For Defense contractors

Find your CUI before your assessor does

Scan the shares you already have, see exactly where Controlled Unclassified Information lives, and keep the whole search on hardware you control.

The problem

What firms like yours run into.

  • Nobody can say with confidence which shares actually hold CUI — it spread across projects, mailboxes, and someone’s desktop years ago.
  • An assessor asks where CUI is stored and the honest answer is a guess, not an inventory.
  • Sensitive material ends up in files nobody marked — copies, exports, and drafts — so the markings alone no longer tell you where it all lives.
  • Export-controlled technical data can’t be handed to a cloud service or a public AI tool — for many programs that alone would be a reportable event.
  • Prime contractors flow their obligations down, so the same bar lands on a small shop with no security staff.

How FileFerret helps

Put your own files to work — privately.

Locate CUI across your shares

Scan the folders you already use and get a per-file inventory of where controlled material actually sits — the documented location an assessor asks for.

Read the markings, not just the word

Banner and portion markings are broken down into their registry categories and dissemination controls, so “CUI” becomes something you can report on by category.

Nothing unfamiliar is swallowed

A marking we don’t recognise is reported as unrecognised rather than dropped, because the unfamiliar ones are exactly the ones worth a human look.

Findings tied to the requirements

Each result points at the requirements it bears on, so a scan becomes evidence you can hand to an assessor instead of a spreadsheet you still have to explain.

Catch sensitive content that was never marked

Files are flagged by the sensitive data inside them — Social Security, card, and account numbers among them — so material that holds controlled information but never got a marking still surfaces.

Runs with no connection at all

The same product runs fully air-gapped — no egress, no call-home — with support by phone, screen-share on your terms, and on-site visits.

Built for your obligations

Supports the NIST SP 800-171 requirement to identify and document where CUI is stored, and keeps controlled material inside a boundary you define rather than a shared cloud. It produces evidence for an assessment — it does not, by itself, confer any CMMC status. See our CMMC & NIST SP 800-171 and ITAR explainers.

See FileFerret on your own files.

We’ll scope your firm’s needs, ship and install a private FileFerret appliance, train your team, and support you for years to come. No client data leaves your office — ever.