Capability statement

Optimal, LLC

Managed Microsoft 365 GCC High enclaves for the defense industrial base — and the governed AI that runs safely inside them. An SBA-certified Service-Disabled Veteran-Owned Small Business.

SDVOSB — Service-Disabled Veteran-Owned Small Business, SBA VetCert certified

Core competencies

  • Managed Microsoft 365 GCC High

    Design, build, migration, and ongoing management of CMMC-ready GCC High environments for contractors handling CUI and ITAR-controlled data. Tenant provisioning and hardening, Entra ID and Conditional Access, Defender and Purview, migration with spillage controls, and sustained operations after go-live. The tenant is registered to the client; Optimal manages it.

  • CMMC readiness & NIST SP 800-171 engineering

    Implementation of the 110-control set inside the enclave, System Security Plan authoring, POA&M tracking, evidence collection, and a Shared Responsibility Matrix documenting the External Service Provider relationship required under 32 CFR 170.

  • Governed AI engineering

    A Zero Trust access layer for AI in the cloud the client already licenses — one authenticated gateway to every approved model, per-key virtual credentials, fail-closed prompt and response guardrails, default-deny egress, and a request-ID-joined audit trail. Self-hostable and client-owned.

  • AI security assessment & adversarial testing

    Structured evaluation and offensive red-team testing of AI-enabled systems and agents — prompt injection, system-prompt extraction, model and context manipulation, data and model exfiltration, and excessive-agency chains. Measured to the OWASP LLM Top 10, MITRE ATLAS, and the NIST AI RMF.

Differentiators

  • The compliant environment and the AI inside it, from one vendor

    Most GCC High providers migrate mailboxes and stop. Most AI security firms have never stood up an enclave. Optimal does both, which is why the governed path can be made the fastest path instead of the one users route around.

  • The client owns the tenant

    Not a hosted enclave. The GCC High subscription, the data, the keys, and the audit logs are registered to the client. Replacing Optimal does not mean migrating CUI out of a vendor's boundary.

  • Published reference architecture

    The control pattern Optimal implements is open source and inspectable before an engagement starts, and the client keeps operating it afterward. NINELINE, the AI-native supply-chain security reference implementation, runs inside the client boundary and is air-gap capable.

  • Independence preserved

    Optimal engineers environments to be assessment-ready. Optimal is not a C3PAO, does not perform certified CMMC assessments, and does not grant Authority to Operate. Building the environment and grading it are deliberately separate roles.

Past performance

References available on request. Optimal does not publish customer names or engagement details without written permission — including, and especially, for work inside a CUI boundary.

Company data

Legal name
Optimal, LLC
CAGE code
14HQ0
UEI
TYMSGKDF2K48
Set-aside status
SDVOSB and VOSB — SBA-certified via VetCert
Contact
ryan@gooptimal.io
Website
gooptimal.io

Optimal engineers environments to be assessment-ready. Optimal is not a C3PAO, does not perform certified CMMC assessments, and does not grant an Authority to Operate.