HoundShieldHoundShield
Products
Products by Industry

One firewall · every compliance framework · one deployment

TechnologySOC 2

Engineers pasting API keys & source into Copilot.

HealthcareHIPAA

Clinicians pasting PHI into AI for documentation.

DefenseCMMC L2

DoD contractors leaking CUI into proposal tools.

Legal & FinancePCI

Privileged client data shared with AI assistants.

Five EyesAUKUS

Allied suppliers navigating DISP & Essential 8.

GovernmentSoon

FedRAMP / FISMA — agency AI governance.

SOC 2 · HIPAA · CMMC L2 · 16 engines · <10msAll capabilities
Features
Core Capabilities

Inside the HoundShield firewall engine

AI Prompt Interception

Every LLM request inspected before it leaves the network.

16 Detection Engines

CUI, PII, IP, PHI, secrets, CAGE codes, clearances.

Immutable Audit Trail

SHA-256 tamper-evident logs. C3PAO-ready.

Live Threat Dashboard

Real-time blocked prompts, risk & posture.

Pricing
Pricing

All frameworks included in every plan

Free

Up to 1,000 prompts/mo

$0/mo
Pro

CMMC suite + AI gateway

$199/mo
Growth

PDF reports + C3PAO coord

$499/mo
Enterprise

On-prem · air-gapped

$999/mo
Compare all plans
Partners
Partner Program

Build & grow with HoundShield

RPO / MSP Referral

Co-brand the $499 report · keep the margin.

MSP / Agency

40% per report · 20% recurring · white-label.

Integrations

Drop-in proxy for ChatGPT, Copilot, Claude.

Docs
Documentation

Live in under 5 minutes · no code changes

Quickstart

One URL change → full compliance.

API Reference

Gateway, classifier & audit endpoints.

FAQ

Searchable answers — pricing, HIPAA, CUI.

16 engines · <10ms scan
Sign inStart free

NIST 800-171 Controls · Access Control

AC.2.020 — Verify and Control Connections to External Systems

CMMC Level 2SPRS if unmet: -1MEDIUM priority~6h to implement

Verify and control/limit connections to external systems.

What AC.2.020 means in plain English

When your employees connect company devices to external networks or systems — like using their work laptop on a coffee shop Wi-Fi, connecting to a customer's network, or accessing a cloud service not approved by your company — you need rules around that. Company devices that handle CUI should only connect to trusted, known networks, and there should be a process for approving connections to outside systems.

The assessment question

“Do you have a policy and technical controls that restrict company computers and devices (especially those that handle CUI) from connecting to untrusted external networks without protection — for example, requiring VPN use when on public Wi-Fi, maintaining a list of approved cloud services, and prohibiting CUI work on personal or guest networks?”

How to implement AC.2.020

  1. Establish a written policy requiring employees to use the company VPN whenever working on any non-company network (hotel, coffee shop, client site). The VPN encrypts traffic and routes it through your controlled gateway.
  2. Create an approved cloud services list: document which cloud services employees are authorized to use for work (Microsoft 365 GCC, specific approved SaaS tools) and prohibit use of unauthorized services for CUI (personal Dropbox, personal Google Drive, WeTransfer, etc.).
  3. Enable Microsoft Defender's "Network Protection" feature to block connections to known malicious sites: in Windows Security > Virus and Threat Protection > Virus and Threat Protection Settings, enable Cloud-delivered protection and Automatic sample submission.
  4. Use Microsoft 365 Conditional Access to require that company devices be compliant (enrolled in Intune, up to date) before accessing Microsoft 365 resources — this prevents unmanaged or personal devices from accessing CUI in the cloud.
  5. Conduct a quarterly review of which cloud services are being used: Microsoft 365 GCC Defender for Cloud Apps can generate a Cloud Discovery report showing all cloud services accessed from your network.

Evidence your assessor will ask for

  • Written External Connection Policy or Acceptable Use Policy listing approved and prohibited external services
  • VPN usage policy and evidence that VPN is deployed and required for remote work
  • Approved cloud services list with authorization documentation
  • Conditional Access policy screenshots (if using M365)
  • Cloud Discovery report showing controlled cloud service usage (if available)

Does AI prompt monitoring help with this control? Yes — directly.

AC.2.020 is one of the requirements a local AI prompt firewall concretely evidences. When employees send prompts to ChatGPT, Copilot, or Claude, that traffic crosses your external boundary — HoundShield inspects it on your own infrastructure (self-hosted Docker, Mode B), blocks CUI patterns before transmission, and writes every allowed/blocked event to a SHA-256 hash-chained log attributable to the user. Architecture diagram, active pattern set, and a log sample are the evidence an assessor tests this against for the AI data path.

Full mapping: which 800-171 controls AI prompt monitoring evidences →

More Access Control controls

AC.1.001

Limit System Access to Authorized Users

AC.1.002

Limit System Access to Authorized Transaction Types

AC.2.003

Control CUI Flow per Authorizations

AC.2.004

Separate Duties to Reduce Risk

AC.2.005

Employ Least Privilege

AC.2.006

Use Non-Privileged Accounts for Non-Security Functions

Score yourself against all 110 controls

The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.

Start the free assessment $499 AI risk assessment
HoundShieldHoundShield

Local-only AI compliance firewall for CMMC Level 2, HIPAA & SOC 2. Prompt content never leaves your network.

CMMC LVL 2HIPAASOC 2NIST 800-171DFARS 7012
Product
FeaturesHow it worksPricingCompareDashboardChangelog
Compliance
CMMC Level 2HIPAASOC 2NIST 800-171DFARS 7012
Company
PartnersDocumentationFAQContact salesAboutSecurity
© 2026 HoundShield. All rights reserved. · Privacy · Termshoundshield.com · local-only · zero data exfiltration