Don’t see your question? The help page covers links, status, billing, refunds and sign-in.
Not by design. Every connector reads configuration metadata, not the data itself. AWS uses a CloudFormation role with an inline, configuration-metadata-only policy and no s3:GetObject (no decryption, no object reads). Azure uses a Service Principal with Reader + Security Reader at subscription scope; Microsoft 365 uses read-only Microsoft Graph application permissions; one of them, SharePointTenantSettings.Read.All, is broad enough under Microsoft’s permission model to read SharePoint content, and the scanner makes no content-reading call. Google Workspace uses the read-only Admin SDK Directory scope. Okta and CrowdStrike use read-only API tokens and scopes. The agents read who has MFA enabled, whether CloudTrail is logging, whether a bucket’s public access is blocked, not what’s in the bucket.
Stored connector credentials (Azure, Microsoft 365, Google Workspace, Okta, CrowdStrike) are encrypted at rest with AES-GCM; AWS works through a role your account lets us assume, so no AWS key is stored. Scan evidence is the configuration API response, stored with its SHA-256 hash. Every connector is revocable from your side by deleting the CloudFormation stack, Service Principal, service account, API token, or OAuth2 client, with no support ticket. Once revoked, the next scan cannot read anything.
Details in the privacy policy and the DPA, which the Terms incorporate for every purchase.
No platform can guarantee that, the C3PAO decides. Assessors score each requirement on whether it is implemented and evidenced; the agents keep that evidence organized and dated.
What the platform does: all 110 controls and all 320 assessment objectives are indexed, with the objectives your evidence answers separated from the ones that have none. We do not claim every objective is evidenced; the index counts and names the ones that are not, so they are yours to close rather than your assessor's to discover. Every recorded artifact is listed in the Evidence Library Index with its NIST control ID and its SHA-256 hash. Your team enters its own score in SPRS, now with measured evidence behind the requirements your connected clouds can observe.
Your C3PAO retains its independence and its judgment. We don’t talk to your assessor on your behalf; the package comes to you, and what you share with your assessor is your decision.
Enclave AI is built and running in production, and its agents run end to end on synthetic test subscriptions, from purchase through intake and measurement to delivered documents. It has been hardened week over week since April 2026: code changes in 22 of the 26 weeks from April through September 2026, and more than 16,000 automated tests that run on every change and, since June 2026, on a weekly schedule.
The next milestones are deployment in real Defense Industrial Base customer environments and measured results from them: how the system performs, what it costs to operate, and how useful its evidence is there. The architecture itself is not what remains to be proven.
Enclave AI is Agent-as-a-Service, not a dashboard your team fills in. It is built for CMMC only: the agents, control mappings, evidence collection and SSP generation are tuned to NIST SP 800-171 Rev. 2 and NIST SP 800-171A.
The work product lands in your inbox each cycle, written by the agents, for your team to review and, if you choose, share with your C3PAO: the System Security Plan PDF, the POA&M, the Evidence Library Index, and the SPRS posture report. The agents work whether you log in or not. The deliverables ship whether you read them or not.
Practical implication: if you don’t want to spend your week inside another compliance dashboard, you don’t have to. If your team is one person wearing the compliance hat alongside three other hats, the tier subscriptions are designed for that situation.
A PDF in your inbox within minutes of intake submission. Three things on it:
What it is not: a C3PAO pre-assessment, a certification, a legal opinion, or consulting. It is a measurement, nothing more.
The $999 credits toward your first Level 2 subscription invoice if you start a Level 2 subscription within 30 days of receiving the Snapshot PDF, with the same billing email (terms in the refund policy). Net cost of a Level 2 Readiness Snapshot that converts: $0. Net cost of a Level 2 Readiness Snapshot that confirms you’re not ready and you walk away: $999 well spent.
The full subscription. From the day you subscribe you get the welcome email, the intake, the read-only connectors, the first scan of what you connect, and the first deliverable bundle (SSP, POA&M, CUI scoping package, customer responsibility matrix, evidence library index, and SPRS posture report with its remediation list). Every tier’s core PDFs pass an automated format quality gate that blocks any PDF that fails it. On Fortress, you also get a deliverable cycle every 14 days, the monitoring runbook and the audit-defense exhibit list. On Sovereign, per-entity bundles, the parent-level roll-up, and parent-level account handling.
Billing is annual in advance by default, with a month-to-month option. The card you provide at checkout is charged the tier price on the day you subscribe, the year on the annual link or the month on the monthly link, and again on the same day of each following period until you cancel. Cancellation is self-serve in your Stripe billing portal. The link to it is in your subscription welcome email and on the onboarding page that email opens. If the portal cannot be opened, the page that link opens offers Cancel at the end of the current period, which works without the portal, and written notice to legal@elasticd3m.com from the address on the account is honoured identically. Access continues through the end of the paid period after cancellation.
