rather than procedural, so the record is provable without anyone remembering to make it so.
FORGEis the investigative case management spine; Chain is its defensibility layer. Each item is hashed with SHA-256 at intake. Tamper detection surfaces any later change as a hash mismatch rather than a question. Every access and transfer lands on the audit trail. Authenticated export packages the record with its hashes and a certificate for discovery, oversight, or an inspector general's review.
Digital evidence management systems store media. FORGEdocuments the investigation around it and exports an authenticated record. Admissibility remains a judicial determination; the platform's job is to make the record complete and provable.
What the record holds
- Hash
- SHA-256, computed at intake; tamper detection surfaces any later change as a mismatch.
- Tamper detection
- Any change to an item's content surfaces as a mismatch.
- Audit trail
- Every access and every transfer, with the person and the item.
- Access controls
- Multi-level access controls inside the case system. Classification here means platform access — never national-security classification.
- Export
- Authenticated discovery export with a certificate attached to the package.
Criminal intelligence handled the way 28 CFR Part 23 expects.
Title 28 of the Code of Federal Regulations, Part 23, governs how a criminal intelligence project stores and shares evaluated information. The platform is designed to support each step of the agency's own Part 23 policy — and to record the decisions.
Submission
Evaluated information enters through Intake. The platform is designed to record the reviewer and the documented predicate at entry.
Secure storage
Multi-level access controls inside the case system limit who can open what. Every open is logged.
Inquiry
Each access lands on the audit trail: who opened which record, and when.
Controlled dissemination
Every transfer is recorded with its recipient. Designed to support need-to-know and right-to-know reasons on each release.
Review and purge
Designed to support the project's review clock: reviewer, justification, and purge decision on the record. The agency purges. The platform records it.
The agency's policy governs. The platform is designed to record the decisions so the project can audit them.
Open-source lead development within policy.
Open-source intelligence fails when it drowns analysts in feeds, or when nobody can say later why an alert fired. This layer is designed for the opposite: publicly available information, scored for relevance, summarized for action, with the reason on the record.
LUCID Grid collects continuously across regions, domains, and languages with no analyst tasking. Pulse scores relevance and correlates each event to the entity it concerns. Analysts read summaries, not feeds. The agency sets collection priorities and thresholds. Analysts decide what is evaluated, retained, or shared.
Standalone OSINT tools are built to return feeds. Investigators need relevance scored to a predicate, with the sourcing recorded, inside a workflow designed so that views, associations, and protected activity are not a predicate on their own. The agency's policy defines the predicate; the platform records it.
Alert provenance
- Source
- Publicly available information only — never private or closed sources.
- Relevance
- Scored against the people, places, and matters an investigator has documented — not a keyword.
- Correlation
- Attached by the platform to the entity it concerns. Duplicates collapse.
- Summary
- What changed and why it matters — a product, not a feed.
- Decision
- An analyst evaluates, retains, or shares. The record is designed to show why the alert fired and what was done.
The intelligence layer above the real-time crime center.
A real-time crime center (RTCC) sees what happened. The layer above it records what it meant, who saw it, and who decided. Nothing here replaces the records, dispatch, video, or evidence systems the agency already runs.
Stays where it is
Records management system (RMS)
The incident and the report of record.
Computer-aided dispatch (CAD)
The call and the response.
Video management and license-plate readers (LPR)
What happened, and where.
Digital evidence storage
The media itself.
Tip lines and intake forms
The first report.
What the layer adds
Entity resolution
Records across systems resolve to the same person, place, or matter.
Cross-domain risk scoring
Signals weighed together, against a documented predicate — not one spike in one system.
A case at threshold
Opened in the case system with the timeline already assembled.
An audit of who saw what
Every access and transfer on the record.
Authenticated export
The record packaged for discovery, with its hashes.
Detections, license-plate reads, dispatch events, and tips are designed to arrive as events. APEX resolves them to one entity picture — the same person across the records system, a tip, and an open-source mention — and scores risk across domains. At threshold, a FORGE case opens with the timeline assembled. An investigator or supervisor decides what happens next, and the audit trail records who saw what.
Cross-domain investigations in one case.
Investigations, professional standards, cyber-enabled crime, and vetting each used to run in their own silo. On one platform they share a case, a timeline, and a record. Duplicate records collapse.
Vetting of hires, contractors, and task-force partners
Beneficial-ownership mapping and sanctions, politically exposed person (PEP), and adverse-media screening, delivered as audit-ready reports with the red flags called out. Vetting staff and counsel make the trust decision.
