NtelSec CUI Vault is a managed virtual desktop enclave for defense contractors and other organizations that store, process, or transmit Controlled Unclassified Information (CUI) under DFARS 252.204-7012. Customers access a hardened Windows virtual desktop; CUI remains inside the enclave and is not stored on customer endpoints.
In scope:
Leveraged from Microsoft:
Not in scope:
The CUI Vault platform implements 100% of the FedRAMP Moderate baseline, independently assessed by Kratos, a FedRAMP-recognized third-party assessment organization (3PAO).
Assessments are performed annually. The service is designed and operated to address:
CUI Vault runs on Microsoft Azure Government, which holds its own FedRAMP authorization. Platform-level controls are inherited from Microsoft and documented in the System Security Plan and Customer Responsibility Matrix.
Microsoft is the only subprocessor that stores or processes CUI. Other service providers we use are described in our Privacy Policy.
Access control. Multi-factor authentication for all users and administrators, role-based least-privilege assignment, conditional access restrictions, separately provisioned privileged access, and periodic access reviews.
Data protection. Encryption in transit and at rest using FIPS 140-validated cryptographic modules, with FIPS mode enforced on in-scope systems. CUI remains within the enclave; data egress paths are restricted and monitored.
Monitoring and response. Centralized logging and security monitoring, endpoint detection and response, recurring vulnerability and STIG configuration compliance scanning, and annual independent penetration testing. A documented incident response process: we notify affected customers and support their own DFARS 252.204-7012 cyber incident reporting to DoD, including preserving relevant evidence we control.
Resilience. Backups and a tested Information System Contingency Plan covering recovery of the enclave.
Governance. Formal change control, documented configuration baselines, personnel screening prior to access, and security awareness and CUI handling training at onboarding and annually.
Provided to customers, prospective customers, and government assessors under a non-disclosure agreement: