HoundShieldHoundShield
Products
Products by Industry

One firewall · every compliance framework · one deployment

TechnologySOC 2

Engineers pasting API keys & source into Copilot.

HealthcareHIPAA

Clinicians pasting PHI into AI for documentation.

DefenseCMMC L2

DoD contractors leaking CUI into proposal tools.

Legal & FinancePCI

Privileged client data shared with AI assistants.

Five EyesAUKUS

Allied suppliers navigating DISP & Essential 8.

GovernmentSoon

FedRAMP / FISMA — agency AI governance.

SOC 2 · HIPAA · CMMC L2 · 16 engines · <10msAll capabilities
Features
Core Capabilities

Inside the HoundShield firewall engine

AI Prompt Interception

Every LLM request inspected before it leaves the network.

16 Detection Engines

CUI, PII, IP, PHI, secrets, CAGE codes, clearances.

Immutable Audit Trail

SHA-256 tamper-evident logs. C3PAO-ready.

Live Threat Dashboard

Real-time blocked prompts, risk & posture.

Pricing
Pricing

All frameworks included in every plan

Free

Up to 1,000 prompts/mo

$0/mo
Pro

CMMC suite + AI gateway

$199/mo
Growth

PDF reports + C3PAO coord

$499/mo
Enterprise

On-prem · air-gapped

$999/mo
Compare all plans
Partners
Partner Program

Build & grow with HoundShield

RPO / MSP Referral

Co-brand the $499 report · keep the margin.

MSP / Agency

40% per report · 20% recurring · white-label.

Integrations

Drop-in proxy for ChatGPT, Copilot, Claude.

Docs
Documentation

Live in under 5 minutes · no code changes

Quickstart

One URL change → full compliance.

API Reference

Gateway, classifier & audit endpoints.

FAQ

Searchable answers — pricing, HIPAA, CUI.

16 engines · <10ms scan
Sign inStart free

Answers · CMMC & AI compliance

What evidence does a C3PAO accept for AI usage?

For AI usage, C3PAO assessors accept the same categories of evidence they accept everywhere else: architecture, configuration, records, and policy. Concretely that means four artifacts — a data-flow diagram showing where AI-bound prompts are inspected relative to your boundary, the enforcement configuration (detection patterns and blocking policy), tamper-evident logs attributing allowed and blocked prompt events to individual users, and a written AI acceptable-use policy the technical control actually enforces. A control-mapped assessment report packages the first three into a single reviewable document.

The four artifacts, and what each must show

ArtifactWhat the assessor checksControls it evidences
Data-flow diagramAI traffic routes through an inspection point INSIDE your boundary — not a vendor cloud3.1.3, 3.13.1 (AC.2.003, SC.1.001)
Enforcement configurationActive CUI/PII patterns and a blocking (not just alerting) policy3.1.3, 3.1.22
Tamper-evident event logAllowed AND blocked prompts, per-user attribution, integrity protection (e.g. hash chain)3.3.1, 3.3.2, 3.3.8 (AU.2.001/002/008)
Signed policy + training recordsThe written rule the control enforces, acknowledged by staff3.2.x, 3.6.1

What assessors reject

Screenshots of a vendor dashboard with no data-path diagram behind them; a written AI ban with no technical enforcement (the follow-up question is always 'and what stops it?'); logs that only show blocked events with no user attribution; and any architecture where prompt content leaves the boundary to be scanned — because then the scanning service itself becomes part of the assessment scope.

The packaged version

HoundShield's $499 CMMC AI Risk Assessment produces the packaged artifact: after 14 days running on your own infrastructure (self-hosted Docker), it generates a SHA-256-signed PDF risk-scoring every AI prompt event against NIST 800-171 Rev 2 controls — the architecture, configuration, and records evidence in one document you hand across the table. Pair it with the free control-mapped AI use policy template and the four-artifact set is complete.

Frequently asked questions

No — assessors are barred from recommending products (32 CFR Part 170 conflict-of-interest rules). They evaluate whether your evidence demonstrates the controls. Any architecture that inspects AI traffic inside your boundary, blocks unauthorized flows, and produces attributable, tamper-evident records can satisfy them.

Rarely. A dashboard shows that a tool exists; the assessor needs the data-flow diagram showing where inspection happens, the configuration proving blocking is enforced, and log samples they can trace to individuals. Evidence is tested, not displayed.

Yes — a ban is a policy, and the assessor's next question is what technically enforces it and what the logs show. An unenforced ban is often weaker evidence than monitored, controlled AI usage, because it claims a control that doesn't exist.

Follow your audit-retention policy (commonly 1–3 years for 3.3.1 records). For a first assessment, assessors typically sample recent weeks — which is why a 14-day monitored baseline with a signed report is a workable starting artifact while your retention builds.

Use AI without leaking CUI

HoundShield scans every AI prompt locally and blocks CUI before it leaves your network. One URL change. Under 10 minutes. C3PAO-ready.

Start free Defense overview
HoundShieldHoundShield

Local-only AI compliance firewall for CMMC Level 2, HIPAA & SOC 2. Prompt content never leaves your network.

CMMC LVL 2HIPAASOC 2NIST 800-171DFARS 7012
Product
FeaturesHow it worksPricingCompareDashboardChangelog
Compliance
CMMC Level 2HIPAASOC 2NIST 800-171DFARS 7012
Company
PartnersDocumentationFAQContact salesAboutSecurity
© 2026 HoundShield. All rights reserved. · Privacy · Termshoundshield.com · local-only · zero data exfiltration