These Terms & Conditions ("Terms") are entered into between NtelSec, Inc., a Delaware corporation with principal offices in Reston, Virginia ("NtelSec", "we", "us"), and the customer identified on the applicable order ("Customer", "you"). They govern your use of the CUI Vault services.
These Terms consist of the General Terms (Sections 1–9), which apply to all CUI Vault subscriptions, plus the service schedule that matches the tier you purchased: Schedule A (Self-Assessment tiers — FCI only) or Schedule B (CUI Vault Enclave). Your order identifies which schedule applies.
NtelSec provides the service tier identified in your order. Schedule A governs the Self-Assessment tiers (Level 1 / eligible Level 2), which are FCI-only environments. Schedule B governs the CUI Vault Enclave, a managed environment in which Customer may process CUI. In the event of a conflict between a schedule and the General Terms, the schedule controls for the tier it covers.
Mission Control is the administration surface for all CUI Vault tiers. It is hosted on commercial cloud infrastructure in the United States and is outside the Enclave's assessed authorization boundary.
Regardless of your service tier, you must not upload, submit, or transmit CUI, Covered Defense Information, or classified information through Mission Control — including document uploads, support tickets, chat, and any other portal input. Content subject to safeguarding controls belongs in the Enclave (Schedule B customers) or in your own compliant environment (Schedule A customers).
Use of the services is subject to the NtelSec Acceptable Use Policy. During onboarding, each user must also execute the CUI Vault Rules of Behavior and Acceptable Use Policy and the Customer Responsibility Acknowledgement by electronic signature; those signed documents form part of this agreement for the users who sign them. Enclave usage is monitored for security purposes as described in the Rules of Behavior; users have no expectation of privacy in activity conducted within the Enclave.
Our processing of personal information is described in the Privacy Policy. For customer content we process on your behalf, we act as your processor/service provider. A Data Processing Addendum reflecting applicable U.S. state privacy laws (and, where relevant, GDPR/UK GDPR) is available on request from privacy@ntelsec.com.
Standard SaaS limitation applies, except for willful misconduct, gross negligence, or IP infringement.
Customers indemnify for claims, penalties, or costs from misclassification of data, inaccurate/fraudulent submissions, or failure to meet FAR/DFARS/CMMC obligations.
"If DoD, FAR/DFARS, or CMMC program rules change so that the services provided here no longer meet the minimum legal or contractual requirements for your use case, you agree to migrate to a compliant tier or terminate the service."
The initial subscription term is the period stated in your order (typically one year) and begins on the subscription start date. Subscriptions are for the full term and may not be terminated for convenience mid-term; all fees for the then-current term remain due and are non-refundable. Following the initial term, the subscription automatically renews for successive periods of the same duration unless either party gives written notice of non-renewal at least thirty (30) days before the end of the then-current term.
Either party may terminate on written notice if the other party materially breaches these Terms and fails to cure the breach within thirty (30) days of written notice. NtelSec may also suspend or terminate access as described in Schedule A-9 (prohibited data) and Section 4 (acceptable use).
Upon termination or expiration, data export is provided and remaining copies permanently deleted within 90 days, except as required by law. Enclave media sanitization follows NIST SP 800-88 Rev. 1.
Within ten (10) business days of termination, expiration, or suspension:
Sections 3, 4, 6, 7, 8.4, and 9, and the surviving provisions of the applicable schedule, survive termination or expiration.
These Terms are governed by and construed in accordance with (i) where Customer is a United States federal government entity, the federal laws of the United States; (ii) where Customer is a state or local government entity, the laws of Customer's state; and (iii) for all other customers, the laws of the Commonwealth of Virginia — in each case without giving effect to conflict-of-laws principles. Except where Customer is a federal government entity (in which case disputes are resolved under the Contract Disputes Act and FAR 52.233-1), any legal action or proceeding arising under these Terms will be brought exclusively in the federal or state courts located in Reston, Virginia, and the parties irrevocably consent to the personal jurisdiction and venue therein.
