CUIVault™ — Desktop CUI protection

Encrypt CUI. Enforce the controls.
Keep the evidence.

A Windows desktop application for handling Controlled Unclassified Information — AES-256-GCM encryption under Windows FIPS mode(*), CAC/PIV and MFA sign-in, role-based access, and a hash-chained audit trail that records who did what, to which file, and when. Everything stays on the workstation. One-time license fee, no subscription, no cloud round-trip.

For federal contractors, compliance officers, and program managers responsible for CUI under CMMC.

One-time fee. No subscription. $599 per desktop.

Why CUIVault exists

The control is only half the job. The proof is the other half.

Under CMMC you have to show how Controlled Unclassified Information was protected at rest, who was allowed to touch it, and what they did with it. Most teams can describe the intent and then reconstruct the proof afterward from screenshots, folder permissions, and spreadsheet logs — which is exactly the part that falls apart under review.

CUIVault does both in one step, on the workstation. It enforces the technical control — encryption, authentication, least privilege, session lock, marking — and writes a tamper-evident record of every action as it happens. The evidence is a by-product of doing the work, not a project you run the week before an assessment.

What it does

A CUI workstation with the controls turned on.

Every CUI action — open, create, read, share, export, burn, key use — routes through one enforcement point. That is what makes the policy real and the audit trail complete.

Encrypted vault

AES-256-GCM, at rest, on the desktop.

Authenticated encryption for CUI files, with stored keys protected by a versioned PBKDF2-SHA256 format rather than left in the clear. When policy requires FIPS mode, operations fail closed on a workstation that isn’t running it.

Identity

CAC/PIV and MFA, so actions trace to a person.

Certificate chain validation with CRL/OCSP revocation checking, plus TOTP multi-factor. The authenticated principal is resolved once and carried through the session, so every audited action knows who performed it — and records when identity assurance was lower.

Role-based access

Least privilege, enforced and audited.

Vault Admin, Vault User, and Auditor roles gate privileged functions — policy administration, key management, vault administration, audit review and export — and can be mapped to Windows or domain groups. Denied attempts are recorded, not silently dropped.

Session controls

The screen locks. The vault re-locks.

Idle auto-lock conceals CUI across attached displays and requires re-authentication. Inactivity terminates the session, failed sign-ins trigger a timed lockout with backoff, and a CUI handling notice is presented and acknowledged at startup.

Tamper-evident audit

A record that shows if it was altered.

Structured records chained by hash — identity, action, target, outcome, sequence, previous hash — with built-in chain verification, HMAC-signed bundles, Windows Event Log anchoring, and CEF export to your SIEM. Deployments that need it can fail closed when the audit cannot be written.

Marking & controlled flow

Marked on screen, marked on the way out.

A CUI banner in the workspace, label sidecars written alongside exported files, approved-destination allowlists, removable-media export blocking, and secure burn for files and vault extents.

Operating posture

  • Signed policy store — lockout thresholds, idle timeout, passphrase rules, FIPS-required, export allowlists and role assignments, integrity-checked and administered from a Policy tab.
  • Passphrase policy — length and complexity enforcement, reuse history via non-reversible verifiers, and forced rotation of temporary passphrases.
  • Integrity alerting — encryption tag mismatches and manifest signature drift surface as audited alerts instead of silent exceptions.
  • Scan on ingest — optional antivirus scan before a file enters a vault, defaulting to Windows Defender and failing closed when required but unavailable.
  • DoD SAFE ingestion — strict TLS with no certificate bypass, with the validated certificate chain retained as evidence.
  • Trusted time — NTP-backed timestamps, with a policy switch to refuse audit writes when trusted time is unavailable.

Evidence you can hand over

  • Handling manifest — the human-readable record you attach to your CUI handling documentation.
  • Filtered audit exports — CSV and JSON, scoped to a window, a file, or a person, for review and investigation.
  • Control evidence map — a generated file linking product features to the requirement IDs they support, with each claim classified rather than asserted flat.
  • Build integrity — executable hashes and Authenticode signer status, with unsigned development builds recorded as such.
  • SBOM — CycloneDX component inventory to feed your vulnerability scanning.
  • Cryptographic inventory — what algorithm protects what, separating what the product controls from what the platform and DoD PKI control.
CMMC & NIST SP 800-171

Where CUIVault fits in your 800-171 program.

CMMC Level 2 assessments align to NIST SP 800-171 Rev. 2, and that is the baseline CUIVault maps to. Rev. 3 has been published and we track it for forward readiness — we don’t claim it as your assessment baseline.

No product makes an organization compliant. Compliance is a property of your system and your security program, not a feature you can buy.

So the useful question isn’t whether CUIVault “covers” 800-171. It’s which requirements it enforces technically, which it detects and records, which it merely supplies evidence for, and which stay entirely yours. CUIVault classifies every claim it makes into exactly those four buckets — and ships that classification as a file, so your assessor can check our work instead of taking our word for it.

