Help center · 38 answers
Frequently asked questions
Straight answers on the $499 CMMC AI Risk Assessment Report, pricing, HIPAA, CUI-safe deployment, and Brain AI. Search below, jump to a topic, or share any answer with a deep link.
HoundShield basics
What HoundShield is, who it's for, and how fast you can start.
HoundShield is a local-only AI compliance firewall. It sits between your team and tools like ChatGPT, Copilot, and Claude, scans every prompt on your own hardware in under 10 milliseconds, blocks CUI, PHI, and PII before anything leaves your network, and writes tamper-evident audit evidence mapped to NIST 800-171.
HoundShield works as an OpenAI-compatible proxy: you change one base URL and every AI request passes through 16 local detection engines before it leaves your perimeter. Prompts containing CUI markings, CAGE codes, contract numbers, or clearance terms are blocked instantly and logged to a SHA-256 hash-chained audit trail.
No. In self-hosted Docker mode, scanning happens entirely on your infrastructure and prompt content never leaves your network — unlike cloud DLP tools, which must receive your data to inspect it. Only the hosted trial runs in our cloud, and it is for demos and non-CUI evaluation only.
HoundShield is built for regulated teams that use AI: defense contractors preparing for CMMC Level 2, healthcare organizations protecting PHI under HIPAA, and law firms guarding privileged communications. If your staff use ChatGPT, Copilot, or Claude and an auditor will ever ask for evidence, HoundShield is for you.
Most teams deploy in under 15 minutes: run the Docker gateway, point your AI tools' base URL at it, and verify a test prompt in the audit log. The free tier needs no credit card, and the $499 assessment report delivers signed evidence within days of intake.
Pricing & the $499 report
The one-time $499 CMMC AI Risk Assessment Report, plans, and the free tier.
The CMMC AI Risk Assessment Report costs $499, one time — no subscription and no signup required. We run HoundShield's proxy across 14 days of your real AI traffic and deliver a SHA-256-signed PDF that scores every prompt event against NIST 800-171, the evidence a C3PAO assessor asks for.
HoundShield subscriptions start free for self-assessment, then scale by coverage: Pro at $199/month adds the AI gateway with 50,000 scans, Growth at $499/month adds unlimited scans plus C3PAO-ready PDF evidence, and Enterprise at $999/month adds on-prem or air-gapped deployment. Annual billing saves 20% on every paid plan.
The $499 report is a one-time engagement: a 14-day scan of your AI traffic and a signed PDF deliverable, with no ongoing commitment. Growth at $499 per month is continuous coverage — unlimited live scanning, alerts, and fresh evidence exports every month. Most teams start with the report, then subscribe to stay covered.
Yes. HoundShield's free tier includes the full 110-control CMMC self-assessment, a live SPRS calculator, and scanning for up to 1,000 prompts per month — no credit card required. Paid plans add the AI gateway at scale, PDF evidence exports, more seats, and email and Slack alerts.
Not necessarily. The 110-control self-assessment is free, and Growth at $499/month adds unlimited scanning plus the C3PAO-ready PDF evidence most contractors need for a Level 2 assessment. Choose Enterprise at $999/month when you need on-prem or air-gapped deployment, white-label PDFs, or a custom SLA.
Yes. Every paid HoundShield plan can be billed annually at a 20% discount compared with month-to-month billing, and every paid plan carries a 30-day money-back guarantee. Annual billing is the typical choice for contractors and healthcare teams budgeting against a fixed compliance deadline. Contact sales for multi-tenant agency pricing.
It is a one-time $499 engagement. HoundShield's proxy runs locally in your environment for 14 days, scoring every AI prompt event against NIST 800-171 Rev 2. You receive a SHA-256-signed PDF documenting what your team sent to AI tools, which controls it implicates, and the remediation sequence.
Fourteen days of passive scanning plus a few days to compile the report. Setup is a one-URL change behind a Docker container you run yourself, so there is no disruption — your team keeps using ChatGPT, Copilot, and Claude normally while the proxy observes and scores the traffic.
