Submit Documents and Understand Security
Purpose: This guide outlines the platform's security compliance. It also provides the mandatory technical rules for preparing and uploading all file submissions.
Table of Contents
1. Prepare Documents for Upload
2. Review Supported Security Classifications
3. Review Platform Security and Compliance
Before You Start
Make sure you know the following mandatory rules and technical limits for all file uploads:
- Tagging Prerequisite: Tag all evidence documents (PDFs) before uploading them to Symphony. Tagging must be done outside of Symphony. See the Manage Your Company's Projects and Tagging guide for full instructions.
- Files must be under 20MB (unless specified otherwise by the solicitation).
- File names cannot exceed 250 characters.
- Prohibited: Classified or encrypted documents are strictly prohibited.
Exception: Password-protected documents must be approved by the requesting agency.
Document Status Color Key
The file folder icons use color-coding to indicate their current status.
| Folder Color | Status | Meaning |
| Orange | Documents Present | The folder contains one or more uploaded files. |
| Gray | Empty | The folder is currently empty; no files have been uploaded. |
| White | Open/Active View | The folder is currently open or selected by the user. |
Steps
1. Prepare Documents for Upload
You must follow specific technical and formatting rules before uploading files to the system.
- Files must be uploaded in Portable Document Format (.pdf) or the specific file type requested by the solicitation.
- Do not combine multiple files into a "zip" folder. Files must be uploaded individually.
- Files must be uploaded directly from your computer. Drag-and-drop from cloud storage (like SharePoint or Google Drive) is not supported.

Document upload window showing a file attachment and a size limit warning.
2. Review Supported Security Classifications
The system handles sensitive government data and restricts certain file types.
- Supported Documents: You may submit documents marked as:
- CUI (Controlled Unclassified Information)
- FOUO (For Official Use Only)
- SBU (Sensitive but Unclassified)
- Prohibited Documents: Classified or encrypted documents are not permitted.

Document library view showing read-only files.
3. Review Platform Security and Compliance
Symphony follows federal security standards to protect and manage your data.
- The platform is hosted on cloud.gov with a Federal Information Security Modernization Act (FISMA) Moderate ATO (Authorization to Operate).
- All data is protected by encryption in transit and at rest.
Compliance visualization showing the text 'FISMA Moderate ATO' and data protected by encryption on a cloud server.
Troubleshooting
Issue | Fix |
File attachment fails to upload. | Check the file size (must be under 20MB) and ensure the file name is under 250 characters. |
You receive an encryption error message. | You must ensure the file is not password-protected or encrypted before uploading. |
You need to upload files from a SharePoint link. | You must download the file to your computer first, and then upload it directly from your local drive. |
You need to see more detail on security protocols. | Contact the GSA National Customer Service Center for assistance. |
Related Articles / Links
- Manage Your Company's Projects and Tagging—Mandatory guide on tagging documents before upload
- GSA National Customer Service Center—For detailed security protocol inquiries
- Submit a Ticket to the Symphony Help Desk—For technical issues
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article