Govern CUI inside your own accreditation boundary
DataXray finds Controlled Unclassified Information and other sensitive content in files across your estate, classifies it and applies the control it needs, all inside your own boundary. It runs on-premises and in closed, air-gapped enclaves, with STIG-compliant deployments, FIPS-compliant cryptography and Authority to Operate achieved on three networks in the U.S. Department of War. Agencies buy it through Carahsoft.
What this buyer answers to
Government and defense teams are judged on whether controlled information is found, marked and protected, and on whether the tool that does it can be accredited. DataXray is built for both: it reads the files where CUI actually sits, and it deploys inside the environments an authorizing official will sign off, including disconnected ones.
- CMMCThe Cybersecurity Maturity Model Certification program sets the security requirements the Department of War places on contractors that handle Federal Contract Information and CUI. Level 2 aligns with the requirements of NIST SP 800-171, and Level 3 adds selected requirements from NIST SP 800-172. Both start from knowing where CUI lives.
- CUIControlled Unclassified Information is government information that requires safeguarding or dissemination controls under law, regulation or government-wide policy, as set out in 32 CFR Part 2002 and the CUI Registry.
- ATO, STIG and FIPSSoftware inside a federal system needs an Authority to Operate from the agency, hardening to DISA Security Technical Implementation Guides, and cryptography that meets federal standards.
Find and mark CUI at the file level
Most CUI is not in a database. It sits in contracts, technical drawings, reports, spreadsheets and email threads on file shares and collaboration sites. DataXray discovers those files without agents, reads their contents, including scanned images, and classifies CUI alongside PII and other sensitive categories, then applies machine-readable tags that downstream controls can act on.
- Every file read, not sampledDataXray opens each file and extracts its text, including scans through OCR, nested archives and email attachments, so CUI buried in an attachment or a scanned form is not missed.
- Classification you can defendLayered classification, from word lists and patterns to NLP, machine-learning annotators, LLM categorization and your own rules with human review, reaches 98.7% accuracy, measured on document-level PII/PCI detection in text-based English files. Predefined annotator packs cover CMMC, and you can define categories that match your agency's CUI categories.
- Tags that drive enforcementClassifications become attributes pushed into the encryption, labeling, access and retention tools you already run, so a file that is flagged is a file that gets protected. See Integrations.
- Evidence per file for an assessmentEvery file carries what was found in it, which rule or model found it and when it was last re-checked, and each scan produces audit logs your SIEM can ingest.
Accredited where it runs
DataXray is deployed inside your own environment, including closed, air-gapped enclaves with no external connectivity, and it is the same software there as anywhere else. Language models run in-boundary, so no inference call leaves the enclave, and the accreditation work rests on controls your security team can inspect.
- Authority to OperateATO has been achieved on three networks in the U.S. Department of War, including closed, air-gapped enclaves. An ATO is granted by the customer agency for a specific system in a specific environment; it is not a portable property of the product.
- STIG-compliant implementationsDeployments are hardened to Security Technical Implementation Guide baselines, which is typically what an accreditation package requires.
- FIPS-compliant cryptographyCryptography meeting U.S. federal standards for the protection of sensitive information.
- Company certificationsOhalo, which builds DataXray, holds SOC 2 Type 2 and ISO 27001.
- Agentless and read-onlyNothing is installed on endpoints or file servers, and sources are accessed read-only with least-privilege service accounts. Users sign in through your identity provider.
Modules built for government work
The same DataXray index, permission model and audit trail feed four modules that government teams use most. Each is described on its own page; here is what each does for a public-sector program.
- AI Platformlets AI assistants read enterprise files only within the user's own permissions and an administrator policy over which classified data categories AI may use.AI Platform
- Curatorturns discovery into a records program: change detection, retention, disposition and capture into accredited systems of record, with CUI markings that travel with each record and routing that fails closed.Curator
- AutoFOIAruns FOIA, Privacy Act, prudential search and mandatory declassification review in one application, with rasterized redaction so released text is provably gone, and it deploys inside classified networks.AutoFOIA
- Redactionremoves, anonymizes or pseudonymizes sensitive content by policy across an estate, for disclosure, research sharing or release.DataXray platform
Buying through Carahsoft
DataXray is available to U.S. federal, defense and civilian teams through Carahsoft on established government contracts, so agencies can buy it through the procurement route they already use rather than a new vendor onboarding.
In production
Public-sector organizations run DataXray today. The UK Health and Safety Executive uses DataXray to redact personal and sensitive data from health and safety datasets, so anonymized versions can be shared with third-party researchers in support of its mission to prevent death, injury and ill health at work.
In the United States, DataXray has achieved Authority to Operate on three networks in the Department of War, including closed, air-gapped enclaves.
Frequently asked questions
Does DataXray help with CMMC?
Yes. CMMC starts from knowing where CUI lives. DataXray discovers and classifies CUI across unstructured sources, applies tags that encryption, access and retention controls act on, and keeps per-file evidence for an assessment. DataXray supports your compliance work; the certification itself is awarded to your organization, not to a tool.
Can DataXray run on a classified or air-gapped network?
Yes. DataXray deploys into closed, air-gapped enclaves with zero external connectivity, and its language models run in-boundary. AutoFOIA adds a classification banner, idle session lock and system-use notification for classified networks.
Is DataXray FedRAMP authorized?
No. FedRAMP authorizes cloud services that a vendor operates. DataXray is deployed inside your own environment and operates under your system's authorization, with ATO achieved on three networks in the U.S. Department of War.
Is DataXray's cryptography FIPS validated?
DataXray uses FIPS-compliant cryptography, meaning cryptography that meets U.S. federal standards for the protection of sensitive information. Ask us for the details your accreditation package needs.
How do agencies buy DataXray?
Through Carahsoft, on established government contracts, for U.S. federal, defense and civilian teams.