A private, governed AI environment for defense contractors that handle CUI.
Your people get AI for real work. Your CUI stays inside a boundary you control. Your leadership gets controls that operate whether or not anyone is watching. We built it for our own delivery team first and run client work in it today.
In most defense contractors, AI arrived before anyone decided anything about it. Engineers, proposal writers, and program staff use commercial tools because the tools are useful. Leadership usually learns the extent of it after the fact.
"If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline."
DFARS 252.204-7012(b)(2)(ii)(D)An AI service is a cloud service. A consumer or standard business AI account does not meet that bar, so a prompt containing CUI sent to one is covered defense information leaving your boundary. Your System Security Plan and your annual affirmation describe that boundary. Unmanaged AI use is a gap between the document and the practice.
Banning AI does not close the gap. It moves the use out of sight and gives up real productivity. What works is a sanctioned place to do the work, with the controls built into it.
The enclave is a private AI workspace hosted in AWS GovCloud on FedRAMP High-authorized infrastructure. Your team drafts, analyzes, and reviews documents with leading AI models, and the content stays inside the governed boundary.
Hosted on FedRAMP High-authorized infrastructure in AWS GovCloud, above the Moderate-equivalent baseline DFARS 7012 sets for covered defense information.
Every prompt passes one enforcement point on the way in and every response on the way out. Identity and authorization checked, payloads inspected, responses labeled and logged, tokens metered.
Oversight runs on metadata: who, when, which model, what data class. Prompt and output bodies stay in the enclave.
The enclave enters your system boundary on paper as well as in practice: SSP updates, data flows, and the acceptable use policy that governs it.
The environment is defined entirely in code and redeploys in under 30 minutes. Configuration is repeatable, reviewable, and yours.
Deployed into your environment, not ours. If you want it operated for you, a vetted partner runs day-to-day operations and Stehrling owns the governance.
Stehrling's delivery team does client work in this environment today, drafting and reviewing the documentation 800-171 programs depend on. We built it for ourselves first, because our work product touches CUI and has to hold up to the same scrutiny as our clients' does.
On August 22, 2026, Stehrling executed the first signed attestation under the Stehrling AI Governance Model, covering our own AI use. Every control we deploy for a client is one we already operate.
Inventory the AI already in use, sanctioned and shadow. Classify the work and the data it touches. Decide per tool: approve, contain, or retire. Design the enclave boundary and write the acceptable use policy.
Deploy the enclave into your environment, connect the gate to your identity provider and data classes, and document it in your SSP. Your team moves sensitive work inside the boundary.
Run the loop: quarterly review of usage, spend, and change, then an annual attestation a named officer can sign. For Continuous Compliance clients, it folds into the program you already have.
Built for mid-size and larger defense contractors with CUI in scope, a workforce that wants to use AI, and leadership that has to answer for it. If AI use today is either banned on paper or unmanaged in practice, this replaces both.
The Stehrling AI Governance Model covers corporate AI use in four planes, one gate, one loop, and one signature. It is free to read, cite, and use under CC BY-ND 4.0. The enclave is how we put it into operation.
We'll walk you through the environment our own team uses, how the gate operates, and what deploying it inside your boundary involves. Response within one business day.
Talk to Stehrling →An independent firm focused exclusively on NIST 800-171 compliance for defense contractors and the DIB.