Private AI for Government, Deployed Inside Your Perimeter

Staff at government agencies and defense contractors are already using AI tools with sensitive data. Lumen, the private AI platform from Cognetryx, runs entirely inside your network. CUI stays put, every interaction is logged, and the CMMC or FISMA conversation has a cleaner answer from the start.

  • CMMC

    DoD's Cybersecurity Maturity Model Certification Final Rule (32 CFR Part 170) took effect December 16, 2024

    32 CFR Part 170, Dec 2024

  • 110

    Security practices required at CMMC Level 2, all drawn from NIST SP 800-171 Rev 2

    NIST SP 800-171 Rev 2

  • M-24-10

    OMB directive requiring every federal agency to designate a Chief AI Officer and publish AI use case inventories

    OMB M-24-10, Mar 2024

See it in action

Every answer traces back to the exact line in your own files

Ask in plain language. Get an answer drawn only from your documents, with the source passage shown and highlighted, so anyone can check the work.

Lumen · grounded in your documents

Can we put CUI into a commercial cloud AI service?

Answer

No. CUI may only be processed inside the accredited authorization boundary. Sending it to a commercial cloud or AI service outside that boundary is prohibited unless the service is separately authorized for CUI.

↳ Section 3, ¶2 · p.7↳ Section 3, ¶5 · p.7

Answered from 2 passages in your CUI Handling Policy

CUI

Defense Solutions GroupControlled Unclassified Information

CUI Handling Policy
Information Security Section

Section 3: CUI Processing & Storage

ScopeAll CUI created, received, or stored under this contract.
BoundaryThe accredited system boundary defined in the system security plan.
StandardNIST SP 800-171 Rev 2 (110 controls); CMMC Level 2.

Control Requirements

1. CUI is labeled, logged, and handled only by authorized personnel with a need to know.

2. CUI may be processed and stored only within the accredited authorization boundary defined in this policy. (NIST 800-171: 3.13.1)

3. Access follows role-based controls inherited from the organization's identity provider.

4. All CUI access events are logged and retained for audit and incident response.

5. Transmitting CUI to a commercial cloud or AI service outside the authorization boundary is prohibited unless that service is separately authorized for CUI. (NIST 800-171: 3.1.20)

6. Media and endpoints holding CUI are encrypted at rest and in transit.

ISP-CUI-03 · Rev 3 · Effective 2026-02-01 · Owner: Information System Security ManagerCUI · Controlled document · p.7

Where Organizations Start

High-Leverage Use Cases in Government and Defense

Most government and defense organizations see fastest value when AI handles work that is already documented, already governed, and already repetitive. Lumen puts your documented institutional knowledge to work and leaves expert judgment with your team.

Contract & Policy Q&A

Staff query contract terms, SOW requirements, agency directives, or FAR/DFARS clauses without pulling a contracting officer into every routine question. Answers cite the governing document directly.

CMMC & Compliance Documentation

Prepare System Security Plan sections, CMMC assessment artifacts, and POA&M updates from your existing documentation. Staff spend less time hunting for evidence and more time organizing it.

Proposal & RFP Support

Summarize requirements documents, identify compliance obligations across solicitations, and draft proposal sections grounded in past performance documentation, all without sending content to an external processor.

Staff Onboarding & Training

New staff get consistent, program-specific answers to questions about procedures, regulations, and requirements. Onboarding accelerates and interpretive variance across a team or program office falls.

FISMA & ATO Preparation

Assemble control evidence, draft POA&M updates, and organize assessment documentation from internal records. When assessors arrive, your team is not building the package from scratch.

Deliverable & SOW Review

Review deliverables against statement of work requirements, flag gaps, and generate first-draft responses to government technical inquiries. Humans review and approve. The AI shortens the drafting cycle.

Compliance Mapping

How the Architecture Addresses What Assessors and Auditors Ask

Federal and defense compliance frameworks are converging on the same questions about AI governance and data handling. Here is how Lumen directly addresses each framework without bolt-on tooling.

