COMPLIANCEARMOR // PLATFORM + APPLIANCE

Assess with AI. Close on hardware you own.

Cyber AB RPO #1449 110/110 NIST 800-171 controls assessed CMVP-validated FIPS crypto Local LLM, zero cloud AI calls
ASSESS / DOCUMENT / ENCLAVE / OWN · NIST 800-171 · CMMC Level 2

ComplianceArmor from Petronella Technology Group, Inc. pairs a local-LLM platform that scores all 110 NIST 800-171 controls and writes your SSP, POA&Ms, SPRS score, and Evidence Request Tracker with a FIPS-validated on-premises appliance that actually stores and protects the CUI. Delivered by CMMC Registered Practitioners. Nothing touches a cloud you do not own.

Choose your next step

Join the waitlist

Rollout is cohort-based. Hold your spot for the platform, the appliance, or both. No payment, no commitment, and a CMMC Registered Practitioner reaches out when your cohort opens.

Get on the list

See the AI platform

How a local-only LLM assesses all 110 controls and writes the SSP, POA&Ms, SPRS score, and Evidence Request Tracker without your data leaving the building.

Explore the platform

See the appliance

A sovereign CUI enclave on your rack: encrypted file store and encrypted mail on CMVP-validated FIPS modules, validated before it ships.

Explore the appliance

Compare the alternatives

Side by side against cloud CUI overlay services and a GCC High migration: data location, economics, workflow, and lock-in.

See the comparison
Cyber AB Registry RPO #1449 Registered Provider Organization verify
Controls Assessed 110/110 Every NIST 800-171 control: AI first pass, RP review
FIPS Validation CMVP #4766 NIST-listed cryptographic module verify
Founded 2002 23+ years of regulated IT and security
Cloud AI Dependencies 0 Assessment runs on a local LLM only
The Thesis

The compliance loop no software vendor closes

Compliance SaaS ends at a dashboard and a to-do list. Assessors do not certify dashboards; they verify that CUI is actually protected. ComplianceArmor pairs the assessment engine with the sovereign enclave it recommends, so the finding and the fix come from the same engagement.

The Star // Platform

AI that does the assessment work itself

Point it at your evidence. The engine scores every control, writes the narratives, and builds the artifact set an assessor expects to see.

  • All 110 NIST 800-171 controls, scored with rationale
  • System Security Plan written control by control
  • POA&Ms and SPRS score computed
  • Evidence Request Tracker for every gap
  • Reviewed and delivered by a CMMC Registered Practitioner
+
The Closer // Appliance

A sovereign enclave that holds the CUI

An on-premises, no-cloud appliance shipped as a hardened golden image. Your hardware, your keys, your disks.

  • Encrypted CUI file store and encrypted CUI mail
  • All crypto in CMVP-validated FIPS modules
  • Edit CUI in place over an encrypted share
  • Coexists with Microsoft 365 Commercial
  • Site-based pricing, not per-seat

In Short

  • ComplianceArmor is two halves of one loop: an AI compliance platform that assesses and documents, and an on-premises CUI enclave appliance that protects.
  • The AI runs locally. No cloud API calls; control narratives, diagrams, and evidence never leave your side of the boundary.
  • The appliance is validated before it ships: golden images clone-tested end to end, cryptography in NIST CMVP-validated modules, keys sealed per deployment.
  • Edit-in-place: engineers open, edit, and save CUI directly over encrypted SMB 3.1.1, with no download and re-upload round trip, demonstrated live and air-gapped in July 2026.
  • Transparent From-pricing: appliance deployment From $9,997, appliance license From $6,000 per site per year, fees 100% upfront.
  • Rollout is cohort-based: join the waitlist and a CMMC Registered Practitioner scopes your environment when your cohort opens.
Self-Route

Which half do you need first?

