Secure Configuration Guide
How to securely configure and use your account, projects, and data on CAVATICA.
-
Accounts and administration
- CAVATICA does not provide a customer organizational administrator role. You create and manage your own account — see Sign up for CAVATICA and Account settings. The highest customer privilege on the platform is project Admin.
- Accounts should belong to named individuals. Do not share your credentials.
- When a member leaves your organization or project, a project administrator should remove them from your projects; users can manage or close their own account from Account settings.
- Administrative functions above the project level (account management and monitoring) are performed by Velsera staff through an internal administrative console and are covered by the platform’s FedRAMP security controls. Contact Support for organizational requests.
FedRAMP’s Secure Configuration Guide rules cover several categories of guidance. The following records which elements apply to CAVATICA and why:
2. Applicability of FedRAMP guide elements
| Guide element | Applicability | Basis |
|---|---|---|
| Top-level administrative accounts (customer organization) | Not applicable | CAVATICA does not provide a customer organizational administrator role. FedRAMP defines a top-level administrative account as the most privileged account for a customer organization; no such account exists on this platform. Administrative functions above the project level are performed by Velsera under the platform’s FedRAMP security controls. |
| Security settings operable only by top-level administrative accounts | Not applicable | No customer-operable settings of this kind exist on the platform. |
| Centralized (organization-wide) MFA enforcement | Not applicable | Enabling and enforcing MFA is the responsibility of customer organizations and their users; the platform does not provide centralized enforcement. eRA Commons logins are authenticated by the identity provider, which applies its own MFA. |
| Project and volume permissions, download/export controls, secure defaults, publication, change log | Applicable | Covered in the sections below. |
-
Authentication
- You can log in with an eRA Commons account or a dedicated CAVATICA account — see Sign up for CAVATICA.
- We recommend enabling multi-factor authentication on your account — see Set up two-factor authentication. Enabling and enforcing MFA is the responsibility of your organization and its users; the platform does not enforce it centrally.
- eRA Commons logins are authenticated by the identity provider, which applies its own multi-factor authentication; the platform’s MFA option does not apply to those sessions.
- Passwords for CAVATICA accounts are screened against lists of common and breached passwords at sign-up.
-
Project permissions
New project members receive permissions set by the project Admin/Owner. “Read” is the minimal permission granted. When adding a member, Write, Copy and Execute are pre-selected by default — review these and grant only what the member needs before saving.
- Grant members only the permissions they need for their role in the project.
- Read shows file names and metadata only. Copy lets a member view file content and download files. Write allows modifying and deleting project files and workflows. Execute runs analyses billed to the project. Admin can change other members’ permissions and add members.
Procedures: Set permissions
-
Data download and export controls
- File downloads are unrestricted by default. The download restriction can only be chosen when a project is created and cannot be reverted — enable it for projects holding controlled-access data. To cover Data Studio as well, also block network access.
- Write access to a volume allows exporting files out of the platform. Grant it only to members authorized to move data off the platform.
-
Secure defaults
Setting Default Operated by New project member permissions Write, Copy, Execute pre-selected when adding a member (“Read” always granted; Admin not granted by default) — set by the project Admin/Owner Project Admin/Owner File downloads Unrestricted Project creator (at creation, irreversible) Multi-factor authentication Opt-in per user; eRA Commons logins carry the identity provider’s MFA Each user Password breach screening On Platform (not configurable) -
Reporting a security issue
If you believe you have found a security vulnerability or suspect your account has been compromised, contact Velsera Security immediately at [email protected].
-
Change log
Date Change Until 2026-08-16 Guidance previously distributed across individual documentation pages. 2026-08-16 Revised version; aligned content as per template, determinations and security contact added.
Updated about 1 hour ago
Did this page help you?
