HoundShieldHoundShield
Products
Products by Industry

One firewall · every compliance framework · one deployment

TechnologySOC 2

Engineers pasting API keys & source into Copilot.

HealthcareHIPAA

Clinicians pasting PHI into AI for documentation.

DefenseCMMC L2

DoD contractors leaking CUI into proposal tools.

Legal & FinancePCI

Privileged client data shared with AI assistants.

Five EyesAUKUS

Allied suppliers navigating DISP & Essential 8.

GovernmentSoon

FedRAMP / FISMA — agency AI governance.

SOC 2 · HIPAA · CMMC L2 · 16 engines · <10msAll capabilities
Features
Core Capabilities

Inside the HoundShield firewall engine

AI Prompt Interception

Every LLM request inspected before it leaves the network.

16 Detection Engines

CUI, PII, IP, PHI, secrets, CAGE codes, clearances.

Immutable Audit Trail

SHA-256 tamper-evident logs. C3PAO-ready.

Live Threat Dashboard

Real-time blocked prompts, risk & posture.

Pricing
Pricing

All frameworks included in every plan

Free

Up to 1,000 prompts/mo

$0/mo
Pro

CMMC suite + AI gateway

$199/mo
Growth

PDF reports + C3PAO coord

$499/mo
Enterprise

On-prem · air-gapped

$999/mo
Compare all plans
Partners
Partner Program

Build & grow with HoundShield

RPO / MSP Referral

Co-brand the $499 report · keep the margin.

MSP / Agency

40% per report · 20% recurring · white-label.

Integrations

Drop-in proxy for ChatGPT, Copilot, Claude.

Docs
Documentation

Live in under 5 minutes · no code changes

Quickstart

One URL change → full compliance.

API Reference

Gateway, classifier & audit endpoints.

FAQ

Searchable answers — pricing, HIPAA, CUI.

16 engines · <10ms scan
Sign inStart free

Answers · CMMC & AI compliance

Is ChatGPT HIPAA compliant?

No — ChatGPT is not HIPAA-compliant by default. The consumer and Plus versions offer no Business Associate Agreement (BAA), so entering protected health information (PHI) discloses it to a vendor with no HIPAA obligations — a potential reportable breach. OpenAI supports BAAs only for its API and enterprise offerings, and even then organizations must add safeguards like minimum-necessary limits, access controls, and audit trails. Most healthcare teams get compliant by blocking PHI locally before prompts leave their network.

Why consumer ChatGPT fails HIPAA

HIPAA requires a Business Associate Agreement before any third party creates, receives, maintains, or transmits PHI on a covered entity's behalf. Consumer ChatGPT has no BAA, and its terms do not contemplate PHI at all. The moment a nurse pastes a patient chart in to summarize it, PHI has been disclosed to OpenAI with no HIPAA protections attached.

This is not a fringe behavior problem. Netskope's May 2025 analysis found 81% of data policy violations in healthcare organizations involved regulated data — and generative AI prompts are one of the fastest-growing channels for it.

The paths to compliant AI use

  1. BAA-covered pathway: use OpenAI's API or enterprise offerings under a signed BAA, with minimum-necessary discipline, access controls, and audit logging layered on. A BAA is necessary but not sufficient.
  2. Block-PHI-locally pathway: keep staff on the AI tools they already use, but route traffic through a firewall running on your own infrastructure that scans each prompt for PHI markers and blocks matches before they leave the network.
  3. Most clinics combine both: a BAA-covered pathway for sanctioned workflows, and local blocking as the safety net for everything else.

Why cloud DLP tools don't solve this

A DLP product that scans your prompts in the vendor's cloud has to receive your PHI in order to protect it — which puts you back in BAA territory with the DLP vendor itself. Local scanning avoids the recursion: HoundShield's self-hosted deployment inspects prompts in under 10ms on your own infrastructure, so PHI never leaves your boundary to be checked.

Frequently asked questions

OpenAI supports Business Associate Agreements for its API and enterprise offerings on request — but a BAA covers the vendor relationship, not your workflows. You still need minimum-necessary limits, access controls, and audit trails to be defensible.

PHI sent to a vendor with no BAA is an impermissible disclosure, which triggers a four-factor breach risk assessment and potentially notification to patients and HHS. Loop in your Privacy Officer immediately and preserve the conversation record for scoping.

Policy-only bans rarely hold — staff switch to personal devices and accounts, and you lose visibility entirely. An enforced technical control that blocks PHI but allows clean prompts keeps the productivity win while making the policy real.

Dedicated ambient-scribe vendors typically sign BAAs and are purpose-built for PHI — a different risk profile from staff pasting charts into consumer chatbots. Vet the scribe's BAA and data handling, and still control what general-purpose AI tools can receive.

Use AI without leaking CUI

HoundShield scans every AI prompt locally and blocks CUI before it leaves your network. One URL change. Under 10 minutes. C3PAO-ready.

Start free Defense overview
HoundShieldHoundShield

Local-only AI compliance firewall for CMMC Level 2, HIPAA & SOC 2. Prompt content never leaves your network.

CMMC LVL 2HIPAASOC 2NIST 800-171DFARS 7012
Product
FeaturesHow it worksPricingCompareDashboardChangelog
Compliance
CMMC Level 2HIPAASOC 2NIST 800-171DFARS 7012
Company
PartnersDocumentationFAQContact salesAboutSecurity
© 2026 HoundShield. All rights reserved. · Privacy · Termshoundshield.com · local-only · zero data exfiltration