Compliance answers, quoted word for word.
Stuword answers your team’s compliance questions from your own verified documents and the controlling standard. Every answer quotes the exact clause. When your documents don’t cover something, it says so.
Yes. Your Access Control Policy requires MFA for all administrative access to production systems, naming CNC and MES terminals1. NIST SP 800-171 also requires it for network access by non-privileged accounts2.
“Multifactor authentication shall be enforced for remote access and for all administrative access to production systems, including CNC and MES terminals.”
“Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.”
Live demo
Ask Stu a question.
This is the Stuword workspace for a sample manufacturer, Meridian Precision. Click an example question or type your own, then open the Library and Review queue tabs.
- Ask about MFA
- Ask about visitor tours
- Ask for an export classification
- Request an action list
- Approve a page in the Library
Ask Stu
Cited answers from Meridian's verified documents and the NIST SP 800-171 pack — word for word. Anything outside your documents is labeled, and hard calls go to a person.
Screen log #0871
4. AUTHENTICATION REQUIREMENTS
4.1 All user accounts shall be uniquely assigned. Shared or group accounts are prohibited on systems that store or process controlled information.
4.2 Multifactor authentication shall be enforced for remote access and for all administrative access to production systems, including CNC and MES terminals.
§4.1All user accounts shall be uniquely assigned. Shared or group accounts are prohibited on systems that store or process controlled information.
§4.2Multifactor authentication shall be enforced for remote access and for all administrative access to production systems, including CNC and MES terminals.
CNC and MES terminals — confirm or correct before this page is queryable.
Stu drafted a 3-item action list from §4.2 of the Access Control Policy and 800-171 §3.5.3. Employees see it only as DRAFT — NOT REVIEWED until you approve. Your approval is written to the audit log.
Blocked by the scope gate — HR benefits isn't in Meridian's configured domains. Approving answers this request only; widening the domain list is a separate, audited admin action.
Guardrail audit trail
- Jul 20 · 09:41 · scope-gate blocked export-control query · routed to empowered official ·
#1283 - Jul 19 · 16:07 · guardrail policy v7 activated after eval pass (12/12) · by D. Reyes ·
#1281 - Jul 19 · 11:52 · SSP upload quarantined at pre-index CUI screen ·
#0871
What your team gets
Answers your assessor can trace back to the page.
Generic AI tools summarize and guess. Stuword quotes your verified text, checks every citation mechanically, and keeps a person in charge of anything your team would act on.
Cited answers, not summaries
Every claim quotes and links its source clause. A mechanical check verifies each citation against the verified text before the answer is shown. A citation that doesn’t match is stripped, visibly.
Your documents, verified first
Uploads pass OCR and a page-by-page review by your designated reviewer. Nothing unverified is ever quoted, and the answer tells you when a document is still pending.
Recommendations are gated
“What should we do” lists arrive as drafts pending your named reviewer’s sign-off, recorded in an audit log. Employees never act on unreviewed output.
How a pilot runs
Useful in week one. Verification never blocks what’s cleared.
Start with your highest-value policies. Each document becomes queryable as your reviewer clears it, with hands-on onboarding from us.
Upload your corpus
Policies, procedures and plans. A pre-index screen holds back anything that looks like CUI before it enters the system.
Verify page by page
Your reviewer confirms parsed text against the source scan in a side-by-side workbench.
Your team asks questions
Anyone you authorize gets cited answers on the documents that have already cleared.
Review, then rely
Draft action lists queue for your compliance owner. The audit trail records who asked, what was answered and from which document version.
Security and scope
The boundaries are the point.
Stuword is designed for regulated teams, so it refuses the questions software shouldn’t answer and keeps controlled data out of the hosted pilot.
“A confidently wrong classification is the one answer nobody should get from software.” Why Stu routes export-control questions to a person
No CUI in the hosted pilot
The pilot runs on public standards plus your uncontrolled policies. Documents flagged as possible CUI are quarantined before indexing. You are never asked to put controlled data in the cloud.
Export-control questions go to people
Stuword refuses classification, jurisdiction and licensing questions by design and routes them to your empowered official or export counsel.
Informational, with the paper trail to prove it
Stuword is a research tool, not legal or regulatory advice. It gives you cited sources, verified text and named human review: a diligence record your assessor can read.
Questions
What teams ask us first.
Who is Stuword for?
Small and mid-size manufacturers in the defense supply chain preparing for CMMC Level 2, where one or two people carry compliance and everyone else keeps asking them what the policy says.
Where do the answers come from?
Only two places: the NIST SP 800-171 standard, which we maintain and verify, and your own policies after your reviewer has verified them. Stu does not answer from general web knowledge.
Do we have to upload CUI?
No. The hosted pilot excludes CUI by agreement. A pre-index screen quarantines anything that looks like controlled information before it is embedded or made queryable.
How long until my team gets value?
Most teams ask their first cited questions in week one. Each document becomes queryable as soon as its pages are verified, so you never wait for the whole corpus.
Is this legal or compliance advice?
No. Stuword reports what your verified documents and the standard say, with citations. Compliance decisions stay with your qualified staff, and the audit log shows that they did.
Design-partner pilot
See Stu answer from your own policies.
A 30-minute call with the founder. We walk through the product, look at where your CMMC preparation stands, and decide together whether a pilot makes sense.
- A live walkthrough of the questions your team asks most
- Which of your documents to verify first
- Pilot scope, timeline and terms, with no obligation