01
I need an SSP and an SPRS score now
Start with the platform: AI assessment, SSP, POA&Ms, SPRS, evidence tracker.
02
My CUI is scattered across laptops and M365 Commercial
You need the enclave appliance: consolidate CUI onto encrypted hardware you own.
03
I am paying per-seat for a cloud CUI service or quoting GCC High
Read the comparison: ownership, edit-in-place, and site-based economics.
04
I want the whole loop, assessed and closed
Join the waitlist. Cohort onboarding, scoped by a CMMC Registered Practitioner.
The Platform

AI CMMC compliance software that runs entirely on your side of the boundary

Most compliance tools give you 110 empty text boxes. ComplianceArmor reads your evidence and does the first pass itself, offline, on a local model, with a human Registered Practitioner accountable for what ships.

Assess

Local-LLM gap assessment

The engine evaluates all 110 NIST 800-171 controls against your actual evidence. The model runs on hardware you control; there are no third-party AI calls, so control narratives, network diagrams, and evidence never enter a vendor cloud.

How the gap analysis works
Document

Assessor-grade artifacts, generated

The System Security Plan written control by control, POA&Ms for every gap, your computed SPRS score, and an Evidence Request Tracker that tells you exactly what is missing before an assessor asks.

See the SSP generator
Review

A Registered Practitioner stands behind it

AI speed, human accountability. Every package is reviewed and delivered by a CMMC Registered Practitioner. We are a Cyber AB Registered Provider Organization: we prepare you for assessment; certification itself is always performed by an independent C3PAO.

Our CMMC practice
Frameworks

CMMC first, framework-wide

Built for CMMC Level 2 and NIST 800-171, with framework modules for HIPAA, PCI DSS, SOC 2, and CCPA documentation packages on the same engine.

CMMC software module
PROVEN.LIVE.2026-07-04 // AIR-GAPPED DEMO

Edit CUI in place. No download. No re-upload. No version chaos.

The daily-life failure of most secure file services is the round trip: download the CAD file, edit it, re-upload it, hope nobody else did the same in parallel. ComplianceArmor serves CUI over an encrypted SMB 3.1.1 share with encryption enforced, so your engineers open the file, edit it, and hit save. That is the whole workflow. We demonstrated it live on an air-gapped network segment: a client workstation editing a file inside the enclave directly, with the share provably unreachable from outside the enclave.

The old way

download > edit > re-upload > conflict > email the "final_v3" copy

ComplianceArmor

open > edit > save

The Appliance

A sovereign CUI enclave appliance, validated before it ships

Shipped as hardened golden virtual-machine images and deployed on a small server in your office. Every image is cloned and re-validated end to end before release; encryption keys are sealed to each deployment's own virtual TPM on first boot, never shared between customers.

Windows SKU

Windows Server 2022, FIPS mode

Full-volume BitLocker XTS-AES-256 on both the OS and CUI volumes, keys sealed to a per-deployment virtual TPM, native SMB 3.1.1 file service with encryption required, and co-located CUI mail with S/MIME. Clone validation runs 18 automated evidence checks; the current golden passed all 18 with zero failures.

Linux SKU

Ubuntu Pro FIPS

LUKS2 AES-256-XTS encryption at rest on the CUI volume, Kerberos-authenticated NFSv4.2 with krb5p privacy as the CUI transport, and an encrypted mail stack. The assessor-facing verify harness runs on every clone and must return an overall PASS before handoff.

Modules

Field capture, VPN, and CUI mail Live-built

Mobile field capture (photos and documents land directly in the encrypted enclave), a FIPS IKEv2 remote-access VPN with certificate-based mutual authentication, and an end-to-end CUI mail stack with a tamper-evident audit chain. Each module was live-built and validated on its own appliance clone in July 2026.

Roadmap

Voice and video In validation

Secure voice and video conferencing inside the enclave is in validation: the cryptographic core is verified, and end-to-end call flows are being proven now. We publish status honestly; nothing on this page is sold as done before it is validated.

Validated, Not Marketed

The certificate numbers behind the encryption claims

We do not self-attest. All appliance cryptography is performed by operating-system modules holding their own NIST CMVP validation certificates, published where anyone can verify them. When an assessor asks, you cite certificate numbers, not marketing language.

