Identity and access
Use IRONKEEP MFA or your identity provider through SAML or OIDC, with SCIM for user lifecycle control.
Defense & CMMC
IRONKEEP gives defense contractors one place for mail, files, docs, chat, and meetings, so CUI work, controls, and assessment evidence stay connected.
Workspace flow
Each product handles one part of the workflow while identity, audit, retention, legal hold, recovery, and assessment evidence stay shared.
Keep CUI in email, calendar, and contacts inside the configured boundary.
Store and share controlled files with scoped permissions, history, and recovery.
Create and edit docs, spreadsheets, and presentations without exporting CUI to another suite.
Keep project conversations and attachments under the same identity, audit, and retention controls.
Run calls and screen sharing with invite-only guests, controlled recordings, and auditable actions.
CMMC security
IRONKEEP keeps identity, access, audit, retention, recovery, and evidence workflows aligned across the work in scope. Your organization still owns its CMMC program and assessment.
Use IRONKEEP MFA or your identity provider through SAML or OIDC, with SCIM for user lifecycle control.
Requests, stored content, and encryption keys remain scoped to the organization and workflow in scope.
Audit logs, retention, legal holds, recovery, and scoped exports support CMMC assessments.
IRONKEEP staff cannot read decrypted tenant content, create product users, or run tenant decrypt operations.
Operational experience. The team previously built a NIST 800-171-aligned secure computing environment, with experience across DoD intelligence and enterprise compliance infrastructure.
Why IRONKEEP →Pilot path
Scope the CUI workflow.
Identify the users, systems, data flows, contracts, and external parties involved.
Configure and migrate.
Confirm identity, retention, and sharing controls, then move the agreed mail, files, and collaboration work.
Operate and collect evidence.
Use built-in controls, logs, holds, recovery, and exports to support your CMMC assessment work.
Who it's for
Keep the CMMC boundary focused.
Start with the users and systems that handle CUI, then expand only after the first boundary is understood.
Split tools scatter CMMC evidence.
Mail, files, chat, and meetings each create separate identities, logs, retention rules, and recovery paths.
Outgrowing consumer workflows.
Move controlled work into one suite without treating software alone as a shortcut to CMMC certification.
FAQ
Customer data is hosted in the United States. Tenant-scoped encryption keys and tenant isolation keep organizations separate and prevent routine operator access to tenant content.
IRONKEEP brings access, encryption, audit, retention, legal hold, recovery, and evidence workflows across one connected suite. Your organization still owns its CUI scope, policies, configuration, contracts, and assessment.
No. IRONKEEP is pursuing FedRAMP authorization but is not currently authorized.
Timing depends on mailbox and file volume, identity requirements, and the workflow in scope. Private beta onboarding starts with a bounded migration plan for your organization.
No. IRONKEEP provides a governed work layer and supporting evidence, but your organization remains responsible for its CMMC program and any assessment.
No. Zero operator access to tenant content is enforced by explicit deny rules on decrypt operations. IRONKEEP staff cannot read decrypted tenant content, run tenant decrypt operations, create product users, or generate tenant search tokens.
Defense & CMMC
Enter your email to request a defense pilot and open the CMMC readiness checklist.
Private beta
Choose the regulated workflow you want to scope.
Enter your email to start scoping the healthcare workflow.
Enter your email to request a defense pilot and open the CMMC readiness checklist.