Skip to main content
Manufacturing

Trade Secrets Stay on Your
Facility's Machines.

Engineers, supply chain managers, and quality teams are using ChatGPT, Claude, and Copilot every day, pasting proprietary formulations, CUI, ITAR-controlled specifications, and supplier contracts into prompts. Shield sits on your facility's machines and stops industrial secrets from ever reaching an external AI model. No cloud. No vendor access. Just a local proxy that redacts sensitive data before it leaves your network.

Talk to Our TeamSee Data Redaction in Action
Quick Answer

Shield for Manufacturing is a local desktop application that stops trade secrets, CUI, ITAR-controlled technical data, and supplier contracts from ever leaving your facility's computers, before that data reaches ChatGPT, Claude, Copilot, or any AI model. It runs on your existing machines, requires no cloud infrastructure, and helps manufacturers meet ITAR, NIST 800-171, CMMC 2.0, and ISO 27001 requirements without changing how engineers and supply chain teams use AI tools.

ITAR / EAR
Export controls on technical data

The International Traffic in Arms Regulations (ITAR) and Export Administration Regulations (EAR) control the export of defense-related and dual-use technical data. When a manufacturer's employee pastes specifications, drawings, or process parameters into an AI prompt, that data may constitute a "deemed export" if it reaches servers outside the United States, which most cloud AI providers operate. Violations carry civil and criminal penalties regardless of intent.

Source: 22 CFR §§ 120-130 (ITAR); 15 CFR §§ 730-774 (EAR)
NIST 800-171 / CMMC
CUI protection for defense contractors

NIST SP 800-171 defines 110 security controls for protecting Controlled Unclassified Information (CUI) in non-federal systems. CMMC 2.0 mandates third-party assessment for defense contractors handling CUI. When CUI, contract numbers, technical data packages, delivery schedules, is pasted into an AI prompt, it leaves the contractor's assessed environment. Shield keeps CUI within your NIST 800-171 boundary by redacting it before transmission.

Source: NIST SP 800-171 Rev. 2; 32 CFR Part 170 (CMMC)
Zero
Proprietary data leaves your facility

Shield runs locally on your manufacturing facility's machines, no cloud processing, no vendor data access. Trade secrets, CUI, ITAR-controlled technical data, and supplier contracts never reach external AI providers. The redaction mapping stays on your machine, inside your facility's network boundary. For air-gapped environments, Shield operates entirely offline.

Shield operates within your facility's network boundary

Pasting ITAR or CUI data into an AI prompt may constitute an export

When a manufacturing engineer pastes proprietary formulations, defense contract details, or CUI into an AI prompt, that data leaves your facility's controlled environment and arrives at an external provider's servers, which may be located outside the United States. Under ITAR and EAR, this can constitute a "deemed export" requiring authorization. NIST 800-171 and CMMC 2.0 require contractors to protect CUI, and that obligation doesn't disappear just because an employee is using a third-party AI tool. Shield eliminates this vector entirely: export-controlled and CUI data never leaves your network, so it never creates an ITAR, EAR, or CMMC compliance exposure.

Interactive Demo

What Industrial Data Looks Like in AI Prompts

Three real-world scenarios where manufacturing teams send sensitive industrial data to AI models. Click each tab to see the raw prompt with proprietary information, and how Shield redacts it before it leaves your network.

