Early Adopter — landing now

DenseSense / Regulated-Data Discovery

Your entire assessment scope rests on one fact: which of your machines hold regulated data. Get that fact wrong and every control you pass is scored against the wrong boundary. DenseSense goes looking for that data where it actually lives — and reports it by file and by location, so you scope against what is there, not what you remember putting there.

DenseSense intel view: files found on a share — some carrying CUI markings, some unmarked drawings flagged for review

What it looks for

1 · Government markings

The highest-confidence signal there is: a document the owner already labeled. DenseSense reads banner and portion markings — the bare word CUI, the CONTROLLED control marking, the CUI// construction, and legacy markings like FOUO that still mean the same thing today.

2 · Forms and structured records

Standardized government and contract forms, and structured records where an identifier repeats down a column. A header that reads SSN over ten thousand rows is a record set, not ten thousand loose matches — and it is reported that way.

3 · Regex patterns, corroborated

Patterns for the data types that carry their own integrity checks. A pattern hit alone is a lead; a pattern with its context and its checksum is a finding. The two are never merged into one number.

4 · The places data hides

Downloads folders, desktops, mail stores, cloud-sync roots, mapped shares. Working copies nobody filed are where regulated data actually accumulates — not the tidy folder it was supposed to live in.

5 · Confidence, never a single count

Every finding carries a tier — Confirmed when a marking or a validated identifier is present, Probable and Possible below that. A marked file and a pattern guess are different claims, and DenseSense keeps them separate.

6 · Findings you can act on

Results roll up to files, files to locations. Not “3,182 matches” — “these fourteen files on this share carry CUI markings, here are the paths.” The report defaults to paths and counts, never the regulated content itself.

DenseSense findings rolled up by file and location, with confidence tier and marking category
Findings roll up to files and locations, each with its confidence tier. Screenshots shown run against a staged demonstration corpus, not customer data.

What a marking does — and does not — prove

A marking establishes provenance, not truth. It tells you the owner already made a call; it does not settle the question by itself. Two facts the law is explicit about, and DenseSense is built around both: a banner is not a category — correctly marked CUI Basic carries the bare word CUI, with no category token at all — and under 32 CFR 2002.20, the absence of a marking is not the absence of CUI. Regulated data can legally carry no marking whatsoever. So “no markings found” is never rendered as “clean”: it is reported as what it is — markings not found, which is not an answer to whether regulated data is present. Automated detection finds the provable half and says so plainly; it does not claim to find what carries no signal.

Provenance, not verdictA marking is evidence; the tier says how strong
Content stays putReports carry paths and counts, not the regulated data
Landing nowIn active build; Early Adopters shape what ships

Know where your regulated data is — before an assessor asks.

DenseSense is in active build and opening to Early Adopters. Get in now to help decide what ships, run it against your own shares as it lands, and scope your CMMC boundary against the data that is actually there.