Logo

Security & Trust

TechnoMile is committed to maintaining our clients’ trust, keeping your data safe, and supporting your compliance with federal cybersecurity mandates. 

Flexible, Secure Deployment Options

Built for Compliance, Clear on Responsibility

Understanding who is responsible for what is foundational to a strong security and compliance posture. TechnoMile offers multiple deployment options across our product suites – each with a clear division of security responsibilities designed to support your organization's FedRAMP and CMMC compliance objectives.

Our CRM and CLM applications run on our proprietary TechnoMile GovCloud Platform alongside Salesforce or Microsoft Dynamics 365, pairing our own secure infrastructure with industry-leading, FedRAMP and CMMC certified platforms. SIMS Suite products can be deployed in SIMS Cloud – a CMMC Level 2 certified environment managed by TechnoMile – or on-premises within your own infrastructure. The responsibility matrices available below give your security and compliance teams the clarity they need, no matter which deployment path you choose.

Reponsibility Matrices

Growth & Contracts Suite Deployments

TechnoMile's Growth and Contracts Suites include products and services that are deployed on our proprietary TechnoMile GovCloud Platform as well as on top of either Salesforce or Microsoft Dynamics 365 in the CSP (Cloud Service Provider) environment. Together, these environments deliver end-to-end support for compliance with federal cybersecurity mandates. Learn more below.

TechnoMile GovCloud Platform

TechnoMile products and services in this environment include: ElevateAI Service, Transform Copilot, GovSearchAI, and GovSearch NoticesIQ. TechnoMile GovCloud Platform is hosted in a FedRAMP High Authorized AWS environment. TechnoMile implements and operates controls directly, following NIST 800-53 Rev. 5., and has attained FedRAMP Moderate Equivalency with a 3PAO-validated Body of Evidence.

Responsibility Matrix for TechnoMile GovCloud Platform - At a Glance

TechnoMile Customer
Access & authentication setup
User & account management
Application security configuration
Data handling & CUI controls
Audit & monitoring
Incident response
Vulnerability & risk management
Security awareness & training
Personnel security
Platform deployment & maintenance

View Detailed Matrix

Salesforce CSP Environment

TechnoMile products and services in these environments include: Growth CRM, WinIt CRM, Pre-Award Management, Contract Lifecycle Management, and Agreement Management – deployed on Salesforce Government Cloud Plus or Salesforce Commercial Cloud. TechnoMile is certified by Salesforce to deploy into these environments and our applications undergo routine independent security assessment by Salesforce. Infrastructure-layer controls are inherited from Salesforce; TechnoMile implements application-layer controls on top.

Responsibility Matrix for Salesforce Deployment - At a Glance

TechnoMile Customer
Application Access & authentication setup
User & account management
Application security configuration
Data handling & CUI controls
Audit & monitoring
Incident response
Vulnerability & risk management
Security awareness & training
Personnel security
Application deployment
CRM Administration & Maintenance

View Detailed Matrix

Microsoft CSP Environment

TechnoMile products and services in these environments include: Growth CRM, WinIt CRM, Pre-Award Management, Contract Lifecycle Management, and Agreement Management – deployed on Microsoft Azure Government. TechnoMile is certified by Microsoft to deploy into this environment and our applications undergo routine independent security assessment by Microsoft. Infrastructure-layer controls are inherited from Microsoft; TechnoMile implements application-layer controls on top.

Responsibility Matrix for Microsoft Deployment - At a Glance

TechnoMile Customer
Application Access & authentication setup
User & account management
Application security configuration
Data handling & CUI controls
Audit & monitoring
Incident response
Vulnerability & risk management
Security awareness & training
Personnel security
Platform Application deployment
CRM Administration & Maintenance

View Detailed Matrix

SIMS Suite Deployments

TechnoMile's SIMS Suite includes products and services that can be hosted either in the SIMS Cloud – a CMMC Level 2 certified environment – or on-prem in the client's own environment, depending on each client's IT resources, operational preferences, and compliance needs. Learn more below.

