Compliance & Security

Fingerprint data is among the most sensitive categories of personal information. Vettr's operational model is built around the understanding that every step of the process carries a compliance obligation — to the applicant, to your organisation, and to the relevant regulatory frameworks.

How Vettr Handles Compliance

Compliance is not a policy document we reference when something goes wrong. It is the structure around which our entire operational process is built.

✓

CJIS-Aligned Processing

All fingerprint data is handled in alignment with FBI Criminal Justice Information Services (CJIS) Security Policy requirements. Personnel who handle fingerprint data operate under applicable security provisions, and our processes reflect CJIS standards for access, handling, and transmission of criminal justice information.

✓

Chain of Custody

From the moment an applicant's fingerprints are captured to the point at which results are delivered to your authorised contact, every step is documented. You receive a complete audit trail suitable for regulatory review, internal compliance documentation, and any future dispute or query.

✓

Applicant Consent Management

Applicant consent is documented as a standard part of every submission workflow. Consent forms are retained in accordance with applicable requirements and are available for audit or legal review purposes. No fingerprint submission is processed without documented authorisation from the applicant.

✓

Data Retention Policy

Fingerprint biometric data is not retained by Vettr beyond what is strictly required for submission and reconciliation. Once a submission is completed and confirmed, biometric data is not held in Vettr systems. Results are retained in accordance with applicable law and your organisation's documented retention requirements.

✓

Applicant Privacy

Applicant personal information is treated as confidential and is handled in accordance with applicable federal and state privacy frameworks. Information is collected only for the purpose of processing the fingerprint submission and is not shared with any third party beyond the relevant repository and your organisation's authorised contacts.

✓

Secure Result Delivery

Background check results are delivered only to the named authorised contact designated by your organisation. Results are never sent to the applicant directly unless your organisation specifically requests this and the applicant has separately authorised it. Delivery methods are designed to prevent unauthorised access or inadvertent disclosure.

FBI CJIS Security Policy

The FBI's Criminal Justice Information Services (CJIS) Security Policy establishes the minimum security requirements for the access, use, and handling of criminal justice information — including fingerprint data submitted to FBI repositories.

Vettr's operational processes are designed with CJIS standards as the baseline, not as an optional framework. This includes requirements around:

  • Personnel security — background vetting of individuals who handle fingerprint data
  • Physical security of equipment used in fingerprint capture and data transmission
  • Access controls — limiting access to criminal justice information to authorised personnel only
  • Incident response procedures for any suspected data security event
  • Audit and accountability — maintaining records of system access and actions
Institutions with specific CJIS compliance questions related to their own use of Vettr's services are encouraged to contact us directly. We can provide documentation to support your internal compliance review.
Compliance Framework Overview
FBI CJIS Security PolicyBaseline Standard
Applicant ConsentRequired Before Capture
Chain of CustodyDocumented End-to-End
Biometric Data RetentionSubmission Only
Result DeliveryAuthorised Contact Only
Audit TrailFull Lifecycle Record

What Compliance Means for Your Organisation

When your organisation uses Vettr for fingerprinting submissions, you are engaging a service partner whose processes are designed to support your compliance obligations — not transfer your liability to another party.

Practically, this means:

  • Your organisation designates authorised contacts; results are delivered only to those contacts
  • Consent documentation is managed by Vettr but available to your organisation for audit
  • Your HR or compliance team receives chain-of-custody confirmation for every submission
  • Records are structured for your regulatory reporting requirements, not generic output formats
  • Any submission query or reconciliation issue has a named Vettr contact to resolve it

Applicant Privacy & Rights

Applicants whose fingerprints are submitted through Vettr retain their rights under applicable law, including the right to review and challenge information held by the relevant repository in the event of an adverse finding.

Vettr's role is to facilitate the submission process accurately and securely. We do not make employment or licensing decisions, and we do not advise organisations on how to act on background check results — that determination rests with your organisation and its legal advisers.

  • Applicants are informed of the purpose of fingerprint collection before capture
  • Consent is obtained in writing before any submission is processed
  • Vettr does not retain biometric data beyond submission requirements
  • Applicants may request documentation of their submission from Vettr

Common Compliance Enquiries

Live scan fingerprint data is transmitted electronically through approved channels to the FBI's Next Generation Identification (NGI) system or the relevant state repository (in Florida's case, FDLE). Transmission uses encrypted data channels. FD-258 ink cards are sent via US mail to the FBI's designated processing address, in accordance with FBI submission requirements.
No. Fingerprint biometric data is not retained in Vettr systems beyond what is required for the submission process. Once a submission is transmitted and confirmed, the biometric record is not held on Vettr equipment or systems. This is consistent with the principle that biometric data should be collected only for its stated purpose and retained only as long as necessary.
Results are delivered only to the authorised contact designated by your organisation at the time of submission. This contact must be a named individual with the appropriate authority within your organisation to receive this information. Results are not shared with any other party, including the applicant, unless your organisation specifically authorises this and applicable law permits it.
For each submission, Vettr provides: submission confirmation with a reference number and timestamp; chain-of-custody documentation from capture through result delivery; applicant consent record confirmation; and result delivery confirmation to your authorised contact. For organisations with specific audit documentation requirements, additional reporting formats can be discussed.
In the event of a suspected data security incident involving fingerprint or personal data handled by Vettr, we will notify affected organisations and relevant authorities in accordance with applicable law and our incident response procedures. We maintain documented incident response procedures aligned with CJIS Security Policy requirements. Contact us directly if you have a security concern related to a Vettr submission.

Compliance Questions? We Can Walk You Through Our Processes.

If you have specific compliance or security requirements for your organisation's engagement with Vettr, contact us directly. We provide documentation to support your internal compliance review.