Assess with AI. Close on hardware you own.
ComplianceArmor from Petronella Technology Group, Inc. pairs a local-LLM platform that scores all 110 NIST 800-171 controls and writes your SSP, POA&Ms, SPRS score, and Evidence Request Tracker with a FIPS-validated on-premises appliance that actually stores and protects the CUI. Delivered by CMMC Registered Practitioners. Nothing touches a cloud you do not own.
Join the waitlist
Rollout is cohort-based. Hold your spot for the platform, the appliance, or both. No payment, no commitment, and a CMMC Registered Practitioner reaches out when your cohort opens.
Get on the listSee the AI platform
How a local-only LLM assesses all 110 controls and writes the SSP, POA&Ms, SPRS score, and Evidence Request Tracker without your data leaving the building.
Explore the platformSee the appliance
A sovereign CUI enclave on your rack: encrypted file store and encrypted mail on CMVP-validated FIPS modules, validated before it ships.
Explore the applianceCompare the alternatives
Side by side against cloud CUI overlay services and a GCC High migration: data location, economics, workflow, and lock-in.
See the comparisonThe compliance loop no software vendor closes
Compliance SaaS ends at a dashboard and a to-do list. Assessors do not certify dashboards; they verify that CUI is actually protected. ComplianceArmor pairs the assessment engine with the sovereign enclave it recommends, so the finding and the fix come from the same engagement.
AI that does the assessment work itself
Point it at your evidence. The engine scores every control, writes the narratives, and builds the artifact set an assessor expects to see.
- All 110 NIST 800-171 controls, scored with rationale
- System Security Plan written control by control
- POA&Ms and SPRS score computed
- Evidence Request Tracker for every gap
- Reviewed and delivered by a CMMC Registered Practitioner
A sovereign enclave that holds the CUI
An on-premises, no-cloud appliance shipped as a hardened golden image. Your hardware, your keys, your disks.
- Encrypted CUI file store and encrypted CUI mail
- All crypto in CMVP-validated FIPS modules
- Edit CUI in place over an encrypted share
- Coexists with Microsoft 365 Commercial
- Site-based pricing, not per-seat
In Short
- ComplianceArmor is two halves of one loop: an AI compliance platform that assesses and documents, and an on-premises CUI enclave appliance that protects.
- The AI runs locally. No cloud API calls; control narratives, diagrams, and evidence never leave your side of the boundary.
- The appliance is validated before it ships: golden images clone-tested end to end, cryptography in NIST CMVP-validated modules, keys sealed per deployment.
- Edit-in-place: engineers open, edit, and save CUI directly over encrypted SMB 3.1.1, with no download and re-upload round trip, demonstrated live and air-gapped in July 2026.
- Transparent From-pricing: appliance deployment From $9,997, appliance license From $6,000 per site per year, fees 100% upfront.
- Rollout is cohort-based: join the waitlist and a CMMC Registered Practitioner scopes your environment when your cohort opens.
Which half do you need first?
AI CMMC compliance software that runs entirely on your side of the boundary
Most compliance tools give you 110 empty text boxes. ComplianceArmor reads your evidence and does the first pass itself, offline, on a local model, with a human Registered Practitioner accountable for what ships.
Local-LLM gap assessment
The engine evaluates all 110 NIST 800-171 controls against your actual evidence. The model runs on hardware you control; there are no third-party AI calls, so control narratives, network diagrams, and evidence never enter a vendor cloud.
How the gap analysis worksAssessor-grade artifacts, generated
The System Security Plan written control by control, POA&Ms for every gap, your computed SPRS score, and an Evidence Request Tracker that tells you exactly what is missing before an assessor asks.
See the SSP generatorA Registered Practitioner stands behind it
AI speed, human accountability. Every package is reviewed and delivered by a CMMC Registered Practitioner. We are a Cyber AB Registered Provider Organization: we prepare you for assessment; certification itself is always performed by an independent C3PAO.
Our CMMC practiceCMMC first, framework-wide
Built for CMMC Level 2 and NIST 800-171, with framework modules for HIPAA, PCI DSS, SOC 2, and CCPA documentation packages on the same engine.
CMMC software moduleEdit CUI in place. No download. No re-upload. No version chaos.
The daily-life failure of most secure file services is the round trip: download the CAD file, edit it, re-upload it, hope nobody else did the same in parallel. ComplianceArmor serves CUI over an encrypted SMB 3.1.1 share with encryption enforced, so your engineers open the file, edit it, and hit save. That is the whole workflow. We demonstrated it live on an air-gapped network segment: a client workstation editing a file inside the enclave directly, with the share provably unreachable from outside the enclave.
