Secure Configuration Guide

How to securely configure and use your account, projects, and data on BioData Catalyst powered by Seven Bridges.

  1. Accounts and administration

    BioData Catalyst does not provide a customer organizational administrator role. You create and manage your own account — see Sign up for BioData Catalyst powered by Seven Bridges and Account settings. The highest customer privilege on the platform is project Admin.
  • Accounts should belong to named individuals. Do not share your credentials.
  • When a member leaves your organization or project, a project administrator should remove them from your projects; users can manage or close their own account from Account settings.
  • Administrative functions above the project level (account management and monitoring) are performed by Velsera staff through an internal administrative console and are covered by the platform’s FedRAMP security controls. Contact Support for organizational requests.
  1. Applicability of FedRAMP guide elements

    FedRAMP’s Secure Configuration Guide rules cover several categories of guidance. The following records which elements apply to BioData Catalyst and why:
Guide elementApplicabilitybasis
Top-level administrative accounts (customer organization)Not applicableBioData Catalyst does not provide a customer organizational administrator role. FedRAMP defines a top-level administrative account as the most privileged account for a customer organization; no such account exists on this platform. Administrative functions above the project level are performed by Velsera under the platform’s FedRAMP security controls.
Security settings operable only by top-level administrative accountsNot applicableNo customer-operable settings of this kind exist on the platform.
Centralized (organization-wide) MFA enforcementNot applicableEnabling and enforcing MFA is the responsibility of customer organizations and their users; the platform does not provide centralized enforcement. eRA Commons/Login.gov logins are authenticated by the identity provider, which applies its own MFA.
Project and volume permissions, download/export controls, secure defaults, publication, change logApplicableCovered in the sections below.

These determinations are recorded in the platform’s FedRAMP Certification Package.

  1. Authentication

    • You log in with your eRA Commons account via Login.gov — see Sign up for BioData Catalyst.
    • eRA Commons/Login.gov logins are authenticated by the identity provider, which applies its own multi-factor authentication.
    • For platform-credential sessions, we recommend enabling multi-factor authentication on your account — see Set up two-factor authentication. Enabling and enforcing MFA is the responsibility of your organization and its users; the platform does not enforce it centrally.
  2. Project permissions

    New project members receive permissions set by the project Admin/Owner. “Read” is the minimal permission granted. When adding a member, Write, Copy and Execute are pre-selected by default — review these and grant only what the member needs before saving.
  • Grant members only the permissions they need for their role in the project.
  • Read shows file names and metadata only. Copy lets a member view file content and download files. Write allows modifying and deleting project files and workflows. Execute runs analyses billed to the project. Admin can change other members’ permissions and add members.

Procedures: Project permissions

  1. Data download and export controls

    • File downloads are unrestricted by default. The download restriction, found under Advanced settings in Modify project settings, cannot be reverted once applied — enable it for projects holding controlled-access data. Combined with blocked network access, it also covers the Data Studio space.
    • Write access to a volume allows exporting files out of the platform. Grant it only to members authorized to move data off the platform — see Security concerns when working with volumes.
  2. Secure defaults

SettingDefaultOperated by
New project member permissionsWrite, Copy, Execute pre-selected when adding a member (“Read” always granted; Admin not granted by default) — set by the project Admin/OwnerProject Admin/Owner
File downloadsUnrestrictedProject creator (at creation, irreversible)
Multi-factor authenticationeRA Commons/Login.gov logins carry the identity provider’s MFA; platform MFA opt-in per userPassword breach screening
Password breach screeningOnPlatform (not configurable)

  1. Reporting a security issue

    If you believe you have found a security vulnerability or suspect your account has been compromised, contact Velsera Security immediately at [email protected].
  2. Change log


DateChange
Until 2026-08-16Guidance previously distributed across individual documentation pages.
2026-08-16Revised version; aligned content as per template, determinations and security contact added.