Inward — your environment
Data-Protection Scoping
Turns the obligations in your contracts into a defensible boundary, from your own documents and your own systems.
- Input
- Contracts, task orders, flow-downs, DD 254s, and your declared data estate
- Method
- NIST SP 800-60 categorization, the CUI Registry, and NIST SP 800-171
- Obligation status
- Reaches confirmed — the clause is quoted from your document, with the line cited
- Traceable decision model, clause to safeguard
- Boundary with a recorded basis for every inclusion and exclusion
- Decision records with owner, authority, and review cadence
- Prioritized protection roadmap
Outward — your supply chain
Contractor Risk Intelligence
Assesses a federal contractor from public sources when you have no access to their documents or systems.
- Input
- Public award, subaward, registration, exclusion, and screening data
- Method
- Three risk domains, nineteen weighted factors, and classification gates
- Obligation status
- Stops at strongly indicated — public data cannot confirm a clause
- Composite classification with an explicit confidence figure
- Organizational, data, and supply-chain domain scores
- Inferred obligations with the basis for each
- The sources that were not available, stated plainly
Risk intelligence, not a compliance determination. It renders no CMMC, FOCI, or export-control determination, and is not for consumer-credit, employment, or insurance-eligibility use.