The old way
download > edit > re-upload > conflict > email the "final_v3" copy
ComplianceArmor
open > edit > save
A sovereign CUI enclave appliance, validated before it ships
Shipped as hardened golden virtual-machine images and deployed on a small server in your office. Every image is cloned and re-validated end to end before release; encryption keys are sealed to each deployment's own virtual TPM on first boot, never shared between customers.
Windows Server 2022, FIPS mode
Full-volume BitLocker XTS-AES-256 on both the OS and CUI volumes, keys sealed to a per-deployment virtual TPM, native SMB 3.1.1 file service with encryption required, and co-located CUI mail with S/MIME. Clone validation runs 18 automated evidence checks; the current golden passed all 18 with zero failures.
Ubuntu Pro FIPS
LUKS2 AES-256-XTS encryption at rest on the CUI volume, Kerberos-authenticated NFSv4.2 with krb5p privacy as the CUI transport, and an encrypted mail stack. The assessor-facing verify harness runs on every clone and must return an overall PASS before handoff.
Field capture, VPN, and CUI mail Live-built
Mobile field capture (photos and documents land directly in the encrypted enclave), a FIPS IKEv2 remote-access VPN with certificate-based mutual authentication, and an end-to-end CUI mail stack with a tamper-evident audit chain. Each module was live-built and validated on its own appliance clone in July 2026.
Voice and video In validation
Secure voice and video conferencing inside the enclave is in validation: the cryptographic core is verified, and end-to-end call flows are being proven now. We publish status honestly; nothing on this page is sold as done before it is validated.
The certificate numbers behind the encryption claims
We do not self-attest. All appliance cryptography is performed by operating-system modules holding their own NIST CMVP validation certificates, published where anyone can verify them. When an assessor asks, you cite certificate numbers, not marketing language.
| Cryptographic module | CMVP certificate | Standard | Status |
|---|---|---|---|
| Windows Kernel Mode Cryptographic Primitives Library (cng.sys) | #4766 | FIPS 140-2 | Active until 2026-09-21 |
| Windows Cryptographic Primitives Library (bcryptprimitives.dll) | #4825 | FIPS 140-2 | Active until 2026-09-21 |
| Ubuntu 22.04 Kernel Crypto API | #4894 | FIPS 140-3 | Validated |
| Ubuntu 22.04 OpenSSL | #4794 | FIPS 140-3 | Validated |
Stated plainly for the record: the Windows platform ships on FIPS 140-2 validated modules with a published sunset date and a documented transition path; the Ubuntu SKU's modules are FIPS 140-3. An issued validation with a sunset date is still an issued validation, and your assessor will appreciate that we say so out loud. The exact module versions and certificates for your running appliance are captured by the operator at assessment time, never pre-filled.
A PreVeil alternative and GCC High alternative you own outright
Defense contractors handling CUI are usually offered two paths: bolt a cloud encryption overlay onto their existing tenant, or migrate the whole company to a government cloud. Both leave your most sensitive data on infrastructure you rent. Here is how the third path compares.
| ComplianceArmor appliance | Cloud CUI overlay services | GCC High migration | |
|---|---|---|---|
| Where CUI lives | On your hardware, in your building, on disks you own | Vendor cloud, encrypted, but hosted and controlled by the vendor | Microsoft government cloud tenant |
| Economics | Site-based license; the tenth engineer costs the same as the first | Per-seat, per-year, forever | Tenant migration project plus elevated per-seat licensing |
| CUI edit workflow | Edit in place over an encrypted share: open, edit, save | Typically download, edit, re-upload through the vendor client | Native, but only after full tenant migration |
| M365 Commercial coexistence | Yes. Business email stays put; only the CUI channel moves to the appliance | Yes, as an overlay on the existing tenant | No. The point is moving off Commercial |
| FIPS validation basis | NIST CMVP certificate numbers you can cite to an assessor | Varies by vendor; verify the certificate, not the brochure | Microsoft platform validations |
| Exit path | You keep the hardware, the images, and the data. It is yours | Export and off-board through the vendor | Second migration project |
Transparent From-pricing, 100% upfront
Final scope depends on node count and site topology, so every figure is a From-price confirmed in writing before work begins. Fixed-fee milestones are invoiced 100% upfront at contract execution.
Every quote is locked in writing before work begins. No surprise change orders, no per-seat creep.
Get in line for the ComplianceArmor rollout
Join the waitlist
Rollout is cohort-based so every deployment gets a CMMC Registered Practitioner's attention. Joining costs nothing and commits you to nothing: you hold a spot, we send a short confirmation, and when your cohort opens we reach out to scope your environment.
