# ACIN Privacy and Security Overview 2026-05-15 This three-page overview is the first batch's most detailed statement of ACIN's claimed security, privacy, ownership, release-control, and audit structure. It identifies controls and principles but does not include the underlying policies, configuration evidence, assessment results, or audit records. ## Key takeaways - ACIN claims MFA, role-based access, full audit logging, encryption, continuous monitoring, AWS GovCloud, restricted access, and automated accountability tracking (p. 1). - Participating agencies must comply with training, access-authorization, user-accountability, background-screening, and data-handling requirements (p. 2). - "Participating agencies retain ownership and control of the data they contribute to ACIN" (p. 2). - The document defines its Third Agency Rule: one participating agency "cannot release another agency's information without authorization from the originating agency" (p. 2). - It says ACIN is not a public surveillance system, public-facing investigative database, criminal-intelligence repository under 28 CFR Part 23, replacement system, or unrestricted sharing platform (p. 2). - Privacy controls include least privilege, user auditing, controlled dissemination, legal/policy oversight, Arkansas FOIA-exemption compliance, PII protection, and annual policy/security reviews (pp. 2-3). - "Every authorized action performed within ACIN is logged and subject to audit review" (p. 3). The production includes no audit export or review report. ## Cross-references - [[Arkansas Criminal Intelligence Network]] - [[Third Agency Rule]] - [[CJIS Compliance]] - [[T014 - ACIN Analytical Reach vs Non-Surveillance Classification]]