Security & Trust

The data that matters never leaves your network.

Every cloud-based AI DLP tool sends your CUI to its servers to scan it — that transfer is itself a potential CUI spill under DFARS 7012. HoundShield scans everything locally. Nothing leaves your network. That is the foundation of our security posture, and the one property a cloud competitor structurally cannot copy.

Local-only by design

The scanning engine runs inside your network. Prompt content, CUI, PHI, and PII are inspected on-premise and never transmitted to our servers. This is the entire architecture — not a configuration option.

Encryption everywhere

AES-256 for any quarantined content at rest, TLS 1.3 for all data in transit. Payment data is handled entirely by Stripe; we never store card numbers.

Tamper-evident audit trail

Every compliance event is written to an append-only, SHA-256-hash-chained log — the evidence format a C3PAO assessor expects, and one that makes silent alteration detectable.

Tenant isolation

Row-Level Security isolates each organization's metadata. Access follows least privilege; authentication is handled by Supabase with session-token verification on every protected route.

Hardened by default

HSTS, CSP, X-Frame-Options DENY, nosniff, and a strict referrer policy ship on every response. API routes are rate-limited. Dependencies are scanned for known vulnerabilities.

Responsible disclosure

We publish a security.txt (RFC 9116) and welcome good-faith research. Report a vulnerability and we will acknowledge it and work with you on a fix.

Where the scanner runs matters

The local-only guarantee is a property of deployment, not just code. Our marketing and dashboard plane runs on Vercel, which is not FedRAMP-authorized — so the hosted trial is for non-CUI evaluation only. For any CUI workload, run Mode B: the proxy in your own infrastructure, where prompt content never crosses your boundary.

Handling CUI? Run Mode B.

HoundShield scans prompts locally in under 10ms. That CUI-safe property holds only when the scanner runs inside your own boundary. Pick the deployment mode that matches your data:

A · Hosted trial

On Vercel — not FedRAMP-authorized. Demo and non-CUI evaluation only.

B · Self-hosted Docker

Your own infrastructure. CUI-safe — prompt content never leaves your boundary. Right for CUI-handling contractors.

C · Air-gapped

Isolated network. CUI-safe. For enterprise / IL-5+ environments.

Compliance alignment

HoundShield is a control engineered to help you satisfy specific obligations. It maps to all 110 NIST 800-171 Rev 2 controls for SPRS scoring and is built for the following frameworks:

  • CMMC Level 2
  • NIST 800-171
  • DFARS 252.204-7012
  • HIPAA
  • SOC 2
  • ISO 27001 (mapping)

Report a vulnerability

Found something? Email security@houndshield.com or read our machine-readable policy at /.well-known/security.txt. Please give us a reasonable window to remediate before public disclosure. Good-faith research conducted under these terms will not be pursued as a violation of our Acceptable Use Policy.

Live service status: houndshield.com/status