scm.cc / FedRAMP 20x KSIs

How scm.cc handles trust

Plain statements of what the product does, taken from its documented behavior. This page makes no certification, authorization or compliance claim.

Read-only connections

Source connections (cloud, code and database security tools) are read-only. Credentials are validated before anything is stored and encrypted at rest (AES-256-GCM).

Auditor access

An organization owner or admin can mint a read-only Auditor API token. Only a hash of the token is stored, every read is access-logged and visible to members, and a revoked token stops working immediately.

Evidence you can check

Monthly continuous-monitoring runs pin their inputs with tamper-evident hashes and can be replayed. Evidence coverage is reported as coverage, not as a compliance verdict.

Sourced references

The FedRAMP 20x indicator list is pinned to the official page and checked weekly for changes. Every indicator has its own page: all 46 Key Security Indicators.

Per-organization trust pages are published by each organization from its own account and are opt-in.