HoundShieldHoundShield
Products
Products by Industry

One firewall · every compliance framework · one deployment

TechnologySOC 2

Engineers pasting API keys & source into Copilot.

HealthcareHIPAA

Clinicians pasting PHI into AI for documentation.

DefenseCMMC L2

DoD contractors leaking CUI into proposal tools.

Legal & FinancePCI

Privileged client data shared with AI assistants.

Five EyesAUKUS

Allied suppliers navigating DISP & Essential 8.

GovernmentSoon

FedRAMP / FISMA — agency AI governance.

SOC 2 · HIPAA · CMMC L2 · 16 engines · <10msAll capabilities
Features
Core Capabilities

Inside the HoundShield firewall engine

AI Prompt Interception

Every LLM request inspected before it leaves the network.

16 Detection Engines

CUI, PII, IP, PHI, secrets, CAGE codes, clearances.

Immutable Audit Trail

SHA-256 tamper-evident logs. C3PAO-ready.

Live Threat Dashboard

Real-time blocked prompts, risk & posture.

Pricing
Pricing

All frameworks included in every plan

Free

Up to 1,000 prompts/mo

$0/mo
Pro

CMMC suite + AI gateway

$199/mo
Growth

PDF reports + C3PAO coord

$499/mo
Enterprise

On-prem · air-gapped

$999/mo
Compare all plans
Partners
Partner Program

Build & grow with HoundShield

RPO / MSP Referral

Co-brand the $499 report · keep the margin.

MSP / Agency

40% per report · 20% recurring · white-label.

Integrations

Drop-in proxy for ChatGPT, Copilot, Claude.

Docs
Documentation

Live in under 5 minutes · no code changes

Quickstart

One URL change → full compliance.

API Reference

Gateway, classifier & audit endpoints.

FAQ

Searchable answers — pricing, HIPAA, CUI.

16 engines · <10ms scan
Sign inStart free

Answers · CMMC & AI compliance

What happens if you paste CUI into ChatGPT?

Pasting CUI into ChatGPT transmits it to OpenAI's servers — systems not authorized to hold Controlled Unclassified Information. For a defense contractor, that is a potential cyber incident under DFARS 252.204-7012, which requires rapid reporting to DoD through DIBNet within 72 hours of discovery, evidence preservation for at least 90 days, and notification up your contract chain. Deleting the chat afterward does not un-disclose the data. The right response is a scoped incident process now and a technical control that prevents the next one.

The immediate consequences, in order

  1. The data has left your covered system: OpenAI's infrastructure received the content, and depending on account settings it may be retained.
  2. The 72-hour clock may be running: if the content was CUI, DFARS 252.204-7012 directs a rapid report through DoD's DIBNet portal — which requires a medium-assurance certificate most contractors don't have on hand.
  3. Evidence must be preserved: 7012 requires preserving images of affected systems and monitoring data for at least 90 days from the report.
  4. Your prime may need to know: flowdown clauses commonly require notifying the prime contractor or contracting officer.

What deleting the conversation does and doesn't do

Submitting a deletion request and turning off chat history are sensible mitigation steps — document both. But they are mitigation, not remedy: the disclosure already happened, and your reporting obligations are triggered by the incident, not by whether the vendor still holds the data.

Preventing the next one

The corrective action assessors respect is technical: route all AI traffic through a proxy on your own infrastructure that scans prompts locally and blocks CUI patterns before transmission, writing every event to a tamper-evident log. That converts this incident's corrective action into standing evidence for flow control (3.1.3), boundary protection (3.13.1), and audit (3.3.1).

Frequently asked questions

If the content was CUI, treat it as one until scoping says otherwise. DFARS 7012 reporting turns on whether a cyber incident affected covered defense information — a disclosure to an unauthorized system qualifies. Involve counsel and your contracts team immediately.

DIBNet (dibnet.dod.mil) is DoD's portal for defense industrial base cyber incident reporting. Submitting requires a DoD-approved medium-assurance certificate — procure one before you need it, because issuance takes days the 72-hour clock does not give you.

It matters for scoping and mitigation — an account with history and training enabled has broader retention exposure — but the disclosure itself occurred at submission. Document the account type and settings in your incident record either way.

Local prompt scanning: a self-hosted proxy inspects every AI-bound prompt inside your network in under 10ms and blocks CUI patterns before they leave. Employees keep their AI tools; CUI stays inside the boundary; the log becomes assessor evidence.

Use AI without leaking CUI

HoundShield scans every AI prompt locally and blocks CUI before it leaves your network. One URL change. Under 10 minutes. C3PAO-ready.

Start free Defense overview
HoundShieldHoundShield

Local-only AI compliance firewall for CMMC Level 2, HIPAA & SOC 2. Prompt content never leaves your network.

CMMC LVL 2HIPAASOC 2NIST 800-171DFARS 7012
Product
FeaturesHow it worksPricingCompareDashboardChangelog
Compliance
CMMC Level 2HIPAASOC 2NIST 800-171DFARS 7012
Company
PartnersDocumentationFAQContact salesAboutSecurity
© 2026 HoundShield. All rights reserved. · Privacy · Termshoundshield.com · local-only · zero data exfiltration