Skip to main content

Swif.ai and FedRAMP: What You Need to Know

Updated today

Swif.ai is not currently FedRAMP authorized.
However, this does not mean that your organization cannot use Swif.ai when working with government agencies or contractors—as long as you do not process Controlled Unclassified Information (CUI) or other regulated federal data through Swif.ai.


What is CUI?

Controlled Unclassified Information (CUI) refers to sensitive information that requires protection but is not classified under federal law. Examples include:

  • Law enforcement records

  • Proprietary technical data

  • Export-controlled information

When a Cloud Service Provider (CSP) handles CUI for U.S. federal entities, it may need to comply with the Federal Risk and Authorization Management Program (FedRAMP).


When FedRAMP Is NOT Required

If your organization:

  • Does not process CUI in Swif.ai, and

  • Does not use Swif.ai to store, transmit, or handle CUI, Criminal Justice Information (CJI), or International Traffic in Arms Regulations (ITAR)-controlled data,

then FedRAMP does not apply to your use of Swif.ai.


Analogy from AWS GovCloud

AWS GovCloud explains this clearly in their documentation:
You can operate workloads in GovCloud without FedRAMP as long as you do not store regulated data in unauthorized locations or fields.
For example:

  • You cannot put CUI, CJI, or ITAR-regulated details in AWS resource tags, because tags are stored in plain text and are not encrypted.

  • Similarly, with Swif.ai, avoid entering regulated data in unapproved fields or using the platform for storing such data.


Practical Guidance for Using Swif.ai with Government Entities

  • Allowed: Managing devices, enforcing security policies, tracking compliance posture for non-regulated data.

  • Not Allowed: Storing CUI, CJI, or ITAR-regulated details in Swif.ai (including in device notes, custom fields, or file uploads).

  • Recommended: Clearly separate systems that handle regulated data from systems like Swif.ai that do not require FedRAMP.


Summary

  • Swif.ai is not FedRAMP authorized at this time.

  • You can use Swif.ai for government-related work as long as no CUI or other regulated federal data is processed.

  • Always follow your agency’s or contractor’s compliance guidelines when deciding how and where to store sensitive data.

Did this answer your question?