In-enclave compliance firewall for defense
Built for the Defense Industrial Base under CMMC 2.0 / NIST 800-171. Detect unmarked and derivative CUI/ITAR at the boundary.Intelligence that keeps 100% of your data inside your enclave.
How it works
Work normally in your flow
Atium inspects outbound email and documents inside your enclave.
Detect suspected CUI
A cascade of fine-tuned classifiers and an in-enclave SLM flag unmarked and derivative CUI/ITAR with evidence.
Route to an authorized holder
Suspected CUI is routed to the ISSO for designation — Atium never self-designates.
Deploys inside your enclave
On-prem or Azure Government / GCC High. No external AI calls. No data leaves your boundary.
“Grammarly for Compliance” integrated directly into your communication workflow
Risky messages are surfaced with evidence before they become an incident you have to report.
Zero egress — data never leaves your infrastructure
All detection runs inside your enclave (on-prem or Azure Gov / GCC High). CUI and ITAR-controlled data are never routed through commercial cloud AI.
Multi-stage detection cascade: deterministic + ML + in-enclave SLM
Deterministic rules enforce known CUI markings, ML surfaces unmarked and derivative material, and the in-enclave SLM explains why — all designed around a strict false-positive budget.
Human-in-the-loop designation by an authorized holder
Atium flags suspected CUI with evidence and routes it to the ISSO — it never self-designates, keeping you on the right side of CUI handling rules.
ISSO review portal with assessor-ready audit trail
Suspected CUI is queued for review; every decision is hash-chained and tamper-evident, mapped to NIST 800-171 controls for CMMC assessors.