Updated July 21, 2026
TL;DR: Defense contractors can't use AI security tools that route telemetry outside their perimeter. Noma Security's Kong Gateway plugin requires outbound HTTPS to
api.noma.security:443, creating a direct architectural conflict with ITAR data residency and CMMC Level 2 information flow requirements. Prediction Guard deploys a fully self-hosted, air-gapped sovereign AI control plane that enforces governance policies at runtime, generates SIEM-ready audit logs, and keeps every AI input, governance decision, and audit record inside your infrastructure with zero external telemetry.
Most defense contractors evaluate AI security tools without asking the single most important architectural question: where does the telemetry go? You determine whether a tool is a compliance asset or a regulatory liability under ITAR and CMMC Level 2 by answering that question precisely. For organizations handling Controlled Unclassified Information (CUI) in AI workflows, the data boundary is a legal mandate enforced by DCSA assessors and CMMC Third-Party Assessment Organizations (C3PAOs), not a preference. This article compares Noma Security and Prediction Guard on the architectural dimensions that ITAR and CMMC actually measure, and identifies what a self-hosted sovereign AI control plane must do to satisfy a defense examiner today.
What defense contractors need in an ITAR-compliant AI governance platform
ITAR and CMMC Level 2 impose specific technical requirements on how data moves through AI systems. Understanding those requirements precisely is the starting point for any governance tool evaluation.
Managing CUI for AI workflows
CUI flowing through an AI system creates export control risk at every handoff: prompt assembly, model processing, output generation, and telemetry transmission. Under 22 CFR § 120.50, allowing a non-United States person to access technical data is considered an export even if the data never physically leaves the country, meaning infrastructure design itself can create violations when AI inputs route through systems where provider access can't be ruled out.
Air-gapped AI deployment requirements
Air-gapped deployments exist because some operational environments can't tolerate any external network dependency during runtime. For defense programs handling CUI, an air-gapped AI deployment requires the control plane, model inference, and audit log generation to operate with zero outbound internet access.
Mapping AI controls to CMMC 2.0
CMMC Level 2 requires full implementation of all 110 controls in NIST SP 800-171, including information flow controls that govern where data can travel within and between systems. The CMMC Assessment Guide specifies that flow control restrictions include keeping export-controlled information from being transmitted in the clear to the internet and limiting information transfers between organizations based on data structures and content. An AI governance tool with mandatory outbound connections to vendor infrastructure as part of its enforcement architecture creates measurable compliance risk under these controls before a C3PAO ever reviews it.
Ensuring SIEM-ready governance logs
Defense security operations teams need structured audit logs forwarded to local SIEM infrastructure. Log retention inside your perimeter ensures the evidence trail is under your control when a DCSA assessor requests it, and local SIEM forwarding integrates detection events into the incident response workflows your team already operates, without creating a dependency on a vendor portal for investigation.
Evaluating Noma Security for ITAR compliance gaps
Noma Security provides runtime policy enforcement and real-time monitoring capabilities. The evaluation challenge for defense contractors is not whether Noma enforces policies at runtime, it is where the enforcement telemetry routes.
Ensuring ITAR data residency
Noma's Kong Gateway plugin requires outbound HTTPS access on port 443 to api.noma.security. The plugin streams AI traffic data to the Noma Security Console for audit trails and behavioral analysis, and enables Noma to inspect prompts and responses in real time against external Noma infrastructure. For a non-defense organization, this architecture is operationally acceptable. For a defense contractor handling CUI, this outbound data flow creates a direct conflict with ITAR data residency requirements and CMMC Level 2 information flow controls. The Practical AI episode 360, co-hosted by Prediction Guard founder Daniel Whitenack, covers why vendor-mediated telemetry crossings break the trust boundary that regulated data depends on.