Criminal investigations, professional standards, and ethics matters
Intake routes the report, CaseOps runs the case, and Chain keeps the record — in one case system, on one timeline. Investigators run the investigation.
Cyber-enabled crime context
Threat-actor profiling with attribution confidence, and exposure prioritized by mission impact. Cyber analysts read the profiles, tune priorities, and decide the response. It is not a security information and event management (SIEM) replacement or a vulnerability scanner.
Personnel on extradition, task-force, and protective assignments
Risk-tiered briefings, in-travel monitoring, and an emergency SOS that opens a case on activation. Duty staff respond to alerts and SOS activations; the platform is designed to deliver them with the case context attached. Supports ISO 31030 compliance programs.
Built for the use policy you will have to publish.
Many jurisdictions now require a public use policy and an impact report before a new investigative technology is acquired. The platform is designed to make that policy easy to write and easy to audit — and to support agency policy and applicable law.
Policy sections it is designed to support
- Purpose
- Authorized use
- Data access
- Retention
- Auditing and oversight
- Third-party sharing
Purpose-limited access
Multi-level access controls inside the case system. A record opens for the people the case authorizes, and the log shows who.
Audit logging for oversight
Every access and transfer is written to the audit trail and exportable with authentication for an auditor, an inspector general, or a privacy commission.
Retention on the record
Designed to support the agency's retention policy: review, justification, and purge decisions recorded. The agency decides. Nothing purges automatically.
Open-source only
The open-source layer works with publicly available information, by definition. Collection priorities and thresholds are the agency's to set.
Dissemination recorded
Every transfer is a logged event with its recipient. Designed to support the need-to-know and right-to-know reasons your policy requires.
Assistance disclosed
Designed to support disclosure, first-draft retention, and audit obligations for assisted records under state law. Counsel determines applicability.
EternaEdge is designed to support agencies' evidence-handling and audit requirements, and how the platform is secured — governed access, encryption in transit, layered audit logging, and what remains roadmap — is documented at our security page.
How agencies fund and buy it.
Investigative and intelligence platforms are commonly funded through federal justice and homeland security programs and purchased through contracts that shorten procurement.
Eligibility is determined by the funding agency. EternaEdge does not draft agency specifications or applications; a vendor that helps write a solicitation is generally excluded from bidding on it. What we will do is walk through your acquisition path with the people who own it.
- Justice Assistance Grant (JAG)
- Investigative and intelligence platforms commonly fall under the program area for planning, evaluation, and technology improvement. Your State Administering Agency determines eligibility.
- UASI and SHSP
- Urban Area Security Initiative and State Homeland Security Program projects for fusion centers and information sharing.
- COPS technology awards
- Community Oriented Policing Services technology and equipment awards, where congressionally directed.
- Cooperative and state term contracts
- Purchasing vehicles that shorten procurement where the agency's own rules allow.
Investigative case management from intake to discovery export.
One platform foundation, five product pillars, one assistant layer. Start with the investigative spine, add open-source lead development, and expand from there — every pillar stands on the same governed foundation.
Documentation that discloses itself.
Four assistants designed to work across every module — a capability multiplier designed to let an agency scale the program without scaling the team.
Sentinel is designed to monitor every source around the clock. Oracle is designed to correlate signals and deliver briefings on demand. Scribe is designed to draft case summaries and chronologies as work proceeds, aware of the chain of custody. Guide is designed to keep people moving through the workflow. Investigators and supervisors stay in command: every consequential step routes to a human for decision, and every automated action is logged.
The design is intended to support the disclosure, first-draft retention, and audit-trail obligations agencies now carry for assisted records under state law. The investigator authors, reviews, and signs. The record is designed to show what was drafted and who approved it.
AI assistants operate within APEX, using governed, auditable data. They do not bypass authority, workflows, or oversight.
Early warning, defensible action, and a record that holds up.
What the platform is designed to change for an agency, and the record it leaves behind at every step.
Early warning
Open-source leads and cross-domain signals resolve to the people and matters an investigator has documented — surfaced while there is still time to act, and never a basis for action on their own.
Defensible action
An investigator or supervisor decides at every consequential step. What was detected, what automation did, and who approved it are on the record.
Audit-ready record
Hashed evidence, a complete audit trail, logged transfers, and authenticated export — the record a prosecutor, an auditor, or an oversight body can follow.
Frequently asked questions.
