Defense · CMMC Level 2 · NIST 800-171
Leak CUI into ChatGPT and you've failed your C3PAO assessment.
Roughly 80,000 DoD contractors must reach CMMC Level 2 to keep their contracts, and AI prompt leakage is the most common unaddressed gap in the defense industrial base. HoundShield blocks CUI, CAGE codes and contract data locally — the only architecture that doesn't itself create a DFARS 7012 spill — and generates the SSP, POA&M and SPRS evidence your assessor needs.
What it is
A local-only AI firewall plus a full CMMC suite: 110-control assessment, live SPRS scoring and C3PAO-ready document export.
Who it's for
ISSOs and IT security managers at 50–500 person defense contractors preparing for a C3PAO assessment.
How you use it
One URL change routes your team's AI through the gateway; the dashboard tracks your SPRS score and open controls in real time.
What it detects for you
How it works
- 01
Change one URL
Point ChatGPT, Copilot or Claude at your HoundShield proxy. Live in 10 minutes.
- 02
CUI is blocked locally
Nothing leaves your network — so HoundShield itself can never cause a DFARS 7012 spill.
- 03
Export C3PAO evidence
Generate your SSP, POA&M and SPRS attestation as SHA-256 signed PDFs on demand.
How HoundShield supports CMMC L2 / NIST 800-171
| Control / requirement | How HoundShield maps to it | Status |
|---|---|---|
| 3.1 — Access Control | CUI blocked at the AI egress point | Enforced |
| 3.3 — Audit & Accountability | SHA-256 signed log of every prompt | Logged |
| 3.13 — System & Comms Protection | Prompt content never leaves your boundary | Enforced |
| 3.14 — System & Info Integrity | Real-time CUI-leak detection & quarantine | Alerted |
Common questions
Does HoundShield itself cause a DFARS 7012 spill?+
No — and that's the entire point. Detection is local; CUI never transits to us. Cloud DLP tools that scan in their own cloud can't make that claim.
Does it generate C3PAO evidence?+
Yes. Your SSP, POA&M and SPRS attestation export as SHA-256-signed PDFs, mapped to all 110 controls.
How long does deployment take?+
Most teams are live in under 10 minutes — it's a single base-URL change with a Docker deployment. No agent installs on individual machines.
Can we run it fully on-prem or air-gapped?+
Yes. HoundShield runs self-hosted via Docker for CUI workloads, and air-gapped for the most sensitive environments.
A C3PAO assessment is estimated at $31k–$150k
Industry estimates put a Level 2 assessment in the tens to low hundreds of thousands. Don't fail it on an AI leak. One URL change. 10 minutes. C3PAO-ready.
Protect your CUI