Process Engineer Using AI to Optimize Proprietary Formulation
Before Shield
Optimize the curing cycle for our proprietary carbon-fiber prepreg system. Current formulation: 42.3% bis-maleimide resin (BMI-7742), 31.7% epoxy novolac (EN-5501), 26.0% thermoplastic toughener (TPX-9). Cure schedule: ramp at 1.8°C/min to 180°C, hold 120 min at 350 kPa autoclave pressure. Target Tg: 232°C minimum per internal spec MFG-SPEC-7742-Rev-C. Current first-pass yield: 87.3%. Competitor benchmark: Hexcel 8552 achieves 91% with similar chemistry. Client: Lockheed Martin, contract #F33657-24-C-7742 for F-35 Block 4 wing skins.
After Shield
Optimize the curing cycle for our proprietary carbon-fiber prepreg system. Current formulation: [RESIN_PERCENTAGE] [RESIN_TYPE], [RESIN_PERCENTAGE] [RESIN_TYPE], [RESIN_PERCENTAGE] [TOUGHENER_TYPE]. Cure schedule: ramp at [RATE] to [TEMPERATURE], hold [DURATION] at [PRESSURE] autoclave pressure. Target Tg: [TEMPERATURE] minimum per internal spec [SPEC_ID]. Current first-pass yield: [YIELD_PERCENTAGE]. Competitor benchmark: [COMPETITOR] achieves [BENCHMARK] with similar chemistry. Client: [CUSTOMER], contract [CONTRACT_NUMBER] for [PROGRAM].
Detected (9 matches)
Trade Secret, Formula42.3% bis-maleimide (BMI-7742)
Trade Secret, Formula31.7% epoxy novolac (EN-5501)
Trade Secret, Process1.8°C/min to 180°C, hold 120 min
Trade Secret, Process350 kPa
Trade Secret, Quality232°C
Trade Secret, Yield87.3%
ITAR, CustomerLockheed Martin
ITAR, ProgramF-35 Block 4
CUI, ContractF33657-24-C-7742

Compliance

Manufacturing Regulatory Frameworks Shield Supports

FrameworkScopeKey RequirementShield's Role
ITARDefense articles and technical data on the U.S. Munitions List (USML)Export-controlled technical data must not be transferred to foreign persons or foreign servers without authorization; uploading to cloud AI constitutes a potential deemed exportRedacts USML-related technical data, military specifications, defense program identifiers, contractor names, weapon system references, before prompts reach external AI providers. Controlled data never leaves the facility's network boundary.
NIST 800-171Controlled Unclassified Information (CUI) in non-federal systems110 security controls across 14 families including access control, audit, and system integrity; CUI must be protected when processed, stored, or transmittedKeeps CUI within the contractor's NIST 800-171 boundary by redacting contract numbers, technical data, delivery schedules, and program identifiers before they are transmitted to external AI services.
CMMC 2.0Defense contractor cybersecurity certification (Levels 1-3)Third-party assessment of NIST 800-171 control implementation; CUI must be protected within the contractor's assessment boundary at Levels 2 and 3Supports CMMC compliance by preventing CUI transmission outside the assessment boundary. Redaction happens locally, within the contractor's CMMC scope, so CUI never reaches non-compliant external services.
DTSATrade secrets, manufacturing processes, formulas, techniquesThe Defend Trade Secrets Act (18 U.S.C. § 1836) provides federal civil protection for trade secrets; owners must take "reasonable measures" to keep information secretDemonstrates reasonable measures by automatically redacting proprietary manufacturing data, formulations, process parameters, yield data, engineering drawings, before they reach external AI models where trade secret protection is uncertain.
ISO 27001Information security management system (ISMS)Annex A controls require protection of intellectual property and third-party data throughout processing and transmission; risk assessment must cover all data flows including AI tool usageAdds a technical control at the AI data egress point. Redaction events are logged with cryptographic hashes for audit evidence, supporting ISO 27001 control objectives for information transfer and supplier security.
EARDual-use items and technology on the Commerce Control List (CCL)Export-controlled technology must not be transferred without authorization; cloud AI uploads of controlled technical data may require export licensingRedacts dual-use technical data, commercial aerospace specifications, advanced materials parameters, electronics manufacturing data, preventing inadvertent export through AI prompt submission.

Architecture

Industrial Data Never Leaves Your Facility Network

Shield runs as a local proxy on your facility's machines. When an engineer, supply chain manager, or quality specialist sends a prompt to an AI model, Shield intercepts it, redacts all trade secrets, CUI, ITAR-controlled data, and proprietary information, and only then forwards the clean prompt to the external LLM. The redaction mapping stays on your machine, inside your facility's network boundary.

🏭 FacilityPLM / ERP / MESprompt + CUI / ITAR data🛡️ ShieldLocal Redaction ProxyCUI → [REDACTED] · ITAR → [REDACTED]clean prompt only🤖 AI ProviderChatGPT / Claude / etc.AI responserehydrate locallyresponse with data restoredYour Facility NetworkExternal Internet

Local Installation

Install Shield on any Mac, Windows, or Linux machine, including air-gapped workstations. No cloud infrastructure, no vendor data access, no industrial data leaves your network.

