Our position is simple: a claim you can't check is worth nothing to an investigator — that's true of an AI answer, and it's just as true of a vendor's benchmark. So here is the methodology, stated plainly, including its limits.
The reference workload
The scale figures on our homepage come from one production deployment: a single real homicide investigation processed end-to-end on agency-side hardware. Out of respect for the case and the agency, we do not name it publicly — and we say so rather than imply otherwise. What we can state precisely:
- 128,000+ documents in one case — scanned reports, interview and call audio, photographs, phone extractions, office documents, and records returns — ingested, read, and indexed by the platform's on-device vision, speech-to-text, and parsing pipeline.
- ~1.8 million evidence passages indexed for hybrid keyword + semantic search; roughly 300,000 extracted entities and 340,000 timeline events structured from the same corpus.
- The entire pipeline ran on-premises on desktop-class hardware — no cloud processing, no third-party model APIs.
How the search latency was measured
- ~17 ms is the measured database-side latency of a semantic (vector-similarity) query across all ~1.8M indexed passages, on a single desktop-class node with 128 GB unified memory — the same entry-tier machine described on our hardware page. It is a median of repeated warm queries, not a best-of run.
- It measures retrieval — the step that finds candidate evidence. End-to-end question-to-cited-answer time additionally includes language-model generation, which depends on answer length and hardware tier; on the reference node, typical grounded chat answers complete in seconds. We deliberately do not average those into a single misleading number.
- Ingest throughput (reading 128k documents in the first place) is measured in days on a single node, not minutes — processing a large cold case is a batch job, and we size hardware tiers accordingly. We will estimate ingest time for your caseload honestly during scoping.
The offer that matters: reproduce it yourself. During an evaluation we will run this same benchmark suite on your hardware, on a sample corpus you control, with your IT staff watching the network interface. Zero-egress in air-gapped mode is verified the same way — at the switch, not on a slide.
What you can independently verify during evaluation
- Built-in validation report. The platform generates a signed validation report from inside your deployment — document counts, index integrity, processing coverage, and configuration — so acceptance is based on your instance, not our marketing.
- Automated test suite. The release you deploy ships with its automated test suite; your technical staff can run it and see the results directly.
- Audit trail inspection. Every action lands in an append-style audit log; reviewers can trace any AI finding to its retrieval sources.
- Integrity checks. Case data carries SHA-256 integrity verification; evidence is mounted read-only to the application. Modify-attempt behavior can be demonstrated live.
- Egress control. In air-gapped mode a fail-closed egress control blocks non-approved outbound connections; verify with your own network monitoring during the trial.
Security architecture, in one page
- Boundary. For CJI, the entire stack — ingestion models, language models, search index, database, and application — runs on agency-owned hardware inside your CJIS boundary. There is no third-party model API in the air-gapped configuration; nothing about the architecture requires internet access.
- Evidence handling. Original material is read-only to the platform; analysis and AI output are stored beside the record, never written into it. Redacted or exported copies are generated as new artifacts with an audit record.
- Access. Role-based access control with MFA and lockout protections; per-case assignment gates who can see what.
- Accountability. Immutable audit trail of user and system actions, built for disclosure and courtroom scrutiny; AI findings carry their sources.
- Recovery. Automated, verified backup and restore paths, exercised — not just configured.
- CJIS posture. CJIS compliance is a property of a whole deployment — hardware, network, personnel, policy — not of any single product. CaseLead is built to operate inside a CJIS-compliant environment and to make that the default. We will work through the CJIS Security Policy control mapping with your CSO/ISO during procurement.
What we don't claim
- No third-party certification of these benchmarks exists yet; that is why the reproduce-it-yourself offer is standing policy, and why acceptance testing on your instance is part of every deployment.
- We do not publish customer names or testimonials from active law-enforcement casework, and we are skeptical of vendors who do. References for procurement are handled directly, agency-to-agency, where appropriate.
- The public demo runs in the cloud on de-identified sample data only — it demonstrates the workflow, not the air-gapped deployment.
Procurement packet. Need this in writing for a file? This page is maintained as the current validation brief — print or save it as PDF. For the deployment-specific version (your hardware sizing, your control mapping, acceptance criteria), request it through the contact form and we'll prepare it for your agency. The general Security & Compliance Whitepaper is published for your IT and CJIS reviewers.
Start a 30-day evaluation → — reproduce these numbers on your own case, on hardware we scope with you, and keep the validation report.