Mandatory MFA

Users complete time-based one-time-password multi-factor authentication before accessing the product.

Need-to-know access

Role-aware permissions limit case access, and database policies scope records to the appropriate organization.

Private evidence

Evidence is stored privately and accessed through short-lived controlled links. Trusted uploads record a SHA-256 file hash.

Recorded activity

Case and audit events create an append-only history of material activity for review.

Application access

Truett distinguishes administrative and investigator permissions and enforces organization-scoped database access. Individual matters can be limited to the people who need them.

Evidence handling

Uploaded evidence is kept in private storage. Access uses controlled, short-lived links rather than public object URLs. File hashes help identify the uploaded file; Truett does not market this as legal chain of custody.

Operational controls

The application records case activity and separate audit activity. It also supports retention, legal-hold, and deletion workflows. These product controls do not amount to a certification or a guarantee of compliance.

Questions or disclosures

For security questions, contact the support address in the footer. Do not include employee, case, interview, or evidence details in an initial email.