CUI Vault provides an enclave designed to help implement the 17 FAR 52.204-21 controls (Level 1) and complete Level 2 self-assessment for non-prioritized acquisitions without hosting CUI.
"These tiers MUST NOT be used to store, process, or transmit CUI or other information subject to DFARS 252.204-7012 (covered defense information)." Migration to the CUI Vault Enclave (Schedule B) is required if CUI handling becomes necessary.
Platform provides guidebooks, templates (SSP, POA&M), and auto-scoring workbooks. "You are solely responsible for the accuracy of the score and affirmation."
"While the subscription to CUI Vault (Level 1 / Level 2 Self-Assessment tiers) is active and in good standing, Customer may reference the platform and its provided documentation/templates as part of its self-assessment, SSP, POA&M, and SPRS submission." Upon termination, customers must cease all representations regarding platform reliance.
"We operate the enclave to support your Level 1 / Level 2 self-assessment activities, but do not represent or warrant FedRAMP-equivalency for these Self-Assessment tiers." Standard templates aligned to DoD methodology are provided; "final tailoring and accuracy are your responsibility." An upgrade path to the CUI Vault Enclave (Schedule B) is available.
Storage, processing, or transmission in Self-Assessment tiers is prohibited for:
"We do not guarantee that use of CUI Vault (Level 1 / Level 2 Self-Assessment tiers) will, by itself, satisfy your contractual or regulatory obligations." "You acknowledge that Level 1 and certain Level 2 self-assessments are permitted by DoD only in specific circumstances (e.g., non-prioritized acquisitions)."
Customers represent and warrant that statements regarding CUI Vault usage, SPRS scores, and control implementation are accurate and not misleading. If customers knowingly misrepresent reliance post-termination, assert benefits while unsubscribed, or submit false certifications:
If DoD, DCMA/DIBCAC, C3PAO, or prime contractor requests evidence, customers will provide it; platform will reasonably cooperate regarding evidence it controls. "We reserve the right to suspend or terminate access if we detect, or reasonably suspect, CUI or other prohibited data in this tier." If reasonable basis exists believing customers are handling CUI in FCI-only tiers, continuing post-termination reliance, or misrepresenting compliance posture, platform may request documentation and notify affected primes, authorities, or C3PAOs.
NtelSec provides a managed, multi-tenant virtual desktop and productivity environment hosted in Microsoft Azure Government and Microsoft 365 GCC High (U.S. Government regions only) in which Customer may process, store, and transmit CUI in support of its NIST SP 800-171 / CMMC Level 2 obligations. Encryption in transit and at rest uses FIPS 140-2 validated cryptographic mechanisms (TLS 1.2+ and AES-256).
The Enclave operates under NtelSec's FedRAMP Moderate-equivalent security program, independently assessed by a FedRAMP-recognized third-party assessment organization. The Enclave is not FedRAMP Authorized and NtelSec does not represent that it holds a FedRAMP authorization. Customer remains responsible for determining that the Enclave's posture satisfies the requirements of Customer's specific contracts.
Security of Customer's enclave operates under a shared responsibility model. NtelSec implements and maintains the platform-level controls described in the customer System Security Plan and Customer Responsibility Matrix provided during onboarding; Customer is responsible for the customer-side controls identified there, including user authorization and review, personnel screening, security awareness and CUI-specific training, adherence to the Rules of Behavior, and incident reporting cooperation.
Customer is the data owner of all CUI it stores, processes, or transmits within its enclave. Customer is responsible for ensuring it has the right to place data in the Enclave and for complying with the dissemination controls that apply to that data.
The Enclave is authorized for CUI up to the FedRAMP Moderate baseline. Customer must not introduce:
Enclave activity is logged and monitored for security and compliance purposes, as described in the Rules of Behavior each user signs. Users have no expectation of privacy in activity conducted within the Enclave.
On termination, Customer content is exported and remaining copies deleted per Section 8.3. System media containing CUI are sanitized or destroyed using processes aligned to NIST SP 800-88 Rev. 1 and Microsoft's FedRAMP-compliant data destruction processes.
Sections B-3 through B-7 survive termination for so long as NtelSec holds any Customer content.