FrameworkThe RequirementHow Lumen Addresses It
CMMC Level 2 (32 CFR Part 170)All 110 NIST SP 800-171 practices required for any system touching Controlled Unclassified Information. Effective December 2024 for DoD contracts.No CUI leaves the network. Existing CMMC controls extend to the AI deployment without introducing new cloud scope that requires additional certification documentation.
NIST SP 800-171 Rev 2110 security requirements for protecting CUI in nonfederal systems and organizations, covering access control, audit, configuration, and communications protection.Architecture satisfies access control, audit logging, and system integrity requirements without adding external surface area. Existing controls extend to cover the deployment.
FISMA (44 U.S.C. § 3551)Federal agencies must authorize all IT systems through the Authorization to Operate process under NIST Risk Management Framework guidance.Deploys as internal infrastructure inside the existing authorization boundary. Does not occupy a cloud service position and does not require a separate ATO as a standalone cloud system.
ITAR (22 CFR Parts 120-130)Export-controlled defense technical data cannot be transmitted to foreign nationals or foreign-operated systems, including inadvertent routing through foreign cloud infrastructure.All processing stays inside the organization's own infrastructure. No query routing to cloud APIs. No foreign server in the data path.
CLOUD Act (18 U.S.C. § 2523)U.S. authorities can compel major cloud providers to produce government data from servers worldwide, regardless of where the data is physically stored.Data never reaches a cloud provider. There is no data stored at a third party for a legal demand to reach.
OMB M-24-10 (Mar 2024)Federal agencies must designate a Chief AI Officer, publish AI use case inventories, and establish governance over AI tools used within the agency.On-premises deployment produces auditable, inventoriable AI interactions that satisfy use case tracking and governance obligations without cloud exposure or vendor dependency.

Common Questions

What Government and Defense Leaders Ask

Does Lumen process Controlled Unclassified Information on external servers?

No. Lumen runs entirely inside your organization's network. CUI does not leave your perimeter to reach the AI. This means the AI deployment does not expand your CUI handling footprint beyond what your existing CMMC Level 2 certification already covers. The system runs on your hardware, is managed by your team, and is governed by your existing security controls.

Does Lumen have FedRAMP authorization?

Lumen deploys as internal infrastructure, not as a cloud service. Federal agencies and contractors using Lumen are not deploying a cloud service into their environment. They are running self-hosted AI inside their own authorization boundary. The FedRAMP question applies to cloud services accessed over the internet; it does not apply in the same way to on-premises deployments managed inside the agency's or contractor's own network. Read more about how our deployment model works →

How does Lumen address ITAR concerns for defense contractors?

ITAR (22 CFR Parts 120-130) prohibits the export of defense technical information to foreign nationals or foreign-operated systems. Because Lumen runs inside your network on your hardware, queries containing export-controlled technical data never leave your controlled environment. There is no external routing, no cloud API, and no foreign server in the data path.

How does Lumen fit into an existing CMMC Level 2 certification?

CMMC Level 2 requires implementation of all 110 NIST SP 800-171 security practices. An AI tool that routes data to an external cloud provider introduces new scope that may require additional controls documentation. Lumen runs inside your existing boundary, so you are not adding new external scope. The relevant 800-171 controls (access control, audit and accountability, configuration management, and system and communications protection) apply to the on-premises deployment through your existing security program.

Can Lumen be deployed in an air-gapped or isolated network environment?

Lumen is designed for network isolation and has been deployed in environments with strict data controls. Air-gapped and network-isolated deployments are supported. Contact us to discuss the specific network architecture for your environment, including any program security review or facility security officer involvement required.

How long does deployment take for a government contractor or agency?

Most deployments go live in four weeks, with full production in 90 days. For programs with complex security approval requirements (ATOs, program security reviews, or FSO involvement), we work alongside your security team through that process concurrently with deployment preparation. Timeline depends on infrastructure readiness and the scope of documentation to be integrated.

See it answer from real documents

A 30-minute live demo. We reply within 24 hours.

See it in action