The first deliverable bundle ships after your intake, so you can judge the work product before your next renewal. You can cancel in the Stripe billing portal before the next renewal.
No. Stripe checkout, intake, scan, PDF in inbox, the entire buy-and-deliver path is self-service. Links, order status, downloads, billing and refund requests start from the help page.
Above 10 entities, or a custom contract structure, is not offered self-serve at this time.
Six Level 2 subscription tiers, billed annually with a month-to-month option, all managed in the Stripe billing portal:
Annual pricing per tier: Standing $8,340, Sentinel $11,940, Garrison $17,940, Standard $29,940, Fortress $59,940, Sovereign $149,940. Annual equals twelve times monthly on every tier; there are no discounts. Every tier also has a month-to-month option billed monthly in advance. Fair-use thresholds in Terms of Service.
Level 1 protects Federal Contract Information. It is the 15 basic safeguarding requirements of FAR 52.204-21, self-assessed by your organization every year, with results entered in SPRS and an annual affirmation by your Affirming Official (32 CFR 170.15, 170.22). Level 1 does not permit a POA&M (32 CFR 170.21(a)(1)). Level 1 is priced separately from Level 2, and Level 1 checkout is not open yet.
SaaS sells you a subscription plus homework: the software holds the forms, and your people spend the labor hours filling them in, every cycle, for every entity. That does not scale. In AaaS the agents do the work. They measure, collect and record evidence, draft and maintain the documents, and deliver a report for a named person to approve or deny. People keep accountability, authorization and professional judgment.
If a dashboard is what you want, this isn’t the right product. If outcome-shaped work product is what you want, it is.
Each connector is read-only, scoped, and revocable:
Each measured finding stores an excerpt of the API response behind it with its SHA-256 hash. Deliverable cadence by tier: every 90 days on Standing, every 60 days on Garrison, every 30 days on Sentinel and Standard, every 14 days on Fortress, and every 14 days per entity on Sovereign. Separately, every connected cloud is re-scanned about every seven days, and a control that regressed is flagged in your workspace.
You still get a readiness package. The intake captures the parts the cloud connectors can’t reach, on-prem infrastructure, niche SaaS, process-only controls, contractual posture. In your System Security Plan, each requirement with evidence states whether it was measured from a connected source or attested by your team, so anyone you share it with, including your C3PAO, sees the distinction. Connected sources today are AWS, Azure, Microsoft 365, Google Workspace, Okta and CrowdStrike; other environments are covered from your recorded evidence.
On the weekly re-scan. About every seven days the platform re-reads each connected source and compares the result with the previous snapshot. A requirement that moved from met to not met is flagged in your workspace with the change in the SPRS estimate, and the next deliverable cycle is built from the current state. On Sovereign, the board narrative adds a “Movement since the previous cycle” section. We do not promise “drift detected in minutes”. We promise the deliverable bundle reflects the measured posture each cycle.
Every document delivered to your inbox is a PDF. On every tier: System Security Plan, POA&M, CUI Scoping Package, Customer Responsibility Matrix, Evidence Library Index, and SPRS posture report. Fortress adds the monitoring runbook and the Audit-Defense Exhibit List; Sovereign adds the board narrative, the portfolio roll-up, the C3PAO handoff pack and the flow-down matrix. The Exports and verification section of your workspace links the same work as files you can load into your own tooling: posture, POA&M, scope, CRM and the evidence index as Markdown; your readiness result as JSON or CSV, plus an eMASS-aligned JSON or CSV for import; and your System Security Plan, POA&M and readiness self-assessment results as OSCAL JSON (the System Security Plan in OSCAL 1.1.2, the other two in OSCAL 1.2.3). Our automated tests check each OSCAL file against NIST’s published OSCAL JSON schema for the version it declares. We do not produce Word or Excel files. The Evidence Library Index maps each recorded artifact to its NIST control ID and the assessment objectives it answers, with the SHA-256 hash you recorded for it. The same section links your evidence integrity certificate, a JSON document sealed with SHA-256 over the roots of your evidence manifest, control attestations, recorded CUI scope and annual affirmation and, when a signing key is provisioned, signed with Ed25519, so an assessor can verify the record offline. It is issued once at least one evidence artifact or control attestation is recorded. The section also links a point-in-time posture statement and the verify page, which checks either one without an account. The signature covers that certificate, not the PDFs.