The compliance evaluation is straightforward: if the enforcement telemetry containing AI interaction data routes to a vendor's external infrastructure, the organization can't demonstrate that CUI remained within its defined perimeter. That gap is a finding during a CMMC assessment, not a documentation issue to resolve after the fact.
|
Capability |
Noma Security |
Prediction Guard |
|---|---|---|
|
Deployment model |
Hybrid / third-party-connected |
Fully self-hosted / air-gapped |
|
Telemetry routing |
Outbound HTTPS to |
100% localized within perimeter |
|
Audit log storage |
Vendor cloud / external console |
Customer's local SIEM (Splunk, Datadog, CrowdStrike, syslog) |
|
Runtime enforcement |
Yes, with external telemetry |
Yes, entirely within the perimeter |
Bridging NIST and CMMC control gaps
Noma's runtime enforcement routes telemetry to external infrastructure. CMMC Level 2 requires not only that AI interactions are governed, but that the governance evidence stays within the organization's perimeter. The NIST AI RMF Manage function requires active intervention capability at the moment of the interaction, with a verifiable evidence record that a C3PAO can retrieve from the organization's own systems. A tool that enforces policies at runtime while routing the enforcement record externally satisfies the enforcement requirement but creates a gap in the evidence residency requirement.
Audit readiness for self-hosted deployments
Retrospective log analysis doesn't satisfy defense examiners. A DCSA assessor evaluating AI governance controls needs evidence that policy enforcement happened at the time of the interaction, stored inside the organization's perimeter, and retrievable from the organization's own SIEM. This is the structural distinction between an audit log and a vendor-hosted event record. Active runtime enforcement that generates logs inside the customer's infrastructure satisfies both requirements. External telemetry that the customer retrieves from a vendor portal satisfies neither.
Key features for ITAR-ready AI security platforms
Defining what an ITAR-ready AI governance platform must actually do establishes the evaluation criteria before any vendor comparison.
Automating NIST AI RMF compliance
The NIST AI RMF core includes four functions: Govern, Map, Measure, and Manage. Automating these functions means the governance infrastructure enforces policies without depending on individual developer compliance. That requires a system that registers AI assets, tracks their configurations, and enforces policies on every interaction as it happens.
Mapping controls to NIST AI RMF
We map Prediction Guard's control plane capabilities to NIST AI RMF functions and CMMC practices below, based on control requirements in NIST SP 800-171 and the CMMC Assessment Guide.
|
Prediction Guard control |
NIST AI RMF function |
CMMC Level 2 practice |
|---|---|---|
|
Runtime input redaction |
Govern, Manage |
Media Protection (MP family) |
|
SIEM-ready audit log generation |
Measure, Manage |
Audit and Accountability (AU family) |
|
AI System registration (CycloneDX AIBOM export) |
Govern (Supply Chain) |
System and Services Acquisition (SA family) |
|
Prompt injection enforcement |
Map, Manage |
System and Information Integrity (SI family) |
Enforcing ITAR compliance at runtime
OWASP identifies prompt injection as a top-ranked vulnerability class for LLM-integrated applications, particularly the indirect variant where adversarial instructions are embedded in external content the model retrieves. For a defense AI system, a successful prompt injection attack isn't just a security incident: it's a potential unauthorized access event against CUI-adjacent data. Runtime enforcement that intercepts and blocks malicious inputs before they reach the model eliminates this exposure at the architectural level. The OWASP Top 10 for Agentic Applications 2026 extends this frame to multi-step agent architectures where autonomous execution amplifies the impact of single-request attacks, making runtime enforcement even more critical than in single-model deployments. The Practical AI episode 361 covers how standards, certification, and assurance frameworks are being applied to agentic AI to close exactly this class of runtime gap.
Prediction Guard for CMMC Level 2 AI compliance
Prediction Guard deploys a sovereign AI control plane entirely inside the customer's infrastructure. The governance logic, policy enforcement, and audit log generation all run within the perimeter, with no outbound telemetry required for any governance decision.
Self-hosted governance for AI workloads
Prediction Guard supports three self-hosted deployment configurations: self-hosted, cloud VPC, and air-gapped. In all three configurations, the control plane enforces AI governance policies on every model or agent call as it happens: checking the call, allowing it, blocking it, or rewriting it before the response returns. No data transits Prediction Guard's systems. The Practical AI episode 358 covers how enterprise Kubernetes stacks are being restructured to support governed AI systems with MCP integrations inside the customer's own infrastructure.
