🛡️ RADAR

Know where your sensitive government data lives — and what it requires.

RADAR is a force-multiplier for teams working with federal contracts. It helps organizations identify and locate sensitive government data, including CUI, ITAR, and EAR-controlled information, and understand the requirements that apply to it.

What RADAR does

RADAR is a force-multiplier for teams working with federal contracts. It helps organizations identify and locate sensitive government data, including CUI, ITAR, and EAR-controlled information, and understand the requirements that apply to it.

Beyond identifying the data, RADAR helps determine the governing authority, jurisdiction, safeguarding and handling requirements, who is authorized to access it, where it can be stored, how long it should be retained, and any other restrictions tied to that information.

Who it's for

Any federal contractor that handles, stores, processes, or exchanges sensitive government information and needs greater visibility into what data they have, where it resides, and which regulatory requirements apply to it.

NIST SP 800-171 controls RADAR is compliant with

Rev 2 — the version currently enforced under DFARS 252.204-7012.

Access Control

  • 3.1.1 — Limit system access to authorized users
  • 3.1.2 — Limit access to authorized transactions/functions
  • 3.1.8 — Limit unsuccessful logon attempts
  • 3.1.11 — Terminate a user session after a defined condition
  • 3.1.20 — Verify and control connections to external systems

Audit and Accountability

  • 3.3.1 — Create and retain system audit logs and records
  • 3.3.2 — Trace user actions to individual users
  • 3.3.8 — Protect audit information from unauthorized access, modification, and deletion
  • 3.3.9 — Limit management of audit logging to a subset of privileged users

Identification and Authentication

  • 3.5.1 / 3.5.2 — Identify and authenticate users, processes, and devices
  • 3.5.7 — Enforce minimum password complexity
  • 3.5.10 — Store and transmit only cryptographically-protected passwords

System and Communications Protection

  • 3.13.1 — Monitor, control, and protect communications at external boundaries
  • 3.13.6 — Deny network traffic by default, allow by exception

About Clear Federal

Clear Federal was established to address a recurring challenge across the federal contracting community: many organizations lack a clear understanding of whether their contracts involve sensitive information such as FCI, CUI, ITAR, or EAR-controlled data, what regulatory requirements apply, and what safeguards are required.

Clear Federal helps bring that clarity by identifying where sensitive government data exists within the organization, understanding the authorities and requirements that govern it, and giving teams the practical knowledge to handle it appropriately, implement the right safeguards, and develop strategies to reduce compliance and data exposure.

Request a Demo

Tell us a bit about your organization. We'll set up a call to walk through RADAR and figure out the right fit — as a Docker container you run yourselves, or a custom-built appliance.