Logo

TechnoMile Responsibility Matrices: Detailed

Understanding who is responsible for what is foundational to a strong security and compliance posture. TechnoMile offers multiple deployment options across our product suites – each with a clear division of security responsibilities designed to support your organization's FedRAMP and CMMC compliance objectives.

The matrices below provide a more detailed view of the division of security responsibilities for each TechnoMile product offering and deployment option. For additional information – including requests for Body of Evidence and 3PAO assessment details – contact your TechnoMile Sales Representative or Customer Success Manager.

Growth & Contracts Suite Deployments

TechnoMile's Growth and Contracts Suites include products and services that are deployed on our proprietary TechnoMile GovCloud Platform as well as on top of either Salesforce or Microsoft Dynamics 365 in the CSP (Cloud Service Provider) environment. Together, these environments deliver end-to-end support for compliance with federal cybersecurity mandates. Learn more below.

TechnoMile GovCloud Platform

TechnoMile products and services in this environment include: ElevateAI Service, Transform Copilot, GovSearchAI, and GovSearch NoticesIQ. TechnoMile GovCloud Platform is hosted in a FedRAMP High Authorized AWS environment. TechnoMile implements and operates controls directly, following NIST 800-53 Rev. 5., and has attained FedRAMP Moderate Equivalency with a 3PAO-validated Body of Evidence.

Responsibility Matrix for TechnoMile GovCloud Platform - Detailed

Functional Area TechnoMile's Role Customer's Role
Access & authentication setup Owns identity infrastructure, MFA enforcement, session controls, and authentication mechanisms platform-wide None at the control level (customers federating via SSO/SAML still configure their own IdP — a configuration choice, not an assigned obligation)
User & account management Manages account lifecycle for OAuth-based users; provides the account framework, audit support, and inactivity/expiration enforcement mechanisms For SSO/SAML-integrated organizations: creates, modifies, reviews, and disables accounts in their own IdP; defines roles/conditions of use for their users
Application security configuration Owns secure baseline configuration, change control, and configuration monitoring None at the control level
Data handling & CUI controls Owns the technical safeguards: encryption, boundary protection, and the system's capability to enforce access restrictions Determines what data constitutes CUI, properly marks/labels it, and restricts which of their own users can access it (e.g., field- and record-level access configuration). TechnoMile's system can't make this determination on the customer's behalf.
Audit & monitoring Owns audit log generation, retention, protection, and review processes None at the control level
Incident response Owns incident detection, handling, and reporting for the platform Reasonable expectation to report suspected issues involving their own users — standard practice, not a formally assigned control
Vulnerability & risk management Owns vulnerability scanning, flaw remediation, and risk assessment None at the control level
Security awareness & training Owns and documents the security awareness/training program that satisfies the control Best practice for customers to train their own end users — not an assigned control
Personnel security Owns screening, vetting, and personnel security processes for TechnoMile staff/contractors with system access None at the control level
Platform deployment & maintenance Owns hosting, deployment, maintenance, physical security (via AWS), and assessment/authorization activities None at the control level

Salesforce CSP Environment

TechnoMile products and services in these environments include: Growth CRM, WinIt CRM, Pre-Award Management, Contract Lifecycle Management, and Agreement Management – deployed on Salesforce Government Cloud Plus or Salesforce Commercial Cloud. TechnoMile is certified by Salesforce to deploy into these environments and our applications undergo routine independent security assessment by Salesforce. Infrastructure-layer controls are inherited from Salesforce; TechnoMile implements application-layer controls on top.

