HoundShieldHoundShield
Products
Products by Industry

One firewall · every compliance framework · one deployment

TechnologySOC 2

Engineers pasting API keys & source into Copilot.

HealthcareHIPAA

Clinicians pasting PHI into AI for documentation.

DefenseCMMC L2

DoD contractors leaking CUI into proposal tools.

Legal & FinancePCI

Privileged client data shared with AI assistants.

Five EyesAUKUS

Allied suppliers navigating DISP & Essential 8.

GovernmentSoon

FedRAMP / FISMA — agency AI governance.

SOC 2 · HIPAA · CMMC L2 · 16 engines · <10msAll capabilities
Features
Core Capabilities

Inside the HoundShield firewall engine

AI Prompt Interception

Every LLM request inspected before it leaves the network.

16 Detection Engines

CUI, PII, IP, PHI, secrets, CAGE codes, clearances.

Immutable Audit Trail

SHA-256 tamper-evident logs. C3PAO-ready.

Live Threat Dashboard

Real-time blocked prompts, risk & posture.

Pricing
Pricing

All frameworks included in every plan

Free

Up to 1,000 prompts/mo

$0/mo
Pro

CMMC suite + AI gateway

$199/mo
Growth

PDF reports + C3PAO coord

$499/mo
Enterprise

On-prem · air-gapped

$999/mo
Compare all plans
Partners
Partner Program

Build & grow with HoundShield

RPO / MSP Referral

Co-brand the $499 report · keep the margin.

MSP / Agency

40% per report · 20% recurring · white-label.

Integrations

Drop-in proxy for ChatGPT, Copilot, Claude.

Docs
Documentation

Live in under 5 minutes · no code changes

Quickstart

One URL change → full compliance.

API Reference

Gateway, classifier & audit endpoints.

FAQ

Searchable answers — pricing, HIPAA, CUI.

16 engines · <10ms scan
Sign inStart free

NIST 800-171 Controls · System and Communications Protection

SC.1.001 — Monitor and Protect Communications at Boundaries

CMMC Level 1SPRS if unmet: -5CRITICAL priority~12h to implement

Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.

What SC.1.001 means in plain English

You need a firewall between your network and the internet, and it needs to be actually configured — not just plugged in with default settings. The firewall watches all traffic going in and out and blocks anything suspicious. If you have separate networks (like an office network and a shop floor network), put a firewall or at least managed switch rules between them too. Check your firewall logs periodically to see if anything sketchy is trying to get in.

The assessment question

“Do you have a properly configured firewall at your internet boundary that monitors and controls inbound and outbound network traffic, and do you review firewall logs for suspicious activity?”

How to implement SC.1.001

  1. If you are using the basic router from your ISP, replace it with a proper firewall. A pfSense appliance (Netgate 1100 for ~$189) or a Ubiquiti Dream Machine (~$379) gives you real firewall capabilities with logging.
  2. Configure your firewall with a "deny all inbound" default rule, then create specific allow rules only for traffic you actually need (e.g., inbound VPN, outbound web browsing, outbound email).
  3. Enable firewall logging and review logs weekly for blocked connection attempts, especially from foreign IP addresses or unusual ports.
  4. If you have different network segments (office, shop floor, guest WiFi), configure firewall rules between them so the guest WiFi cannot reach your CUI systems.
  5. Document your firewall rules in a spreadsheet: rule number, source, destination, port, protocol, action (allow/deny), and business justification.

Evidence your assessor will ask for

  • Firewall configuration export showing rule set with deny-by-default policy
  • Network diagram showing firewall placement at external and key internal boundaries
  • Firewall log samples showing traffic is being monitored and suspicious traffic blocked
  • Documented firewall rule set with business justifications for each allow rule
  • Evidence of periodic firewall log review (review notes or screenshots)

Does AI prompt monitoring help with this control? Yes — directly.

SC.1.001 is one of the requirements a local AI prompt firewall concretely evidences. When employees send prompts to ChatGPT, Copilot, or Claude, that traffic crosses your external boundary — HoundShield inspects it on your own infrastructure (self-hosted Docker, Mode B), blocks CUI patterns before transmission, and writes every allowed/blocked event to a SHA-256 hash-chained log attributable to the user. Architecture diagram, active pattern set, and a log sample are the evidence an assessor tests this against for the AI data path.

Full mapping: which 800-171 controls AI prompt monitoring evidences →

More System and Communications Protection controls

SC.1.005

Implement Subnetworks for Public Components

SC.2.002

Employ Effective Security Architecture

SC.2.003

Separate User and System Management Functionality

SC.2.004

Prevent Unauthorized Info Transfer via Shared Resources

SC.2.006

Deny Network Traffic by Default

SC.2.007

Prevent Remote Device Split Tunneling

Score yourself against all 110 controls

The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.

Start the free assessment $499 AI risk assessment
HoundShieldHoundShield

Local-only AI compliance firewall for CMMC Level 2, HIPAA & SOC 2. Prompt content never leaves your network.

CMMC LVL 2HIPAASOC 2NIST 800-171DFARS 7012
Product
FeaturesHow it worksPricingCompareDashboardChangelog
Compliance
CMMC Level 2HIPAASOC 2NIST 800-171DFARS 7012
Company
PartnersDocumentationFAQContact salesAboutSecurity
© 2026 HoundShield. All rights reserved. · Privacy · Termshoundshield.com · local-only · zero data exfiltration