TRUST CENTER
RTIO — the Real-Time Intelligence Overlay — unifies public safety, built for agencies that own their mission and their data.
Revelio holds itself to a different posture, and states plainly where each part of it stands. TODAY: all generative AI runs on Amazon Bedrock inside the AWS GovCloud (US) boundary, with per-prompt audit logs an agency can pull on demand; tenant separation is enforced by a deny-by-default policy engine tested on every build; and each agency's data is encrypted under a key that agency can revoke. COMMITTED, AND DATED BELOW: per-tenant infrastructure isolation, federated learning with a published privacy budget, a model card for every AI surface, and the CJIS, GovRAMP and HIPAA milestones. ONE ITEM IS NOT A ROADMAP ENTRY: a prohibited-class list — person-of-interest content, investigative material, patient data, juvenile records, PCII — is permanently excluded from cross-tenant training, with no approval path, now or later. The mission this protects is simple: equip first responders with the data they need to come home safely without ever becoming the reason data is used against the public they serve.
WHERE REVELIO IS
Sequenced, dated, and verifiable.
- Standard | Status | Target | Notes — AWS GovCloud (US) | IN PLACE | — | us-gov-west-1, multi-AZ. Single region today; second region below. — FIPS-validated cryptography | IN PLACE | — | FIPS endpoints where AWS provides them in GovCloud; tracking the FIPS 140-3 transition. — HIPAA BAA (per agency) | AVAILABLE TO EXECUTE | Before any PHI | Revelio signs a BAA with each agency. Revelio's AWS BAA covers AWS as a subprocessor and does not substitute for it. — CJIS Security Policy v6.0 | IN PROGRESS | Attestation Q4 2026 to Q1 2027 | Control mapping under way; vendor track open with GBI, Georgia's CJIS Systems Agency; third-party assessor selection pending GBI guidance. — CJIS personnel screening | IN PROGRESS | Q4 2026 | Fingerprint-based background checks and security awareness training, per GBI requirements. — Automated security monitoring | COMMITTED | Before go-live — Cross-region backup | COMMITTED | Before go-live | 24-hour restore objective. — Independent penetration test | COMMITTED | Before general availability — Cross-region warm standby and failover drills | TARGETED | Post-pilot | Designed, not deployed. — Multi-party approval for privileged access | COMMITTED | At second engineering hire — Privileged-access workstations with session recording | COMMITTED | At second engineering hire — GovRAMP (formerly StateRAMP) | TARGETED | Under evaluation — FedRAMP Moderate | TARGETED | Sponsor TBD | Boundary designed for. — FirstNet Trusted / Listed | TARGETED | To be confirmed | Procurement signal, not blocking. — Legend: IN PLACE means operating today. IN PROGRESS means started, with an owner and a date. COMMITTED and TARGETED mean not yet in place. Revelio does not list an item as in place until a document, an infrastructure resource, or a passing test proves it.
HOW IT'S BUILT
AWS GovCloud (US). Deny-by-default today. Per-tenant isolation committed.
TODAY: RTIO runs on AWS GovCloud (US), region us-gov-west-1, across multiple availability zones. Compute is pooled on a tenant-namespaced cluster, and tenant separation is enforced at the authorization layer by a Cedar policy engine — deny-by-default, fail-closed, and covered by an automated allow/deny test matrix that runs on every build. Each agency's data is encrypted under a customer-managed key that agency can rotate or revoke. Generative AI runs on Amazon Bedrock, in-boundary only. Every record RTIO ingests carries a source reference, so any correlation the platform makes traces back to the exact system it came from. COMMITTED, NOT YET IN PLACE: a dedicated per-tenant Aurora cluster, S3 bucket and OpenSearch index as an enterprise isolation tier; application-level field encryption for designated sensitive fields; and PII/CJI redaction at ingress before any data reaches a model.
Reference architecture (request via packet)
CROSS-TENANT AI TRAINING
Default off. Per-data-class opt-in. Not yet running.