Native SIEM integration for AI logs
The SIEM integration workflow in the Prediction Guard Admin Console operates through four steps:
- Open the Monitor page in the Admin Console.
- Click Configure under the target integration (Splunk, Datadog, CrowdStrike, or generic syslog).
- Confirm to activate the integration.
- The live integration signals Prediction Guard to format audit log output using the field structure that SIEM expects natively.
Prediction Guard doesn't store SIEM API keys, HTTP Event Collector (HEC) tokens, or endpoint credentials. It configures output formatting only, and the customer's existing ingestion pipeline handles delivery under their own controls. For a C3PAO assessment, this means the evidence trail is in the customer's SIEM, under the customer's retention policy, with no dependency on a vendor portal for retrieval.
Air-gapped deployment configurations
The Prediction Guard control plane is CPU-only. Models can run on GPU or CPU depending on workload, and the platform is hardware and infrastructure agnostic. Organizations can run the governance control plane on commodity compute without specialized hardware investment, while maintaining flexible model serving infrastructure. In an air-gapped environment, this eliminates the dependency on externally hosted GPU acceleration that would otherwise require outbound connectivity.
CMMC Level 2 compliance mapping and FCA risk
For CMMC Level 2 audit readiness, Prediction Guard generates structured audit logs as a byproduct of every enforcement decision. When the control plane blocks a prompt injection attempt, the log records the enforcement event, the policy triggered, and the outcome, all within the customer's perimeter.
The False Claims Act dimension makes the audit evidence package a legal priority, not just a compliance one. A misconfigured AI governance architecture that routes CUI-adjacent telemetry to external vendor infrastructure is an FCA exposure before any incident happens.
Criteria for selecting ITAR-compliant AI tools
Use the following criteria to evaluate AI governance tools against ITAR and CMMC Level 2 requirements before procurement, not during assessment.
- Map product controls to NIST and OWASP. Require a structured mapping document, not a general compliance claim. The mapping should link specific product capabilities to named NIST AI RMF functions, NIST SP 800-171 control families, and OWASP item numbers. If a vendor can't produce this document, a C3PAO can't validate the alignment claim. The NIST AI RMF implementation playbook on the Prediction Guard blog shows what this mapping looks like in practice.
- Retain audit logs in your environment. Log generation and log storage are separate capabilities. A governance tool that generates logs and stores them in vendor infrastructure creates an evidence residency gap for CMMC AU.L2-3.3.1. The tool must generate structured, SIEM-ready logs consumed by your own SIEM under your retention policy. Verify this architecture before procurement, not during the assessment.
- Operationalize AI in regulated environments. Developer ergonomics matter for adoption. A governance control plane that requires developers to rewrite their toolchain creates resistance that leads to workarounds. Prediction Guard's OpenAI-compatible and Anthropic-compatible APIs mean existing SDK code works unchanged: developers update only the
base_urlparameter. This reduces deployment friction while maintaining full governance enforcement. The AI engineers overview details the developer integration model. - Assess air-gapped AI environment risks. Third-party AI components introduce supply chain risk that CMMC's System and Services Acquisition (SA) control family requires organizations to manage. Evaluate each AI component in the deployment: the base model, fine-tuning layers, the inference infrastructure, and the governance control plane itself. Registering every AI asset (models, fine-tuning layers, inference infrastructure, and the governance control plane) into an AI System produces the inventory a C3PAO can validate. The CycloneDX AIBOM is the audit export derived from that registration. CycloneDX supports transparency in AI systems by representing datasets, models, and configurations in a machine-readable format, documenting provenance for datasets and supporting risk identification around bias, data integrity, and model security. Tools that can't produce a machine-readable AI asset inventory leave a gap in the supply chain risk evidence package.
CMMC Level 2 AI integration checklist
Use this checklist to verify your AI governance deployment satisfies CMMC Level 2 requirements before a C3PAO assessment.
- Define the AI system assessment boundary and register all AI assets in a structured inventory.
- Verify zero outbound telemetry calls to external vendor APIs during runtime policy enforcement.
