Skip to content
joyo.

Security

Built to be questioned in court.

Every design decision starts with one question: can you prove what happened to this evidence? Here's how Joyo makes that answer yes.

  • On-premise
  • Encrypted end to end
  • Every action logged

Architecture

Your data never leaves your perimeter.

Every Joyo component runs inside your agency's network. Field units sync over encrypted links, and nothing depends on an outside cloud.

Your agency network
  1. FieldJoyo ScoutRugged units capture and seal items, offline if needed.
    Encrypted sync
  2. Lab serverLabFlow + LensCase management and analytics on your own servers.
    Internal network only
  3. StorageArchive + LedgerOriginals and the audit log on write-once storage.
Public internetNo cloud dependency. Nothing leaves unless you export it.

Principles

Six commitments, on every deployment

Your hardware, your data

Joyo runs on servers and devices your agency owns. Case data doesn't leave your network unless you send it.

HowOn-premise install, no cloud dependency

Integrity checks built in

Files are hashed at intake and checked again on transfer and on a schedule. Any mismatch raises an alert.

HowSHA-256 at intake, transfer and nightly

Encrypted everywhere

Data is encrypted at rest on every device and in transit between the field and the lab.

HowFull-disk encryption + TLS for sync

Least-privilege access

Roles decide who can see, edit, approve or export, down to the individual case.

HowRole- and case-level permissions

People make the call

Automated suggestions are labeled as such and need an examiner's sign-off before they reach a report.

HowMandatory review before release

Complete audit trail

Joyo Ledger records every login, change and export, in a form you can hand to an auditor or a court.

HowHash-chained, append-only log

Try it

Tampering doesn't go unnoticed.

Joyo Ledger links every entry to the one before it with a SHA-256 hash. Change one record and every hash after it stops matching. Edit an entry below and watch the chain catch it.

Verifying chain…

  1. Entry 1 Genesis
    Time09:14
    ByField unit 07
    ActionItem sealed at scene
    Hash—
    Status—
  2. Entry 2 Linked to 1
    Time11:02
    ByIntake desk
    ActionReceived, weight 12.40 g
    Hash—
    Status—
  3. Entry 3 Linked to 2
    Time13:20
    ByExaminer
    ActionAnalysis results recorded
    Hash—
    Status—
  4. Entry 4 Linked to 3
    Time14:37
    BySenior examiner
    ActionResults approved
    Hash—
    Status—

Live demo running in your browser with sample entries. No real case data.

Access control

The right people, and only them.

Permissions are set per role and narrowed to assigned cases. Here is the default setup most labs start from.

Default role permissions
RoleViewCreate / editApproveExportConfigure
Field officerCaptures items at the scene Own cases Own cases———
ExaminerRuns analysis in the lab Own cases Own cases— Own cases—
ReviewerChecks and releases results——
Lab managerAssigns work, sets policy
AuditorRead-only oversight———

Default roles shown. Every role and permission can be configured per agency.

FAQ

Questions security teams ask us

Short answers to what comes up in every security review. Need more detail? Our team can walk your IT and security staff through it.

Where is our data stored?

On servers and devices your agency owns, inside your own network. Joyo doesn't require a cloud service to run.

Can Joyo staff access our case data?

No, not by default. Support sessions happen only when your administrator grants time-limited access, and every session is recorded in Joyo Ledger.

How do updates reach systems that are offline?

We ship signed update packages you can install from removable media. Each package is verified before it runs.

What happens if a field device is lost?

The device is encrypted, so data on it can't be read without credentials. An administrator can revoke the device so it can no longer sync.

How long are audit logs kept?

As long as your retention policy says. Logs are append-only and can be exported for long-term storage.

Does Joyo work with our existing forensic tools?

Yes. Joyo imports exported files from common examination tools and checks their hashes on intake. Your existing tools and licenses stay as they are.

Need our security documentation for a tender?

We'll send architecture details and answers for your security questionnaire.

Request the security pack