SIMS Cloud 

TechnoMile products and services in this environment can include: SIMS, SIMS Employee Portal, SIMS Lobby, SIMS Workflow, and SIMS Dashboards. SIMS Cloud is hosted in a FedRAMP High Authorized AWS environment. SIMS Cloud implements and operates controls directly, following NIST 800-171 Rev. 2., and has attained CMMC Level 2 certification with a 3PAO-validated Body of Evidence.

Responsibility Matrix for SIMS Cloud - At a Glance

TechnoMile Customer
Access & authentication setup
User & role management
Application security configuration
Data handling & CUI controls
Audit & monitoring
Incident response
Vulnerability & risk management
Security awareness & training
Personnel security
Platform deployment & maintenance

View Detailed Matrix

SIMS On-Prem Deployment

TechnoMile products and services in this environment can include: SIMS, SIMS Employee Portal, SIMS Lobby, SIMS Workflow, and SIMS Dashboards.

With on-premises deployment, organizations host SIMS within their own infrastructure and are responsible for maintaining security compliance in accordance with their applicable security programs and requirements.

Commitment to Information Security

Security Policies & Procedures

TechnoMile is committed to maintaining our clients’ trust and keeping data secured. We maintain a written Information Security Program that is overseen by our Chief Information Officer and outlines the administrative, technical, and physical safeguards that we employ to protect our systems and ensure data security, integrity, and availability.

  • .01

    TechnoMile maintains a SOC 2 Type II attestation – a copy of the report may be obtained under NDA through TechnoMile’s Trust Center 

  • .02

    TechnoMile maintains an Information Security Program based on SOC 2 that aligns to NIST 800-171 security controls

  • .03

    TechnoMile performs internal and third-party penetration testing on production infrastructure

  • .04

    TechnoMile deploys our TechnoMile Platform and Services into FedRAMP-authorized cloud environments based on data types and compliance requirements

  • .05

    TechnoMile maintains formal IT security policies and procedures that:

    • Guide our collection, storage, and maintenance of personally identifiable information (PII) to protect PII from unauthorized disclosure 

    • Protect the physical and logical integrity of our IT resources by establishing standards for network security, protection against malicious software programs, connecting devices to the network, remote access, event monitoring, etc. 

    • Outline standards – such as user authorization/access requests, password policies, anti-virus software use, application of software updates, vulnerability management, encryption of storage devices, etc. – to appropriately secure IT systems, network resources, and applications 

    • Require all TechnoMile employees to participate in annual information security awareness training

  • .06

    TechnoMile Utilizes a secure Microsoft 365 cloud environment that complies with a broad range of legal and regulatory standards to manage its infrastructure and data, leveraging the Microsoft 365 compliance center, as well as Microsoft 365 intelligent security solutions for identity and access management, threat protection, information protection, and security management  

  • .07

    Partners with top-tier cloud services provider, Amazon Web Services (AWS), to host our TechnoMile Platform and Services in an environment that includes physical and logical protections and delivers robust performance and reliability:

    • Dual Next-Generation Firewalls from Cisco in high-availability routing  

    • Multiple layers of network security controls, including policy-based-routing (PBR), Web Application Firewall (WAF), and Intrusion-Detection/Intrusion-Prevention Systems (IDS/IPS) 

    • Advanced asymmetric encryption for protection of in-transit data from end-to-end 

    • At-rest data encryption of personally identifiable information (PII) to achieve a high level of data protection   

    • Real-time, continuous security monitoring 

    • State-of-the-art hosting facilities with availability zones to support automatic fail-over, environmental protections like fully redundant power systems, temperature/climate control, and protection against fire and water damage, as well as N+1 core applications 

    • Use of standardized, proven server configurations underpinned by optimized hardware results in predictable, stable performance 

    • Predictive high-availability and hot spare hardware delivers improved availability