The Federal Risk and Authorization Management Program (FedRAMP) is a government-wide program designed to grant Cloud Service Providers, like Lucid Software, a standard approach to security and authorization.
Lucid is FedRAMP Certified at Class C (Moderate) security impact level. The Lucid FedRAMP environment enables public sector customers with heightened security needs to collaborate with confidence so they can see and build the future.
For more information about Lucid features that are FedRAMP Certified, check out our article.
Plan availability: Enterprise only.
- Read the Lucid Plans article for more information about what is available on your account or the Upgrade your Lucid account article for instructions to upgrade.
Secured features
The following features in the FedRAMP environment are disabled by default and are required to be enabled by an admin:
- Publishing
- Guest Collaborators
- Developer tools
Sharing documents and boards is secured. Users in the FedRAMP environment are able to share documents with other FedRAMP users only. To learn more about sharing, check out our Share with collaborators in Lucid article.
Admin: enable features
If you are an account owner or account admin, you can enable collaboration features by following the steps below:
- Select Admin to open the admin panel.
- Click Security from the left-side menu.
From the dropdown menu, select Sharing.
- Check the boxes next to the features to enable.
Learn more: See the Lucid admin panel: Security settings article for more information.
You can permit users on your account to use Developer tools through the Lucid admin panel. Here's how:
- Select Admin to open the admin panel.
- Click Security from the left-side menu.
From the options, select User feature controls.
-
Click the toggle next to “Allow users to unlock developer tools”.
- The toggle will move to the right to indicate it is enabled.
- Click Save changes.
Learn more: Check out our Developer tools in Lucid article or this documentation from Lucid's Developer Docs for more information.
Prepare your network for Lucid users
If you are filtering traffic by domain, you will need to allow the following domain through your firewalls or other filters:
https://*.lucidgov.app
Set up a Lucid SAML 2.0 connection
The basic information needed to set up a SAML connection in your IDP:
| SP identifier/entityID/audience restriction: | lucidchart.com |
| Sign on URL: | https://lucidgov.app/saml/sso/<yourdomain> |
| ACS/Reply URL primary Index = 0: | https://lucidgov.app/saml/sso/<yourdomain> |
| SSO Service Binding: | We default to POST, but can work with REDIRECT (please contact us if you are using REDIRECT) |
| Digest Algorithm: | SHA-256 |
| nameID: | We prefer working with email, but can work with other values |
In compliance with FedRAMP requirements, we offer assertion encryption for SAML identity providers you add to your Lucid GovSuite account. To learn more, refer to our SAML overview article.
Attribute Statement
The Attribute Statement table found in our SAML overview article provides the values that you should use.
FAQ
What is Lucid's FedRAMP authorization status?
Lucid is designated as FedRAMP Certified at Class C (Moderate) security impact level. Lucid is listed on the FedRAMP Marketplace and offers Lucid GovSuite to provide government and contractor teams with a secure, cloud-based environment for visual collaboration.
What infrastructure is Lucid's FedRAMP environment built on and what does it include?
Lucid's FedRAMP environment is built on AWS GovCloud infrastructure and includes Lucid GovSuite.
How can I get access to Lucid Training Labs in the FedRAMP environment?
To remain compliant and provide a better experience, we have created a unique domain for GovCloud users to access Lucid Training Labs: govtraining.lucid.co. Before you can access Lucid Training Labs for GovCloud, an admin needs to enable access from the Lucid admin panel. Learn more and see the steps to Get access to Lucid Training Labs for GovCloud in the Lucid Community.
Give feedback on this article
Have feedback about this article? Tell us about your experience here.