Privacy Policy for Exhibit In-Sight Software Suite
Updated — September 2026
🔒 Zero-Cloud Evidence Architecture: In-Situ Software Solutions Inc. does not host, process, view, or back up any police evidence, case notes, search warrants, or crime scene photographs on cloud servers. All evidentiary records remain 100% sovereign on your agency's local hardware.
In-Situ Software Solutions Inc. ("we", "us", or "our") develops the Exhibit In-Sight desktop Mobile Data Terminal (MDT) application and the Exhibit In-Sight Mobile companion application for Android (collectively, the "Software" or "Apps"). Our software is engineered exclusively for authorized Canadian law enforcement, policing, and statutory regulatory bodies. We are strictly committed to protecting personal privacy, maintaining data sovereignty, and safeguarding the chain-of-custody integrity of investigative records.
This Privacy Policy outlines how we handle the limited administrative data required to operate our commercial services and software licensing, and details the local, zero-cloud architecture under which the Software manages evidentiary data.
1. Administrative Data Collection & Statutory Privacy Alignment
To provide our services, process subscriptions, and authenticate software licenses, we collect limited business-to-business administrative and billing information. We do not host, view, transmit, access, or collect any police evidence or operational case data.
The handling of information under this agreement falls into two distinct statutory categories:
- Commercial & Billing Data: Our commercial operations, website, and subscription licensing management are governed by the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial private-sector privacy legislation (such as the British Columbia Personal Information Protection Act and Alberta PIPA).
- Evidentiary Case Data: Sensitive investigative case data, officer notes, and evidence records remain exclusively within the physical custody and control of the subscribing police service, governed by applicable provincial public sector privacy and freedom of information legislation (such as the British Columbia Freedom of Information and Protection of Privacy Act [FOIPPA], Ontario Freedom of Information and Protection of Privacy Act [FIPPA] / Municipal Freedom of Information and Protection of Privacy Act [MFIPPA], and Alberta Freedom of Information and Protection of Privacy Act [FOIP]). Because In-Situ Software Solutions Inc. maintains zero custody, hosting, or electronic access to operational evidence, In-Situ Software Solutions Inc. is legally neither a "data processor" nor a "data custodian" of agency investigative records.
Our administrative data collection utilizes the following third-party infrastructure:
- Stripe & Squarespace: When an authorized agency subscribes via our website, Stripe securely collects the agency name, administrative contact name, billing email address, phone number, municipal address, and credit card information. In-Situ Software Solutions Inc. does not process, handle, or store payment card numbers.
- Google Cloud Platform (Canadian Data Sovereignty): To verify active, trial, or suspended subscription states, our licensing server records your agency's administrative account metadata in Google Cloud Firestore. In strict compliance with Canadian public sector data residency requirements, this database infrastructure is hosted entirely within Google Cloud's Toronto, Canada (
northamerica-northeast2) sovereign region.
- Resend: An automated transactional email delivery service utilized strictly to dispatch your agency's unique Agency Billing Key and download portal authentication credentials. Administrative contact data is encrypted in-transit, and Resend operates strictly as a data processor.
2. Evidentiary Data Collection and Zero-Cloud Processing
The Software is utilized by police personnel to record and structure contemporaneous investigative evidence, including officer identities, badge numbers, exhibit descriptions, seizure locations, timestamps, and crime scene photographs. We guarantee a zero-cloud data processing architecture for all operational records:
- 100% Local In-Memory Processing & Cryptographic Hashing: All data processing—including image scaling, JPEG compression, and text extraction from uploaded PDF search warrants—executes exclusively in local system RAM on agency-owned hardware. At the instant of capture on a mobile device, photographs are scaled and stamped with an immutable SHA-256 digital fingerprint in memory before being written to local disk. No evidentiary data is ever transmitted to external cloud OCR, machine-learning, or analytics endpoints.
- Desktop/MDT Storage (.eis Containers): Master case files are compiled as proprietary container files (
.eis) stored on physical workstations, encrypted drives, or internal agency network storage entirely of the agency's choosing. The Software automatically maintains up to three (3) generational rolling backups in an adjacent, operating-system-hidden directory (Exhibit In-Sight Backups). Note: Neither the primary .eis container nor the rolling backups apply application-layer AES encryption in order to optimize live scene read/write throughput. Agencies maintain responsibility for securing evidence at rest by enforcing operating-system-level Full Disk Encryption (e.g., Microsoft BitLocker on MDTs and hardware-backed File-Based Encryption on mobile devices).
- Mobile Sandbox, Biometrics & Explicit Offline Export: Mobile data is stored exclusively within the secure internal SQLite sandbox of the Android device. In compliance with modern security standards, the mobile application manifest strictly enforces
allowBackup="false", preventing the Android operating system from copying the app sandbox to personal or commercial cloud services (e.g., Google Drive, Samsung Cloud). Biometric verifications (Fingerprint or Face unlock) are managed entirely by Android's hardware-backed Secure Element / Trusted Execution Environment (TEE) and are never accessed or stored by the application. Authorized users retain the ability to manually export encrypted-in-transit or offline rescue packages (.eis_mobile) outside the sandbox via the Android Sharesheet (e.g., to email or encrypted USB) for desktop ingestion.
