MILESTONECUI Vault has achieved FedRAMP Moderate equivalency.FedRAMP Moderate equivalency achieved.Read the announcement

CUI Vault – Terms & Conditions

v2.0 · Effective July 14, 2026

These Terms & Conditions ("Terms") are entered into between NtelSec, Inc., a Delaware corporation with principal offices in Reston, Virginia ("NtelSec", "we", "us"), and the customer identified on the applicable order ("Customer", "you"). They govern your use of the CUI Vault services.

These Terms consist of the General Terms (Sections 1–9), which apply to all CUI Vault subscriptions, plus the service schedule that matches the tier you purchased: Schedule A (Self-Assessment tiers — FCI only) or Schedule B (CUI Vault Enclave). Your order identifies which schedule applies.

1 — Definitions

  • "FCI" (Federal Contract Information) — Information provided by or generated for the Government under a contract not intended for public release. FCI does not include CUI. (FAR 52.204-21).
  • "CUI" (Controlled Unclassified Information) — Information the Government creates or possesses, or that an entity creates for or on behalf of the Government, that requires safeguarding or dissemination controls pursuant to law, regulation, or Government-wide policy.
  • "Level 1 Self-Assessment" — The contractor's annual self-assessment (and senior official affirmation) against the 17 basic safeguarding requirements in FAR 52.204-21, posted to SPRS.
  • "Level 2 Self-Assessment (non-prioritized)" — A contractor self-assessment against the 110 NIST SP 800-171 controls allowed only for non-prioritized acquisitions.
  • "FedRAMP-Equivalent" — A cloud environment independently assessed by a FedRAMP-recognized 3PAO showing 100% implementation of the FedRAMP Moderate baseline with no open POA&Ms.
  • "Enclave" — The CUI Vault managed environment hosted in Microsoft Azure Government and Microsoft 365 GCC High, provided under Schedule B.
  • "Mission Control" — The CUI Vault administration portal at mc.ntelsec.com used for account management, onboarding, billing, and support. Mission Control is not part of the Enclave (see Section 3).

2 — Services & Schedules

NtelSec provides the service tier identified in your order. Schedule A governs the Self-Assessment tiers (Level 1 / eligible Level 2), which are FCI-only environments. Schedule B governs the CUI Vault Enclave, a managed environment in which Customer may process CUI. In the event of a conflict between a schedule and the General Terms, the schedule controls for the tier it covers.

3 — Mission Control (Administration Portal)

Mission Control is the administration surface for all CUI Vault tiers. It is hosted on commercial cloud infrastructure in the United States and is outside the Enclave's assessed authorization boundary.

Regardless of your service tier, you must not upload, submit, or transmit CUI, Covered Defense Information, or classified information through Mission Control — including document uploads, support tickets, chat, and any other portal input. Content subject to safeguarding controls belongs in the Enclave (Schedule B customers) or in your own compliant environment (Schedule A customers).

4 — Acceptable Use & Signed Policies

Use of the services is subject to the NtelSec Acceptable Use Policy. During onboarding, each user must also execute the CUI Vault Rules of Behavior and Acceptable Use Policy and the Customer Responsibility Acknowledgement by electronic signature; those signed documents form part of this agreement for the users who sign them. Enclave usage is monitored for security purposes as described in the Rules of Behavior; users have no expectation of privacy in activity conducted within the Enclave.

5 — Privacy & Data Protection

Our processing of personal information is described in the Privacy Policy. For customer content we process on your behalf, we act as your processor/service provider. A Data Processing Addendum reflecting applicable U.S. state privacy laws (and, where relevant, GDPR/UK GDPR) is available on request from privacy@ntelsec.com.

6 — Liability & Indemnification

6.1 Limitation of Liability

Standard SaaS limitation applies, except for willful misconduct, gross negligence, or IP infringement.

6.2 Indemnity

Customers indemnify for claims, penalties, or costs from misclassification of data, inaccurate/fraudulent submissions, or failure to meet FAR/DFARS/CMMC obligations.

7 — Changes in Law / Program Requirements

"If DoD, FAR/DFARS, or CMMC program rules change so that the services provided here no longer meet the minimum legal or contractual requirements for your use case, you agree to migrate to a compliant tier or terminate the service."

8 — Term, Termination & Data Return

8.1 Term and Renewal

The initial subscription term is the period stated in your order (typically one year) and begins on the subscription start date. Subscriptions are for the full term and may not be terminated for convenience mid-term; all fees for the then-current term remain due and are non-refundable. Following the initial term, the subscription automatically renews for successive periods of the same duration unless either party gives written notice of non-renewal at least thirty (30) days before the end of the then-current term.

