Skip to main content
Government & Defense

CUI and ITAR Data Stays Inside
Your Security Boundary.

Defense contractors, federal analysts, and acquisition officers use ChatGPT, Claude, and Copilot every day \u2014 pasting CUI-marked reports, ITAR-controlled technical specifications, and source selection data into prompts. Shield sits on your machines and stops government data from ever reaching an external AI model. No cloud. No foreign server transit. Just a local proxy that redacts sensitive data before it leaves your accredited security boundary.

See Shield for GovernmentSee Data Redaction in Action
Quick Answer

Shield for Government & Defense is a local desktop application that stops controlled unclassified information (CUI), ITAR technical data, procurement-sensitive documents, and intelligence reports from ever leaving your machines \u2014 before that data reaches ChatGPT, Claude, Copilot, or any AI model. It runs entirely within your accredited security boundary, requires no cloud infrastructure, and helps defense contractors and federal agencies meet NIST 800-171, ITAR, CMMC 2.0, FISMA, and DFARS 7012 requirements without changing how staff use AI tools.

NIST 800-171
110+ security controls for CUI protection

NIST Special Publication 800-171 Revision 3 (published May 2024) defines the security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations. Defense contractors, universities, and state governments handling CUI under federal contracts must implement these controls. When an employee sends CUI through an external AI provider, that data leaves the controlled environment that 800-171 was designed to protect.

Source: NIST SP 800-171 Rev. 3 (2024); 32 CFR Part 2002
6+ Frameworks
Regulations governing government data in AI use

Government agencies and contractors must navigate NIST SP 800-171 (CUI protection), ITAR (defense article export controls), CMMC 2.0 (defense contractor cybersecurity certification), FedRAMP (cloud service authorization), FISMA (federal information security), and DFARS 252.204-7012 (safeguarding covered defense information). Each framework imposes independent obligations — and AI tool usage can simultaneously create exposure across multiple compliance dimensions.

Multiple statutes — NIST, ITAR (22 CFR 120-130), CMMC (32 CFR 170), FISMA (44 U.S.C. § 3551), DFARS
Zero
Government data leaves your security boundary

Shield runs locally on your machines — no cloud processing, no vendor data access, no foreign server transit. CUI, ITAR technical data, procurement-sensitive documents, and intelligence reports never reach external AI providers. The redaction mapping stays on your machine, inside your facility’s accredited security boundary. You maintain affirmative control over government data at all times.

Shield operates within your accredited security boundary

CUI exposure through AI tools is a compliance and national security risk

When a defense contractor engineer pastes ITAR-controlled guidance algorithm parameters into an AI coding assistant, that data may transit through servers outside the United States \u2014 potentially accessible to foreign nationals. Under ITAR, this constitutes a deemed export violation. When a federal analyst pastes a CUI-marked threat assessment into a summarization tool, the data leaves the agency\u2019s accredited security boundary \u2014 creating exposure under FISMA and NIST 800-171. Shield eliminates both vectors: sensitive government information never leaves your network, so it never creates an export control or information security compliance exposure.

Interactive Demo

What Government Data Looks Like in AI Prompts

Three real-world scenarios where government personnel and defense contractors send CUI, ITAR-controlled data, and procurement-sensitive information to AI models. Click each tab to see the raw prompt with controlled information \u2014 and how Shield redacts it before it leaves your security boundary.

Defense Contractor Engineer Debugging ITAR-Controlled Code

An aerospace engineer at a defense contractor uses an AI coding assistant to debug a navigation system module. The code contains ITAR-controlled technical data including guidance algorithm parameters, test range coordinates, and system performance specifications.

Before Shield
Debug this C++ navigation module for the AGM-158C LRASM guidance system. The inertial navigation Kalman filter is diverging at waypoint transition. Current gain matrix: K = [0.0234, 0.0018; 0.0018, 0.0156]. Test data from China Lake range (35.6869° N, 117.6885° W) shows position error exceeding 12m after 47 seconds of flight. The seeker lock-on threshold is defined in document NAVAIR-SPEC-8842-B, paragraph 4.3.2. Export classification: ITAR Category VIII(f). Contract number: N00019-25-C-0042. POC: Dr. James Morrison, james.morrison@defense-co.com, DSN 312-555-8291.
After Shield
Debug this C++ navigation module for the [SYSTEM_NAME] guidance system. The inertial navigation Kalman filter is diverging at waypoint transition. Current gain matrix: K = [MATRIX_VALUES]. Test data from [RANGE_NAME] range ([COORDINATES]) shows position error exceeding [MEASUREMENT] after [DURATION] of flight. The seeker lock-on threshold is defined in document [TECHNICAL_SPEC], paragraph [PARAGRAPH_REF]. Export classification: [EXPORT_CONTROL_CATEGORY]. Contract number: [CONTRACT_NUMBER]. POC: [PERSON_NAME], [EMAIL], [PHONE].
Detected (10 matches)
ITAR — SystemAGM-158C LRASM
ITAR — TechnicalK = [0.0234...]
CUI — LocationChina Lake range
CUI — Coordinates35.6869° N, 117.6885° W
ITAR — SpecNAVAIR-SPEC-8842-B
ITAR — CategoryCategory VIII(f)
CUI — ContractN00019-25-C-0042
PII — NameJames Morrison
PII — Emailjames.morrison@defense-co.com
PII — PhoneDSN 312-555-8291