One Environment Variable

Set SHIELD_PROXY_URL and every AI call from that machine flows through Shield automatically. Zero code changes to your existing tools, Teamcenter, SAP, Windchill, or custom MES.

Full Audit Trail

Every redaction event is logged with a cryptographic hash. Prove to DCMA assessors, ITAR auditors, and ISO 27001 certifiers exactly what data was caught and when, with tamper-evident integrity.

Custom Detection Rules

Define patterns for your proprietary part numbers, material specs, engineering drawing references, and CUI contract identifiers. Run in audit-only mode first to validate coverage across your facility.

FAQ

Common Questions

No, and that's the critical distinction. Shield runs locally on your facility's machines and never transmits technical data to external servers. Under ITAR (22 CFR §§ 120-130) and EAR (15 CFR §§ 730-774), an "export" includes transferring controlled technical data to a foreign person or server, including uploading it to a cloud-based AI provider. When Shield redacts ITAR-controlled technical data before it reaches an external AI model, the controlled data never leaves your facility. There is no export because the export-controlled information never crosses your network boundary. Shield itself doesn't store, transmit, or process the controlled data. It operates on it locally and the original stays on your machine.
Shield uses a multi-layered detection approach that goes well beyond PII patterns. For trade secrets, Shield can be configured with custom detection rules for your specific data formats: proprietary part numbers, material formulations, chemical ratios, process parameters (temperatures, pressures, ramp rates), engineering drawing references, CMM measurement data, and supplier/customer identities. Unlike PII, which follows standardized patterns (SSN format, email structure), trade secrets require domain-specific pattern matching that your security team can define and deploy through Shield's policy engine. Shield also supports file-level pattern detection for CAD formats, STEP files, and technical data packages.
Shield operates at the API layer. It sits between your AI client and the LLM provider, not inside any specific manufacturing system. Whether your engineers copy data from Siemens Teamcenter, SAP, PTC Windchill, Oracle ERP, or a custom MES, Shield catches it as long as the AI request flows through Shield's local proxy. This means Shield works with your entire manufacturing software stack, PLM, ERP, MES, QMS, and SCM platforms, with zero integration work. One environment variable redirects all AI traffic through Shield, regardless of which system the data originally came from.
CMMC 2.0 (Cybersecurity Maturity Model Certification) requires defense contractors to protect Controlled Unclassified Information (CUI) at specified maturity levels. When an engineer or supply chain manager pastes CUI into an AI prompt, contract numbers, technical data, delivery schedules. That CUI is transmitted to an external service that almost certainly doesn't meet CMMC requirements. Shield prevents this by redacting CUI before it reaches the external AI provider. The redaction happens locally, within your CMMC assessment boundary, so the CUI never leaves your controlled environment. This supports compliance with CMMC practices across access control (AC), audit and accountability (AU), and system and communications protection (SC) families.
Manufacturing environments generate vast streams of sensor data, temperatures, pressures, vibration signatures, flow rates. That often contain process intellectual property when combined with context (machine identifiers, production schedules, quality thresholds). Shield can be configured to detect and redact structured industrial data patterns: machine IDs, sensor readings with contextual labels, production counts, OEE metrics, and SCADA tag references. For air-gapped manufacturing networks, Shield runs entirely offline, no internet connectivity required for the redaction engine itself. The AI client would need connectivity to reach the LLM provider, but Shield's redaction logic operates locally regardless of network topology.
Shield installs on any Mac, Windows, or Linux machine. For facility-wide deployment, your IT and OT teams can push Shield via existing endpoint management tools or group policy. Every machine gets the same policy configuration, consistent trade secret and CUI protection across engineering workstations, quality lab computers, supply chain terminals, and shop-floor kiosks. Audit logs can be centrally collected for compliance reporting. Shield supports offline policy updates for air-gapped environments, and its lightweight footprint means minimal impact on manufacturing workstations that may already be resource-constrained.

Ready to Protect Your Industrial Data?

Shield installs in minutes. Your trade secrets, CUI, ITAR-controlled technical data, and supplier contracts stay on your facility's machines, where ITAR, NIST 800-171, CMMC 2.0, and your customers expect them to be.

Talk to Our TeamHow Shield Works

Last updated: July 22, 2026