# ICEPIC
**Entity class:** Federal analytical information system
**Domain:** Homeland security / identity resolution / relationship analysis / information sharing
**Doc Type:** Historical System Node
**Maturity:** Developed
## Definition
**ICEPIC**, the Immigration and Customs Enforcement Pattern Analysis and Information Collection system, was an ICE analytical environment established in 2008 to search DHS information, resolve identities, discover non-obvious relationships, develop leads, and support law-enforcement and counterterrorism analysis. DHS records place its retirement in 2012 and replacement by [[wiki/DHS Pattern and Information Collaboration Sharing System|DPICS2]].
## What “Identity and Relationship Analysis” Means
In plain language, ICEPIC helped analysts ask: **Who is this person, and who do they know—or what people, addresses, phones, vehicles, accounts, documents, organizations, and events are connected to them?**
[[wiki/Identity and Relationship Analysis|Identity and Relationship Analysis]] separates two operations. Identity resolution determines whether variant names, aliases, dates of birth, document numbers, addresses, or other identifiers refer to the same entity. Relationship analysis maps typed connections among resolved entities. A shared address, phone, vehicle, credit-card number, case, or encounter can generate an investigative lead without establishing why the connection exists.
ICEPIC's value came from correlating records that human analysts might otherwise have queried separately. Its risk came from the same capability: a false identity merge, stale address, reused number, or misunderstood association could propagate through an analytical report. DHS policy required human review, but the scale and opacity of the system made provenance and contestability consequential.
## Source Systems and Analytical Layer
ICEPIC did not ordinarily collect information directly from individuals. It ingested and analyzed information held in source environments, especially:
- [[wiki/Treasury Enforcement Communications System|TECS]], the customs and law-enforcement system whose name preserves its origin in the Treasury-era U.S. Customs Service; and
- the [[wiki/Enforcement Integrated Database|Enforcement Integrated Database]] and ENFORCE environment, which held immigration encounter, arrest, booking, detention, and removal information.
This makes ICEPIC a secondary **identity-and-relationship-analysis layer**, not a synonym for its source databases. [[wiki/Investigative Case Management|Investigative Case Management]] later modernized relevant ICE case-management functions.
## External Sharing Through LEIS
The [[wiki/DHS Law Enforcement Information Sharing Service|Law Enforcement Information Sharing Service]] exposed selected person-centered data to authorized state, local, tribal, federal, and international law-enforcement partners. The historical briefing describes standardized [[wiki/Law Enforcement Exchange Specification|LEXS]] messages aligned with [[wiki/National Information Exchange Model|NIEM]], with [[wiki/IBM DataPower|DataPower]] transforming messages between partner and backend formats.
Initial responses could return basic identity and address fields. A selected detailed response could return additional identifiers, including document, vehicle, phone, email, and credit-card numbers. **A credit-card number in a person record is not the same as a transaction history, and ICEPIC was not a universal database of every card swipe.** [[wiki/Financial Transaction Data|Transaction-level records]] ordinarily arise in payment and financial systems; BSA reporting and lawful investigative processes provide separate routes to them.
## Austin Interface
The historical DHS briefing lists **LEAP (NCTCOG)** among existing MOU partners. Austin's 2012 participation agreement with NCTCOG supplies the municipal route: **Austin users → regional [[wiki/Law Enforcement Analysis Portal|LEAP]] → DHS LEIS → selected federal records**. This establishes an interface and agreement path. A claim about a particular query, returned record, or onward action still requires query logs, audit records, case files, or other implementation evidence.
## Lifecycle and Successor Architecture
The system lineage documented in the 2019 LEIS privacy assessment is:
1. **ICEPIC (2008–2012):** analytical repository and relationship-discovery environment;
2. **DPICS2 (2012–2014):** successor repository; and
3. **standalone LEIS (after 2014):** exchange service retrieving selected information from source systems rather than relying on the retired ICEPIC/DPICS2 repositories.
This is functional continuity at the level of information exchange with a material architectural change. The record does not establish that every ICEPIC algorithm, dataset, user, or retention rule continued unchanged.