Compliance

How Shield Maps to Government Security Frameworks

Federal agencies and defense contractors operate under multiple overlapping security frameworks. Shield's local proxy architecture provides a single technical control that supports compliance across NIST 800-171, ITAR, CMMC 2.0, FedRAMP, FISMA, and DFARS 7012 \u2014 without adding cloud dependencies to your authorization boundary.

FrameworkScopeKey RequirementHow Shield Helps
NIST SP 800-171Nonfederal systems processing, storing, or transmitting CUIImplement 110+ security controls across 14 control families; demonstrate compliance through self-assessment or third-party assessment under CMMCRedacts CUI — including export-controlled technical data, procurement-sensitive information, and PII — before prompts reach external AI providers. Keeps CUI within the contractor’s security boundary, directly supporting access control and system integrity requirements.
ITARDefense articles, technical data, and defense services on the U.S. Munitions List (USML)Prevent export of ITAR-controlled technical data to foreign persons or foreign-accessible systems unless authorized by license or exemptionBlocks ITAR technical data — weapon system parameters, guidance algorithms, specification references, export classification markings — from reaching AI provider servers that may be outside the U.S. or accessible to foreign nationals. Eliminates deemed export risk from AI tool usage.
CMMC 2.0Defense contractors handling FCI and CUI under DoD contractsLevel 1 (self-assessment for FCI), Level 2 (third-party C3PAO assessment for CUI), Level 3 (government-led assessment); phased implementation through 2027Supports Access Control (AC), Audit and Accountability (AU), and System and Communications Protection (SC) control families by preventing unauthorized CUI disclosure through AI tool usage — a vector existing boundary controls were not designed to address.
FedRAMPCloud service providers offering services to federal agenciesSecurity assessment and authorization at Low, Moderate, or High impact levels; continuous monitoring and annual reassessmentShield’s local architecture means government data never reaches un-FedRAMP-authorized AI cloud services. This eliminates the requirement to assess the AI provider’s FedRAMP status — because the sensitive data never enters their environment.
FISMAFederal agency information systems and dataAnnual security reviews, incident reporting, continuous monitoring; agency heads responsible for information security programs under 44 U.S.C. § 3551Provides auditable controls for AI tool usage within federal agencies. Every redaction event is logged with a cryptographic hash, supporting FISMA’s continuous monitoring and annual assessment requirements. Gives CISOs a verifiable answer to ‘where does our CUI go when staff use AI tools?’
DFARS 252.204-7012Defense contractors handling Covered Defense Information (CDI)Implement NIST SP 800-171, use FedRAMP-authorized cloud services for CDI, report cyber incidents within 72 hoursKeeps CDI within the contractor’s controlled environment — satisfying the safeguarding requirement without requiring FedRAMP authorization for the AI provider. Audit logs support the 72-hour incident reporting obligation with verifiable evidence of what data was intercepted and when.

Architecture

Government Data Never Leaves Your Accredited Boundary

Shield runs as a local proxy on your agency or contractor machines. When an engineer, analyst, or contracting officer sends a prompt to an AI model, Shield intercepts it \u2014 redacts all CUI, ITAR technical data, export-controlled specifications, procurement-sensitive details, and PII \u2014 and only then forwards the clean prompt to the external LLM. The redaction mapping stays on your machine, inside your facility's accredited security boundary.

🏛️ Gov / ContractorCUI · ITAR · FOUOprompt + CUI/ITAR data🛡️ ShieldLocal Redaction ProxyCUI → [CUI_REDACTED] · ITAR → [EXPORT_CTRL]clean prompt only🤖 AI ProviderChatGPT / Claude / etc.AI responserehydrate locallyresponse with gov data restoredAccredited Security BoundaryExternal Internet

Local Installation

Install Shield on any Mac, Windows, or Linux machine — including GFE and contractor-managed systems. No cloud infrastructure, no vendor data access, no data leaves your accredited boundary.

Deemed Export Prevention

ITAR technical data and export-controlled specifications are redacted locally — before any prompt reaches a server outside the U.S. or accessible to foreign nationals. Eliminates deemed export exposure at the source.

