Trade Secrets Stay on Your
Facility's Machines.
Engineers, supply chain managers, and quality teams are using ChatGPT, Claude, and Copilot every day, pasting proprietary formulations, CUI, ITAR-controlled specifications, and supplier contracts into prompts. Shield sits on your facility's machines and stops industrial secrets from ever reaching an external AI model. No cloud. No vendor access. Just a local proxy that redacts sensitive data before it leaves your network.
Shield for Manufacturing is a local desktop application that stops trade secrets, CUI, ITAR-controlled technical data, and supplier contracts from ever leaving your facility's computers, before that data reaches ChatGPT, Claude, Copilot, or any AI model. It runs on your existing machines, requires no cloud infrastructure, and helps manufacturers meet ITAR, NIST 800-171, CMMC 2.0, and ISO 27001 requirements without changing how engineers and supply chain teams use AI tools.
The International Traffic in Arms Regulations (ITAR) and Export Administration Regulations (EAR) control the export of defense-related and dual-use technical data. When a manufacturer's employee pastes specifications, drawings, or process parameters into an AI prompt, that data may constitute a "deemed export" if it reaches servers outside the United States, which most cloud AI providers operate. Violations carry civil and criminal penalties regardless of intent.
NIST SP 800-171 defines 110 security controls for protecting Controlled Unclassified Information (CUI) in non-federal systems. CMMC 2.0 mandates third-party assessment for defense contractors handling CUI. When CUI, contract numbers, technical data packages, delivery schedules, is pasted into an AI prompt, it leaves the contractor's assessed environment. Shield keeps CUI within your NIST 800-171 boundary by redacting it before transmission.
Shield runs locally on your manufacturing facility's machines, no cloud processing, no vendor data access. Trade secrets, CUI, ITAR-controlled technical data, and supplier contracts never reach external AI providers. The redaction mapping stays on your machine, inside your facility's network boundary. For air-gapped environments, Shield operates entirely offline.
Pasting ITAR or CUI data into an AI prompt may constitute an export
When a manufacturing engineer pastes proprietary formulations, defense contract details, or CUI into an AI prompt, that data leaves your facility's controlled environment and arrives at an external provider's servers, which may be located outside the United States. Under ITAR and EAR, this can constitute a "deemed export" requiring authorization. NIST 800-171 and CMMC 2.0 require contractors to protect CUI, and that obligation doesn't disappear just because an employee is using a third-party AI tool. Shield eliminates this vector entirely: export-controlled and CUI data never leaves your network, so it never creates an ITAR, EAR, or CMMC compliance exposure.
Interactive Demo
What Industrial Data Looks Like in AI Prompts
Three real-world scenarios where manufacturing teams send sensitive industrial data to AI models. Click each tab to see the raw prompt with proprietary information, and how Shield redacts it before it leaves your network.
Compliance
Manufacturing Regulatory Frameworks Shield Supports
| Framework | Scope | Key Requirement | Shield's Role |
|---|---|---|---|
| ITAR | Defense articles and technical data on the U.S. Munitions List (USML) | Export-controlled technical data must not be transferred to foreign persons or foreign servers without authorization; uploading to cloud AI constitutes a potential deemed export | Redacts USML-related technical data, military specifications, defense program identifiers, contractor names, weapon system references, before prompts reach external AI providers. Controlled data never leaves the facility's network boundary. |
| NIST 800-171 | Controlled Unclassified Information (CUI) in non-federal systems | 110 security controls across 14 families including access control, audit, and system integrity; CUI must be protected when processed, stored, or transmitted | Keeps CUI within the contractor's NIST 800-171 boundary by redacting contract numbers, technical data, delivery schedules, and program identifiers before they are transmitted to external AI services. |
| CMMC 2.0 | Defense contractor cybersecurity certification (Levels 1-3) | Third-party assessment of NIST 800-171 control implementation; CUI must be protected within the contractor's assessment boundary at Levels 2 and 3 | Supports CMMC compliance by preventing CUI transmission outside the assessment boundary. Redaction happens locally, within the contractor's CMMC scope, so CUI never reaches non-compliant external services. |
| DTSA | Trade secrets, manufacturing processes, formulas, techniques | The Defend Trade Secrets Act (18 U.S.C. § 1836) provides federal civil protection for trade secrets; owners must take "reasonable measures" to keep information secret | Demonstrates reasonable measures by automatically redacting proprietary manufacturing data, formulations, process parameters, yield data, engineering drawings, before they reach external AI models where trade secret protection is uncertain. |
| ISO 27001 | Information security management system (ISMS) | Annex A controls require protection of intellectual property and third-party data throughout processing and transmission; risk assessment must cover all data flows including AI tool usage | Adds a technical control at the AI data egress point. Redaction events are logged with cryptographic hashes for audit evidence, supporting ISO 27001 control objectives for information transfer and supplier security. |
| EAR | Dual-use items and technology on the Commerce Control List (CCL) | Export-controlled technology must not be transferred without authorization; cloud AI uploads of controlled technical data may require export licensing | Redacts dual-use technical data, commercial aerospace specifications, advanced materials parameters, electronics manufacturing data, preventing inadvertent export through AI prompt submission. |
Architecture
Industrial Data Never Leaves Your Facility Network
Shield runs as a local proxy on your facility's machines. When an engineer, supply chain manager, or quality specialist sends a prompt to an AI model, Shield intercepts it, redacts all trade secrets, CUI, ITAR-controlled data, and proprietary information, and only then forwards the clean prompt to the external LLM. The redaction mapping stays on your machine, inside your facility's network boundary.
Local Installation
Install Shield on any Mac, Windows, or Linux machine, including air-gapped workstations. No cloud infrastructure, no vendor data access, no industrial data leaves your network.
One Environment Variable
Set SHIELD_PROXY_URL and every AI call from that machine flows through Shield automatically. Zero code changes to your existing tools, Teamcenter, SAP, Windchill, or custom MES.
Full Audit Trail
Every redaction event is logged with a cryptographic hash. Prove to DCMA assessors, ITAR auditors, and ISO 27001 certifiers exactly what data was caught and when, with tamper-evident integrity.
Custom Detection Rules
Define patterns for your proprietary part numbers, material specs, engineering drawing references, and CUI contract identifiers. Run in audit-only mode first to validate coverage across your facility.
FAQ
Common Questions
Related Articles
Ready to Protect Your Industrial Data?
Shield installs in minutes. Your trade secrets, CUI, ITAR-controlled technical data, and supplier contracts stay on your facility's machines, where ITAR, NIST 800-171, CMMC 2.0, and your customers expect them to be.
Last updated: July 22, 2026