What problem does this solve?
Controlled technical data rarely stays where it was meant to. It spreads into shared drives, personal email, unmanaged workstations, cloud tools that were never scoped for it, and shop-floor machines running operating systems that can no longer be patched. Every additional system holding that data widens the assessment boundary, and a wider boundary means more controls to implement, more evidence to produce, and a more expensive and difficult assessment.
Who is it for?
Small and mid-sized manufacturers and machine shops holding defense or other controlled work — particularly subcontractors to primes, where compliance obligations arrive through contract flow-down rather than direct negotiation.
How does Epyk approach it?
Scope reduction comes before implementation. The first work is mapping where controlled data actually lives and moves today: which drives, machines, users, email paths, and outside services touch it. That map usually shows controlled work has spread into systems that never needed it, and shrinking that footprint is the single largest lever on both cost and difficulty.
The environment is then built around a defined enclave — segmented network paths, role-based access, isolation for machines and controllers that cannot be patched or centrally managed, and logging designed to produce usable evidence rather than noise. Legacy equipment is isolated rather than replaced wherever the machine is still productive.
Local-first infrastructure is a structural advantage here rather than a preference. Controlled data that never leaves the facility is simpler to bound, simpler to document, and simpler to defend.
Epyk is an implementation partner, not an accredited assessor. Assessment and certification are performed by an accredited third-party assessment organization, and no engagement guarantees a specific assessment outcome.
What deployment models are possible?
On-premise enclave with no required cloud dependency, segmented network with machine-level isolation, role-based access with multi-factor authentication, and local logging, audit trails, and evidence retention.
What is available now?
Controlled-data boundary mapping, enclave and segmentation design, role-based access paths, logging and audit-trail implementation, legacy machine and controller isolation, and private local AI deployment that keeps controlled documents off public model platforms. These are delivered through a scoped engagement.
Documentation is part of the work: network and segmentation diagrams, data-flow maps, asset and access inventories, and control evidence packages. Authoring a full System Security Plan or Plan of Action and Milestones is not part of this scope — Epyk produces the technical documentation and evidence those documents draw on. Assessment and certification remain with an accredited third-party organization.
What experience is this based on?
Epyk has designed controlled-data segmentation and machine-isolation architecture for a manufacturer holding active government work — including network segmentation planning for a legacy shop-floor environment, export-controlled and CUI-scoped boundary definition, and per-machine inclusion controls to keep controlled systems separated from general operations. It builds on prior data center infrastructure and industrial controls work.
This is design and planning experience. It is not presented as a completed, independently assessed, or certified deployment.
What requires discovery or custom implementation?
Current data flows and where controlled data actually resides, which machines and users touch it, existing network topology and what can be segmented without stopping production, contractual flow-down requirements, applicable NIST SP 800-171 control expectations, DFARS 252.204-7012 safeguarding obligations, retention requirements, and which personnel are authorized for access.