Cryptographic moduleCMVP certificateStandardStatus
Windows Kernel Mode Cryptographic Primitives Library (cng.sys) #4766 FIPS 140-2 Active until 2026-09-21
Windows Cryptographic Primitives Library (bcryptprimitives.dll) #4825 FIPS 140-2 Active until 2026-09-21
Ubuntu 22.04 Kernel Crypto API #4894 FIPS 140-3 Validated
Ubuntu 22.04 OpenSSL #4794 FIPS 140-3 Validated

Stated plainly for the record: the Windows platform ships on FIPS 140-2 validated modules with a published sunset date and a documented transition path; the Ubuntu SKU's modules are FIPS 140-3. An issued validation with a sunset date is still an issued validation, and your assessor will appreciate that we say so out loud. The exact module versions and certificates for your running appliance are captured by the operator at assessment time, never pre-filled.

The Alternatives

A PreVeil alternative and GCC High alternative you own outright

Defense contractors handling CUI are usually offered two paths: bolt a cloud encryption overlay onto their existing tenant, or migrate the whole company to a government cloud. Both leave your most sensitive data on infrastructure you rent. Here is how the third path compares.

ComplianceArmor applianceCloud CUI overlay servicesGCC High migration
Where CUI lives On your hardware, in your building, on disks you own Vendor cloud, encrypted, but hosted and controlled by the vendor Microsoft government cloud tenant
Economics Site-based license; the tenth engineer costs the same as the first Per-seat, per-year, forever Tenant migration project plus elevated per-seat licensing
CUI edit workflow Edit in place over an encrypted share: open, edit, save Typically download, edit, re-upload through the vendor client Native, but only after full tenant migration
M365 Commercial coexistence Yes. Business email stays put; only the CUI channel moves to the appliance Yes, as an overlay on the existing tenant No. The point is moving off Commercial
FIPS validation basis NIST CMVP certificate numbers you can cite to an assessor Varies by vendor; verify the certificate, not the brochure Microsoft platform validations
Exit path You keep the hardware, the images, and the data. It is yours Export and off-board through the vendor Second migration project
Pricing

Transparent From-pricing, 100% upfront

Final scope depends on node count and site topology, so every figure is a From-price confirmed in writing before work begins. Fixed-fee milestones are invoiced 100% upfront at contract execution.

Appliance deployment From$9,997 One-time. Golden-image deployment, clone validation on your hardware, key ceremony, evidence bundle.
Appliance license From$6,000/site/yr Site-based, not per-seat. Updates, golden-image refreshes, and license to operate.
Enclave license (5 seats) From$2,916/yr The hosted-enclave entry point for small CUI teams.
Enclave-web standup From$2,500 One-time standup of the web-accessible enclave tier.
Monitoring on the appliance From$6,900/yr Managed monitoring floor when it runs on the appliance.
Everything else Scoped on the call Endpoint securing, XDR, training, and assessment-readiness engagements are quoted after discovery so the number reflects your environment, not a generic range.

Every quote is locked in writing before work begins. No surprise change orders, no per-seat creep.

Early Access

Get in line for the ComplianceArmor rollout

Join the waitlist

Rollout is cohort-based so every deployment gets a CMMC Registered Practitioner's attention. Joining costs nothing and commits you to nothing: you hold a spot, we send a short confirmation, and when your cohort opens we reach out to scope your environment.

One confirmation email, a handful of short notes about how the platform and appliance work, and a heads-up when your cohort opens. Unsubscribe anytime with one click. We never share your information.

You are on the list.

Watch your inbox for a confirmation from Petronella Technology Group, Inc. Rollout is cohort-based; a CMMC Registered Practitioner will reach out when your cohort opens. Want to move faster? Book a scoping call now or run the ROI numbers while you wait.

Deployment Path

From waitlist to a working enclave

01

Waitlist + scoping

Join the list. When your cohort opens, a CMMC Registered Practitioner scopes your CUI footprint, sites, and node count.

02

AI assessment sprint

The platform assesses all 110 controls and generates your SSP, POA&Ms, SPRS score, and Evidence Request Tracker.

03

Appliance deployment

Your appliance deploys from the golden image and is clone-validated on site, with keys sealed to its own virtual TPM.