- Configure real-time PII and sensitive-data redaction on all AI inputs before model processing.
- Export an AI Bill of Materials in CycloneDX format covering models, datasets, and governance metadata.
- Route structured audit logs natively to local SIEM infrastructure (Splunk, Datadog, or syslog) under your own retention policy.
- Confirm governance policies are enforced at the moment of the AI interaction, not retrospectively.
- Document the control-to-framework mapping linking control plane capabilities to NIST SP 800-171 control families.
- Validate that your air-gapped deployment configuration resolves all governance checks locally with no external dependencies.
If you're currently using Noma Security and can't clear item two on this checklist, book a deployment scoping call to assess whether self-hosted deployment fits your infrastructure and compliance requirements. To review which NIST AI RMF functions Prediction Guard addresses at the system level, see the NIST AI RMF 1.0 implementation playbook on the Prediction Guard blog.
FAQs
Is Prediction Guard ITAR-compliant?
Prediction Guard deploys entirely within your self-hosted, air-gapped environment, ensuring no regulated CUI or governance telemetry leaves your perimeter. Because the control plane, governance logic, and audit log generation all operate inside your infrastructure, the architecture satisfies ITAR's data residency requirement by design.
Does Prediction Guard store our audit logs?
No. Prediction Guard generates structured, SIEM-ready audit logs as a byproduct of runtime enforcement, and those logs are consumed and retained entirely within your own SIEM (Splunk, Datadog, or generic syslog). Prediction Guard doesn't hold SIEM API keys, HEC tokens, or any SIEM credentials.
Can we run open-source models on Prediction Guard?
Yes. Prediction Guard is model agnostic and supports open-source model families including Llama and Mistral running on your local CPU or GPU infrastructure, with no restriction to a curated vendor list.
What is the architectural challenge with Noma Security for ITAR deployments?
Noma's Kong Gateway plugin requires outbound HTTPS access to api.noma.security:443 to stream AI traffic data to the Noma Security Console. This mandatory external connection routes AI interaction telemetry outside the customer's perimeter, creating a data flow that conflicts with ITAR's data residency requirements and CMMC Level 2's information flow control requirements for organizations handling CUI.
Does changing to Prediction Guard require rewriting our AI code?
No. Prediction Guard provides OpenAI-compatible and Anthropic-compatible APIs, so existing SDK calls work unchanged. Developers update only the base_url parameter to point at the Prediction Guard control plane endpoint. Governance enforcement is transparent at the code level and non-negotiable at the system level.
What is the AIBOM and why does it matter for CMMC?
For CMMC Level 2, the primary capability is AI System registration: every AI asset in scope (models, datasets, dependencies, and governance metadata) is registered into a structured AI System inventory. The AIBOM (AI Bill of Materials) in CycloneDX format is the audit export derived from that registration, providing a machine-readable record a C3PAO can validate against your registered AI systems to satisfy supply chain risk management requirements in the System and Services Acquisition (SA) control family.
Key terms glossary
Sovereign AI control plane: A self-hosted governance infrastructure that runs inside your perimeter, allowing you to compose, secure, and govern disparate AI models, tools, and Model Context Protocol (MCP) servers under a single policy enforcement layer with no external vendor telemetry.
Controlled Unclassified Information (CUI): Information the U.S. government creates or possesses that requires safeguarding under law, regulation, or government-wide policy, including technical data that falls under ITAR export controls.
CMMC Level 2: The CMMC maturity level requiring full implementation of all 110 controls in NIST SP 800-171, applicable to defense contractors handling CUI on DoD programs.
AIBOM (AI Bill of Materials): An exportable inventory of AI assets, models, and datasets in CycloneDX format, used to satisfy CMMC supply chain risk management requirements and provide a structured record for DCSA assessors and C3PAOs.
False Claims Act (FCA): The U.S. federal statute creating liability for knowingly submitting false claims to the government, including misrepresentations of cybersecurity compliance in defense contracts. The DOJ's Civil Cyber-Fraud Initiative uses the FCA to pursue contractors who knowingly deploy deficient cybersecurity controls, requiring only reckless disregard of the truth rather than proof of an actual breach.