Plenty of defense contractors restrict AI tools, and they are right to ask before turning one loose on their compliance data. This page sets out precisely what our AI features do, what they can see, what they never do, and how to switch them off — in enough detail that you can hand it to whoever asks you the question.

The short version.
  • One switch turns it off. AI is on when a workspace starts; an owner or admin can switch it off for the whole workspace at any time, and nothing is sent for AI processing while it is off.
  • Nothing runs on its own. Every AI action happens because a person clicked a control that says AI.
  • Processing happens on our servers through the Anthropic Claude API — never in your browser, never with a key you have to manage.
  • Your data is not used to train AI models.
  • Your documents do not use AI at all. The System Security Plan, POA&M and all 14 policies are built from templates and the answers you recorded.
  • No CUI. CMMC Map is not an approved CUI system — that rule holds with AI on or off.

AI is off until someone turns it on

Every workspace is created with AI features disabled. A workspace administrator turns them on under Settings → AI features, and can turn them off again at any time. Until then, the AI entry points in the app show that AI is off and point at that setting.

The important part is where that switch is enforced. It is not a hidden button — the check runs on our servers on every single AI request. If the workspace setting is off, the request is refused before it reaches a model, no matter where it came from. That includes our own support path: if you ask for help while AI is off, you get an email form, not a model. Off means off.

The setting is enforced server-side on every request. Hiding a button is a user-interface decision; refusing the request is a control.

What each feature can see

When AI is on, three features become available. Each one sends a specific, bounded set of information, and only at the moment you click it.

Feature You do this This is what gets sent
Ask the guide Type a question and send it Your question, plus a summary of your workspace: company profile fields you entered, your current SPRS score and its trend, a per-family rollup of control statuses, your unmet high-value controls, open POA&M items, and your scoping answers
Control scoring Click to draft an assessment for one control The text of that control and the answers you have recorded against it
Evidence analysis Click Analyse with AI on a file you have already uploaded Text extracted from that one file — the first 30,000 characters — and the control it is linked to
The one that surprises people: uploading a file used to start an analysis automatically. It no longer does. A file you upload is stored and nothing else — the analysis is a separate, clearly labelled click on that specific file. If you never click it, no part of that document is ever sent to a model.

What we never do

Your documents are built without AI

This is worth stating plainly, because it is the question behind the question. Your System Security Plan, your POA&M, your System Responsibility Matrix and all 14 policies are generated from document templates filled in with the answers you recorded and the profile you entered. There is no model call anywhere in that path. A workspace that never turns AI on still gets every document, every control, the full assessment, the SPRS score and the security training.

Where a template needs a fact we do not have, it prints a visible [INSERT …] marker rather than inventing one. We would rather hand you a document with an obvious gap in it than a confident-sounding sentence that is not true about your company.

The Claude connector is a separate thing

CMMC Map offers a connector that lets you reach your workspace from your own AI assistant. That is not covered by the workspace AI setting, and the distinction matters: the connector runs inside your AI client, signed in under your account with that provider, subject to whatever agreement your organization has with them. We are not sending your data anywhere — you are pulling it into a tool you already chose and already govern.

You control it by connecting or disconnecting it under Settings → Connected AI assistants. Access is scoped to the one workspace you pick during sign-in.

Where your data lives

Your assessment data and uploaded files are held in our managed database and private file storage, hosted in the United States. Access is scoped to your organization at the database level, and uploaded evidence is readable only by members of your workspace. Files are served through signed, expiring links after a membership check — there is no public URL for anything you upload.

CMMC Map is not an approved CUI system. Do not upload Controlled Unclassified Information, classified material, or export-controlled data. This is in our terms, you agree to it at signup, and it applies whether or not AI features are switched on. The app is for describing and scoring your controls — not for storing the data those controls protect.

Turning AI on or off

  1. Sign in and open Settings.
  2. Find AI features. The current state is shown at the top of the card.
  3. Use the control to turn it on or off. Only a workspace administrator sees it — members see the state, not the switch.
  4. The change takes effect immediately, for everyone in the workspace, on the next request.

Questions we get asked

Which model? Anthropic's Claude API. The model currently in use is Claude Sonnet 4.6, with a smaller Claude model for lighter tasks. We name the current model here rather than in the product so this page stays the single accurate answer; if we change it, we change this page.

Can we trial the product with AI off and turn it on later? Yes, and a good number of our users work exactly that way.

Our policy requires us to record which AI tools process company data. Then record CMMC Map as off, and this page as the reason. If you later turn it on, the three features in the table above are the complete list of what gets sent.

Who do we ask about something not covered here? Write to [email protected]. If the answer belongs on this page, it will end up here.

This page describes how CMMC Map works as of August 17, 2026, and is kept current as the product changes. For the formal terms, see our Privacy Policy and Terms of Service.