04

CUI migration

CUI consolidates into the enclave and your team cuts over to edit-in-place. M365 Commercial stays for everything else.

05

Operate + monitor

Ongoing monitoring on the appliance From $6,900/yr, with golden-image refreshes under the site license.

Why on-premises CUI enclaves are back

For a decade the default answer to every infrastructure question was "move it to the cloud." For most workloads that answer still holds. Controlled Unclassified Information is the exception, because the question an assessor asks is not "is it encrypted?" but "who controls the keys, the disks, and the boundary?" When your CUI sits in a vendor's multi-tenant cloud, the honest answer involves a lot of trust in somebody else's paperwork. When it sits in an encrypted enclave on a server in your office, the answer is short: you do.

The economics point the same direction. Cloud CUI services price per seat per year, which means the cost of compliance scales with headcount forever. A defense subcontractor with a dozen engineers touching CUI can watch a per-seat subscription quietly grow past the cost of owning the hardware outright in the first year or two. The appliance model inverts that: one site license, and the marginal cost of the next engineer is zero.

What "sovereign" actually means here

Sovereign is an overused word, so here is the concrete version. The ComplianceArmor appliance ships as a hardened golden virtual-machine image that runs on hardware you purchase and rack in your own facility. The disks are yours. The encryption keys are generated at your deployment and sealed to your appliance's own virtual TPM; we escrow a recovery key to you, not to us. The AI platform runs its language model on local hardware too, so even the assessment process, which necessarily reads your most sensitive security documentation, happens without a single byte leaving your control. If you ever walk away, you keep everything, because it was never ours to keep.

That posture also answers the FedRAMP question before it is asked. There is no cloud service provider in the CUI path, so there is no cloud service provider to authorize. The boundary discussion with your assessor gets shorter, not longer.

How the AI assessment works without exfiltrating a control narrative

The platform's assessment engine is a local large language model paired with a deterministic coverage layer built around the DoD assessment methodology. You provide the evidence: policies, screenshots, configurations, network diagrams. The engine reads them and scores each of the 110 NIST 800-171 controls, drafting the narrative for your System Security Plan, the POA&M entries for gaps, and the SPRS score DoD primes check before award. A CMMC Registered Practitioner reviews every output before it reaches you, because AI speed without human accountability is how bad SSPs get written.

The result set is the same artifact stack we deliver in our full-service CMMC compliance engagements, produced in a fraction of the calendar time. If you want to estimate what the automation is worth in your environment, the ROI calculator does that math with your numbers.

Where the appliance fits in your 800-171 boundary

The appliance is deliberately narrow: it is the CUI enclave, not a replacement for your IT stack. Business email, calendars, and general file sharing stay in your existing Microsoft 365 Commercial tenant, which is fine, because that tenant never touches CUI. The appliance carries the CUI file share, the CUI mailboxes, and the modules that feed them: mobile field capture for photos and documents from the shop floor, and a FIPS IKEv2 VPN for remote access into the enclave. That small, well-drawn boundary is exactly what makes the assessment conversation tractable: fewer systems in scope, each of them built to be shown to an assessor.

It is also what makes the two halves of ComplianceArmor stronger together. The platform documents a boundary; the appliance is a boundary that arrives pre-documented, with its evidence bundle generated by the same engine that wrote your SSP.

Who Builds This

Registered Practitioners, not resellers

Petronella Technology Group, Inc. has built security and compliance programs for regulated businesses from Raleigh, North Carolina since 2002 and is a Cyber AB Registered Provider Organization (RPO #1449). ComplianceArmor is engineered and delivered by our CMMC Registered Practitioner team, led by founder Craig Petronella (CMMC-RP, CCNA, CWNE, NC Digital Forensics Examiner license #604180). One line we will always draw clearly: as an RPO we prepare you for assessment and stand behind the readiness work; the certification assessment itself is always performed by an independent C3PAO. Anyone who promises to "certify you" is selling something they cannot deliver.

Questions

ComplianceArmor FAQ

What is ComplianceArmor and how is it different from Vanta, Drata, or Secureframe?