Downstream Disclosures & Freedom of Information: Once evidentiary files, photographs, disclosure reports, or audit packages are exported from the application (via court disclosure PDF, Technical Defense ZIP, clipboard copy, or offline .eis_mobile transfer), operational custody of that information transfers entirely to the operating personnel and agency. In-Situ Software Solutions Inc. exercises zero control over, and assumes zero legal responsibility for, the subsequent storage, retention, redaction, dissemination, or disclosure of records under applicable provincial or federal access to information or privacy statutes.
3. In-Transit Wireless Security & Local Network Communication
The Software suite is designed for air-gapped and localized operational deployment. Case data synchronizes directly between mobile companion devices and the desktop MDT over a direct, device-to-device local Wi-Fi connection or cruiser area network (LAN):
- TLS 1.3 / AES-256 In-Transit Encryption: All over-the-air communication between mobile devices and the MDT is encrypted in-transit using TLS 1.3 with AES-256-GCM cipher suites over TCP port 51038.
- SHA-256 Certificate Pinning: The MDT generates an ephemeral 2048-bit RSA X.509 certificate dynamically in memory at boot. The mobile companion application enforces strict cryptographic certificate pinning against the exact SHA-256 fingerprint encoded into the pairing QR code, preventing rogue access points or local Man-in-the-Middle (MitM) interception.
- Discovery Beacon Isolation (UDP Port 51039): UDP broadcasts on port 51039 are restricted strictly to discovery handshakes (
DISCOVER_MDT_REQUEST / DISCOVER_MDT_RESPONSE) containing solely the workstation computer name, active TCP port, license GUID, and the public TLS certificate SHA-256 hash. Zero evidence descriptions, case notes, occurrence numbers, suspect identities, or crime scene photographs are ever transmitted over UDP.
4. Software Licensing & Disconnected Field Operations
To verify active subscription status, the Exhibit In-Sight desktop application periodically connects over outbound HTTPS (TCP port 443) to our Canadian licensing verification server. Once validated online, the desktop application generates a secure, localized cryptographic signature bound to a dynamic 256-bit machine salt stored in the local Windows Registry. This permits up to sixty (60) days of continuous, disconnected field operation without requiring internet connectivity. No case data, evidence details, occurrence files, or personnel identities are ever transmitted during license verification requests.
5. Mobile Device Permissions (Zero-Tracking Disclosure)
To operate securely in field conditions, the Exhibit In-Sight Mobile application requests only the operating system permissions essential for core functionality:
- Camera: Used exclusively to photograph physical exhibits and scan the on-screen pairing QR code displayed on the MDT. Images remain within the app sandbox until explicitly synchronized or exported by the user.
- Vibration / Haptics: Used solely to provide tactile confirmation upon successful barcode or QR code acquisition.
- Wi-Fi & Network State: Required to establish direct, air-gapped TCP/IP socket connections to the MDT local server over local Wi-Fi or vehicle routers.
- Nearby Devices / Location (Android OS Prerequisite): The Android Operating System mandates that applications request "Nearby Devices" (Android 12+) or "Location" (legacy Android versions) in order to scan for local Wi-Fi network adapters and discover local network SSIDs. Exhibit In-Sight Mobile contains zero GPS tracking libraries and does not record, track, monitor, log, or transmit physical geographic coordinates, geolocation telemetry, or device movement. This permission is utilized strictly as an operating system requirement for local Wi-Fi socket discovery.
6. Diagnostic Support Logs & Data Minimization
The Software allows users to export diagnostic .zip logs to email to technical support for troubleshooting. To proactively enforce data minimization:
- Automated Local Purging: The desktop MDT application automatically and permanently purges diagnostic log files older than fourteen (14) days from the local hard drive.
- Anonymized Logging Architecture: The application’s diagnostic logger (
EisLogger) is programmatically instructed to record mechanical actions only and avoid logging case-specific facts, suspect names, occurrence numbers, or physical addresses.
- Explicit Mobile Speed Bump: On mobile devices, support log generation requires explicit user confirmation via an in-app verification dialog. Because automated operating system crash traces may inadvertently capture local folder structures, operating personnel are instructed to review diagnostic archives prior to transmitting them to support channels.
7. Data Deletion, Expungement, and Account Termination
- Mobile Device Records: Evidentiary data and photographs remain within the mobile application's internal sandbox until the user explicitly deletes the file session, clears app storage, or uninstalls the application. Deletion permanently erases records from device flash storage using standard Android operating system file deletion calls.
- Desktop Case Containers: Case containers (
.eis) and rolling backups stored on MDTs or network shares remain under the exclusive control of the agency. Because In-Situ Software Solutions Inc. does not host or possess agency files, we cannot remotely inspect, alter, delete, or recover local case records.
- Cloud Administrative Metadata Expungement: Upon the formal cancellation or termination of an agency's subscription account, agency administrative metadata, billing records, and cloud authentication tokens stored within Google Cloud Platform (Toronto) will be permanently expunged from active production databases within ninety (90) days following termination, subject only to statutory Canadian tax and financial audit retention laws.
8. Contact Information
If you have any questions regarding this Privacy Policy, Canadian data sovereignty alignment, or the Zero-Cloud Evidence Architecture of our software suite, please contact us at: admin@exhibitinsight.com.