AI performs. AI records. AI explains. AI provides evidence. Authorized humans approve the decisions that legally or operationally require human accountability. Agents perform the recurring work; people keep accountability, authorization and professional judgment. Every consequential decision the platform can take, who is accountable for it (the operator, your designated executive, or your authorized user, never an agent), and the code that binds it is enumerated in a decision registry and rendered to /accountability, not typed. Your executives adopt or reject each delivered document from a signed-in seat against the SHA-256 of the exact bytes delivered.
Both, and you choose. Rev. 2 is what 32 CFR 170 binds CMMC Level 2 to today (32 CFR 170.14(c)(3)), what the DFARS 252.204-7012 class deviation keeps as the assessment standard (CMMC FAQ Rev. 2.3, B-A3), and what the CMMC scoring methodology in 32 CFR 170.24 measures, so it is the scored baseline: SPRS estimate, POA&M eligibility, Conditional or Final. Rev. 3 (published May 2024; 97 requirements, 17 families, 422 assessment objectives) is the emerging target. Choose it at intake or from your workspace and your workspace documents (readiness export, OSCAL SSP, workspace view) are also rendered against the Rev. 3 set, mapped through NIST’s own Rev 2 to Rev 3 change analysis, with your Rev. 2 figures alongside. No Rev. 3 score is asserted, because DoD has published none. The one-time Snapshot is scored under Rev. 2.
NIST SP 800-171 defines the security requirements. NIST SP 800-171A defines the assessment procedures. NIST SP 1352, published September 2026, is a NIST primer that gives small businesses a high-level overview of SP 800-171A Rev. 3 assessments; it is reading material. None of them performs the work. Enclave AI™ performs recurring measurement and documentation work against the requirements CMMC uses today: FAR 52.204-21 for Level 1 and NIST SP 800-171 Rev. 2 with SP 800-171A (June 2018) for Level 2 (32 CFR 170.14(c)(3)). DoW has stated it will incorporate Rev. 3 through future rulemaking (CMMC FAQ Rev. 2.3, B-A3). NIST does not endorse products and has no role in DoW’s CMMC implementation (NIST SP 1352).
No, and the framing matters. Operational leverage, not headcount elimination. The platform handles scheduled measurement, evidence collection, and document production. Your compliance lead keeps making executive decisions, what residual risk to accept, what to escalate, what to flag in board reporting. Accountability, authorization and professional judgment stay with your people by design. The platform is built to take the recurring measurement and document work off your compliance lead.
How can DoW establish trustworthy, scalable assurance that a contractor’s asserted implementation state is accurate, today under NIST SP 800-171 Rev. 2, and under Rev. 3 if DoW incorporates it through rulemaking, as its CMMC FAQ (Rev. 2.3, July 2026, B-A3) says it will?
Enclave AI™ by ai4cmmc.ai performs the machine-executable work of establishing and maintaining an evidence-backed NIST SP 800-171 compliance state: measured where a connected source can observe it, substantiated by recorded, hashed evidence where it cannot, and re-measured on a stated schedule. The contractor, its Affirming Official, its assessor, its prime and an authorized government customer, each on the contractor’s grant, read that same recorded state instead of reconstructing it by hand at assessment time. Assessment judgments stay with the contractor and, where one is required, its C3PAO or DIBCAC.
It used to be “How do I prepare for and pass my CMMC assessment?”, a question answered with checklist software, document repositories, consultants, SSP generators, POA&M managers and evidence folders. The question now is “How do I continuously know that the compliance state I am affirming is accurate, and how can I prove it?”
Your Affirming Official affirms continuing compliance in SPRS after each assessment and annually thereafter (32 CFR 170.22). Enclave AI records what was measured, when, from which source, and what your team substantiated, each entry hashed with SHA-256 and carried in a tamper-evident audit chain. On Level 1, the chain’s current head is printed on every document you receive, so a later change is detectable against your own copy; Level 2 evidence certificates are Ed25519-signed and checkable at /verify. The record documents the basis and timing of what was affirmed, with the approver’s recorded identity. The decision stays with your Affirming Official. That record is refreshed on a stated schedule: connected sources are re-scanned about every seven days, a full Level 1 cycle runs every 30 days, and Level 2 runs on your tier’s cycle.
What your Affirming Official reviews before deciding comes from that same record: the recorded state of each requirement, the evidence behind it, what changed since the last measurement, and the open gaps and exceptions. Then your Affirming Official decides whether to affirm.
No. Enclave AI™ is AI-native Agent-as-a-Service (AaaS) for CMMC Level 1 and Level 2 readiness. AI agents perform the recurring measurement, evidence, documentation and readiness workload; accountable humans retain approval, affirmation and professional judgment. Self-assessments are the OSA’s own, and certification assessments are conducted by independent Certified Third Party Assessment Organizations (C3PAOs) authorized by the Cyber AB, or by DCMA DIBCAC. We are an AaaS provider in the CMMC ecosystem, built to make life easier for the OSAs preparing for assessment, the C3PAOs assessing them, the RPOs guiding them, and the MSPs, MSSPs and ESPs supporting them.
