Defense & CMMC

One governed workspace for CMMC.

IRONKEEP gives defense contractors one place for mail, files, docs, chat, and meetings, so CUI work, controls, and assessment evidence stay connected.

CMMC security

Controls for your CMMC assessment scope.

IRONKEEP keeps identity, access, audit, retention, recovery, and evidence workflows aligned across the work in scope. Your organization still owns its CMMC program and assessment.

01

Identity and access

Use IRONKEEP MFA or your identity provider through SAML or OIDC, with SCIM for user lifecycle control.

02

CUI boundary

Requests, stored content, and encryption keys remain scoped to the organization and workflow in scope.

03

Evidence workflow

Audit logs, retention, legal holds, recovery, and scoped exports support CMMC assessments.

04

Operator separation

IRONKEEP staff cannot read decrypted tenant content, create product users, or run tenant decrypt operations.

Operational experience. The team previously built a NIST 800-171-aligned secure computing environment, with experience across DoD intelligence and enterprise compliance infrastructure.

Why IRONKEEP →

Pilot path

From CUI scope to CMMC evidence.

  1. 01

    Scope the CUI workflow.

    Identify the users, systems, data flows, contracts, and external parties involved.

  2. 02

    Configure and migrate.

    Confirm identity, retention, and sharing controls, then move the agreed mail, files, and collaboration work.

  3. 03

    Operate and collect evidence.

    Use built-in controls, logs, holds, recovery, and exports to support your CMMC assessment work.

Who it's for

Built for defense teams with CMMC requirements.

Keep the CMMC boundary focused.

Start with the users and systems that handle CUI, then expand only after the first boundary is understood.

Split tools scatter CMMC evidence.

Mail, files, chat, and meetings each create separate identities, logs, retention rules, and recovery paths.

Outgrowing consumer workflows.

Move controlled work into one suite without treating software alone as a shortcut to CMMC certification.

FAQ

Common CMMC questions.

Where is customer data hosted?

Customer data is hosted in the United States. Tenant-scoped encryption keys and tenant isolation keep organizations separate and prevent routine operator access to tenant content.

How does IRONKEEP support CMMC?

IRONKEEP brings access, encryption, audit, retention, legal hold, recovery, and evidence workflows across one connected suite. Your organization still owns its CUI scope, policies, configuration, contracts, and assessment.

Is IRONKEEP FedRAMP authorized?

No. IRONKEEP is pursuing FedRAMP authorization but is not currently authorized.

How fast is migration?

Timing depends on mailbox and file volume, identity requirements, and the workflow in scope. Private beta onboarding starts with a bounded migration plan for your organization.

Does IRONKEEP replace a CMMC assessment?

No. IRONKEEP provides a governed work layer and supporting evidence, but your organization remains responsible for its CMMC program and any assessment.

Can IRONKEEP staff read my email?

No. Zero operator access to tenant content is enforced by explicit deny rules on decrypt operations. IRONKEEP staff cannot read decrypted tenant content, run tenant decrypt operations, create product users, or generate tenant search tokens.