ComplianceArmor is an AI compliance platform paired with an on-premises CUI enclave appliance, built for CMMC Level 2 and NIST 800-171. General-purpose compliance SaaS platforms monitor your cloud stack and give you checklists to work through yourself. ComplianceArmor does the assessment work itself with a local LLM, generates the SSP, POA&Ms, SPRS score, and evidence tracker, and then, uniquely, ships the encrypted appliance that closes the technical gaps it found. No compliance SaaS vendor closes that loop.

Does the AI assessment send my control data or CUI to the cloud?

No. The assessment engine runs on a local large language model on hardware we or you control, with zero third-party AI API calls. Your control narratives, network diagrams, and evidence never enter a vendor cloud. For organizations whose most sensitive documentation is literally a map of their security posture, this is the design decision everything else follows from.

What does the platform actually generate?

A scored assessment of all 110 NIST 800-171 controls, the System Security Plan written control by control, POA&M entries for every gap, your computed SPRS score, and an Evidence Request Tracker listing exactly what documentation is still needed. Every package is reviewed by a CMMC Registered Practitioner before delivery.

Is the appliance FIPS validated?

The appliance performs all cryptography in operating-system modules that hold NIST CMVP validation certificates: Windows cng.sys (#4766) and bcryptprimitives (#4825) under FIPS 140-2, both Active until 2026-09-21, and Ubuntu 22.04 Kernel Crypto API (#4894) and OpenSSL (#4794) under FIPS 140-3. We cite certificate numbers rather than claiming a blanket "FIPS certified appliance," because that precision is what your assessor will actually check. The module versions running on your appliance are captured at assessment time by the operator.

Is ComplianceArmor a PreVeil alternative or a GCC High alternative?

Yes, it is the ownership path. Cloud CUI overlay services encrypt your data but host it per-seat in their cloud; a GCC High migration moves your whole company to a government tenant. The ComplianceArmor appliance keeps CUI on hardware you own, coexists with your existing Microsoft 365 Commercial tenant, prices by site instead of by seat, and gives your engineers edit-in-place instead of download-and-re-upload workflows.

What is edit-in-place and why does it matter?

Your engineers open, edit, and save CUI files directly over an encrypted SMB 3.1.1 share, with encryption required on the wire. There is no download-edit-re-upload round trip, so no local plaintext copies accumulating on laptops and no version conflicts. We demonstrated the workflow live on an air-gapped network segment in July 2026, including proof that the share is unreachable from outside the enclave.

How much does ComplianceArmor cost?

Appliance deployment is From $9,997 one-time, the appliance license is From $6,000 per site per year, the 5-seat hosted enclave license is From $2,916 per year, enclave-web standup is From $2,500, and managed monitoring on the appliance is From $6,900 per year. Every figure is a From-price scoped to your node count and site topology, locked in writing before work begins, and invoiced 100% upfront at contract execution.

Do you certify us for CMMC?

No, and be wary of anyone who says they can. Petronella Technology Group, Inc. is a Cyber AB Registered Provider Organization (RPO #1449): we architect, deploy, document, and prepare you so the assessment goes smoothly. The certification assessment itself is always performed by an independent C3PAO. That separation of duties is a feature of the CMMC ecosystem, not a limitation.

Which CMMC level does ComplianceArmor support?

The platform and appliance are built for CMMC Level 2, which implements all 110 NIST SP 800-171 controls for organizations handling CUI. If you only handle Federal Contract Information and need Level 1, start with our CMMC compliance practice, which covers all levels and will route you to the right-sized engagement.

How does the waitlist work?

Rollout is cohort-based so every deployment gets Registered Practitioner attention. You join with a name and email, we send one confirmation and a handful of short educational notes, and when your cohort opens an RP reaches out to scope your environment. Joining costs nothing, commits you to nothing, and every email has a one-click unsubscribe.

Ready to close the loop?

Assess with AI. Close on hardware you own. Join the waitlist and a CMMC Registered Practitioner from Petronella Technology Group, Inc. will reach out when your cohort opens.