Yes. The proxy runs on your own infrastructure in Mode B, so prompt content never leaves your network — we never see it. The report is built from local scan results and control mappings only, and the audit trail is SHA-256 hash-chained so evidence cannot be silently altered.
No. The report is a standalone $499 purchase with no subscription, no signup, and no procurement cycle — checkout takes a card and an email address. Many teams later add a monthly plan for continuous monitoring, but the report stands on its own as assessor-ready evidence.
The report is designed as supporting evidence: findings are mapped to specific NIST 800-171 Rev 2 controls with SPRS impact, and every event carries a tamper-evident hash. Assessors make their own judgments, but control-mapped, hash-chained documentation of AI usage is exactly the artifact they ask contractors to produce.
CMMC & getting certified
Level 2, C3PAO assessments, timelines, and what evidence you can export.
CMMC Level 2 requires organizations to implement 110 security practices from NIST SP 800-171 to protect Controlled Unclassified Information (CUI). It is mandatory for defense contractors handling CUI and, for most contracts, requires an assessment by an accredited third-party organization rather than a self-attestation alone.
Timelines vary based on your current posture, but most organizations reach CMMC Level 2 readiness in three to six months with HoundShield. The platform identifies gaps across all 110 controls instantly, provides a prioritized remediation roadmap, and tracks your SPRS score as each practice is closed.
Yes — CMMC Level 2 certification for contracts involving CUI requires an assessment by a CMMC Third-Party Assessment Organization (C3PAO). HoundShield prepares you for that assessment by running continuous self-assessments aligned to the official scoring methodology and packaging the evidence an assessor will ask to see.
The free tier includes the full 110-control CMMC self-assessment in read-only mode, a live SPRS score calculator, scanning for up to 1,000 prompts per month, and community support. Upgrading to Pro adds the AI gateway at scale, editable assessments, and SSP and POA&M generation.
Yes. Growth and Enterprise plans export audit-ready PDF reports — your System Security Plan (SSP), Plan of Action & Milestones (POA&M), and C3PAO evidence packages — while every paid plan exports JSON compliance reports. All artifacts are formatted for assessor review and carry SHA-256-signed evidence.
Prompt content never leaves your network. HoundShield scans locally: in the self-hosted Docker mode (Mode B), the CUI-safe deployment, nothing you scan is transmitted to us. The hosted trial runs on Vercel, which is not FedRAMP-authorized, so it is for non-CUI evaluation only. Audit logs are immutable and SHA-256 hash-chained, and we never train AI models on your data.
HIPAA & healthcare
Using ChatGPT with PHI, the 18 identifiers, and staying HIPAA-safe.
ChatGPT is not HIPAA compliant by default — pasting PHI into a consumer AI tool is an impermissible disclosure without a Business Associate Agreement. HoundShield lets clinical and billing staff use AI safely by detecting all 18 HIPAA identifiers in each prompt and blocking PHI before it reaches the model.
HoundShield scans every AI prompt for the 18 HIPAA Safe Harbor identifiers — names, dates, MRNs, account numbers, biometric data, and more — in under 10ms. Prompts containing PHI are blocked or quarantined before they reach ChatGPT, Copilot, or Claude, and every detection is written to an immutable audit log.
The 18 HIPAA Safe Harbor identifiers include names, geographic data smaller than a state, all date elements, phone and fax numbers, email addresses, Social Security numbers, medical record numbers, health plan beneficiary numbers, account numbers, certificate or license numbers, vehicle and device identifiers, URLs, IP addresses, biometric identifiers, full-face photos, and any other unique identifying code.
Yes. HIPAA applies whenever PHI is created, received, maintained, or transmitted — including pasting it into an AI tool. Without a signed Business Associate Agreement, sending PHI to a cloud AI provider is a reportable breach. HoundShield prevents this by scanning and blocking PHI locally before transmission.
Deployment & security
Cloud, self-hosted Docker, and air-gapped modes — and which is CUI-safe.
