SOLUTION — DEFENSE-INDUSTRIAL BASE · CUI / ITAR / EAR
Keep controlled data out of public AI — at the point of use.
A Technology Control Plan and a CMMC assessment describe what is supposed to happen. Neither intercepts the keystroke when an engineer pastes a controlled drawing, a flight-test dataset, or a propulsion spec into a public LLM. Containment.ai enforces at that moment — deterministically, before the data leaves the endpoint.
FIG. 1 — THE LAYER YOUR CONTROL PLAN CAN'T REACH
Documentation and runtime enforcement are different layers. Only one of them can stop a paste.
DOCUMENTATION & ASSESSMENT — WHAT PLANS COVER
— Technology Control Plans; ITAR/EAR classification; CUI marking
— CMMC / NIST SP 800-171 control mapping and evidence
— Supplier flow-down clauses and attestations
NECESSARY. NOT SUFFICIENT. A CONTROL PLAN DOESN'T STOP A PASTE.
RUNTIME ENFORCEMENT — WHAT CONTAINMENT.AI COVERS
✓ Inspects supported AI chat submissions at the browser, before they leave the endpoint
✓ Designed to block submissions that match your configured export-control or CUI policy
✓ Deterministic and fail-closed by default — no AI model makes the enforcement decision
✓ Reviewable, tamper-evident audit record for each governed ruling
ENFORCEMENT AT THE KEYSTROKE, NOT AT THE AUDIT.
FIG. 2 — THREE CONTROL POINTS, ONE DISCIPLINE
HUMAN PROMPTS
AI Chat Firewall
Inspects employee prompts to ChatGPT, Claude, Gemini, Copilot, and Grok before submission.
EXPLORE →
AGENT ACTIONS
Agent Governance
Authorizes autonomous tool calls and delegated actions pre-execution, against your policy.
EXPLORE →
MISSION BOUNDARY
Mission Authorization Gateway
Deterministic edge action authorization and output conformance with signed, hash-chained decision receipts — the cross-domain mission boundary, designed against NSA cross-domain standards.
EXPLORE →
FIG. 3 — THE ARTIFACT YOUR CONTRACTING OFFICER REVIEWS
Not a policy PDF. A record of the submission the control stopped.
DECISION RECORDTAMPER-EVIDENT · SEE TRUST
EVENTchat.submission → public LLM
CONTENTpasted excerpt: stress-analysis_rev-C
CLASSorganization policy match · itar-cui-v41
POLICYitar-cui-v41 · rule: configured_export_control_policy
RULING
DENY
blocked at the endpoint
sha256:4be1…09f2 · deterministic policy decision · data never left the browser
Evidence, stated precisely
A decision record can support evidence that policy was applied at the point of use. It does not by itself prove period-wide operating effectiveness, and it is not a certification — assurance status stays stated on Trust.
Flow-down without prime budgets
Subs inherit prime-grade CUI obligations with a fraction of the staff. Create the policy workspace free; deploy browser enforcement through a managed pilot — the same enforcement discipline, sized to your seat in the chain. See where you sit →
MAKE AI USABLE ON CONTROLLED PROGRAMS
A 30-minute briefing: how the runtime layer intercepts a controlled paste and authorizes agent actions, with the audit written as the decision is made.