Stehrling AI Governance

Use AI. Keep your reputation.

A private, governed AI environment for defense contractors that handle CUI.

Your people get AI for real work. Your CUI stays inside a boundary you control. Your leadership gets controls that operate whether or not anyone is watching. We built it for our own delivery team first and run client work in it today.

The Situation

Where the data goes when your people use AI

In most defense contractors, AI arrived before anyone decided anything about it. Engineers, proposal writers, and program staff use commercial tools because the tools are useful. Leadership usually learns the extent of it after the fact.

"If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline."

DFARS 252.204-7012(b)(2)(ii)(D)

An AI service is a cloud service. A consumer or standard business AI account does not meet that bar, so a prompt containing CUI sent to one is covered defense information leaving your boundary. Your System Security Plan and your annual affirmation describe that boundary. Unmanaged AI use is a gap between the document and the practice.

Banning AI does not close the gap. It moves the use out of sight and gives up real productivity. What works is a sanctioned place to do the work, with the controls built into it.

What We Deliver First

A governed AI enclave in your own environment

The enclave is a private AI workspace hosted in AWS GovCloud on FedRAMP High-authorized infrastructure. Your team drafts, analyzes, and reviews documents with leading AI models, and the content stays inside the governed boundary.

Inside the boundary

Hosted on FedRAMP High-authorized infrastructure in AWS GovCloud, above the Moderate-equivalent baseline DFARS 7012 sets for covered defense information.

The gate, built in

Every prompt passes one enforcement point on the way in and every response on the way out. Identity and authorization checked, payloads inspected, responses labeled and logged, tokens metered.

Content-free oversight

Oversight runs on metadata: who, when, which model, what data class. Prompt and output bodies stay in the enclave.

Documented for your SSP

The enclave enters your system boundary on paper as well as in practice: SSP updates, data flows, and the acceptable use policy that governs it.

Infrastructure as code

The environment is defined entirely in code and redeploys in under 30 minutes. Configuration is repeatable, reviewable, and yours.

Yours to own

Deployed into your environment, not ours. If you want it operated for you, a vetted partner runs day-to-day operations and Stehrling owns the governance.

We Run It on Ourselves

Our own team uses it on client work today

Stehrling's delivery team does client work in this environment today, drafting and reviewing the documentation 800-171 programs depend on. We built it for ourselves first, because our work product touches CUI and has to hold up to the same scrutiny as our clients' does.

On August 22, 2026, Stehrling executed the first signed attestation under the Stehrling AI Governance Model, covering our own AI use. Every control we deploy for a client is one we already operate.

How the Engagement Runs

Three phases, starting with the AI you already use

01

Design

Inventory the AI already in use, sanctioned and shadow. Classify the work and the data it touches. Decide per tool: approve, contain, or retire. Design the enclave boundary and write the acceptable use policy.

02

Build

Deploy the enclave into your environment, connect the gate to your identity provider and data classes, and document it in your SSP. Your team moves sensitive work inside the boundary.

03

Govern

Run the loop: quarterly review of usage, spend, and change, then an annual attestation a named officer can sign. For Continuous Compliance clients, it folds into the program you already have.

Built for mid-size and larger defense contractors with CUI in scope, a workforce that wants to use AI, and leadership that has to answer for it. If AI use today is either banned on paper or unmanaged in practice, this replaces both.

The Framework Behind It

The Stehrling AI Governance Model is published and free to use

The Stehrling AI Governance Model covers corporate AI use in four planes, one gate, one loop, and one signature. It is free to read, cite, and use under CC BY-ND 4.0. The enclave is how we put it into operation.

Next Step

See the environment running

We'll walk you through the environment our own team uses, how the gate operates, and what deploying it inside your boundary involves. Response within one business day.

Talk to Stehrling →

An independent firm focused exclusively on NIST 800-171 compliance for defense contractors and the DIB.

Fredericksburg, VA