Home/Platform

The Platform

Every component is selected and categorized against CMMC Level 2 requirements and operated by U.S. Persons. It is the mechanism by which the program runs — not the product you are buying.

📄
The Security Platform — capability document
3 pages · TUSA-CAP-002 · free to forward · no sign-up
Download PDF

Your Environment.
Our CMMC Security Stack.

The platform is how the program is operated, not what you are buying. It plugs into your existing environment to form a defensible CMMC Level 2 boundary — and it stops at a hard line: TRANUSA's tooling processes telemetry only. Logs, alerts and metadata. Your CUI and ITAR-controlled content never leaves your boundary.

Client Environment

Everything the client owns and operates

🏢 Facilities & Buildings
🔐 Physical Security
🌐 FIPS-validated Network Gear
🖥️ Workstations
⚙️ OT Machines
🗄️ NAS / Servers
🖨️ Printers & Peripherals
🔒
CMMC L2
Compliant
Environment
TRANUSA Tech Stack

How the program is operated

📊 SIEM
🛡️ Zero Trust
🩺 EDR
🔧 Patch Management
🔍 Vulnerability Mgmt
📋 GRC
☁️ GCC High Tenant
💻 Service Desk & Escalation
🪪 Identity / Licensing

What We Touch, and What We Never Do

Where our boundary stops

TRANUSA tooling processes Telemetry Data only — logs, alerts and metadata. Your Controlled Unclassified Information and your ITAR-controlled technical data never leave your boundary and never enter ours.

This is architectural, not a policy promise. It is written into our mutual NDA, it is why the arrangement is defensible under ITAR and EAR, and it is the first question a serious export-compliance officer will ask you about any provider.

Microsoft 365 GCC High

TRANUSA operates its own Microsoft 365 GCC High tenant — the U.S. sovereign Microsoft environment built for CUI and ITAR-controlled data. Not commercial Microsoft 365 with extra settings. We run our own operations there before we ask a client to, which means every control we recommend has been implemented in a live environment first.

U.S. Persons only

Engineering and monitoring are staffed exclusively by U.S. Persons. No offshore access to any client environment, at any tier, for any reason. For an ITAR-affected environment this is not a preference — a non-U.S. Person with administrative access to controlled technical data is an export, and no amount of contractual language changes that.

Asset categorization, applied properly

CUI Assets
Workstations, servers and storage that touch Controlled Unclassified Information. Fully in scope and fully controlled.
Security Protection Assets
Our monitoring, logging, endpoint and GRC tooling — categorized as SPA under CMMC guidance, which is what makes the arrangement assessable.
Contractor Risk Managed Assets
Network equipment and peripherals that could touch CUI but are managed to reduce that risk, with the controls documented.
Specialized Assets
OT, CNC controllers and shop-floor equipment — isolated and documented rather than pretended away. This is where generalist providers usually come unstuck.
Out-of-Scope Assets
Everything that cannot and does not touch controlled data — commercial-side systems, the front office, the guest network. Out of scope is a category in its own right, and it has to be argued for in the SSP rather than assumed. Getting this boundary right is what keeps the assessment proportionate to the business.

Book a CMMC Readiness Call

Thirty minutes. We review your contract requirements, identify your top compliance gaps, and give you a realistic timeline to audit readiness. No pitch decks, no obligation.

Book Your Call →
or email CMMC@tranusa.com