8.2 Termination for Cause

Either party may terminate on written notice if the other party materially breaches these Terms and fails to cure the breach within thirty (30) days of written notice. NtelSec may also suspend or terminate access as described in Schedule A-9 (prohibited data) and Section 4 (acceptable use).

8.3 Data Return & Deletion

Upon termination or expiration, data export is provided and remaining copies permanently deleted within 90 days, except as required by law. Enclave media sanitization follows NIST SP 800-88 Rev. 1.

8.4 Effect of Termination / Cancellation

Within ten (10) business days of termination, expiration, or suspension:

  • a. Customers must remove all CUI Vault references from ongoing or future SSP, POA&M, SPRS submissions, unless submissions clearly state the environment is no longer in use
  • b. Customers must update or re-affirm submissions to reflect current environment if scores or artifacts relied on CUI Vault
  • c. Customers shall no longer claim or imply control inheritance from CUI Vault
  • d. Upon request, customers shall provide written confirmation of completion

8.5 Survival

Sections 3, 4, 6, 7, 8.4, and 9, and the surviving provisions of the applicable schedule, survive termination or expiration.

9 — Governing Law, Venue, Order of Precedence

These Terms are governed by and construed in accordance with (i) where Customer is a United States federal government entity, the federal laws of the United States; (ii) where Customer is a state or local government entity, the laws of Customer's state; and (iii) for all other customers, the laws of the Commonwealth of Virginia — in each case without giving effect to conflict-of-laws principles. Except where Customer is a federal government entity (in which case disputes are resolved under the Contract Disputes Act and FAR 52.233-1), any legal action or proceeding arising under these Terms will be brought exclusively in the federal or state courts located in Reston, Virginia, and the parties irrevocably consent to the personal jurisdiction and venue therein.

Schedule A — Self-Assessment Tiers (FCI-Only)

Schedule A applies only to CUI Vault Level 1 / Level 2 Self-Assessment subscriptions. These tiers are FCI-only: CUI is prohibited. Schedule A does not apply to the CUI Vault Enclave.

A-1. FCI-Only Enclave

CUI Vault provides an enclave designed to help implement the 17 FAR 52.204-21 controls (Level 1) and complete Level 2 self-assessment for non-prioritized acquisitions without hosting CUI.

A-2. No CUI Handling

"These tiers MUST NOT be used to store, process, or transmit CUI or other information subject to DFARS 252.204-7012 (covered defense information)." Migration to the CUI Vault Enclave (Schedule B) is required if CUI handling becomes necessary.

A-3. Self-Assessment Tooling

Platform provides guidebooks, templates (SSP, POA&M), and auto-scoring workbooks. "You are solely responsible for the accuracy of the score and affirmation."

A-4. Certification Use Rights

"While the subscription to CUI Vault (Level 1 / Level 2 Self-Assessment tiers) is active and in good standing, Customer may reference the platform and its provided documentation/templates as part of its self-assessment, SSP, POA&M, and SPRS submission." Upon termination, customers must cease all representations regarding platform reliance.

A-5. Customer Responsibilities

  • Data classification: "You will classify data before ingestion and ensure no CUI or covered defense information is uploaded to CUI Vault (Level 1 / Level 2 Self-Assessment tiers)."
  • Implement required controls: the 17 basic safeguarding controls for Level 1, and all 110 NIST SP 800-171 controls for Level 2 self-assessment where applicable.
  • SPRS posting & affirmations: "You (not CUI Vault) will post your scores and annual affirmations to SPRS and maintain all evidence for DoD review."
  • Access management & device compliance: "You will provision/de-provision users promptly, enforce MFA, and ensure only compliant, authorized devices access the enclave."
  • Incident reporting: "If you suspect CUI was inadvertently introduced, you must notify us within 24 hours and immediately follow DFARS 252.204-7012 incident reporting if applicable."
  • Migration: Customers agree to migrate to the Enclave (Schedule B) or another FedRAMP-equivalent environment prior to handling CUI or when contract clauses require it.

A-6. Our Responsibilities

"We operate the enclave to support your Level 1 / Level 2 self-assessment activities, but do not represent or warrant FedRAMP-equivalency for these Self-Assessment tiers." Standard templates aligned to DoD methodology are provided; "final tailoring and accuracy are your responsibility." An upgrade path to the CUI Vault Enclave (Schedule B) is available.

A-7. Prohibited Data & Activities

Storage, processing, or transmission in Self-Assessment tiers is prohibited for:

  • a. CUI, Covered Defense Information (CDI), ITAR data
  • b. Personal Health Information (PHI) governed by HIPAA, PCI cardholder data, or data requiring controls beyond FAR 52.204-21's 17 safeguards
  • c. Any data contractually or legally requiring FedRAMP Moderate or equivalent

A-8. Representations & Warranties; Misrepresentation

"We do not guarantee that use of CUI Vault (Level 1 / Level 2 Self-Assessment tiers) will, by itself, satisfy your contractual or regulatory obligations." "You acknowledge that Level 1 and certain Level 2 self-assessments are permitted by DoD only in specific circumstances (e.g., non-prioritized acquisitions)."

