# ACIN Privacy and Security Overview 2026-05-15
This three-page overview is the first batch's most detailed statement of ACIN's claimed security, privacy, ownership, release-control, and audit structure. It identifies controls and principles but does not include the underlying policies, configuration evidence, assessment results, or audit records.
## Key takeaways
- ACIN claims MFA, role-based access, full audit logging, encryption, continuous monitoring, AWS GovCloud, restricted access, and automated accountability tracking (p. 1).
- Participating agencies must comply with training, access-authorization, user-accountability, background-screening, and data-handling requirements (p. 2).
- "Participating agencies retain ownership and control of the data they contribute to ACIN" (p. 2).
- The document defines its Third Agency Rule: one participating agency "cannot release another agency's information without authorization from the originating agency" (p. 2).
- It says ACIN is not a public surveillance system, public-facing investigative database, criminal-intelligence repository under 28 CFR Part 23, replacement system, or unrestricted sharing platform (p. 2).
- Privacy controls include least privilege, user auditing, controlled dissemination, legal/policy oversight, Arkansas FOIA-exemption compliance, PII protection, and annual policy/security reviews (pp. 2-3).
- "Every authorized action performed within ACIN is logged and subject to audit review" (p. 3). The production includes no audit export or review report.
## Cross-references
- [[Arkansas Criminal Intelligence Network]]
- [[Third Agency Rule]]
- [[CJIS Compliance]]
- [[T014 - ACIN Analytical Reach vs Non-Surveillance Classification]]