Answers first. Where a determination belongs to your agency, your counsel, or a court, we say so.
Is EternaEdge CJIS certified or CJIS compliant?
No vendor is. The FBI does not certify, accredit, or endorse products or vendors under the Criminal Justice Information Services (CJIS) Security Policy, and the determination for each deployment belongs to the agency's CJIS Systems Agency, through its own agreements, audits, and personnel screening. EternaEdge is designed to support agencies' evidence-handling and audit requirements — governed access, encryption in transit, layered audit logging, and authenticated export — and we state our security posture plainly on our security page, including what is still roadmap. Bring your CJIS Systems Agency's requirements to the conversation; a platform architect will walk through them with your security officer.
How does FORGE support chain of custody for digital evidence?
FORGE Chain hashes each evidence item with SHA-256 at intake, detects tampering as a hash mismatch, and keeps a complete audit trail of who accessed and transferred what. Authenticated discovery export packages the record with its hashes and a certificate so a qualified person can attest to the copy. This is designed to support authenticated export for discovery; admissibility remains a judicial determination. Investigators, not the platform, decide what is collected, retained, and disclosed.
Does the platform support 28 CFR Part 23?
It is designed to support an agency's own Part 23 policy. No product is a criminal intelligence system on its own; that status attaches to the agency's arrangement for storing and sharing evaluated intelligence. FORGE is designed to record a documented predicate at entry and the reviewer who approved it, to log every access, to record each dissemination with its recipient, and to keep review, justification, and purge decisions on the record inside the retention maximum the regulation sets. The agency's policy governs, and the agency purges. The platform records the decisions so the project can audit them.
Is EternaEdge a records management system?
No. Records management, computer-aided dispatch, video management, license-plate readers, and digital evidence storage stay where they are and remain the systems of record for incidents and media. EternaEdge is the investigative and intelligence layer above them: detections and tips are designed to arrive as events, APEX resolves them to one entity picture, FORGE opens and documents the case, and the audit trail records who saw what. STRATUM adds cyber context for cyber-enabled crime; it is not a SIEM replacement. Nothing here replaces the systems your agency already runs — the layer sits above them.
How is open-source intelligence kept within policy and First Amendment limits?
LUCID works only with publicly available information. It scores relevance against the people, places, and matters an investigator has documented, returns summaries rather than raw feeds, and is designed to record sourcing, retention, and each dissemination. Views, associations, and protected activity are not a predicate; the agency's policy defines when open-source material about a person may be evaluated, and the agency sets the thresholds. Analysts decide what is evaluated, retained, or shared, and the record is designed to show why each alert fired and what was done with it.
Do AI assistants write our reports?
No. Scribe — part of AI FORCE, which is in development — is designed to draft summaries and chronologies inside FORGE; the investigator authors, reviews, and signs. The audit trail records what automation did and who approved it. The design is intended to support the disclosure, first-draft retention, and audit-trail obligations that laws such as California Penal Code §13663 and Utah Code §53-25-602 place on assisted records; your counsel determines applicability. AI assistants operate within APEX, using governed, auditable data. They do not bypass authority, workflows, or oversight.
Does intent scoring profile people or predict where crime will happen?
No. Intent scoring in APEX is designed to support an investigator's assessment of objective, verifiable facts tied to a documented predicate. It does not predict offenses or locations, rank residents or neighborhoods, or identify anyone from images or video. A score is never, on its own, a basis for probable cause or for any action against a person. Every determination is made by an investigator or supervisor and recorded in the case, and the audit trail is designed to show why an alert fired — source, relevance, and verification — so an oversight body can review it.
Can grant funds be used, and how do agencies buy it?
Investigative and intelligence platforms are commonly funded under the Justice Assistance Grant (JAG) program area for planning, evaluation, and technology improvement; under Urban Area Security Initiative and State Homeland Security Program projects for fusion centers and information sharing; and through congressionally directed Community Oriented Policing Services technology awards. Many agencies purchase through cooperative or state term contracts. Eligibility is determined by the funding agency and, for JAG, by your State Administering Agency. EternaEdge does not draft agency specifications or applications; a vendor that helps write a solicitation is generally excluded from bidding on it. Talk to a Platform Architect about your acquisition path.
Bring the case, the leads, and the record onto one platform.
Tell us how investigations, analysis, and oversight are organized at your agency. A platform architect will map one platform foundation, five product pillars, one assistant layer to the way your cases actually move — from intake to discovery.