Read more in our Policy Position on the structural integrity of the CMMC ecosystem.
No. ElasticD3M, LLC is not a Registered Practitioner Organization (RPO) and does not provide CMMC consulting services. It is an Agent-as-a-Service (AaaS) provider: its AI agents perform the recurring measurement, evidence and documentation work, and the customer’s accountable officials make every decision and attest. An RPO may use the platform in its own work if it chooses.
No. The Code of Professional Conduct required by 32 CFR 170.8(b)(17)(ii)(G) bars a CMMC ecosystem member that served as a consultant preparing an organization for a CMMC assessment within the past 3 years from taking part in that organization’s Level 2 certification assessment. The CMMC Level 2 Readiness Snapshot is a measurement product, not a consulting engagement: no advisor, no SOW, no recommendation beyond the factual gap list and its remediation actions. ElasticD3M is not a C3PAO, and your C3PAO plays no part in producing the Snapshot.
No. Level 3 is not offered on this platform. We will not sell you a Level 2 subscription and tell you it covers Level 3.
Under 32 CFR 170.19 today, OT that can process, store or transmit CUI but is unable to be fully secured is a Specialized Asset. At Level 2 you document it in your inventory, SSP and network diagram and show it is managed under your risk-based policies; the assessor’s instruction is “Review the SSP. Do not assess against other CMMC security requirements.” At Level 1 Specialized Assets are not part of the assessment scope. Level 3 is not offered on this platform.
The platform computes no SPRS points for Specialized Assets. At Level 2 the assessor reviews the SSP for these assets (32 CFR 170.19(c)(1)) and does not assess them against other CMMC security requirements. Your inventory, SSP and network diagram still have to account for them.
No. Enclave AI™ documents OT you record. SCADA and OT security readiness is a separate product: ai4scada.ai.
What 32 CFR 170.19 says about operational technology, and what the platform records: Operational technology in your CMMC scope →
No. The Level 2 Readiness Snapshot and the subscription tiers are CMMC / NIST 800-171-specific. If your compliance need is SOC 2, ISO 27001, HIPAA, PCI, or anything other than CMMC / NIST 800-171, this is not the right product for you. Buying it anyway would waste your money.
Stripe Checkout, billed immediately with no free trial. The help page covers billing.
Inside the Stripe billing portal, yourself, without contacting us. Cancelling there stops the renewal. The link is in your subscription welcome email and on the onboarding page that email opens. If the portal cannot be opened, the page that link opens offers Cancel at the end of the current period, which works without the portal, and written notice to legal@elasticd3m.com is honoured identically. Subscriptions are billed annually by default, with a month-to-month option; auto-renewal stops at the end of the then-current paid period. The $999 Level 2 Readiness Snapshot is a one-time purchase. Full cancellation policy.
No. On every tier, the Terms you accept at Stripe checkout (section 8, Customer Data and Confidentiality) and the DPA bind both parties to mutual confidentiality from checkout, before any data flows. If your legal team requires a standalone mutual NDA before subsidiary data flows, send it to legal@elasticd3m.com before you connect.
A custom MSA is not offered self-serve at this time; the Terms accepted at checkout are the agreement.
Enclave AI’s work product is readiness documentation, not a legal opinion, not a certification, not a substitute for a C3PAO assessment, not a guarantee of pass. Every material compliance decision stays with your executives. Full liability terms in the Terms of Service.
No. Pricing is the same for every buyer and there are no discount codes. The C3PAO Partner Program pays nothing to partners either, by design: no fee of any kind attaches to an OSA your firm refers or assesses, so nothing we pay can create a financial interest in an assessment you perform. What the program offers is a consent-gated pipeline dashboard showing the readiness of the OSAs that choose to share it with your firm. Details on the For C3PAO page.
The help page covers links, status, billing, refunds and sign-in.
Start with the $999 CMMC Level 2 Readiness Snapshot →Enclave AI™ is AI-native Agent-as-a-Service (AaaS) for CMMC readiness and compliance operations. AI agents perform the recurring measurement, evidence, documentation and readiness workload; accountable humans retain approval, affirmation and professional judgment. Not SaaS. Not consulting. Not a C3PAO. It serves the OSAs preparing for assessment, the C3PAOs assessing them, the RPOs guiding them, and the MSPs, MSSPs and ESPs supporting them. We do not conduct assessments: self-assessments are the OSA’s own, and certification assessments are conducted by independent Cyber AB-authorized C3PAOs or DCMA DIBCAC. ElasticD3M, LLC is a Texas limited liability company.