Eligible classes when cross-tenant training is enabled (opt-in only, default off)
- - Fire-behavior outcomes (rate of spread, suppression effectiveness, time-to-control)
- ETA estimation (unit-to-incident time, traffic-aware routing)
- Resource-recommendation outcomes (units dispatched vs. units needed)
- Hazmat / mass-casualty resource scaling
- Traffic-congestion patterns (de-identified, aggregated to a 5-minute grid)
Prohibited classes (permanently excluded — no approval path, now or later)
- - Person-of-interest, suspect, victim, witness, or arrestee data
- Investigative content (case files, statements, evidence chain-of-custody)
- Patient or medical data (EMS ePCR, hospital handoffs, mental-health calls)
- Juvenile, sealed-record, or expunged-record data
- Anything tagged PCII (Protected Critical Infrastructure Information)
Governance
TODAY: Revelio does not train models across agencies. No federated-training system is running, and cross-tenant training has never been enabled. COMMITTED, BEFORE ANY CROSS-TENANT TRAINING BEGINS: per-agency, per-data-class opt-in captured in the MSA and surfaced in the admin UI, defaulted off for every class and withdrawable at any time; federated training jobs that run inside each tenant's boundary, with gradients aggregated through a privacy-preserving aggregator before reaching any global model; a published differential-privacy budget with the accounting method stated alongside the values; an independent review body with academic, agency and civil-liberties seats reviewing the permitted-class list on a published cadence; and a documented withdrawal-and-retraining process with a committed timeframe. The prohibited classes above sit outside all of it, permanently.
AI PROVENANCE
One card per AI surface. Committed, not yet published.
COMMITTED: every AI surface will ship with a public model card describing data classes used, opt-in scope, training cadence, performance metrics on held-out data, known limitations, intended use, and an out-of-scope list. Versioned, and independently reviewed. TODAY: none are published. The surfaces below are the ones that will carry them.
- Surfaces (model card links go here as they publish):
- Incident Summary
- Fire-Behavior Prediction
- ETA Estimation
- Resource Recommendation
- Ask Revelio (conversational interface)
AGENCY DATA, AGENCY LOG
Pull the audit trail on demand.
TODAY: every prompt, completion and citation is logged per tenant with source citations, so any AI-derived statement traces back to a primary record. Each agency can request its own audit records in machine-readable form. COMMITTED, NOT YET IN PLACE: immutable object-lock storage for the audit trail, cryptographic integrity proofs, and a documented agency-facing audit API. These are specified in the procurement packet.
WHO TOUCHES AGENCY DATA
A short, named list.
- Amazon Web Services (GovCloud US) | Compute, storage, database, AI inference | us-gov-west-1 — FedRAMP High
- GitHub | Source control and deployment pipeline; no agency data | US
- Microsoft 365 | Corporate email and document storage; no agency operational data | US
- Zoom | Meetings and recorded sessions with agency personnel | US
- Complete as of the date on this page. Revelio notifies agencies 30 days before adding any sub-processor that processes agency data.
RESILIENCE
MULTI-AZ TODAY. CROSS-REGION DR ON THE ROADMAP.
One region today. Active-passive DR designed, not deployed.
TODAY: multi-AZ database, private cluster endpoint, deletion protection, automated self-healing, and a rehearsed rollback procedure with pre-cutover snapshots — all within us-gov-west-1. COMMITTED BEFORE GO-LIVE: cross-region backup to us-gov-east-1, with a 24-hour restore objective. TARGETED POST-PILOT: active-passive failover between us-gov-west-1 and us-gov-east-1, a quarterly drill programme with published reports, and published RTO/RPO targets once measured. No uptime SLA applies during a no-fee design-partner pilot. The agency's existing systems remain authoritative at all times, and RTIO is never in the 911, CAD, or dispatch path.
WHO REVELIO IS
US persons. No interactive production access.
TODAY: all Revelio personnel are US persons. Revelio does not access production interactively — deployments run through continuous integration using short-lived, keyless credentials, and the bootstrap credential is deactivated once that path exists. IN PROGRESS: fingerprint-based background checks and CJIS security awareness training, per GBI requirements, completed before any personnel are granted access to criminal justice information. COMMITTED AT THE SECOND ENGINEERING HIRE: privileged-access workstations with session recording, and multi-party approval for privileged access logged to the same immutable store as agency audit data.
RESEARCHERS
Coordinated disclosure.
Security researchers should email trust@reveliotech.ai with the issue. Revelio acknowledges within one business day and commits to a status update every seven days until resolution. COMMITTED: a published PGP key for encrypted reports.
Need more?
The procurement packet contains the reference architecture, the CIO/CISO hosting brief, the sub-processor list, the pilot agreement with its security and data-processing exhibits, the mutual NDA and the HIPAA BAA. Items marked targeted or committed above — the CJIS assessment, DR drill reports, penetration test results and model cards — are listed there with their current status, and become available as they are issued.