HoundShieldHoundShield
Products
Products by Industry

One firewall · every compliance framework · one deployment

TechnologySOC 2

Engineers pasting API keys & source into Copilot.

HealthcareHIPAA

Clinicians pasting PHI into AI for documentation.

DefenseCMMC L2

DoD contractors leaking CUI into proposal tools.

Legal & FinancePCI

Privileged client data shared with AI assistants.

Five EyesAUKUS

Allied suppliers navigating DISP & Essential 8.

GovernmentSoon

FedRAMP / FISMA — agency AI governance.

SOC 2 · HIPAA · CMMC L2 · 16 engines · <10msAll capabilities
Features
Core Capabilities

Inside the HoundShield firewall engine

AI Prompt Interception

Every LLM request inspected before it leaves the network.

16 Detection Engines

CUI, PII, IP, PHI, secrets, CAGE codes, clearances.

Immutable Audit Trail

SHA-256 tamper-evident logs. C3PAO-ready.

Live Threat Dashboard

Real-time blocked prompts, risk & posture.

Pricing
Pricing

All frameworks included in every plan

Free

Up to 1,000 prompts/mo

$0/mo
Pro

CMMC suite + AI gateway

$199/mo
Growth

PDF reports + C3PAO coord

$499/mo
Enterprise

On-prem · air-gapped

$999/mo
Compare all plans
Partners
Partner Program

Build & grow with HoundShield

RPO / MSP Referral

Co-brand the $499 report · keep the margin.

MSP / Agency

40% per report · 20% recurring · white-label.

Integrations

Drop-in proxy for ChatGPT, Copilot, Claude.

Docs
Documentation

Live in under 5 minutes · no code changes

Quickstart

One URL change → full compliance.

API Reference

Gateway, classifier & audit endpoints.

FAQ

Searchable answers — pricing, HIPAA, CUI.

16 engines · <10ms scan
Sign inStart free

Security & Trust

The data that matters never leaves your network.

Every cloud-based AI DLP tool sends your CUI to its servers to scan it — that transfer is itself a potential CUI spill under DFARS 7012. HoundShield scans everything locally. Nothing leaves your network. That is the foundation of our security posture, and the one property a cloud competitor structurally cannot copy.

Local-only by design

The scanning engine runs inside your network. Prompt content, CUI, PHI, and PII are inspected on-premise and never transmitted to our servers. This is the entire architecture — not a configuration option.

Encryption everywhere

AES-256 for any quarantined content at rest, TLS 1.3 for all data in transit. Payment data is handled entirely by Stripe; we never store card numbers.

Tamper-evident audit trail

Every compliance event is written to an append-only, SHA-256-hash-chained log — the evidence format a C3PAO assessor expects, and one that makes silent alteration detectable.

Tenant isolation

Row-Level Security isolates each organization's metadata. Access follows least privilege; authentication is handled by Supabase with session-token verification on every protected route.

Hardened by default

HSTS, CSP, X-Frame-Options DENY, nosniff, and a strict referrer policy ship on every response. API routes are rate-limited. Dependencies are scanned for known vulnerabilities.

Responsible disclosure

We publish a security.txt (RFC 9116) and welcome good-faith research. Report a vulnerability and we will acknowledge it and work with you on a fix.

Where the scanner runs matters

The local-only guarantee is a property of deployment, not just code. Our marketing and dashboard plane runs on Vercel, which is not FedRAMP-authorized — so the hosted trial is for non-CUI evaluation only. For any CUI workload, run Mode B: the proxy in your own infrastructure, where prompt content never crosses your boundary.

Handling CUI? Run Mode B.

HoundShield scans prompts locally in under 10ms. That CUI-safe property holds only when the scanner runs inside your own boundary. Pick the deployment mode that matches your data:

A · Hosted trial

On Vercel — not FedRAMP-authorized. Demo and non-CUI evaluation only.

B · Self-hosted Docker

Your own infrastructure. CUI-safe — prompt content never leaves your boundary. Right for CUI-handling contractors.

C · Air-gapped

Isolated network. CUI-safe. For enterprise / IL-5+ environments.

Compliance alignment

HoundShield is a control engineered to help you satisfy specific obligations. It maps to all 110 NIST 800-171 Rev 2 controls for SPRS scoring and is built for the following frameworks:

  • CMMC Level 2
  • NIST 800-171
  • DFARS 252.204-7012
  • HIPAA
  • SOC 2
  • ISO 27001 (mapping)

Report a vulnerability

Found something? Email security@houndshield.com or read our machine-readable policy at /.well-known/security.txt. Please give us a reasonable window to remediate before public disclosure. Good-faith research conducted under these terms will not be pursued as a violation of our Acceptable Use Policy.

Live service status: houndshield.com/status

Privacy Policy →Data Processing Agreement →Terms of Service →
HoundShieldHoundShield

Local-only AI compliance firewall for CMMC Level 2, HIPAA & SOC 2. Prompt content never leaves your network.

CMMC LVL 2HIPAASOC 2NIST 800-171DFARS 7012
Product
FeaturesHow it worksPricingCompareDashboardChangelog
Compliance
CMMC Level 2HIPAASOC 2NIST 800-171DFARS 7012
Company
PartnersDocumentationFAQContact salesAboutSecurity
© 2026 HoundShield. All rights reserved. · Privacy · Termshoundshield.com · local-only · zero data exfiltration