Secure Enclave

One hardened environment, built in your own cloud account.

Regulated data scattered across email, laptops, and shared drives is two problems at once: more places an attacker can reach it, and more systems dragged into your assessment boundary. The enclave puts it in one environment we build, harden, and operate for you — which shrinks both at the same time.

The tenant is yours, not ours. And the CUI enclave ships with a full compliance program — controls, documentation, and evidence — not just an environment to figure out.

The problem

Scattered data is what makes all of this expensive.

Nobody decided to spread controlled information across fifteen laptops and a shared drive — it happened one attachment at a time. But every place that data landed is now something you have to defend, document, and answer for.

Everything is in scope

When controlled data can be anywhere, your whole company falls inside the assessment boundary — every system, every user, every device held to the same standard.

Everything is exposed

A phished account or a lost laptop reaches whatever that person could reach. With data spread wide, that’s most of it — and the blast radius is the whole business.

You pay for all of it, forever

Every system in scope needs controls implemented, evidenced, and maintained. Scope isn’t a one-time cost — it’s the multiplier on everything you’ll ever spend here.

Containment is the highest-leverage move available to you. Put the regulated data in one hardened place and most of your business stops being something you have to defend or prove.

Which one do I need?

Two flavors. Same containment model.

The right platform depends on what your data actually is — not on what sounds most secure. Over-buying a government cloud you don’t need is a real and expensive mistake, and we’ll tell you if that’s where you’re headed.

CUI enclave

For CUI, ITAR/EAR, and other controlled or export-restricted data under NIST SP 800-171. Ships with a full compliance program, not just a tenant.

Microsoft GCC High Google Assured Workloads

Non-CUI enclave

For sensitive data that isn’t CUI — customer data, IP, and regulated commercial workloads where SOC 2, HIPAA, or a prime’s security requirements are the driver.

Microsoft 365 Commercial Google Workspace

How we scope it

We determine what data you actually hold and where its jurisdiction sits before recommending a platform. Scoping comes first, procurement second.

Data inventory Scope determination Platform recommendation

How GCC High actually gets delivered. We deploy and manage Microsoft 365 GCC High as an AOS-G partner through Pax8, in a tenant you own outright. And because we operate that environment on your behalf, we act as an External Service Provider — which factors into how your assessment is scoped. We’ll walk you through exactly what that means for you before you sign anything.

What’s included

A working environment, not a locked box.

Your people still need to do their jobs in here. The enclave is a full workspace — email, files, desktops, collaboration — with the controls built into how it was assembled rather than bolted on afterward.

Virtual desktops, or managed endpoints

Most people work inside the boundary through a virtual desktop — the data never lands on the laptop, so personal and unmanaged devices stay out of scope. When the work genuinely needs local hardware — CAD, instrumentation, a machine on the shop floor — we bring that endpoint into the boundary instead: enrolled, hardened, and managed. It’s in scope when we do, and we’ll tell you what that costs before we do it.

Identity, access, and MFA

Conditional access, least-privilege roles, and multi-factor enforced across the environment — the controls that stop a stolen password from becoming an incident.

Endpoint protection and patching

Managed EDR and patch management on everything inside the boundary, kept current by us. Unpatched systems are still the most common way in.

Encrypted backup and recovery

Encrypted, tested backups with a defined recovery path. Ransomware is a backup problem before it’s anything else — and untested backups aren’t backups.

Continuous monitoring and alerting

Logging and detection across the environment, tuned so alerts mean something. Coverage hours and escalation paths are defined in your agreement.

Your tenant, no shared infrastructure

The account is yours from day one and your data never sits alongside another client’s. No lock-in — if you leave, the environment and everything in it stays with you.

CUI enclave only

The compliance program comes with it.

Anyone can sell you a GCC High tenant. The CUI enclave ships with the program that makes it defensible — controls implemented against NIST SP 800-171, documented, evidenced, and maintained as the environment changes.

  • Control implementation mapped to NIST SP 800-171
  • System Security Plan, written for your environment
  • Full policy suite, reviewed and kept current
  • POA&M with owners, dates, and status
  • Evidence collected as a by-product of operating
  • SPRS scoring and annual affirmation support

Two things to be clear about. The Greypike Compliance App is a separate subscription — the program above is delivered by our practitioners, and the App is the platform you can add to run it yourself. And we prepare you for assessment; we’re not a C3PAO and we don’t grade our own work.

Start here

Find out whether you need one.

Start with a scoping session. We’ll work out what data you actually hold, which platform fits it, and what containment would save you — including telling you if an enclave is more than you need. No obligation.

Veteran-founded · Cyber AB RPA-led · Government contractors only