Governed AI · AI security · SDVOSB

Governed AI for the mission.
Designed, red-teamed, run.

Optimal builds and breaks AI systems for regulated environments — governed gateways, adversarial testing, and security assessments inside FedRAMP, CMMC, GovCloud, and air-gapped boundaries. Need the compliant Microsoft 365 enclave underneath it? We build and manage that too.

Not sure yet? Do I actually need GCC High? Get the 2-minute answer →

Sovereign by default• CUI & ITAR-ready• SDVOSB-certified

Engineered and measured to the standards that gate production AI

NIST AI RMFOWASP LLM Top 10MITRE ATLASNIST 800-207CIS BenchmarksDISA STIGISO 42001SOC 2
SDVOSB — Service-Disabled Veteran-Owned Small Business, SBA VetCert certified

Optimal, LLC is a Service-Disabled Veteran-Owned Small Business — SBA-certified and eligible for veteran set-aside contracts. CAGE 14HQ0 · UEI TYMSGKDF2K48.

Download capability statement →

“Optimal assessed the Azure sandbox where our AI agents are being built before anything went live. The report was clear and prioritized, gave us a straight answer on where the build actually stood, and our developer could act on it right away. Fast turnaround and easy to work with.”

Maurisa S. IT Director · AI security assessment
NINELINE · Live demonstrator

NINELINE. Your 9-line for software and AI.

AI-native application and supply-chain security, running. Real SBOM and vulnerability scanning, EPSS and CISA KEV enrichment, and frontier-model reachability analysis that reads your actual codebase — turning thousands of raw findings into an evidence-backed action queue and an exportable VEX record. Deployed in your environment, air-gap capable.

874 Raw findings in
18 Require action
−97.9% Noise eliminated
What we do

Two things, built to work together.

Optimal secures the AI the defense industrial base is putting into production — and builds the compliant place to run it. The intelligence and the sovereign cloud underneath it, from one veteran-owned partner.

Governed intelligence

AI you can actually use on the mission

Most GCC High shops stop at email and files. We stand up governed access to the frontier models authorized for your sovereign cloud — one gateway, fail-closed guardrails, a defensible audit trail — plus assessment and red-teaming of the AI you deploy.

  • Governed AI gateway
  • Adversarial AI red-teaming
  • AI security assessments
  • Secure-adoption advisory
Explore NINELINE →
Managed environment

CMMC-ready GCC High enclaves

We stand up your Microsoft 365 GCC High tenant, migrate your people and data into it, engineer the NIST 800-171 controls, and run it for you — so you stay eligible to win and keep DoD work that touches CUI or ITAR-controlled data.

  • Design, build & migration
  • NIST 800-171 / CMMC L2 alignment
  • Fully managed operations
  • GCC High G5 licensing
Managed GCC High →
NINELINE · The reference implementation

Agents in. Approved resources out.
Everything in between, governed.

This is NINELINE — your 9-line for software and AI, and the working proof behind our Governed AI Engineering. The same open-source Zero Trust design we stand up in your environment, running.

Governed AI gateway reference architecture Callers — agents, users, and CI systems — enter a governed boundary that sits in the client's own tenant. Inside it, a request passes Authorize, then Guard, then Forward before reaching an approved model. A request that fails the allowlist check at Authorize is denied, and a request that trips a guardrail at Guard is blocked before the provider is called. Egress is pinned to an allowlist, so any destination that is not an approved model is dropped. Every stage writes to one structured audit row joined by request ID. CALLERS Agents Users CI / CD GOVERNED BOUNDARY · your tenant · your keys · your logs 01 Authorize allowlist check 02 Guard fail-closed, pre-call 03 Forward per-key credentials ✗ not on the allowlist no token issued ✗ guardrail trips provider never called 04 Prove — one structured audit row, joined by request ID APPROVED MODELS Azure OpenAIAmazon BedrockGoogle Vertex AISelf-hosted ✗ every other destination dropped at the egress allowlist
One governed endpoint. A request that fails at Authorize never gets a token, and one that trips a guardrail at Guard never reaches the provider — both still land in the audit row.
01

Authorize

Cloudflare Access · Okta OIDC

Authenticate the caller, then check the request against a model and resource allowlist. No token is issued for a model you haven't approved.

02

Guard

NeMo Guardrails · PII/secret detectors

Inline detection on prompt and response — injection, jailbreak, PII/DLP, secret exfiltration — fail-closed and pre-call. A blocked request never reaches the provider.

03

Forward

LiteLLM keys · Squid egress

Proxy to the approved model — commercial, GovCloud, or self-hosted — through per-key virtual credentials, with egress pinned to a default-deny allowlist.