You are on the list.
Watch your inbox for a confirmation from Petronella Technology Group, Inc. Rollout is cohort-based; a CMMC Registered Practitioner will reach out when your cohort opens. Want to move faster? Book a scoping call now or run the ROI numbers while you wait.
From waitlist to a working enclave
Waitlist + scoping
Join the list. When your cohort opens, a CMMC Registered Practitioner scopes your CUI footprint, sites, and node count.
AI assessment sprint
The platform assesses all 110 controls and generates your SSP, POA&Ms, SPRS score, and Evidence Request Tracker.
Appliance deployment
Your appliance deploys from the golden image and is clone-validated on site, with keys sealed to its own virtual TPM.
CUI migration
CUI consolidates into the enclave and your team cuts over to edit-in-place. M365 Commercial stays for everything else.
Operate + monitor
Ongoing monitoring on the appliance From $6,900/yr, with golden-image refreshes under the site license.
Why on-premises CUI enclaves are back
For a decade the default answer to every infrastructure question was "move it to the cloud." For most workloads that answer still holds. Controlled Unclassified Information is the exception, because the question an assessor asks is not "is it encrypted?" but "who controls the keys, the disks, and the boundary?" When your CUI sits in a vendor's multi-tenant cloud, the honest answer involves a lot of trust in somebody else's paperwork. When it sits in an encrypted enclave on a server in your office, the answer is short: you do.
The economics point the same direction. Cloud CUI services price per seat per year, which means the cost of compliance scales with headcount forever. A defense subcontractor with a dozen engineers touching CUI can watch a per-seat subscription quietly grow past the cost of owning the hardware outright in the first year or two. The appliance model inverts that: one site license, and the marginal cost of the next engineer is zero.
What "sovereign" actually means here
Sovereign is an overused word, so here is the concrete version. The ComplianceArmor appliance ships as a hardened golden virtual-machine image that runs on hardware you purchase and rack in your own facility. The disks are yours. The encryption keys are generated at your deployment and sealed to your appliance's own virtual TPM; we escrow a recovery key to you, not to us. The AI platform runs its language model on local hardware too, so even the assessment process, which necessarily reads your most sensitive security documentation, happens without a single byte leaving your control. If you ever walk away, you keep everything, because it was never ours to keep.
That posture also answers the FedRAMP question before it is asked. There is no cloud service provider in the CUI path, so there is no cloud service provider to authorize. The boundary discussion with your assessor gets shorter, not longer.
How the AI assessment works without exfiltrating a control narrative
The platform's assessment engine is a local large language model paired with a deterministic coverage layer built around the DoD assessment methodology. You provide the evidence: policies, screenshots, configurations, network diagrams. The engine reads them and scores each of the 110 NIST 800-171 controls, drafting the narrative for your System Security Plan, the POA&M entries for gaps, and the SPRS score DoD primes check before award. A CMMC Registered Practitioner reviews every output before it reaches you, because AI speed without human accountability is how bad SSPs get written.
The result set is the same artifact stack we deliver in our full-service CMMC compliance engagements, produced in a fraction of the calendar time. If you want to estimate what the automation is worth in your environment, the ROI calculator does that math with your numbers.
Where the appliance fits in your 800-171 boundary
The appliance is deliberately narrow: it is the CUI enclave, not a replacement for your IT stack. Business email, calendars, and general file sharing stay in your existing Microsoft 365 Commercial tenant, which is fine, because that tenant never touches CUI. The appliance carries the CUI file share, the CUI mailboxes, and the modules that feed them: mobile field capture for photos and documents from the shop floor, and a FIPS IKEv2 VPN for remote access into the enclave. That small, well-drawn boundary is exactly what makes the assessment conversation tractable: fewer systems in scope, each of them built to be shown to an assessor.
It is also what makes the two halves of ComplianceArmor stronger together. The platform documents a boundary; the appliance is a boundary that arrives pre-documented, with its evidence bundle generated by the same engine that wrote your SSP.
ComplianceArmor tools and modules
Registered Practitioners, not resellers
Petronella Technology Group, Inc. has built security and compliance programs for regulated businesses from Raleigh, North Carolina since 2002 and is a Cyber AB Registered Provider Organization (RPO #1449). ComplianceArmor is engineered and delivered by our CMMC Registered Practitioner team, led by founder Craig Petronella (CMMC-RP, CCNA, CWNE, NC Digital Forensics Examiner license #604180). One line we will always draw clearly: as an RPO we prepare you for assessment and stand behind the readiness work; the certification assessment itself is always performed by an independent C3PAO. Anyone who promises to "certify you" is selling something they cannot deliver.