HoundShield offers three modes. Cloud mode is hosted for fast demos and non-CUI workloads. Self-hosted Docker mode runs entirely inside your network and is CUI-safe for defense workloads. Air-gapped mode supports IL-5+ environments with no outbound connectivity, so even isolated networks get full AI compliance scanning.
The self-hosted Docker mode is CUI-safe because all scanning happens inside your control boundary and no prompt content leaves your network. For the strictest environments, air-gapped mode runs with zero outbound connectivity. Cloud mode is for demos and non-CUI workloads only, never for Controlled Unclassified Information.
No per-machine agent is required. HoundShield works at the network proxy layer, so employees simply change one base URL in their AI tool to point at your HoundShield endpoint. Administrators deploy the gateway once with Docker, and every user is protected immediately without local installs.
Install HoundShield in three steps: deploy the gateway with Docker, point your AI tools' base URL at your HoundShield endpoint, and confirm a test prompt is scanned in your audit log. Most teams finish in under 15 minutes, and no agent needs to be installed on individual machines.
Features & scanning
Detection speed, audit logs, SPRS scoring, and supported AI models.
HoundShield scans each AI prompt in under 10 milliseconds. Detection runs locally across 16 engines, so there is no perceptible latency for users. The streamed AI response is also scanned token-by-token, so if a model begins emitting a credit-card or Social Security number mid-reply, the output is truncated before delivery.
Yes. Every scan decision is written to a tamper-evident audit trail secured with a SHA-256 hash chain, so records cannot be altered without detection. The logs map to NIST 800-171 controls and export as C3PAO-ready PDF evidence, giving assessors and auditors a defensible record of every AI interaction.
SPRS (Supplier Performance Risk System) scoring rates a contractor's NIST 800-171 implementation from -203 to +110. HoundShield automatically calculates your SPRS score across all 110 controls, shows which controls are met or missing, and produces the documentation you file in SPRS for a CMMC Level 2 self-assessment.
HoundShield works with any OpenAI-compatible API and routes approved traffic to over 800 models, including GPT, Claude, Gemini, and open-source models. Because it operates at the network proxy layer, you add new models without changing the compliance configuration or installing anything on user devices.
Brain AI copilot
The built-in compliance copilot — how it works and whether it's CUI-safe.
Brain AI is HoundShield's built-in compliance copilot. It answers CMMC, HIPAA, and SOC 2 questions, explains your SPRS score and missing controls, and guides remediation — all grounded in the 110 NIST 800-171 controls. It runs on the HERMES agent architecture inside your HoundShield deployment.
Yes. Brain AI ships with a local FAQ knowledge layer so core compliance answers and product questions work instantly even with no LLM provider configured. When an API key is present, it adds deeper reasoning, but the demo-critical answers never depend on an external model being reachable.
Brain AI continuously scores your environment against all 110 NIST 800-171 controls, flags which controls are met or missing, drafts remediation steps, and assembles C3PAO-ready evidence. It automates the repetitive assessment and documentation work so your team focuses on closing real gaps before the deadline.
Yes. Brain AI operates inside HoundShield's local-only boundary, so prompt content and compliance data never leave your network. In self-hosted and air-gapped modes all reasoning stays within your control boundary, which keeps Brain AI usable for CUI workloads that cloud assistants cannot legally touch.
Still have questions? Talk to a compliance engineer — we respond within 4 business hours.
CMMC AI Risk Assessment Report
Your staff are pasting sensitive data into ChatGPT and Copilot right now — with no audit trail. We scan 14 days of your real AI traffic locally and hand you the signed evidence your assessor asks for. No subscription, no procurement cycle.
- 14 days of real AI-traffic scanning across 16 local detection engines (CUI · PHI · PII · ITAR)
- Every prompt event scored against NIST 800-171 Rev 2 with your SPRS impact
- SHA-256 hash-chained audit trail — tamper-evident, assessor-defensible
- C3PAO-ready PDF plus a 30-minute readout of findings and next steps
Fixed price. Yours to keep. See a sample report (PDF)