04

Prove

Structured JSON · Postgres

Write a structured audit row joined by request ID — the artifact your reviewers read directly, on your retention, in your account.

No wrapper, no SDK rewrite — point your existing OpenAI- or Anthropic-compatible client at the gateway and every call is governed and logged.

03 / Process

How an engagement runs.

A working method, not a black box. You see the attack surface as we map it, the findings as we prove them, and the fixes as they close.

  1. 01

    Scope

    We define the systems in play, the data they touch, the threat model that actually matters to you, and the rules of engagement. The scope is written to your stack — not lifted from a template.

  2. 02

    Map the attack surface

    We inventory every way in and out: models, prompts, retrieval sources, tools and functions, identities, credentials, and egress paths. You can't secure what hasn't been mapped.

  3. 03

    Test like an adversary

    We run the OWASP LLM Top 10 and MITRE ATLAS techniques against your systems — injection, extraction, manipulation, abuse-case chains — and document what works, with evidence.

  4. 04

    Report for two audiences

    Ranked findings, reproduction steps, business impact, and specific remediation — written for the engineers who fix it and the leaders who own the risk.

  5. 05

    Remediate & retest

    We help close the findings, then prove they're closed. The engagement ends with evidence, not a backlog of open items.

06 / FAQ

Questions we get first.

What does Optimal do?

Optimal does two things that work together. First, we build, migrate, and manage CMMC-ready Microsoft 365 GCC High enclaves for the defense industrial base — the sovereign environment you need to handle CUI and ITAR-controlled data on DoD contracts. Second, we stand up the governed AI that runs safely inside those environments, and assess and red-team the AI systems teams deploy. We're an SBA-certified Service-Disabled Veteran-Owned Small Business (SDVOSB).

What is Microsoft 365 GCC High, and do I need it?

GCC High is a US-sovereign version of Microsoft 365, physically and logically isolated, with US data residency and screened US-person support. If you're a defense contractor handling Controlled Unclassified Information (CUI) or ITAR/export-controlled data, GCC High is the environment built to support the DFARS 252.204-7012 and CMMC Level 2 obligations in your contracts. Optimal stands the enclave up and runs it for you.

Does moving to GCC High make me CMMC compliant?

No environment makes you compliant on its own — CMMC Level 2 is a third-party assessment against the 110 NIST SP 800-171 controls. What GCC High gives you is a foundation built for those controls. Optimal implements and documents the control set inside your enclave (SSP and POA&M), collects the evidence, and gets you assessment-ready. The certified assessment itself is performed independently by an accredited C3PAO — we prepare the environment, we don't grade it.

Is Optimal a product company or a services firm?

Both. We're advisory-led — scoped engagements and managed operations — and we make NINELINE, our AI-native application and supply-chain security platform, deployed inside your own environment rather than sold as multi-tenant SaaS. The control patterns we implement are published as open-source reference architecture, so you can read exactly what we build before we build it.

What is NINELINE?

NINELINE is Optimal's AI-native application and supply-chain security platform: real SBOM and vulnerability scanning, EPSS and CISA KEV enrichment, and frontier-model reachability analysis that reads your actual codebase — turning thousands of raw findings into an evidence-backed action queue and an exportable VEX record. In the reference scan it compressed 874 raw findings to the 18 that required action. It deploys in your environment, air-gap capable, with a live demonstrator at 9line.gooptimal.io.

We already have Azure, AWS, or GCP — can you work in our cloud?

Yes, and it's often the fastest path. We build governed, audited access to the frontier models already available in the cloud you license — Azure OpenAI Service, Amazon Bedrock, and Google Vertex AI — so your teams reach them safely without a new vendor or procurement. It's available to enterprises and to all of SLED (state, local, and education), as well as federal teams.

Can Optimal work with federal, SLED, and enterprise teams?

Yes. Optimal is an SBA-certified Service-Disabled Veteran-Owned Small Business (SDVOSB), eligible for SDVOSB and VOSB set-aside contracts, and works with federal agencies, SLED (state, local, and education) entities, and enterprises. We deliver across GovCloud, commercial cloud (Azure, AWS, GCP), on-prem, and fully air-gapped networks.

Ryan Gutwein, founder and CEO of Optimal
Who you’re hiring

Ryan Gutwein

Founder & CEO. Former C3PAO lead assessor — TS/SCI, CISSP, CCSP, CCP — and a U.S. Air Force Security Forces veteran, now building and breaking agentic systems for regulated environments. Scoping calls are run by Ryan, not a sales team.

Let’s scope
the work.

Tell us the contracts you’re chasing and where you are today. We’ll scope the engagement — an AI assessment or red team, governed AI engineering, or the managed GCC High enclave underneath it. Calls are run by the founder.

Book a scoping call →