Iron Dockets
  • Home
  • Product
  • Industries
  • How it works
  • Contact
  • Privacy
Request demo

Privacy and data protection

How Iron Dockets is built to keep sensitive evidence and personal information under your organisation's control.

Iron Dockets is a tamper-evident custody platform intended for on-premises or sovereign hosting — your organisation runs the API, database, blob storage, and AI services on infrastructure you control. Evidence and case material are not sent to foreign public-cloud platforms by default.

Encryption and storage

Evidence files are stored in blob storage with optional encryption at rest. Keys can be held on the server filesystem or protected via DPAPI on Windows installs. Database records hold custody metadata and manifests — not a substitute for securing the underlying server and backup media.

Access control and audit

The platform supports officer login (JWT), service API keys, and optional device enrollment so field captures can be tied to provisioned handsets. Role policies (field capture, reviewer, admin, external verifier) map to labels in your vertical profile — for example Officer, Investigator, or NPA in law enforcement, or Assessor and Independent Adjuster in insurance.

Security-sensitive actions — including catalog lookups, cross-region fetch attempts, and admin operations — are written to an audit log for oversight and incident review.

POPIA and vertical profiles

Compliance defaults come from a vertical profile JSON file (for example law-enforcement-za with ZA-POPIA). Profiles configure terminology, verification PDF templates, and data-residency rules — including whether cross-region catalog fetch is allowed. When a fetch is denied by policy, the attempt is audited rather than silently permitted.

Private AI

Transcription, batch analysis, and statement assistance run against Ollama on your own servers. Voice recordings and sensitive narrative material are not routed to public cloud language models in the reference architecture.

Ledger anchoring

Cryptographic fingerprints and custody metadata can be anchored on a permissioned Hyperledger Fabric network. Full photographs, video, and audio remain in your blob store — only tamper-evident metadata goes on-chain.

Retention, legal hold, and backup

Legal hold blocks archive and destructive retention actions on held case records. A background archive worker applies retention policies when no hold is active. Scheduled backups can capture database and blob data for disaster recovery — backup scope and off-site storage remain the customer's responsibility.

What verification does and does not claim

The verify service recomputes file hashes, checks ledger references, and returns an explicit integrity claim: tamper-evident since server anchor time. It does not prove scene authenticity, device trustworthiness, or that a human operator acted correctly — only that stored files match anchored fingerprints since ingest.

Production rollout

Each deploying organisation remains responsible for POPIA compliance, information-officer appointments, retention schedules, and data-processing agreements appropriate to its jurisdiction and sector. Iron Dockets provides technical controls; formal legal sign-off forms part of any production deployment.

Iron Dockets

Immutable evidence chain-of-custody for provincial law enforcement

Product
Capabilities Industries How it works Request demo
Legal
Privacy & data protection
Built for

Provincial law enforcement and regulated industries — one tamper-evident platform with sovereign deployment and private AI.

© 2026 Iron Dockets. All rights reserved.