Customer-operated controls · HIPAA & NIST 800-171 mapping

Keep regulated data inside your control boundary.

Evaluate AI prompt controls without pretending every workload is the same. HoundShield scans compatible traffic inside your environment, helps you document the control boundary, and produces an evidence-oriented assessment mapped to HIPAA and NIST 800-171.

Hosted evaluation clearly labelled Self-hosted path for sensitive workloads Your deployment, your boundary Evidence-oriented PDF
HoundShield
Illustrative preview

Example AI control flow

Sample events
120
illustrative only
Blocked sample
8
policy outcome
Example score
84
not a customer score
Sample review
2
illustrative queue
Sample policy decisionsstatic example

Illustrative outcomes for compatible requests intentionally routed through a configured gateway.

BLOCKEDCUI · CAGE 1ABC2 + contract #7ms
PASSEDclean · weekly status email11ms
BLOCKEDSecret · sk-live-…a91 API key5ms
Example classification mixsample

Illustrative categories: CUI, secrets, PII and PHI.

8blocked
CUI 34%
Secrets 24%
PII 27%
PHI 15%
Example policy categoriesstatic sample

Illustrative pattern categories available in a configured deployment.

CUI
61
Secrets
48
PII
83
PHI
27
Source/IP
35
CAGE
19
Illustrative routingexample

Configured destinations vary by the workflow, provider, and deployment you approve.

ChatGPT
46%
Copilot
31%
Claude
18%
Other
5%
Illustrative assessment posture — not a customer scoreExample 84 · 88%
16
Detection engines
54 patterns · CUI · PHI · PII
89%
of healthcare genAI
violations involve regulated data — vs 31% across all industries
110
NIST 800-171 controls
Mapped & SPRS-scored
<10ms
Local scan target
Measured locally; workload dependent

CUI-safe = Mode B (Docker on your infrastructure). The hosted trial runs on Vercel and is not FedRAMP-authorized — use it for non-CUI evaluation only.

Evidence readiness path

From control boundary to reviewable evidence.

HoundShield helps you make the path explicit. Your deployment, configuration, reviewers, and assessment scope determine the result.

01 · Route

Choose the boundary deliberately

Start with the AI traffic and supporting documents you intentionally place inside your deployment and review process.

02 · Verify

Keep a human in the decision loop

Review configured control outcomes and proposed evidence fields before relying on them for an internal assessment or customer response.

03 · Evidence

Build a reviewable record

Organise source-linked decision and document evidence for your own assessment, SSP, POA&M, or customer-review workflow.

Deployment boundary

Evidence supports review. It does not replace it.

Browser-local document review keeps selected files on the operator's device. Validate every deployment, retention decision, and control mapping for your actual contract and environment.

The asymmetric advantage

Start with the boundary your assessor will ask about.

Cloud DLP, productivity-suite governance and local proxy enforcement solve different problems. HoundShield is designed for teams that need a self-hosted control path for AI traffic outside their existing productivity suite. Validate the deployment model against your contract and SSP.

Cloud-routed DLP

Broad cloud DLP can be a strong fit for SaaS data protection. Teams handling controlled data should document its data path and decide whether a cloud inspection model fits their boundary.

Productivity-suite governance

Strong governance inside your productivity suite. It complements—not replaces—a deliberate control path for third-party AI services and developer tools outside that surface.

HoundShield

A self-hosted enforcement option for compatible AI traffic. Detection runs in your environment; use the deployment guide to validate scope, integrations and data residency before rollout.

One platform

A clearer path from assessment to evidence

Map a self-assessment to NIST 800-171 controls, prioritise remediation work, and organise supporting evidence for your internal review and assessment process.

110 controls

CMMC Self-Assessment

Guided questionnaires across all 110 NIST SP 800-171 controls. Your SPRS score updates live as you complete each practice.

Prioritized

AI-Powered Gap Analysis

Brain AI flags unmet controls and generates a remediation roadmap ranked by risk severity and cost — on-device, your key.

Reviewable

SSP & POA&M Export

Generate draft System Security Plan and Plan of Action & Milestones materials with integrity metadata for your review process.

Configured AI Gateway

Inspect compatible requests intentionally routed through HoundShield before they reach an approved upstream AI service.

16 Detection Engines

PHI, CUI, PII, IP, secrets, CAGE codes, contract numbers and clearance markers — 54 shipped patterns, flagged, blocked or quarantined.

Decision Dashboard

Review configured policy outcomes, risk context, and evidence records for the workflows intentionally routed through the deployment.

Start here · scoped assessment

AI Risk Assessment

Review a defined AI workflow, its control boundary, and the assessment materials needed for your internal evidence process. Scope, compatible integrations, deployment mode, retention, and commercial terms are confirmed before sensitive data or production traffic is used.

  • Scoped workflow review for compatible traffic intentionally routed through an agreed customer-operated deployment
  • Policy and control mapping to support your assessment against applicable NIST 800-171 and HIPAA considerations
  • Reviewable decision records with integrity and provenance information where supported by the selected deployment
  • Assessment materials with findings, assumptions, scope, limitations, and recommended next actions for your review
Sensitive workflows require a reviewed customer-operated deployment Scope and timeline confirmed before engagement Review the deployment and data boundary before purchase
$499
assessment engagement · scope confirmed first
Start assessment engagement — $499 Confirm scope before purchase →

Confirm the selected deployment, data boundary, scope, timeline, and commercial terms before using sensitive data or production traffic. See an illustrative sample report (PDF)

FAQ

Questions teams ask before deploying

Still have questions? Talk to a compliance engineer — we respond within 4 business hours.

Ready to validate your AI control boundary?

Start with the deployment path, compatible traffic, and evidence workflow that fit your environment.

Explore the control boundary