Skip to content

 


HOW TERAMIS WORKS

Find the CUI. Validate the Boundary. Monitor What Changes 

Turn Unknown CUI Sprawl Into Defensible Boundary Evidence.

Teramis examines approved data sources to identify potential Controlled Unclassified Information, validate findings, document the resulting CUI footprint, and monitor how that footprint changes over time.
Replace assumptions, incomplete inventories, and broad search results with technical findings that support more informed CMMC scoping and boundary decisions.

Replace interviews, assumptions, and incomplete inventories with technical evidence that supports more accurate CMMC scoping and boundary decisions.


Find the CUI you actually have. Prove the boundary. Monitor what changes.

A Documented Boundary Does Not Always Match the Data Environment

Policies, system diagrams, asset inventories, and employee interviews describe where CUI is expected to exist. They do not necessarily prove where it is stored across the organization.

CUI may also be located in:

  • Microsoft 365 repositories
  • Network file shares
  • Email and attachments
  • Local or distributed endpoints
  • Engineering and CAD repositories
  • PDFs and scanned documents
  • Archives and legacy project folders
  • Other approved cloud, hybrid, or on-premises systems
Teramis Intro Animation

When these locations are not examined, organizations may build a CMMC boundary around incomplete information.

That creates two opposing risks:

Over-scoping can increase licensing, infrastructure, consulting, control implementation, and assessment costs.

Under-scoping can leave CUI outside the documented boundary and create security gaps, assessment rework, and uncertainty around compliance representations.

Highlighted statement:
Before you define the boundary, establish the actual CUI footprint.


DISCOVERY TO CONTINUOUS VISIBILITY WITH THE TERAMIS WORKFLOW

How Teramis Creates CUI Evidence

1. Define the Approved Discovery Scope

The organization identifies the repositories, systems, data sources, and portions of the environment authorized for review.

This helps establish:

  • Which systems will be examined
  • Which repositories are included
  • Which business units or projects are relevant
  • Where CUI is expected to reside
  • Which locations should remain outside the approved boundary
  • What questions the discovery effort must answer
2. Deploy Within the Customer Environment

Teramis is deployed so scanning and analysis remain within the customer-controlled environment.

Its multi-agent architecture can support distributed and complex environments, including situations where data exists across separate repositories, networks, business units, or Microsoft 365 locations.

Key deployment principles:

  • Scanning remains under customer control
  • Sensitive files do not need to be uploaded to an external discovery service
  • Approved repositories can be examined where they reside
  • Multiple scanning agents can support larger or distributed environments
  • Discovery can be limited to the authorized scope

Teramis materials identify in-environment deployment and multi-agent scanning as core differentiators, especially for organizations that do not want sensitive data transferred to a third-party discovery cloud.

3. Scan and Identify Candidate CUI

Teramis examines supported files and repositories to identify content that may contain CUI.

The platform is purpose-built for CUI discovery rather than broad commercial data classification. It is designed to examine complex, technical, structured, unstructured, and visual content commonly found throughout the Defense Industrial Base.

Discovery may include approved sources such as:

  • SharePoint
  • OneDrive
  • Exchange
  • Network file shares
  • Endpoints
  • Email systems
  • CAD and engineering repositories
  • PDFs
  • Images and scanned documents
  • Archives
  • Legacy storage environments
  • Other supported repositories

The result is a more focused set of findings for review rather than an unfiltered collection of broad keyword matches.

Explore CUI Discovery 

4. Validate the Findings

Discovery results must be reviewed and validated before they can support important boundary or compliance decisions.

Teramis uses review and sampling workflows to help confirm the precision of the findings and distinguish relevant CUI from unrelated content or false positives.

Validation helps teams:

  • Confirm whether candidate findings are relevant
  • Review classifications and categories
  • Evaluate representative samples
  • Understand where findings are concentrated
  • Identify exceptions requiring closer review
  • Improve confidence in the resulting CUI inventory

A dashboard may suggest where CUI exists. Validation helps create evidence that can withstand scrutiny.