## Distributed Successor Stack
The modern successor is functional rather than one-for-one. [[wiki/DHS Law Enforcement Information Sharing Service|LEIS/LEISS]] preserved ICEPIC's exchange plane. The analytical and case-management functions moved through [[wiki/FALCON Search and Analysis|FALCON Search & Analysis]], [[wiki/Palantir Gotham|Palantir Gotham]], and [[wiki/Investigative Case Management|ICM]] toward the 2026 [[wiki/Case Management and Analytics Platform|CMAP]] and [[wiki/Enterprise Lakehouse|Enterprise Lakehouse]]. Partner interoperability includes [[wiki/Nlets|Nlets]], [[wiki/Criminal Justice Information Services Division|FBI CJIS]], [[wiki/Office of Biometric Identity Management|OBIM]], and CBP systems. Specialized cyber, OSINT, telecommunications, commercial-data, and device-forensic tools form additional enrichment and collection layers.
The complete model is **authoritative system of record → lakehouse and graph analytics → federated exchange → commercial or open-source enrichment → collection and exploitation**. This preserves the distinction between a documented successor relationship and a function that reappears elsewhere without proof of direct code, dataset, or governance continuity.
## Contact-Tracing Analogy
ICEPIC's expansion from a subject to connected identifiers resembles the graph operation used in [[wiki/Contact Tracing|contact tracing]]: begin with a case, resolve contacts, and follow a chain. The analogy is useful for understanding the computation. It does not make social association equivalent to biological exposure. Counterterrorism analysis must distinguish contact, kinship, commerce, co-location, ideology, operational membership, material support, and criminal conduct.
## Oversight and Evidence Boundary
The original ICEPIC privacy assessment did not fully assess the external LEIS component. DHS later conducted a privacy compliance review and published updated assessments. The 2019 LEIS assessment also records that technical controls cannot prevent an authorized external user from photographing or printing displayed information, leaving agreements, audits, training, and partner controls as important safeguards.
## Sources / Provenance
- [[research/Immigration and Customs Enforcement Pattern Analysis and Information Collection (ICEPIC)|Immigration and Customs Enforcement Pattern Analysis and Information Collection (ICEPIC)]]
- [[research/The Austin Surveillance Field|The Austin Surveillance Field]]
- [DHS — ICEPIC Privacy Impact Assessment](https://www.dhs.gov/xlibrary/assets/privacy/privacy_pia_ice_icepic.pdf)
- [DHS — LEIS Privacy Impact Assessment, 2019](https://www.dhs.gov/sites/default/files/publications/privacy-pia-ice-leiss-july2019_0.pdf)
- [DHS — Privacy Compliance Review of ICEPIC/LEIS](https://www.dhs.gov/publication/privacy-compliance-review-ice-pattern-analysis-and-information-collection-law)
- [DHS — historical LEIS briefing](https://info.publicintelligence.net/DHS-LEISS.pdf)
## Relationships
- **operated by:** [[wiki/United States Immigration and Customs Enforcement|United States Immigration and Customs Enforcement]].
- **source systems:** [[wiki/Treasury Enforcement Communications System|TECS]] and [[wiki/Enforcement Integrated Database|EID/ENFORCE]].
- **analytic method:** [[wiki/Identity and Relationship Analysis|Identity and Relationship Analysis]].
- **external interface:** [[wiki/DHS Law Enforcement Information Sharing Service|DHS Law Enforcement Information Sharing Service]].
- **regional partner route:** [[wiki/Law Enforcement Analysis Portal|Law Enforcement Analysis Portal]].
- **successor:** [[wiki/DHS Pattern and Information Collaboration Sharing System|DPICS2]].
- **case-management modernization:** [[wiki/Investigative Case Management|Investigative Case Management]].
- **distributed modern successor stack:** [[wiki/Case Management and Analytics Platform|CMAP]], [[wiki/Enterprise Lakehouse|Enterprise Lakehouse]], [[wiki/FALCON Search and Analysis|FALCON-SA]], and [[wiki/Investigative Case Management|ICM]].
- **successor-stack research:** [[research/ICEPIC Successor Stack - Distributed Case Management Analytics and Information Sharing|ICEPIC Successor Stack]].
- **cross-domain comparison:** [[wiki/Contact Tracing|Contact Tracing]] and [[wiki/Epidemiological and Threat Network Analysis|Epidemiological and Threat Network Analysis]].