HoundShieldHoundShield
Products
Products by Industry

One firewall · every compliance framework · one deployment

TechnologySOC 2

Engineers pasting API keys & source into Copilot.

HealthcareHIPAA

Clinicians pasting PHI into AI for documentation.

DefenseCMMC L2

DoD contractors leaking CUI into proposal tools.

Legal & FinancePCI

Privileged client data shared with AI assistants.

Five EyesAUKUS

Allied suppliers navigating DISP & Essential 8.

GovernmentSoon

FedRAMP / FISMA — agency AI governance.

SOC 2 · HIPAA · CMMC L2 · 16 engines · <10msAll capabilities
Features
Core Capabilities

Inside the HoundShield firewall engine

AI Prompt Interception

Every LLM request inspected before it leaves the network.

16 Detection Engines

CUI, PII, IP, PHI, secrets, CAGE codes, clearances.

Immutable Audit Trail

SHA-256 tamper-evident logs. C3PAO-ready.

Live Threat Dashboard

Real-time blocked prompts, risk & posture.

Pricing
Pricing

All frameworks included in every plan

Free

Up to 1,000 prompts/mo

$0/mo
Pro

CMMC suite + AI gateway

$199/mo
Growth

PDF reports + C3PAO coord

$499/mo
Enterprise

On-prem · air-gapped

$999/mo
Compare all plans
Partners
Partner Program

Build & grow with HoundShield

RPO / MSP Referral

Co-brand the $499 report · keep the margin.

MSP / Agency

40% per report · 20% recurring · white-label.

Integrations

Drop-in proxy for ChatGPT, Copilot, Claude.

Docs
Documentation

Live in under 5 minutes · no code changes

Quickstart

One URL change → full compliance.

API Reference

Gateway, classifier & audit endpoints.

FAQ

Searchable answers — pricing, HIPAA, CUI.

16 engines · <10ms scan
Sign inStart free

NIST 800-171 Controls · Audit & Accountability

AU.2.007 — Provide System Clock Capability for Audit Timestamps

CMMC Level 2SPRS if unmet: -1MEDIUM priority~2h to implement

Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.

What AU.2.007 means in plain English

If your computer clock is 20 minutes off, your audit logs become useless for investigations because you cannot line up events across different systems. Windows Time (W32tm) can automatically sync your computers to NIST time servers or Microsoft time servers for free. This is a 5-minute configuration change, but many small shops never do it deliberately—their computers drift. This control simply requires you to configure NTP time sync on every system and document that it is working.

The assessment question

“Are all systems that generate audit records configured to synchronize their clocks to an authoritative NTP time source (e.g., time.nist.gov or time.windows.com), and is there evidence this synchronization is active?”

How to implement AU.2.007

  1. On every Windows workstation and server, verify NTP sync: open Command Prompt as Administrator and run "w32tm /query /status". The output should show a time source (e.g., time.windows.com or time.nist.gov) and a Last Successful Sync Time.
  2. If NTP is not configured or syncing to a reliable source, set it: run "w32tm /config /manualpeerlist:time.nist.gov /syncfromflags:manual /reliable:YES /update" followed by "net stop w32tm && net start w32tm && w32tm /resync".
  3. In a domain environment (Active Directory), configure the PDC Emulator domain controller to sync with an external NTP source; all domain members will automatically sync from it. Use Group Policy: Computer Configuration > Administrative Templates > System > Windows Time Service.
  4. Verify network devices (firewall/router) are also NTP-synchronized. Most consumer-grade routers support NTP in their admin panel—set the NTP server to time.nist.gov.
  5. Document the NTP configuration with a screenshot of "w32tm /query /status" output from each system showing it is actively synced, and store in your CMMC evidence folder under "AU — Time Synchronization."

Evidence your assessor will ask for

  • Output of "w32tm /query /status" from each system showing active NTP sync and time source
  • Group Policy or local policy configuration showing NTP server settings
  • Screenshot of network device (router/firewall) NTP configuration
  • Written procedure for checking NTP sync as part of regular maintenance

Does AI prompt monitoring help with this control? Honestly, no.

AU.2.007 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.

Full mapping: which 800-171 controls AI prompt monitoring evidences →

More Audit & Accountability controls

AU.2.001

Create and Retain System Audit Logs

AU.2.002

Ensure User Accountability Through Unique Identifiers

AU.2.003

Review and Update Logged Events

AU.2.004

Alert on Audit Logging Process Failure

AU.2.005

Correlate Audit Review, Analysis, and Reporting

AU.2.006

Provide Audit Record Reduction and Report Generation

Score yourself against all 110 controls

The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.

Start the free assessment $499 AI risk assessment
HoundShieldHoundShield

Local-only AI compliance firewall for CMMC Level 2, HIPAA & SOC 2. Prompt content never leaves your network.

CMMC LVL 2HIPAASOC 2NIST 800-171DFARS 7012
Product
FeaturesHow it worksPricingCompareDashboardChangelog
Compliance
CMMC Level 2HIPAASOC 2NIST 800-171DFARS 7012
Company
PartnersDocumentationFAQContact salesAboutSecurity
© 2026 HoundShield. All rights reserved. · Privacy · Termshoundshield.com · local-only · zero data exfiltration