Deployable CUI Vault - FIPS Boundary You Control
A FIPS-controlled CUI boundary with C3PAO-ready evidence and easy HTTPS integration into your website or enclave-so you reduce scope, meet DFARS, and keep CUI out of your main application.
FIPS 140-3 · CMMC Level 2 · C3PAO-ready evidence
Two ways to run it: the Managed CUI Vault ($1,995/month, see tiers) hosted and operated by MacTech, or the Deployable CUI Vault below, priced per deployment.
Who It's For
The Deployable CUI Vault is for federal programs, defense contractors, and private organizations that need a defensible CUI boundary for CMMC compliance. Deploy it in your enclave or cloud-CUI stays inside the vault; your main app never handles CUI file bytes.
Three tiers by scope. Flat monthly. No per-user fees.
Every tier is the same enclave. What changes is how much of the compliance work MacTech carries: hosting only, hosting with continuous evidence, or hosting with the full record an assessor reads. Prices are read live from the MacTech catalog.
Tier 1
Vault
Where your CUI lives.
$1,995 /month
MAC-VAULT-MGD-001
- Managed FIPS-boundary enclave on Azure, operated by MacTech
- Hardened Windows Server 2025 host, Entra ID, MFA and conditional access
- Boundary documentation and shared-responsibility matrix
- Quarterly evidence export for your assessor
Tier 2
Vault + EnclaveWatch
Evidence that regenerates itself.
$3,450 /month
MAC-VAULT-WATCH-001
- Everything in Vault
- Weekly canonical evidence run, 10-day staleness backstop
- Signed forensic packets and a per-control evidence library
- Drift, break-glass and Defender alerts correlated and reviewed
Tier 3
Vault + EnclaveWatch + Trust Codex
Compliance run as a service.
$5,950 /month
MAC-VAULT-TRUST-001
- Everything in Vault + EnclaveWatch
- Your own Trust Codex tenant: 110 controls, 320 objectives adjudicated
- POA&M management, versioned SSP, assessment package on demand
- Weekly ISSO review signed; monthly summary delivered
Which controls each tier carries for you is published, control by control, in the Vault responsibility matrix. What EnclaveWatch proves, and what it does not, is on the EnclaveWatch page.
FIPS Boundary
All CUI decryption and cryptographic protection occur only inside the vault. Your main application issues tokens only-no CUI bytes through your app.
- Platform: Ubuntu 22.04 LTS with FIPS mode enabled (kernel + OpenSSL FIPS provider). Canonical Ltd. Ubuntu 22.04 OpenSSL Cryptographic Module - NIST CMVP Certificate #4794 (FIPS 140-3 Level 1; current validation status is on the CMVP module list).
- CUI in transit: TLS 1.3 (AES-256-GCM-SHA384) terminated on the vault host.
- CUI at rest: AES-256-GCM application-level encryption using the FIPS-validated module per Certificate #4794.
What's in the Box
The deployable unit (VM image or container) includes everything needed for a defensible CUI boundary and C3PAO handoff.
- OS: Ubuntu 22.04 LTS, FIPS mode (kernel + OpenSSL FIPS provider per CMVP #4794)
- CUI Vault Service: POST/GET/DELETE /v1/files/*; JWT validation; API key for server-side delete; AES-256-GCM encrypt/decrypt
- TLS: nginx - TLS 1.3 termination, security headers, reverse proxy to vault service
- Database: Local PostgreSQL bound to localhost; encrypted CUI (ciphertext, nonce, tag, metadata)
- Hardening: harden_ubuntu_cmmc.py (and optionally harden_ubuntu_stig.py); evidence in /opt/compliance/hardening-evidence
- Validation: cmmc_hardening_validation_evidence.py; evidence in /opt/compliance/validation-evidence
- Policy bundle: Vault-boundary subset of CMMC policies/procedures under /opt/compliance/policies
- Evidence export: Script to produce tarball of hardening + validation evidence + policies for C3PAO
C3PAO Evidence
Hardening and validation evidence are produced by our automation and stored on the vault. An export script collects hardening evidence, validation evidence, and (optionally) the policy bundle into a single tarball for C3PAO handoff. Reference evidence (MAC-RPT-*, FIPS documentation) is available in the repo and can be shipped or linked from the deployable image.
- Hardening evidence: harden_ubuntu_cmmc.py (cloud-safe CMMC Level 2) → /opt/compliance/hardening-evidence
- Validation evidence: cmmc_hardening_validation_evidence.py → /opt/compliance/validation-evidence
- Evidence package: export script builds tarball for C3PAO
HTTPS & API Integration
Your app authenticates users and issues short-lived JWTs for upload and view. The browser uploads and downloads CUI directly to and from the vault over HTTPS-your application never handles CUI file bytes. API: POST /v1/files/upload, GET /v1/files/:id, DELETE /v1/files/:id.
Contact us for integration support and environment configuration.
Artifact Formats
VM image
Packer-built image (e.g. GCE, AWS AMI, Azure VHD) for DoD and federal environments where VM hardening and a FIPS kernel are required.
Container
Dockerfile/OCI image for cloud deployments-same vault service and tooling, with FIPS and hardening applied as documented for the container build.
Ready to deploy a FIPS-controlled CUI boundary?