Enforces

The product technically prevents the thing. Encryption at rest, FIPS fail-closed, role gating, session lock, export destination allowlists.

Detects & audits

The product records it and can show tampering. Hash-chained audit, integrity-failure alerts, denied-access records, chain verification.

Supports evidence

The product produces an artifact your SSP or POA&M can cite. Audit exports, SBOM, build integrity, cryptographic inventory, control evidence map.

Organizational dependency

Yours, not ours. Policy, training, personnel, physical security, incident response, and assessment stay with your security program — CUIVault can feed them, not own them.

Rev. 2 family What CUIVault contributes
3.1 — Access Control Role-based least privilege and privileged-function gating, idle lock and session termination, failed-logon lockout, CUI handling notice, controlled CUI flow, and approved-destination limits on export.
3.3 — Audit & Accountability Identity-tagged records of what happened and when, protected against alteration by hash chaining, restricted to privileged roles for review and export, with NTP-backed timestamps.
3.4 — Configuration Management A signed, integrity-checked security baseline for the application, plus a hardened mode that disables nonessential functionality. Your wider system configuration management stays organizational.
3.5 — Identification & Authentication CAC/PIV certificate authentication with revocation checking, multi-factor, passphrase complexity and reuse history, and stored keys protected by a salted key-derivation function rather than kept in the clear.
3.8 — Media Protection CUI marking on screen and on exported files, chain-of-custody records for exports, removable-media handling controls, and secure burn of files and vault extents.
3.11 — Risk Assessment A CycloneDX SBOM to feed vulnerability scanning, and signed-build evidence supporting timely remediation. Running the risk assessment itself remains yours.
3.13 — System & Communications Protection AES-256-GCM protection of CUI at rest, policy-enforced FIPS-mode operation with key material zeroized after use, and strict TLS with no certificate bypass on the DoD SAFE path.
3.14 — System & Information Integrity Integrity-failure alerting on encryption and manifest verification, optional antivirus scan before ingest, and code-signing evidence for the binaries you deployed.

“Contributes” is deliberate. CUIVault enforces technical controls, records what happened, and produces evidence — your organization still implements, documents, and assesses the requirement.

What CUIVault does not do

Roughly half of 800-171 is not a software problem.

About 50 of the 110 Rev. 2 requirements are organizational and cannot be satisfied by any product: awareness and training, most configuration management, the incident response process, most maintenance, personnel security, physical protection, risk assessment, and security assessment. CUIVault can feed several of them — audit data into incident response, for example — but ownership stays with your security program.

Operating limits

  • FIPS-validated cryptography requires Windows itself to be running in FIPS mode. Outside it, CUIVault fails closed when policy requires FIPS — it does not pretend.
  • Not an authorized component of a solution cleared for classified data. Do not deploy in a SCIF or secure data handling environment without contacting us about CSFC validation.
  • Secure overwrite is best-effort on SSDs, wear-leveling media, journaling filesystems, and cloud-synced folders. Verified media sanitization remains an organizational process.
  • Once content leaves CUIVault’s control, recall is not claimed.

Compliance limits

  • Beyond Ordinary is a Cyber AB Registered Practitioner Organization, not a C3PAO. We help you prepare and document. We do not assess, certify, or determine your compliance.
  • Rev. 3 mapping is maintained for forward readiness. Your CMMC Level 2 baseline today is Rev. 2.
  • The post-quantum readiness indicator signals that a deployment is tracking CNSA 2.0. It is a transition-mode signal, not a compliance attestation.
  • Evidence supports your SSP and POA&M. It does not write them, and it does not replace your assessment.
Pricing

CUIVault pricing

A single-fee desktop license — not a subscription. Optional update and support plans are available. Once payment is received, we’ll send the download key required to install the software.

  • Requires Microsoft’s .NET runtime.
  • Writes a human-readable CSV manifest you can attach to your CUI handling records.
  • Designed to make federal compliance documentation straightforward.
  • One-week evaluation license available on request.
  • Discounted pricing for federal employees.
  • Includes Raffael Herrmann’s QRCoder library (MIT License), trimmed to the minimum we required.
  • (*) For CMMC compliance, Windows must be running in FIPS mode. This product is not an authorized component of a solution cleared for classified data handling. Please do not deploy in a SCIF or secure data handling environment without contacting us about CSFC validation.
Download your software purchase

Licensing details

  • .NET Framework
  • $599 per desktop installation, one-time fee. Optional support and update plans available.
  • Need to talk with someone? We’re contractors ourselves — reach out via the contact form and a person will respond.
See it before you buy

Walk through CUIVault against your own control matrix.

Bring a real CUI workflow and the requirements you’re worried about to the 30-minute call. We’ll show the enforcement, the audit record it produces, and the evidence you could hand an assessor — and we’ll tell you plainly which of your gaps this doesn’t close, before you spend the $599.

Cookie Compliance

We use cookies to ensure you get the best experience on our website. By continuing to use our site, you accept our use of cookies, privacy policy and terms of service.