Responsibility Matrix for Salesforce Deployment - Detailed

Functional Area TechnoMile's Role Customer's Role
Access & authentication setup Builds application-layer authentication on top of identity controls inherited from Salesforce Government Cloud Plus Customers federating via SSO/SAML configured through their own IdP
User & account management Provides the account framework within the application; supports role-based access control Creates, modifies, reviews, and disables their own users' accounts and roles, typically through their Salesforce org or federated IdP
Application security configuration Owns TechnoMile application code, secure configuration, and change control on top of the Salesforce Government Cloud Plus None at the control level
Data handling & CUI controls Owns data/CUI-handling technical safeguards built into the TechnoMile application; inherits encryption and boundary protection from the Salesforce Government Cloud Plus environment Determines what data constitutes CUI, properly marks/labels it, and restricts which of their own users can access it within the application (e.g., field- and record-level access configuration). Neither TechnoMile nor the underlying platform can make this determination on the customer's behalf.
Audit & monitoring None at the control level Customer is responsible for auditing and monitoring CRM data and account activity within their environment
Incident response Owns incident handling for the TechnoMile application Reasonable expectation to report suspected issues involving their own users — standard practice
Vulnerability & risk management Owns vulnerability management for the TechnoMile application None at the control level
Security awareness & training Owns TechnoMile's internal training program Best practice for customers to train their own end users
Personnel security None at the control level Owns screening and vetting for internal personnel with system access
Platform deployment & maintenance Owns application deployment and maintenance; hosting, physical security, and infrastructure maintenance are inherited from Salesforce Government Cloud Plus None at the control level

Microsoft CSP Environment

TechnoMile products and services in these environments include: Growth CRM, WinIt CRM, Pre-Award Management, Contract Lifecycle Management, and Agreement Management – deployed on Microsoft Azure Government. TechnoMile is certified by Microsoft to deploy into this environment and our applications undergo routine independent security assessment by Microsoft. Infrastructure-layer controls are inherited from Microsoft; TechnoMile implements application-layer controls on top.

Responsibility Matrix for Microsoft Deployment - Detailed

Functional Area TechnoMile's Role Customer's Role
Access & authentication setup Builds application-layer authentication on top of identity controls inherited from Microsoft Azure Government Customers federating via SSO/SAML configured through their own IdP
User & account management Provides the account framework within the application; supports role-based access control. Creates, modifies, reviews, and disables their own users' accounts and roles, typically through their M365 tenant or federated IdP
Application security configuration Owns TechnoMile application code, secure configuration, and change control on top of the Microsoft Azure Government None at the control level
Data handling & CUI controls Owns data/CUI-handling technical safeguards built into the TechnoMile application; inherits encryption and boundary protection from the Microsoft Azure Government environment Determines what data constitutes CUI, properly marks/labels it, and restricts which of their own users can access it within the application (e.g., field- and record-level access configuration). Neither TechnoMile nor the underlying platform can make this determination on the customer's behalf.
Audit & monitoring None at the control level. Customer is responsible for auditing and monitoring CRM data and account activity within their environment
Incident response Owns incident handling for the TechnoMile application Reasonable expectation to report suspected issues involving their own users — standard practice
Vulnerability & risk management Owns vulnerability management for the TechnoMile application. None at the control level
Security awareness & training Owns TechnoMile's internal training program. Best practice for customers to train their own end users
Personnel security None at the control level. Owns screening and vetting for internal personnel with system access
Platform application deployment & maintenance Owns application deployment and maintenance; hosting, physical security, and infrastructure maintenance are inherited from Microsoft Azure Government None at the control level

SIMS Suite Deployments

TechnoMile's SIMS Suite includes products and services that can be hosted either in the SIMS Cloud – a CMMC Level 2 certified environment – or on-prem in the client's own environment, depending on each client's IT resources, operational preferences, and compliance needs. Learn more below.

SIMS Cloud 

TechnoMile products and services in this environment can include: SIMS, SIMS Employee Portal, SIMS Lobby, SIMS Workflow, and SIMS Dashboards. SIMS Cloud is hosted in a FedRAMP High Authorized AWS environment. SIMS Cloud implements and operates controls directly, following NIST 800-171 Rev. 2., and has attained CMMC Level 2 certification with a 3PAO-validated Body of Evidence.

Responsibility Matrix for SIMS Cloud - Detailed

Download Detailed Matrix

SIMS On-Prem Deployment

TechnoMile products and services deployed in this environment can include: SIMS, SIMS Employee Portal, SIMS Lobby, SIMS Workflow, and SIMS Dashboards.

With on-premises deployment, organizations host SIMS within their own infrastructure and are responsible for maintaining security compliance in accordance with their applicable security programs and requirements.