One hardened environment, built in your own cloud account.
Regulated data scattered across email, laptops, and shared drives is two problems at once: more places an attacker can reach it, and more systems dragged into your assessment boundary. The enclave puts it in one environment we build, harden, and operate for you — which shrinks both at the same time.
The tenant is yours, not ours. And the CUI enclave ships with a full compliance program — controls, documentation, and evidence — not just an environment to figure out.
Scattered data is what makes all of this expensive.
Nobody decided to spread controlled information across fifteen laptops and a shared drive — it happened one attachment at a time. But every place that data landed is now something you have to defend, document, and answer for.
Everything is in scope
When controlled data can be anywhere, your whole company falls inside the assessment boundary — every system, every user, every device held to the same standard.
Everything is exposed
A phished account or a lost laptop reaches whatever that person could reach. With data spread wide, that’s most of it — and the blast radius is the whole business.
You pay for all of it, forever
Every system in scope needs controls implemented, evidenced, and maintained. Scope isn’t a one-time cost — it’s the multiplier on everything you’ll ever spend here.
Containment is the highest-leverage move available to you. Put the regulated data in one hardened place and most of your business stops being something you have to defend or prove.
Two flavors. Same containment model.
The right platform depends on what your data actually is — not on what sounds most secure. Over-buying a government cloud you don’t need is a real and expensive mistake, and we’ll tell you if that’s where you’re headed.
CUI enclave
For CUI, ITAR/EAR, and other controlled or export-restricted data under NIST SP 800-171. Ships with a full compliance program, not just a tenant.
Non-CUI enclave
For sensitive data that isn’t CUI — customer data, IP, and regulated commercial workloads where SOC 2, HIPAA, or a prime’s security requirements are the driver.
How we scope it
We determine what data you actually hold and where its jurisdiction sits before recommending a platform. Scoping comes first, procurement second.
How GCC High actually gets delivered. We deploy and manage Microsoft 365 GCC High as an AOS-G partner through Pax8, in a tenant you own outright. And because we operate that environment on your behalf, we act as an External Service Provider — which factors into how your assessment is scoped. We’ll walk you through exactly what that means for you before you sign anything.
A working environment, not a locked box.
Your people still need to do their jobs in here. The enclave is a full workspace — email, files, desktops, collaboration — with the controls built into how it was assembled rather than bolted on afterward.
Virtual desktops, or managed endpoints
Most people work inside the boundary through a virtual desktop — the data never lands on the laptop, so personal and unmanaged devices stay out of scope. When the work genuinely needs local hardware — CAD, instrumentation, a machine on the shop floor — we bring that endpoint into the boundary instead: enrolled, hardened, and managed. It’s in scope when we do, and we’ll tell you what that costs before we do it.
Identity, access, and MFA
Conditional access, least-privilege roles, and multi-factor enforced across the environment — the controls that stop a stolen password from becoming an incident.
Endpoint protection and patching
Managed EDR and patch management on everything inside the boundary, kept current by us. Unpatched systems are still the most common way in.
Encrypted backup and recovery
Encrypted, tested backups with a defined recovery path. Ransomware is a backup problem before it’s anything else — and untested backups aren’t backups.
Continuous monitoring and alerting
Logging and detection across the environment, tuned so alerts mean something. Coverage hours and escalation paths are defined in your agreement.
Your tenant, no shared infrastructure
The account is yours from day one and your data never sits alongside another client’s. No lock-in — if you leave, the environment and everything in it stays with you.
The compliance program comes with it.
Anyone can sell you a GCC High tenant. The CUI enclave ships with the program that makes it defensible — controls implemented against NIST SP 800-171, documented, evidenced, and maintained as the environment changes.
- Control implementation mapped to NIST SP 800-171
- System Security Plan, written for your environment
- Full policy suite, reviewed and kept current
- POA&M with owners, dates, and status
- Evidence collected as a by-product of operating
- SPRS scoring and annual affirmation support
Two things to be clear about. The Greypike Compliance App is a separate subscription — the program above is delivered by our practitioners, and the App is the platform you can add to run it yourself. And we prepare you for assessment; we’re not a C3PAO and we don’t grade our own work.
Useful on its own. Better with the rest.
The enclave is a delivery vehicle, not a prerequisite for anything else we do. Plenty of clients buy monitoring or compliance without one. But when it’s there, everything else gets cheaper and easier — because there’s less ground to cover.
Less to prove
Scope is the multiplier on compliance cost. Contain the data and most of your business falls outside the boundary you have to control and evidence.
ComplianceLess to watch
Monitoring a contained environment beats monitoring data spread across laptops and inboxes. Fewer places to look means the looking is actually good.
CybersecuritySomewhere to run AI
An accredited environment is what makes in-boundary AI possible at all — assistants and agents working on your data without it ever leaving your control.
AIStart here
Find out whether you need one.
Start with a scoping session. We’ll work out what data you actually hold, which platform fits it, and what containment would save you — including telling you if an enclave is more than you need. No obligation.
Veteran-founded · Cyber AB RPA-led · Government contractors only