CUI-Aware Detection

Detects CUI banner markings (CUI//REL TO USA, CUI//NOFORN), export control classifications (ITAR Category, ECCN), CAGE codes, UEI numbers, and contract identifiers — patterns unique to government data workflows.

Audit-Ready Logging

Every redaction event is logged with a cryptographic hash and timestamp. Supports NIST 800-171 audit requirements, CMMC assessment evidence, and DFARS 72-hour incident reporting with verifiable forensic records.

FAQ

Common Questions

Controlled Unclassified Information (CUI) is information the U.S. Government creates or possesses that requires safeguarding or dissemination controls under law, regulation, or government-wide policy — but is not classified. CUI is organized into 20+ categories across two groups: CUI Basic (requiring standard safeguarding) and CUI Specified (with additional requirements from authorizing law). Shield detects CUI patterns across the most common government-use categories: export-controlled technical data (ITAR/EAR), procurement-sensitive information (source selection, IGCE), law enforcement sensitive data, and personally identifiable information (PII). You can add custom patterns for your agency’s specific CUI marking conventions — including banner markings like CUI//REL TO USA or CUI//NOFORN.
Shield’s local proxy architecture directly supports several NIST SP 800-171 controls — most notably the access control (3.1), audit and accountability (3.3), and system and communications protection (3.13) families. Because Shield redacts CUI before it ever reaches an external system, the data protection boundary remains within your controlled environment — aligning with the core principle of 800-171: protecting the confidentiality of CUI in nonfederal systems. DFARS 252.204-7012 requires contractors to implement NIST 800-171 and report cyber incidents within 72 hours. Shield’s tamper-evident audit logs give you a verifiable record of every redaction event, which supports both compliance demonstration and incident response. Shield is a technical safeguard — it doesn’t replace your SSP or POA&M, but it adds a provable control to your security boundary.
A ‘deemed export’ occurs when ITAR-controlled technical data is released to a foreign person within the United States — including through a visual inspection, oral briefing, or electronic transmission. When a defense contractor engineer pastes ITAR technical data into an AI prompt that’s processed by servers outside the U.S. or accessible to foreign nationals, that constitutes a potential deemed export violation. Shield blocks this vector: ITAR-controlled data — weapon system parameters, guidance algorithm values, technical specification references, export classification markings — is redacted locally before the prompt ever leaves your machine. The LLM provider never sees the controlled data, eliminating the deemed export exposure. Shield runs entirely within your facility’s security boundary, consistent with the export control principle that ITAR data must remain under effective U.S. person control.
Shield is designed for Controlled Unclassified Information (CUI) and ITAR-protected technical data — not for classified national security information. Classified systems operate under separate authorities (Executive Order 13526, NISPOM, ICD 503) and require dedicated air-gapped infrastructure. Shield can be deployed on JWICS or SIPRNet if authorized, but the core use case is protecting the vast volume of sensitive-but-unclassified government work — the acquisition documents, threat assessments, contractor deliverables, and program data that government personnel handle daily on unclassified networks. For those unclassified environments, Shield provides the same data protection guarantees without requiring classification-level infrastructure changes.
CMMC 2.0 (Cybersecurity Maturity Model Certification) requires defense contractors handling CUI to meet Level 2 certification — implementing the 110 controls from NIST SP 800-171 and passing a third-party assessment (C3PAO). Shield directly supports several CMMC domains: Access Control (AC) by preventing unauthorized disclosure of CUI to external AI providers; Audit and Accountability (AU) through cryptographic audit logging of every redaction event; and System and Communications Protection (SC) by enforcing boundary protection at the application layer. Shield doesn’t replace your full CMMC compliance program — you still need an SSP, POA&M, and third-party assessment — but it closes a growing gap: AI tool usage that your existing boundary controls weren’t designed to address.
Yes. Shield installs on standard macOS, Windows, and Linux workstations — including government-furnished equipment (GFE), contractor-owned systems authorized for CUI processing, and virtual desktop infrastructure (VDI) environments. For enterprise deployments across agencies or contractor teams, Shield supports centralized policy management: your security team defines what categories of data to redact (CUI categories, export-controlled data, PII, procurement-sensitive info), deploys the policy to every endpoint via standard device management tools, and collects audit logs centrally. Shield does not require cloud connectivity — all redaction processing and policy enforcement happens on the local machine.

Ready to Secure Your Agency's AI Usage?

Shield installs in minutes. Your CUI, ITAR technical data, and procurement-sensitive documents stay inside your accredited security boundary \u2014 where NIST 800-171, ITAR, CMMC, and your mission require them to be.

Talk to Our TeamHow Shield Works

Last updated: July 15, 2026