PARTNERSHIPCUI Vault and Trout Software partner to extend the CUI boundary to the machine.CUI Vault partners with Trout Software.Read the announcement

CUI Vault security & compliance

Last reviewed October 2026

NtelSec CUI Vault is a managed virtual desktop enclave for defense contractors and other organizations that store, process, or transmit Controlled Unclassified Information (CUI) under DFARS 252.204-7012. Customers access a hardened Windows virtual desktop; CUI remains inside the enclave and is not stored on customer endpoints.

Service profile

Provider
NtelSec, Inc.
Hosting platform
Microsoft Azure Government
Data residency
Continental United States
Personnel
U.S. persons located in the United States
Access
Windows 11 clients only. No browser-based or mobile access. Multi-factor authentication is required for all users.

Scope

In scope:

  • The CUI Vault enclave: virtual desktops, network, storage, security monitoring and administration.
  • Identity and access management for customer users.
  • Productivity applications delivered within the virtual desktop.
  • CUI Vault’s configuration and operation of the Microsoft services it uses.
  • Transfer of CUI to authorized external parties through approved encrypted channels.

Leveraged from Microsoft:

  • CUI Vault is hosted in Microsoft Azure Government. Email, file and identity services are delivered through Microsoft 365 GCC High. Each holds its own FedRAMP High authorization.
  • The controls Microsoft implements for those platforms are inherited from Microsoft.

Not in scope:

  • Customer-owned endpoints.
  • Customer corporate networks.
  • Any other system outside the CUI Vault boundary.

Compliance posture

The CUI Vault platform implements 100% of the FedRAMP Moderate baseline, independently assessed by Kratos, a FedRAMP-recognized third-party assessment organization (3PAO).

CUI Vault is not FedRAMP Authorized and NtelSec does not represent that it holds a FedRAMP authorization. FedRAMP Moderate equivalency is the standard described by DoD for cloud service offerings under DFARS 252.204-7012(b)(2)(ii)(D).

Assessments are performed annually. The service is designed and operated to address:

  • DFARS 252.204-7012
  • NIST SP 800-53 Rev. 5 (FedRAMP Moderate baseline)
  • NIST SP 800-171 Rev. 2
  • CMMC Level 2 — inherited and shared control coverage is documented in the Customer Responsibility Matrix
  • DISA Security Technical Implementation Guides (STIGs)

CUI Vault runs on Microsoft Azure Government, which holds its own FedRAMP authorization. Platform-level controls are inherited from Microsoft and documented in the System Security Plan and Customer Responsibility Matrix.

Microsoft is the only subprocessor that stores or processes CUI. Other service providers we use are described in our Privacy Policy.

Read what the assessment covered.

Security program

Access control. Multi-factor authentication for all users and administrators, role-based least-privilege assignment, conditional access restrictions, separately provisioned privileged access, and periodic access reviews.

Data protection. Encryption in transit and at rest using FIPS 140-validated cryptographic modules, with FIPS mode enforced on in-scope systems. CUI remains within the enclave; data egress paths are restricted and monitored.

Monitoring and response. Centralized logging and security monitoring, endpoint detection and response, recurring vulnerability and STIG configuration compliance scanning, and annual independent penetration testing. A documented incident response process: we notify affected customers and support their own DFARS 252.204-7012 cyber incident reporting to DoD, including preserving relevant evidence we control.

Resilience. Backups and a tested Information System Contingency Plan covering recovery of the enclave.

Governance. Formal change control, documented configuration baselines, personnel screening prior to access, and security awareness and CUI handling training at onboarding and annually.

Documentation available on request

Provided to customers, prospective customers, and government assessors under a non-disclosure agreement:

  • System Security Plan
  • Security Assessment Report and assessor attestation
  • Plan of Action and Milestones summary
  • Customer Responsibility Matrix (CMMC Level 2)
  • Penetration test attestation letter
  • Continuous monitoring summary reporting
  • Security policies and procedures
Request documentation

Contact

Documentation
trust@ntelsec.com
Security
security@ntelsec.com
Vulnerability reports
vuln-report@ntelsec.com · see our disclosure policy
General inquiries
Contact us