Customers represent and warrant that statements regarding CUI Vault usage, SPRS scores, and control implementation are accurate and not misleading. If customers knowingly misrepresent reliance post-termination, assert benefits while unsubscribed, or submit false certifications:

  • Services may be immediately terminated
  • Customers shall indemnify for all damages, penalties, costs including attorneys' fees
  • Customers shall pay liquidated damages of $25,000 or 150% of prior 12 months' fees, whichever is greater
  • Right reserved to notify impacted primes, contracting officers, and DoD

A-9. Audit, Cooperation & Evidence

If DoD, DCMA/DIBCAC, C3PAO, or prime contractor requests evidence, customers will provide it; platform will reasonably cooperate regarding evidence it controls. "We reserve the right to suspend or terminate access if we detect, or reasonably suspect, CUI or other prohibited data in this tier." If reasonable basis exists believing customers are handling CUI in FCI-only tiers, continuing post-termination reliance, or misrepresenting compliance posture, platform may request documentation and notify affected primes, authorities, or C3PAOs.

Schedule B — CUI Vault Enclave

Schedule B applies only to CUI Vault Enclave subscriptions. The Enclave is a managed environment in Microsoft Azure Government and Microsoft 365 GCC High in which Customer may process, store, and transmit CUI.

B-1. The Enclave

NtelSec provides a managed, multi-tenant virtual desktop and productivity environment hosted in Microsoft Azure Government and Microsoft 365 GCC High (U.S. Government regions only) in which Customer may process, store, and transmit CUI in support of its NIST SP 800-171 / CMMC Level 2 obligations. Encryption in transit and at rest uses FIPS 140-2 validated cryptographic mechanisms (TLS 1.2+ and AES-256).

B-2. Security Posture

The Enclave operates under NtelSec's FedRAMP Moderate-equivalent security program, independently assessed by a FedRAMP-recognized third-party assessment organization. The Enclave is not FedRAMP Authorized and NtelSec does not represent that it holds a FedRAMP authorization. Customer remains responsible for determining that the Enclave's posture satisfies the requirements of Customer's specific contracts.

B-3. Shared Responsibility; Customer Data Ownership

Security of Customer's enclave operates under a shared responsibility model. NtelSec implements and maintains the platform-level controls described in the customer System Security Plan and Customer Responsibility Matrix provided during onboarding; Customer is responsible for the customer-side controls identified there, including user authorization and review, personnel screening, security awareness and CUI-specific training, adherence to the Rules of Behavior, and incident reporting cooperation.

Customer is the data owner of all CUI it stores, processes, or transmits within its enclave. Customer is responsible for ensuring it has the right to place data in the Enclave and for complying with the dissemination controls that apply to that data.

B-4. Incidents & DFARS 252.204-7012

  • NtelSec will notify Customer promptly and without undue delay after confirming any security incident that NtelSec determines affects Customer's data or users, consistent with its incident response procedures and applicable law.
  • Customer (not NtelSec) is responsible for its own reporting obligations under DFARS 252.204-7012, including reporting cyber incidents to DoD within 72 hours where required. NtelSec will reasonably cooperate with Customer's DFARS reporting, including preservation of relevant media and evidence NtelSec controls.
  • Customer must report suspected incidents affecting the Enclave to NtelSec within 24 hours of discovery.

B-5. Prohibited Data (Enclave)

The Enclave is authorized for CUI up to the FedRAMP Moderate baseline. Customer must not introduce:

  • a. Classified information of any level
  • b. Information requiring safeguards beyond the FedRAMP Moderate baseline (e.g., data requiring FedRAMP High)
  • c. ITAR-controlled technical data, PHI governed by HIPAA, or PCI cardholder data, unless expressly authorized by NtelSec in writing for Customer's enclave

B-6. Monitoring

Enclave activity is logged and monitored for security and compliance purposes, as described in the Rules of Behavior each user signs. Users have no expectation of privacy in activity conducted within the Enclave.

B-7. Data Return & Sanitization

On termination, Customer content is exported and remaining copies deleted per Section 8.3. System media containing CUI are sanitized or destroyed using processes aligned to NIST SP 800-88 Rev. 1 and Microsoft's FedRAMP-compliant data destruction processes.

B-8. Survival

Sections B-3 through B-7 survive termination for so long as NtelSec holds any Customer content.