Secure Configuration Guidance
Cahill Swift Compliance Management Platform (CSCMP) · Last updated August 2026
This page provides secure configuration guidance for agency customers of the Cahill Swift Compliance Management Platform, per FedRAMP rule SCG-CSO-RSC. Guidance will expand as the platform completes its FedRAMP 20x Class C certification and services become generally available.
Administrative accounts
Access. Administrative access to the platform is provisioned through federated single sign-on. Agency administrators authenticate through their organization's identity provider; PIV/CAC-based and phishing-resistant multi-factor authentication are supported. The platform does not use local passwords for administrative accounts.
Configuration. Administrative privileges follow least-privilege role assignment. We recommend agencies: designate at least two administrators (no single point of failure), assign the minimum role required for each user's function, and review administrative role assignments at least quarterly.
Operation. All administrative actions within the platform are logged with tamper-evident audit records. Administrative sessions time out after inactivity and require re-authentication.
Decommissioning. When an administrator leaves your organization or changes roles, disable their access in your identity provider; federated access to the platform ends immediately. Contact security@cahillswift.com to request removal of residual account records or a report of a departed administrator's audit history.
General configuration recommendations
-
Access the platform only via HTTPS at its official service address; the platform does not serve unencrypted connections.
-
Restrict user provisioning to your organization's identity provider group assignments rather than individual invitations, where supported.
-
Direct any suspected security issue to security@cahillswift.com.
-
Questions
For configuration assistance or documentation requests: security@cahillswift.com · 617-314-9208