HoundShieldHoundShield
Products
Products by Industry

One firewall · every compliance framework · one deployment

TechnologySOC 2

Engineers pasting API keys & source into Copilot.

HealthcareHIPAA

Clinicians pasting PHI into AI for documentation.

DefenseCMMC L2

DoD contractors leaking CUI into proposal tools.

Legal & FinancePCI

Privileged client data shared with AI assistants.

Five EyesAUKUS

Allied suppliers navigating DISP & Essential 8.

GovernmentSoon

FedRAMP / FISMA — agency AI governance.

SOC 2 · HIPAA · CMMC L2 · 16 engines · <10msAll capabilities
Features
Core Capabilities

Inside the HoundShield firewall engine

AI Prompt Interception

Every LLM request inspected before it leaves the network.

16 Detection Engines

CUI, PII, IP, PHI, secrets, CAGE codes, clearances.

Immutable Audit Trail

SHA-256 tamper-evident logs. C3PAO-ready.

Live Threat Dashboard

Real-time blocked prompts, risk & posture.

Pricing
Pricing

All frameworks included in every plan

Free

Up to 1,000 prompts/mo

$0/mo
Pro

CMMC suite + AI gateway

$199/mo
Growth

PDF reports + C3PAO coord

$499/mo
Enterprise

On-prem · air-gapped

$999/mo
Compare all plans
Partners
Partner Program

Build & grow with HoundShield

RPO / MSP Referral

Co-brand the $499 report · keep the margin.

MSP / Agency

40% per report · 20% recurring · white-label.

Integrations

Drop-in proxy for ChatGPT, Copilot, Claude.

Docs
Documentation

Live in under 5 minutes · no code changes

Quickstart

One URL change → full compliance.

API Reference

Gateway, classifier & audit endpoints.

FAQ

Searchable answers — pricing, HIPAA, CUI.

16 engines · <10ms scan
Sign inStart free

NIST 800-171 Controls · Access Control

AC.2.013 — Employ Cryptographic Mechanisms for Remote Access

CMMC Level 2SPRS if unmet: -3HIGH priority~8h to implement

Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.

What AC.2.013 means in plain English

When your employees connect remotely to your systems, the connection must be encrypted — meaning the data traveling back and forth is scrambled so that anyone who intercepts it on the internet can't read it. A VPN (Virtual Private Network) using modern encryption like AES-256 satisfies this. Plain Remote Desktop open to the internet, unencrypted FTP, or HTTP (not HTTPS) do not.

The assessment question

“Is all remote access to your systems protected by strong encryption — for example, using a VPN with AES-256 encryption, TLS 1.2 or higher for web-based access, or SSH for server access — rather than unencrypted protocols?”

How to implement AC.2.013

  1. Deploy a VPN solution that uses AES-256 encryption for all remote worker connections. OpenVPN (free, uses AES-256 by default) or WireGuard (free, uses ChaCha20 encryption which is FIPS-acceptable) are excellent free options.
  2. Never expose Remote Desktop (RDP) port 3389 directly to the internet — it must only be accessible through an encrypted VPN. Check your firewall/router settings to confirm port 3389 is not open externally.
  3. Ensure any web portals used for remote access use HTTPS (TLS 1.2 or 1.3 minimum) and not plain HTTP. Verify by checking that the URL starts with "https://" and the browser shows a padlock icon.
  4. For file transfer, use SFTP (Secure FTP) or SharePoint/OneDrive (which uses TLS) rather than plain FTP. Disable FTP on your servers if it is running.
  5. Document which encryption protocol and minimum key length is in use for each remote access method in your System Security Plan.

Evidence your assessor will ask for

  • VPN configuration screenshots showing encryption protocol and cipher suite (AES-256 or equivalent)
  • Firewall rule export or screenshot confirming RDP port 3389 is blocked from external access
  • Network diagram or written description of all remote access paths and their encryption methods
  • SSL/TLS configuration for any web portals (e.g., SSL Labs test result showing TLS 1.2+)
  • Written Remote Access Policy specifying required encryption standards

Does AI prompt monitoring help with this control? Honestly, no.

AC.2.013 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.

Full mapping: which 800-171 controls AI prompt monitoring evidences →

More Access Control controls

AC.1.001

Limit System Access to Authorized Users

AC.1.002

Limit System Access to Authorized Transaction Types

AC.2.003

Control CUI Flow per Authorizations

AC.2.004

Separate Duties to Reduce Risk

AC.2.005

Employ Least Privilege

AC.2.006

Use Non-Privileged Accounts for Non-Security Functions

Score yourself against all 110 controls

The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.

Start the free assessment $499 AI risk assessment
HoundShieldHoundShield

Local-only AI compliance firewall for CMMC Level 2, HIPAA & SOC 2. Prompt content never leaves your network.

CMMC LVL 2HIPAASOC 2NIST 800-171DFARS 7012
Product
FeaturesHow it worksPricingCompareDashboardChangelog
Compliance
CMMC Level 2HIPAASOC 2NIST 800-171DFARS 7012
Company
PartnersDocumentationFAQContact salesAboutSecurity
© 2026 HoundShield. All rights reserved. · Privacy · Termshoundshield.com · local-only · zero data exfiltration