ComplianceArmor FAQ
What is ComplianceArmor and how is it different from Vanta, Drata, or Secureframe?
ComplianceArmor is an AI compliance platform paired with an on-premises CUI enclave appliance, built for CMMC Level 2 and NIST 800-171. General-purpose compliance SaaS platforms monitor your cloud stack and give you checklists to work through yourself. ComplianceArmor does the assessment work itself with a local LLM, generates the SSP, POA&Ms, SPRS score, and evidence tracker, and then, uniquely, ships the encrypted appliance that closes the technical gaps it found. No compliance SaaS vendor closes that loop.
Does the AI assessment send my control data or CUI to the cloud?
No. The assessment engine runs on a local large language model on hardware we or you control, with zero third-party AI API calls. Your control narratives, network diagrams, and evidence never enter a vendor cloud. For organizations whose most sensitive documentation is literally a map of their security posture, this is the design decision everything else follows from.
What does the platform actually generate?
A scored assessment of all 110 NIST 800-171 controls, the System Security Plan written control by control, POA&M entries for every gap, your computed SPRS score, and an Evidence Request Tracker listing exactly what documentation is still needed. Every package is reviewed by a CMMC Registered Practitioner before delivery.
Is the appliance FIPS validated?
The appliance performs all cryptography in operating-system modules that hold NIST CMVP validation certificates: Windows cng.sys (#4766) and bcryptprimitives (#4825) under FIPS 140-2, both Active until 2026-09-21, and Ubuntu 22.04 Kernel Crypto API (#4894) and OpenSSL (#4794) under FIPS 140-3. We cite certificate numbers rather than claiming a blanket "FIPS certified appliance," because that precision is what your assessor will actually check. The module versions running on your appliance are captured at assessment time by the operator.
Is ComplianceArmor a PreVeil alternative or a GCC High alternative?
Yes, it is the ownership path. Cloud CUI overlay services encrypt your data but host it per-seat in their cloud; a GCC High migration moves your whole company to a government tenant. The ComplianceArmor appliance keeps CUI on hardware you own, coexists with your existing Microsoft 365 Commercial tenant, prices by site instead of by seat, and gives your engineers edit-in-place instead of download-and-re-upload workflows.
What is edit-in-place and why does it matter?
Your engineers open, edit, and save CUI files directly over an encrypted SMB 3.1.1 share, with encryption required on the wire. There is no download-edit-re-upload round trip, so no local plaintext copies accumulating on laptops and no version conflicts. We demonstrated the workflow live on an air-gapped network segment in July 2026, including proof that the share is unreachable from outside the enclave.
How much does ComplianceArmor cost?
Appliance deployment is From $9,997 one-time, the appliance license is From $6,000 per site per year, the 5-seat hosted enclave license is From $2,916 per year, enclave-web standup is From $2,500, and managed monitoring on the appliance is From $6,900 per year. Every figure is a From-price scoped to your node count and site topology, locked in writing before work begins, and invoiced 100% upfront at contract execution.
Do you certify us for CMMC?
No, and be wary of anyone who says they can. Petronella Technology Group, Inc. is a Cyber AB Registered Provider Organization (RPO #1449): we architect, deploy, document, and prepare you so the assessment goes smoothly. The certification assessment itself is always performed by an independent C3PAO. That separation of duties is a feature of the CMMC ecosystem, not a limitation.
Which CMMC level does ComplianceArmor support?
The platform and appliance are built for CMMC Level 2, which implements all 110 NIST SP 800-171 controls for organizations handling CUI. If you only handle Federal Contract Information and need Level 1, start with our CMMC compliance practice, which covers all levels and will route you to the right-sized engagement.
How does the waitlist work?
Rollout is cohort-based so every deployment gets Registered Practitioner attention. You join with a name and email, we send one confirmation and a handful of short educational notes, and when your cohort opens an RP reaches out to scope your environment. Joining costs nothing, commits you to nothing, and every email has a one-click unsubscribe.
Ready to close the loop?
Assess with AI. Close on hardware you own. Join the waitlist and a CMMC Registered Practitioner from Petronella Technology Group, Inc. will reach out when your cohort opens.
Petronella Technology Group, Inc. · Raleigh, North Carolina · Cyber AB Registered Provider Organization RPO #1449 · 919-348-4912 · support@petronellatech.com
Building toward a C3PAO assessment? Start with the CMMC compliance practice for the full readiness path, or check your current standing with the free SPRS score calculator and the CMMC Level 2 self-assessment walkthrough.