5. Package the Evidence

Validated findings are organized into outputs that help technical, compliance, executive, and advisory stakeholders understand the actual CUI footprint.

Teramis can support the production of:

  • CUI inventory information
  • File-level findings
  • Repository and location details
  • Boundary evidence
  • Exception lists
  • Validation and sampling output
  • Findings requiring customer action
  • Spillage reports
  • Delta reports
  • Monitoring history
  • Assessment-readiness evidence

The Teramis workflow is defined as Scan, Validate, Package, and Monitor. Its intended outputs include the CUI inventory, boundary proof, exceptions, delta reports, spillage reporting, and a monitoring trail.

6. Review and Assign Next Steps

Teramis identifies where CUI exists and which findings require attention. Internal administrators, security teams, compliance leaders, or approved service providers determine what happens next.

Possible next steps may include:

  • Confirming whether a file belongs in the approved boundary
  • Reviewing access or storage locations
  • Investigating an unexpected finding
  • Updating scope documentation
  • Planning customer-led migration
  • Assigning action to an internal administrator
  • Updating an SSP, asset inventory, or boundary diagram
  • Scheduling a follow-up scan

Teramis reports the findings. It does not make the customer’s operational, legal, or compliance decisions.

7. Re-Scan and Monitor What Changes

CUI is not static. New files are created, attachments are forwarded, project folders are copied, employees change roles, and systems evolve.

Recurring scans help identify:

  • New CUI findings
  • Changes since the previous scan
  • CUI appearing outside approved locations
  • Potential spillage
  • Boundary drift
  • Reappearance of previously addressed findings
  • Repositories requiring additional review

Scan frequency can be aligned with the likelihood of change, operational importance, and the risk associated with each repository.

Explore Continuous Monitoring

THE COMMERCIAL STORY

One Platform. Three Essential Outcomes.

Find

Discover candidate CUI across approved Microsoft 365 environments, file systems, endpoints, email, technical repositories, and supported file types.

Questions answered:

  • Where does CUI exist?
  • Which repositories contain it?
  • Which files require review?
  • Is CUI located outside expected systems?
  • What may belong inside the documented boundary?

Prove

Validate findings and organize the evidence needed to compare the documented CMMC boundary with the actual data environment.

Questions answered:

  • Does the documented boundary match reality?
  • Which findings support the current scope?
  • What exceptions require investigation?
  • What evidence can support an internal review?
  • What information may be relevant during assessment preparation?

Monitor

Repeat the discovery process to detect new findings, movement, potential spillage, and changes to the CUI footprint.

Questions answered:

  • Has new CUI appeared?
  • Has CUI moved outside approved locations?
  • What changed since the previous scan?
  • Is the boundary beginning to drift?
  • Which findings require follow-up?


The Find, Prove, Monitor framework is the approved Teramis commercial story and should remain consistent across the website.

 

 

 

FROM RAW DATA TO ACTIONABLE EVIDENCE: WHAT TERAMIS PRODUCES

Give Every Stakeholder a Clearer View of the CUI Footprint 

CUI Inventory

A structured view of discovered and validated CUI findings across the approved environment.

File-Level Findings

Information that helps teams understand which files, repositories, and locations require review.

Boundary Evidence

Discovery output that can be compared with the documented CMMC scope, system diagrams, asset inventories, and approved CUI destinations.

Exception Reporting

A focused list of findings located outside expected or approved areas.

Validation Output

Sampling and review information that supports confidence in the discovery results.

Customer Action Queue

A prioritized record of findings that administrators, security teams, or approved providers may need to investigate or address.

Delta and Spillage Reports

Results that show what changed between scans and where new or moved CUI may have appeared.

Monitoring Trail

A historical record of recurring discovery activity and changes to the CUI footprint.

Keep the Stack. Add Defensible Evidence.

Teramis Provides Ground Truth.
Existing Tools Act on It.

Teramis is not intended to replace every security, governance, compliance, or assessment platform in the environment.

It provides specialized CUI discovery and validation output that strengthens the tools and services already in use.

01

Inputs

Data Sources

Microsoft 365, file shares, endpoints, CAD repositories, scans, archives, email systems, and other approved sources.

02

Specialized Ground Truth

Teramis

CUI discovery, validation, inventory, exceptions, boundary evidence, and recurring monitoring.

03

Existing Tools Act on the Output

Governance, Enforcement, and Evidence

Labels and Access Governance

Existing tools may apply labels, manage permissions, review access, or govern collaboration.

Policy and Enforcement

DLP and security platforms may enforce rules, restrict movement, or prevent unauthorized activity.

Compliance and Evidence Management

GRC systems, advisors, and assessment teams may organize controls, documentation, findings, and assessment evidence.

Teramis does not replace the security stack. It gives the stack a more defensible understanding of where CUI actually exists.

A PRECISE ROLE IN THE CUI WORKFLOW 

✅What Teramis Does

Teramis helps organizations:

  • Discover candidate CUI
  • Categorize and catalog findings
  • Validate discovery results
  • Identify file and repository locations
  • Produce CUI inventory information
  • Document boundary exceptions
  • Compare results between scans
  • Monitor for movement and potential spillage
  • Provide evidence that supports CMMC planning and review

⛔What Teramis Does Not Do

Teramis does not:

  • Move files
  • Tag files
  • Quarantine files
  • Delete files
  • Remediate files
  • Alter discovered content
  • Make legal reporting decisions
  • Replace a C3PAO or formal assessment
  • Guarantee CMMC certification

One Workflow. Multiple High-Stakes Use Cases.

Apply CUI Discovery Evidence Across the Compliance Lifecycle

CMMC Scoping

Identify the actual CUI footprint before defining systems, assets, users, and controls as part of the assessment boundary.

CUI Boundary Validation

Compare the documented boundary with findings from the underlying data environment.

CUI Migration Support

Provide file and location information that authorized administrators can use when preparing customer-led migration into approved environments.

Ongoing CUI Spillage Management

Run recurring scans to identify CUI that appears outside approved locations.

Post-Breach CUI Impact Assessment

Examine approved portions of affected systems to help determine whether candidate CUI may have been present.

Supply Chain and M&A Risk Review

Test whether representations about an organization’s CUI footprint align with the discovered environment.

A Shared Source of CUI Truth

Support Technical, Compliance, Executive, and Partner Decisions

Security and IT Teams

Understand where CUI exists and which systems or files require closer review.

Compliance and GRC Teams

Compare technical findings with SSPs, asset inventories, policies, and documented boundaries.

Executive Leadership

Gain stronger evidence for decisions involving risk, investment, scope, and compliance representations.

CMMC Advisors and RPOs

Support scoping recommendations with technical findings rather than relying only on interviews and assumptions.

MSPs and MSSPs

Create repeatable CUI discovery and monitoring services across customer environments.

Assessment-Readiness Teams

Organize inventory, validation, exception, and monitoring information that may support assessment preparation.

Keep the Stack. Add Defensible Evidence.

Teramis Provides Ground Truth.
Existing Tools Act on It.

Teramis is not intended to replace every security, governance, compliance, or assessment platform in the environment.

It provides specialized CUI discovery and validation output that strengthens the tools and services already in use.

Approved Inputs

Data Sources

Microsoft 365, file shares, endpoints, CAD repositories, scans, archives, email systems, and other approved sources.

Specialized Ground Truth

Teramis

CUI discovery, validation, inventory, exceptions, boundary evidence, and recurring monitoring.

Existing Tools Act on the Output

Governance, Enforcement, and Evidence

Labels and Access Governance

Existing tools may apply labels, manage permissions, review access, or govern collaboration.

Policy and Enforcement

DLP and security platforms may enforce rules, restrict movement, or prevent unauthorized activity.

Compliance and Evidence Management

GRC systems, advisors, and assessment teams may organize controls, documentation, findings, and assessment evidence.

See the Workflow in Action

Find the CUI You May Not Know You Have

See how Teramis examines approved data sources, validates findings, produces boundary evidence, and monitors what changes over time.

Start with a conversation about your environment, data sources, CMMC objectives, and current scoping questions.